EP3932005A1 - Procédé et système pour émettre des certificats de clé publique, système d'ingénierie ou système de commande et installation technique - Google Patents
Procédé et système pour émettre des certificats de clé publique, système d'ingénierie ou système de commande et installation techniqueInfo
- Publication number
- EP3932005A1 EP3932005A1 EP20718202.3A EP20718202A EP3932005A1 EP 3932005 A1 EP3932005 A1 EP 3932005A1 EP 20718202 A EP20718202 A EP 20718202A EP 3932005 A1 EP3932005 A1 EP 3932005A1
- Authority
- EP
- European Patent Office
- Prior art keywords
- component
- certificate
- certification module
- publicly
- identifier
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Pending
Links
- 238000000034 method Methods 0.000 title claims abstract description 42
- 230000008569 process Effects 0.000 claims description 14
- 238000003860 storage Methods 0.000 claims description 12
- 238000004519 manufacturing process Methods 0.000 claims description 11
- 238000009434 installation Methods 0.000 claims description 9
- 230000005540 biological transmission Effects 0.000 claims description 8
- 238000004891 communication Methods 0.000 description 8
- 238000007689 inspection Methods 0.000 description 6
- 238000012546 transfer Methods 0.000 description 3
- VYZAMTAEIAYCRO-UHFFFAOYSA-N Chromium Chemical compound [Cr] VYZAMTAEIAYCRO-UHFFFAOYSA-N 0.000 description 2
- 235000013361 beverage Nutrition 0.000 description 2
- 238000010276 construction Methods 0.000 description 2
- 238000011161 development Methods 0.000 description 2
- 230000006870 function Effects 0.000 description 2
- 230000010354 integration Effects 0.000 description 2
- 230000001105 regulatory effect Effects 0.000 description 2
- 238000010200 validation analysis Methods 0.000 description 2
- 238000013459 approach Methods 0.000 description 1
- 230000008859 change Effects 0.000 description 1
- 230000001010 compromised effect Effects 0.000 description 1
- 230000001276 controlling effect Effects 0.000 description 1
- 238000013461 design Methods 0.000 description 1
- 238000009826 distribution Methods 0.000 description 1
- 230000008676 import Effects 0.000 description 1
- 238000012545 processing Methods 0.000 description 1
- 238000012552 review Methods 0.000 description 1
- 239000000126 substance Substances 0.000 description 1
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/32—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
- H04L9/3263—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials involving certificates, e.g. public key certificate [PKC] or attribute certificate [AC]; Public key infrastructure [PKI] arrangements
- H04L9/3268—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials involving certificates, e.g. public key certificate [PKC] or attribute certificate [AC]; Public key infrastructure [PKI] arrangements using certificate validation, registration, distribution or revocation, e.g. certificate revocation list [CRL]
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/08—Network architectures or network communication protocols for network security for authentication of entities
- H04L63/0823—Network architectures or network communication protocols for network security for authentication of entities using certificates
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/06—Network architectures or network communication protocols for network security for supporting key management in a packet data network
- H04L63/062—Network architectures or network communication protocols for network security for supporting key management in a packet data network for key distribution, e.g. centrally by trusted party
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L67/00—Network arrangements or protocols for supporting network services or applications
- H04L67/01—Protocols
- H04L67/12—Protocols specially adapted for proprietary or special-purpose networking environments, e.g. medical networks, sensor networks, networks in vehicles or remote metering networks
Definitions
- the invention relates to a method for issuing public Lich trust certificates for system components of a technical system.
- the invention relates to a system for issuing publicly trustee certificates for system components of a technical system, an engineering or control system for a technical system and a technical system.
- Digital certificates are used in the context of technical systems. In particular, when it comes to certificates that are used at runtime, one also speaks of operational certificates. Secure, non-compromised and trustworthy communication between different system components, such as devices and / or applications, can be enabled via certificates. By using certificates, for example, authentication and communication integrity of communication participants can be achieved using cryptographic means.
- RA registration authorities
- CSR certificate signing requests
- CA Certificate Authority
- a system component in the role of a client or an applicant directs its certificate application to the registration office (RA), which in the case of approval / validation sends the application to the certification authority (CA), which is located in the system (“Onsite -CA ”) or a trust center (“ Offsite CA “or” CA as a Service ”) is forwarded.
