Sequence Control Components for Secure Privileged Resource Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Industrial automation systems face challenges in managing and supervising the use of control applications that require extensive security authorizations, as the intended purpose of these privileges is often unclear, leading to security risks and resource-intensive, error-prone access authorization management.

Innovation Solution

A system and method that utilize sequence control components, executed within a sequence control environment, to provide controlled access to security-critical resources by specifying required privileges and using additional sequence control components for secure interprocess communication, monitored by a management component adhering to device-specific security policies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If control applications are granted extensive security authorizations to access security-critical resources, then their functionality and capability to perform critical tasks is improved, but the security risk and difficulty of supervising compliance with security policies increases

Engineering Contradiction:
Improvecapability to access security-critical resourcesVSAvoidsecurity risk and supervision difficulty
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces a sidecar container as an intermediary component that runs alongside the main control application container. This sidecar acts as a mediator that handles all access requests to security-critical resources, implementing security policies and monitoring compliance. The main application does not directly access sensitive resources but communicates through the sidecar, which enforces authorization rules and logs access patterns for audit purposes.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the control application into separate containers: the main application container and one or more sidecar containers. Each container has specific responsibilities - the main container handles business logic while sidecar containers manage security-critical functions. This segmentation isolates security risks and allows independent management of security policies for different resources.

Inventive Principle:
Principle #1Segmentation

2Ease of manufacture

If traditional access authorization management methods are used for control applications, then implementation is straightforward, but the management becomes resource-intensive and error-prone

Engineering Contradiction:
Improveease of implementationVSAvoidresource consumption in authorization management
Core Design Contradiction:
Ease of manufactureVSLoss of energy

Solution Approach 1:

The sidecar containers automatically manage their own access authorizations and security policies without requiring manual configuration for each access request. The system self-regulates by having the sidecar monitor its own access patterns, enforce policies, and generate audit logs automatically. This reduces the need for external security management resources while maintaining comprehensive control.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The sidecar container serves multiple functions simultaneously: it acts as a security gateway, policy enforcement point, audit logger, and communication broker. This multi-functionality consolidates what would otherwise require multiple separate management systems into a single component, reducing overall resource consumption and simplifying implementation.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20250362652A1Method and System for Providing Control Applications
Publication Date: 2025.11.27 SIEMENS AG
  • US20250362652A1 patent drawing
  • US20250362652A1 patent drawing

AI summary

System and method for providing control applications via sequence control components, in the case of control applications of which the execution demands selected privileges, wherein a specification of each of the required safety-critical resources is established, an additional sequence control component, which is provided for providing access to each of the required safety-critical resources, is determined based on the the specifications, execution of the respective sequence control component together with the additional sequence control component is accordingly started, an interface for interprocess communication between the respective sequence control component and the additional sequence control component is set up via a sequence control environment, and the access to the respectively required safety-critical resources is provided via the interprocess communication between the respective sequence control component and the additional sequence control component.