Security Unit for Centralized Industrial Control System Configuration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Industrial control systems face challenges in determining and managing security levels across heterogeneous and modular components, particularly when providing online access, as conventional methods are time-consuming, error-prone, and lack systematic approaches for assessing overall security.

Innovation Solution

A security unit that communicates with industrial control system components via a data network, allowing centralized assignment and management of security levels, with a security assignor that adjusts operational settings and a security requestor that queries and compares security levels to ensure compliance with system security standards, providing users with a centralized view and instructions for attaining desired security settings.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If centralized security level assignment is implemented, then ease of operation is improved, but device complexity increases

Engineering Contradiction:
Improveease of security configurationVSAvoidsecurity unit structure
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent introduces a security unit as an intermediary component between the user and the multiple industrial control system components. This security unit centralizes security level assignment and distribution, allowing users to configure security settings for multiple components through a single interface rather than configuring each component individually. The security unit acts as a mediator that receives security level inputs, processes them according to system security policies, and distributes appropriate security configurations to the target components, thereby improving ease of operation while managing complexity through centralized control.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Device complexity

If individual component security configuration is performed manually, then device complexity is reduced, but loss of time increases

Engineering Contradiction:
Improvesecurity configuration structureVSAvoidtime for security setup
Core Design Contradiction:
Device complexityVSLoss of time

Solution Approach 1:

The patent implements preliminary action by having the security unit pre-establish security level assignments and configurations before they are needed by the individual components. The security unit maintains a centralized repository of security level definitions and policies, and can pre-configure security settings for multiple components simultaneously. When security configuration is required, the security unit already has the necessary security levels prepared and can distribute them to multiple components in a coordinated manner, significantly reducing the time required for security setup compared to manual individual configuration.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If systematic security level determination is implemented, then reliability is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity level assessmentVSAvoidsecurity management structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent incorporates feedback mechanisms in the security unit that systematically determine and verify security levels of components. The security unit queries components to obtain their current security level information, compares these levels against system-defined security policies and requirements, and provides feedback to both the user interface and the components themselves. This feedback loop ensures that security levels are systematically determined and maintained according to established criteria, improving reliability. The complexity is managed by automating this feedback process within the security unit rather than requiring complex external verification systems.

Inventive Principle:
Principle #23Feedback

Data Source

PatentEP3457655B1A security unit and method for an industrial control system
Publication Date: 2023.09.06 CODESYS HLDG GMBH
  • EP3457655B1 patent drawingFigure 1
  • EP3457655B1 patent drawingFigure 2
  • EP3457655B1 patent drawingFigure 3

AI summary

A security unit for an industrial control system comprises an interface adapted to communicate with a plurality of components of an industrial control system via a data network, a security assignor adapted to access a first component among the plurality of components via the interface, and further adapted to assign a first security level pertaining to the first component to the first component. The security assignor is further adapted to access a second component among the plurality of components via the interface, and to assign a second security level pertaining to the second component to the second component. The security assignor is adapted to assign the first security level and the second security level to the first component and the second component, respectively, in accordance with a system security level pertaining to the industrial control system.