- RA registration office
- CA certification authority
- Secure connections to websites are often indispensable from a requirements perspective. Certificates are required for this.
- Certificates should not only be accepted from controlled end devices on which they have been stored as trustworthy, but should also be able to be verified at any time by any other end device, such as mobile devices. This would make it possible, for example, for an operator / user to have data about a control system of a technical system displayed on a mobile device (BYOD).
- BYOD mobile device
- certificates must be verifiable in the entire certificate chain up to the generally recognized Trusted Root Certificates (TRC) (see for example the "Root CA Policy" of
- Google Chrome These are a handful of certificates that are classified as trustworthy across browsers and operating systems and do not have to be installed individually.
- Certificates are tied to trust. The exhibitor must therefore be able to verify and subsequently attest that an applicant has control over a domain.
- Lets-Encrypt see, for example, https://letsencrypt.org/).
- trust is generated in that the owner of a server has to demonstrate that he has control over the server and the domain connected to it.
- the certification body CA
- this approach cannot be used for closed networks and areas (LetsEncrypt is based on the ACME protocol). This would not be the case, for example, for a controller, such as a PLC of a technical system with a closed network.
- Certification management protocols such as the Certificate Management Protocol (CMP, see for example
- This object is achieved by a method for issuing publicly trusted certificates for system components of a technical system, in which
- a certification module of at least one component of a technical system that is to receive a publicly trusted certificate at least one preferably requests a clear component identifier and / or at least one preferred for at least one component of a technical system that is to receive a publicly trusted certificate generates a unique component identifier
- the certification module transmits the at least one queried and / or at least one generated component identifier together with a certificate request for a publicly trusted certificate for the at least component to a registration authority (RA),
- RA registration authority
- the registration authority uses the at least one component identifier to check whether the at least one component belonging to the component identifier is assigned to at least one authorized person or at least one authorized company, whose responsibility is for the at least one component,
- the registration authority requests a publicly trusted certificate for the at least one component in the event that this is the case
- the requested publicly trusted certificate is created and transmitted to the certification module and is preferably stored in a protected area, in particular of the certification module.
- the invention provides for a certification module to be provided with which components that are to receive a publicly trusted certificate are unambiguously can be identified, or with which at least one preferably unique and / or temporary identifier for the components to be certified is generated in particular in the event that components have not yet been put into operation and therefore no identifier can (yet) be retrieved from them can be.
- the certification module then contacts a central service and transmits the (respective) certificate application for a publicly trusted certificate for the preferably uniquely identified component (s) or the uniquely identifiable component (s) based on the generated identifier (s) together with the ( the) identifier (s).
- the registration authority can then check whether the (respective) identified / identifiable component can be assigned to a person or a company for whom the component is responsible stands, in particular whose property the component is.
- the person or the company is preferably a customer who has purchased the component.
- the fact that a component is the responsibility of the person or company means in particular that the person or company has control over the component, which is preferably contractually guaranteed and / or that the consequences are contractually regulated it has if a possible misuse of the requested certificate takes place.
- the at least one component identifier can, for example, be a serial number and / or a machine / device certificate and / or a fingerprint and / or a type designation.
- a serial number and / or a device or machine certificate and / or a fingerprint and / or a type pen designation queried and / or generated as component identifier.
- a database for example a customer database, in order to check whether a component to be certified has been assigned to a person / company bearing responsibility.
- the check in step c) includes that the registration office is stored in a database in which component identifiers are stored together with associated authorized persons and / or companies who preferably represent the owners of associated components, after at least searches for an entry for the component identifier transmitted together with the certificate request.
- Associated components are to be understood as components belonging to the stored component IDs. It is preferred that components for which an identifier is stored in the database are the responsibility of the authorized person / company, which is particularly preferably guaranteed by contract.
- the certificate request (the certificate request) is preferably approved / validated for the component in question. If no such entry is found, however, it is expediently rejected and a requested certificate is therefore not created.
- the database can be given, for example, by what is known as an "industrial mall" from Siemens.
- a database includes both own customer data and data from third-party providers, such as OEMs.
