Update Verification Apparatus for Industrial Control Systems

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Control systems are vulnerable to malicious code and updates can cause issues, requiring a method to securely manage and verify patches and updates to prevent security problems and ensure integrity.

Innovation Solution

An apparatus and method for verifying updates in a control system, including a file type classification unit, integrity verification unit, and update file generation unit, which classifies, verifies, and generates a final update file using Reference Data Sets and virus check tools, preventing malicious code and ensuring integrity, and manages patch history to automate update notifications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If update files are directly installed in the control system, then update efficiency is improved, but security risk increases due to potential malicious code

Engineering Contradiction:
Improveupdate efficiencyVSAvoidsecurity risk
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an external verification server as an intermediary between the update source and the control system. This server performs integrity verification and malicious code detection on update files before they are installed, thereby maintaining update efficiency while eliminating security risks through pre-verification

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If integrity verification is performed on all update files, then security is improved, but processing time increases

Engineering Contradiction:
Improveintegrity verificationVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs integrity verification and malicious code detection in advance during the update file preparation stage, before the actual update installation. This preliminary action ensures that when updates are installed, they are already verified, thus maintaining high reliability without adding time loss during the critical installation phase

Inventive Principle:
Principle #10Preliminary action

3Reliability

If a separate verification apparatus is used, then security is improved by isolating the control system, but system complexity increases

Engineering Contradiction:
Improvesecurity isolationVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The verification server is designed to handle multiple update files and perform various verification functions (integrity check, malicious code detection, policy verification) in a unified system. This multi-functional approach provides security isolation without proportionally increasing complexity, as the same infrastructure handles diverse verification tasks

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Measurement precision

If manual verification of update files is performed, then accuracy is improved, but labor cost increases

Engineering Contradiction:
Improveverification accuracyVSAvoidlabor requirement
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system implements automated verification processes where the verification server automatically performs integrity checks, malicious code detection, and policy verification on update files without human intervention. This self-service approach maintains high verification accuracy through systematic automated checks while eliminating the need for manual labor

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11144644B2Update management apparatus of industry control system, apparatus and method for update verification
Publication Date: 2021.10.12 ELECTRONICS & TELECOMM RES INST
  • US11144644B2 patent drawing
  • US11144644B2 patent drawing
  • US11144644B2 patent drawing

AI summary

An update management apparatus and an update verification apparatus and method of a control system. The update verification apparatus of the control system includes a file type classification unit for classifying one or more input update files into any one file type of a firmware file, a patch file, and another type of file; an integrity verification unit for verifying integrity of the update files based on the file types of the update files; and an update file generation unit for generating a final update file from the update files, the integrity of which has been verified.