Update Verification Apparatus for Industrial Control Systems
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Control systems are vulnerable to malicious code and updates can cause issues, requiring a method to securely manage and verify patches and updates to prevent security problems and ensure integrity.
Innovation Solution
An apparatus and method for verifying updates in a control system, including a file type classification unit, integrity verification unit, and update file generation unit, which classifies, verifies, and generates a final update file using Reference Data Sets and virus check tools, preventing malicious code and ensuring integrity, and manages patch history to automate update notifications.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If update files are directly installed in the control system, then update efficiency is improved, but security risk increases due to potential malicious code
Solution Approach 1:
The patent introduces an external verification server as an intermediary between the update source and the control system. This server performs integrity verification and malicious code detection on update files before they are installed, thereby maintaining update efficiency while eliminating security risks through pre-verification
2Reliability
If integrity verification is performed on all update files, then security is improved, but processing time increases
Solution Approach 1:
The patent performs integrity verification and malicious code detection in advance during the update file preparation stage, before the actual update installation. This preliminary action ensures that when updates are installed, they are already verified, thus maintaining high reliability without adding time loss during the critical installation phase
3Reliability
If a separate verification apparatus is used, then security is improved by isolating the control system, but system complexity increases
Solution Approach 1:
The verification server is designed to handle multiple update files and perform various verification functions (integrity check, malicious code detection, policy verification) in a unified system. This multi-functional approach provides security isolation without proportionally increasing complexity, as the same infrastructure handles diverse verification tasks
4Measurement precision
If manual verification of update files is performed, then accuracy is improved, but labor cost increases
Solution Approach 1:
The system implements automated verification processes where the verification server automatically performs integrity checks, malicious code detection, and policy verification on update files without human intervention. This self-service approach maintains high verification accuracy through systematic automated checks while eliminating the need for manual labor
Data Source
AI summary
An update management apparatus and an update verification apparatus and method of a control system. The update verification apparatus of the control system includes a file type classification unit for classifying one or more input update files into any one file type of a firmware file, a patch file, and another type of file; an integrity verification unit for verifying integrity of the update files based on the file types of the update files; and an update file generation unit for generating a final update file from the update files, the integrity of which has been verified.