- step e) key material can be transmitted to the certification module together with the publicly trusted certificate.
- the certification module can preferably transfer certificates to a protected memory of the plant / industrial component in a way that is protected from being read and changed.
- the plant / industrial component itself can then preferably secure a web server or other aspects using the certificate.
- a person / company confirms legally binding that they are the owner of the component, for example by agreeing that this applies to all components that have been purchased and, in particular, that are stored in a database, or it is (with certainty) who is known Is the owner / person responsible (a legal assurance can also be given as part of the certificate acquisition, for example in an engineering system).
- the (respective) component for which a certificate applied for is to apply can be clearly identified by the certification module.
- the certification module also ensures that the certificate and any key material is never directly accessible to the person / company, in particular the customer, but can only be installed in a secure manner in the predetermined and assigned target component. This ensures that a certificate can only be installed on a component for which there is a legally responsible owner. This does not require the registration authority and / or the certification authority to have access to the component or a web server of such a component.
- the method according to the invention is suitable both for the initial (first-time) issuing of a publicly trustworthy certificate and for the renewal of the certificate (renewed issuance).
- the method according to the invention for issuing certificates is thus a method for the initial issuing and / or renewal of publicly trusted certificates.
- Certificate applications can accordingly be both applications for the purpose of the initial application (bootstrapping) as well as the renewal (update) of certificates.
- the certification module is preferably located on site at the technical system, in particular in the same network as the technical system. In particular, it is implemented on hardware that forms part of the technical system and / or the network of such a system.
- the certification module is part of an engineering system of the technical plant or is functionally connected to an engineering system of the technical plant.
- Industrial engineering systems also known as project engineering tools for industrial applications, can be used for solution design and implementation as well as for later operating and / or management processes. Solutions are to be understood here as industrial solutions, especially for the process and / or discrete industry.
- the engineering of an automation project usually comprises one or more of the following steps: determining the required functionality in the project, determining which components are required to offer this functionality, assigning functionality and an actual physical position the components in the system, assignment of communication structures to the components (e.g. which components are allowed to communicate with which other components and how they communicate, what the actual purpose of the component is), etc.
- An automation project correlates with a real project, e.g. the construction of a new production / manufacturing line in a new or existing industrial plant or a new or existing process plant.
- Some of the many examples in which such automation projects are implemented are the manufacture of vehicles in the automotive industry, the manufacture of electronics, the manufacture of food and beverage products and many more.
- the engineering system is usually used to generate one or more configurations of system / automation components as part of an industrial automation project.
- the industrial automation projects can be, for example, factory automation projects, projects for the automation of the process industry and all other automation projects in an industrial context.
- a system or automation component can be a hardware component and / or a software component or a combination of both, in particular for use in the above-mentioned automation project.
- Plant and automation components include: programmable logic controllers (PLC), I / O modules, industrial communication devices, industrial network components, sensors, actuators, drives and other industrial devices that are often used in the process or automation industry.
- Software components that share hardware with other components can also be configured using an engineering system.
- An engineering system (sometimes also referred to as an engineering tool) has very precise knowledge of the automation products in the plant. It knows the exact hardware (e.g. using the serial number) or the specific product (e.g. using the MLFB, i.e. the machine-readable brand name), but is also able to uniquely identify or identify a component such as a device do (e.g. via a permanently burned-in or safely played machine or device certificate). Likewise, an engineering system usually already has options for securely transferring data to the corresponding automation devices (in the sense of forgery-proof and not visible or readable by third parties).
- the certification module is integrated into an engineering system of the plant, it cannot be ruled out that it represents a stand-alone tool or stand-alone module or part of another Tools educates. Then there is preferably a functional connection with the engineering system. This means that the tool can also change the network, for example when the system / industrial component operates in a network that is not only accessible from the outside, but cannot itself contact other networks with the outside world.
- the invention offers several advantages. For systems, a certificate creation and deployment process that is integrated into the engineering and, in particular, tied to the customer contractual relationship, can be obtained.
- the integration into the engineering offers an extended, simpler and safer handling, for example a significantly smaller hurdle than with the integration of a standardized protocol in every system component / every product.
- the engineering system naturally knows device-specific access and distribution routes.
- a CSR generation and / or transmission is possible through the certification module, which is preferably integrated into the engineering system, possibly even before the actual device is available and installed.
- a certificate and, if necessary, any key material can be deployed in the course of the download or commissioning, again preferably supported by the engineering.
- a technical trust relationship can be maintained between a certification authority (CA) and system components, such as end devices, since a customer and the devices actually purchased can be identified on the basis of one component identifier (i.e. one or more unique features).
- CA certification authority
- the necessary steps can run automatically without a user or customer having to intervene manually.
- the certification module which is preferably part of an engineering system of the plant or is functionally connected to such a system, obtains the certificates from a preferred external CA.
- Certificate procurement can be provided as a service (Certificate as a Service, CaaS), for example for customers who have purchased system components to be certified.
- CaaS Certificate as a Service
- the certification module can represent a functional unit that can be implemented, for example, by a software component on suitable hardware. It may be that the certification module is implemented by software that is located on the hardware of an engineering system of the technical system. Of course, it is also possible for the certification module to comprise separate “own” hardware. Then, in a preferred embodiment, the certification module or its hardware is functionally connected to an engineering system of the technical installation.
- a registration office of a technical system is understood to mean a functional entity that receives registration requests such as certificate applications from components of the technical system, checks them and, if successful, forwards them in particular to a certification center of the technical system.
- the registration body is primarily intended to deal with applications for certification of system components of the technical system.
- the registration office can be a local registration office that can communicate with a higher-level global registration office, which, for example, can in turn be in direct connection with a certification office of the technical system.
- the registration authority may include or be provided by a registration service.
- the registration authority to which the certification module according to the invention transmits the at least one component identifier together with the certificate application is designed and / or set up to determine / check / validate whether using the at least one component identifier, in other words using one or more unique features the (respective) component is assigned to a person / company and is their / his responsibility, in particular whether a legally binding customer relationship exists for the (respective) component.
- the registration authority ascertains / checks / validates for which application on the at least one component the publicly trusted certificate applied for is intended. Then the registration point is designed and / or set up accordingly.
- the technical system is in particular a production or process system. It can be a system from the process industry, such as a chemical, pharmaceutical, petrochemical or a system from the food and beverage industry. This also includes all systems from the production industry, plants in which e.g. Cars or goods of all kinds are produced.
- Technical systems which are suitable for carrying out the method according to the invention can also come from the field of energy generation. Wind turbines, solar systems or power plants for generating energy are also included in the term technical system.
- these systems each have a control system or at least one computer-aided module for controlling and regulating the ongoing process or production.
- PKI Public Key Infrastructure
- the term "Public Key Infrastructure” is used to connect a security infrastructure for a technical system, the services for a secure exchange of data between communication partners of the technical system. With the help of the public key infrastructure, certificates can be issued, distributed and checked.
- a certificate is understood to be a digital data record that confirms certain properties (in this case of machines, devices, applications and the like). The authenticity and integrity of the certificate can be verified using cryptographic processes.
- Publicly trusted certificates are to be understood in particular as those that can be verified in the entire certificate chain up to generally recognized Trusted Root Certificates (TRC).
- TRC Trusted Root Certificates
- Publicly trusted certificates can also be called publicly recognized certificates.
- Publicly trusted / recognized certificates are in particular those issued by members of the CA / Browser Forum (see https://cabforum.org/).
- Publicly trustworthy / recognized certificates that are requested / issued within the scope of the method according to the invention are particularly preferably SSL (Secure Sockets Layer) or TLS (Transport Layer Security) certificates.
- a system component can be, for example, a control device such as a PLC (Programmable Logic Controller, PLC), a device, in particular a field device, an application or the like. It is in particular an automation component or an automation device.
- a control device such as a PLC (Programmable Logic Controller, PLC)
- PLC Process Control Controller
- a device in particular a field device, an application or the like. It is in particular an automation component or an automation device.
- the at least one system component preferably has at least one web server or represents a web server.
- a certificate management protocol can be used to transmit the at least one certificate application from the certification module to the registration authority. It can be a common, in the context of certificate management for a technical installation, in particular a control system of such a protocol commonly used, for example, the Certificate Management Protocol (CMP for short, see, for example, RFC 4210/4211 of the Internet Engineering Task Force (IETF)). CMP can in particular be or will be implemented via https. It should be emphasized that a standard protocol can be used, but does not have to be. The certification module and the RA can also communicate with one another in a purely proprietary manner.
- CMP Certificate Management Protocol
- IETF Internet Engineering Task Force
- the components are already installed in the system.
- the certification module can read features here, uniquely identify a component (and ensure that there is no other entity with the same features) and securely transfer data and certificates to the component.
- the components (server) have not yet been installed in the system, but this may first be configured.
- the certification module may first have to generate the at least one component identifier required for the target component (in other words, one or more unique features, e.g. a machine certificate).
- Publicly trusted certificates can, however, be requested and generated in advance and kept in the certification module internally for the configured device. Later during commissioning, the certification module then preferably ensures that the at least one preferably unique component identifier (in other words, unique features) is actually present or can be introduced in a forgery-proof manner and is then preferably introduced. If this has been ensured, the publicly trustee certificate can also be transferred there.
- a further advantageous embodiment is therefore characterized in that, in the event that the certification module in step a) did not query any component identifier (in particular because the at least one component was not yet in operation - offline scenario), the certification module before the transmission of the publicly trustworthy certificate to the at least one component and / or the storage device connected or connectable to the at least one component Queries component identifier of the at least one component and preferably transmits the queried component identifier to the registration office.
- the (then) queried component identifier can be transmitted to the registration authority.
- the registration authority can store these in a database.
- the certification module checks before the transmission of the publicly trusted certificate to the at least one component and / or the storage device connected or connectable to the at least one component whether there is at least one component identifier generated by it in step b) can be saved / filed in a forgery-proof manner in the component.
- an SD card or a (USB) dongle can receive the complete configuration for a controller (such as a PLC) when downloading, but the actual component can be replaced immediately if a spare part is needed. The download is only made indirectly to the actual component.
- the representative for example the card or the (USB) dongle, must be clearly identifiable and must be protected against unauthorized access - the data in the protected area must therefore not be easily readable.
- the relevant component can then take the configuration from the representative, such as the SD card or dongle.
- the certificate should preferably be encrypted and only the relevant component should preferably be used when reading the Configuration to be able to decrypt the certificate.
- the certification module expediently has (at least at any point in time) access to the component to be validated or a storage device representing a proxy, such as an SD card or a dongle. This applies in particular if the certification module is part of an engineering system or is functionally linked to one.
- the publicly trusted certificate (if necessary with accompanying material) can preferably be encrypted directly for the target component. This ensures that the certificate is completely secured and can only be decrypted there.
- each project in the engineering system can be provided with a customer-specific key so that in the offline case the certification authority (CA) can secure the transport at least up to the certification module.
- the certification authority CA
- the material for the specific component such as the specific end device, can in turn be encrypted. Consistent protection is thus also possible.
- a database in particular can include an entry according to which a user / a person / a company has a certain number of automation components of a given type. After a certificate application has been approved or a certificate has been issued for such a component, the number would increase one reduced.
- an in particular unique component identifier is preferably played back, that is to say transmitted to the database and stored there. If possible, certificate updates should no longer be carried out for such "general hits" but rather for the specific identifier.
- a further advantageous embodiment of the method according to the invention is characterized in that the registration authority requests the publicly trustworthy certificate in step d) from a certification authority, in particular by validating the certificate application and / or forwarding it to the certification authority.
- the certification authority can then create or obtain the requested publicly trusted certificate for the at least one component.
- the certification module further preferably transmits the publicly trusted certificate transmitted to it in step e) to the at least one component and / or to a storage device connected or connectable to the at least one component.
- a storage device is preferably a “representative”, for example an SD card, a (USB) dongle or another storage medium onto which a configuration for the component can / will be loaded.
- the key material is, in particular, that which was transmitted to the certification module together with the certificate, in particular from a certification authority.
- the publicly trusted certificate is preferably stored in a forgery-proof certificate memory of the at least one component and / or of the memory device connected or connectable to the at least one component.
- a direct connection between the certification module or between hardware on which the certification module is implemented can be used for the transmission of the publicly trusted certificate from the certification module to the at least one component and / or to the storage device connected or connectable to the at least one component , and the at least one component and / or the storage device connected or connectable to the at least one component exist or be produced.
- “directly” is to be understood in particular to mean that the certification module can communicate “directly” with the component. It preferably means that the certification module is located in the same network from which the component can be reached and no intermediary is required.
- a direct wired or wireless connection can exist or be established.
- the certification module queries the at least one component identifier from the at least one component in step b), with a direct connection between the certification module or between hardware on which the certification module is implemented and the at least a component exists or is produced.
- Another object of the invention is a system for issuing publicly trusted certificates for system components of a technical system, comprising a certification module and a registration authority,
- the certification module is designed and / or is directed to query at least one preferably unique component identifier from at least one system component that is to receive a publicly trusted certificate and / or to generate at least one preferably unique component identifier for at least one system component that is to receive a publicly trusted certificate
- the registration authority is designed and / or set up to use the at least one component identifier to check whether the at least one Component belonging to the component thinking is assigned to at least one authorized person or at least one authorized company, in particular the property of at least one authorized person or at least one authorized company, and in the event that so, a publicly trusted certificate for the to request at least one component
- the certification module is designed and / or set up to receive the requested publicly trusted certificate and preferably to store it in a protected area.
- the system according to the invention is particularly suitable for carrying out the method according to the invention.
- the system according to the invention comprises a database in which component identifiers are stored together with associated authorized persons and / or companies, who are preferably owners of associated components, and the registration authority is designed and / or set up for or within the framework checking whether the at least one component belonging to the component identifier is assigned to at least one authorized person or at least one authorized company, to search the database for at least one entry for the at least one component identifier transmitted together with the certificate request.
- the certification module preferably forms a (local) “front end” or a (local) “front end” unit of the system or is part of such a unit.
- the registry is - if necessary together with a database and a Certification authority - preferably part of a (central) "backend” or a central “backend” unit of the system.
- the certification module is preferably located on site at or in the technical system, while the registration service is preferably located away from it, for example in a computing center. In particular, the registration service can be contacted by several certification modules that can be located at / in different systems and receive certificate applications together with component IDs.
- a certification authority can be a further component of a "backend” / a "backend” unit of the system.
- a separate / external certification body can exist which trusts the registration body of the system according to the invention.
- a separate / external certification authority can be given by a certification authority such as VeriSign or another known certification authority, which preferably has a Trusted Root Certificate (TRC).
- the invention also relates to an engineering or control system for a technical installation comprising a certification module that is designed and / or set up to
- RA registration authority
- the certification module can be an inspection unit
- an inspection unit is present, it is preferably designed and / or set up to query (in other words read out) at least one preferably unique component identifier from the at least one component that is to receive the publicly frustrated certificate and / or for the at least one component that the public Lich frustrated certificate is to receive, to generate at least one preferably unique component identifier.
- the deployment unit is preferably designed and / or set up to transmit a publicly frustrated certificate that has been created to the (respective) component, that is to say to upload it to it. It is preferably designed and / or set up to receive publicly frustrated certificates created by a certification authority in order to then be able to pass them on to the (respective) component.
- the invention relates to a technical installation, in particular a manufacturing or processing installation.
- the technical system according to the invention preferably comprises at least one engineering or control system according to the invention.
- a gateway and / or edge device can alternatively or additionally also be used.
- the certification module is provided / implemented on an edge device.
- the certification module can, for example, be executed as an app on an edge device / device. If an edge device is used, the request (certificate applications), renewal and secure import of public Trusted certificates on the components, such as devices in the local network of a technical system, take place fully automatically, while the gateway / edge device also allows access to the Internet and the public infrastructure.
- An edge device is conveniently (as the name suggests) on the outer edge of the closed network and has two network accesses / network adapters. The edge device is then in particular both in the closed internal network and in the public Internet. The devices or components in the closed network, however, usually have no access to the Internet. This is particularly useful in operation for automatic renewals, since the engineering system is not required and the certification module is not first used internally to obtain the ID and then manually switch to the public Internet.
- the figure shows a system component G and an exemplary embodiment of a system according to the invention for the issuing of publicly trust certificates in a purely schematic representation.
- the system component G is given by a programmable logic controller, or PLC for short, and is part of a technical system, not shown, in particular a manufacturing or process system.
- the system includes, inter alia a plurality of sensors that deliver measured values for the controller G, and actuators that receive control values from the controller G. In this way, a process running in the system can be monitored and influenced.
- the controller G is with the sensors and actuators as well as other system components in a known manner via a Plant network connected.
- the system network is a local, closed network and the controller G cannot be reached from outside via the Internet.
- the controller G is characterized by a unique component identifier K, which is given by a device certificate K in the embodiment described here.
- the controller G should receive a certificate.
- the controller G or a web server on this should receive such a certificate, which can be verified up to a trusted root certificate TRC and which is also referred to as a publicly trusted certificate C.
- the controller G has a forgery-proof certificate store CS, which is used in a manner known per se to securely store or store a digital certificate.
- a publicly trustee certificate C can be stored in the Certificate Store CS.
- a system S according to the invention is therefore provided for issuing publicly trusted certificates C for system components G of a technical system, which can be used to obtain such a certificate C for the controller G and to store it in it (also referred to as "deployment”) ).
- the embodiment shown in the figure of such a system S according to the invention includes a certification module ZM, which represents a "front-end” unit or “front end” component of the system 1 and is located on site at or in the technical system.
- the certification module ZM is integrated into an engineering system ES of the technical system. Specifically, it is a functional unit or a functional module that is implemented by software that is located on the hardware of the engineering system ES.
- the engineering system forms part of the illustrated embodiment of a system S according to the invention for the issuing of publicly trusted certificates.
- the engineering system ES can run on standard hardware, such as a conventional PC or industrial PC.
- the certification module ZM - as in the example shown - is integrated into an engineering system S of the system, this also representing or part of a stand-alone tool or stand-alone module another tool can be. Then there is a functional connection between the engineering system ES and the certification module ZM.
- the ZM certification module can also be implemented on an edge device which is located on the outer edge of the closed system network and has two network accesses / network adapters, so that it is located both in the closed internal system network and in the public Internet.
- the engineering system ES has very precise knowledge of the automation products in a technical system. It knows the exact hardware (e.g. using the serial number) or the specific product (e.g. using the MLFB), but is also able to clearly identify a component, such as the controller G, or make it identifiable (e.g. using a machine or device certificate that is burned in or that can be safely uploaded). Likewise, the engineering system ES usually has options for transferring data securely to the corresponding components, such as automation devices (in the sense of forgery-proof and not visible or readable by third parties).
- the system S also comprises a backend or a backend unit BE with a registration agency RA, a database D and a certification agency CA.
- the backend or the backend unit BE is not arranged on site at the plant, but is located in a computing center, which is, for example, a few or many kilometers away from the plant. Communication between the certification module ZM and the backend BE is possible via the public Internet.
- the certification module ZM is designed to communicate with components G of the system.
- the certification module ZM comprises an inspection unit IE, which is designed to query (in other words, read out) unambiguous component identifiers K from components G that are to receive a publicly trusted certificate C, and for components G that have a publicly trusted certificate C should receive, preferably to generate a clear component identifier K.
- the query or “probing” is indicated in the figure by an arrow pointing from the inspection unit IE to the device certificate forming the component identifier K.
- the inspection unit IE is also designed to transmit queried and / or generated component identifiers K together with a certificate request CSR for a publicly trusted certificate C for the respective component G to the registration office RA.
- the transmission is indicated in the figure by an arrow pointing from the inspection unit IE to the registration office RA, in addition to which a certificate request CSR for the controller G together with the device certificate K of the controller G is shown purely schematically.
- the certification module ZM also has a deployment unit DE which is designed to transmit publicly trusted certificates C to the (respective) component G, that is to say to upload them to them. It is trained to receive publicly trusted certificates C created or procured by the certification authority CA and then to pass them on to the (respective) component G.
- the registration office RA is designed to use the at least one component identifier K to check whether the at least one component belonging to the component identifier K nents, in the present case the controller G is assigned to at least one authorized person or at least one authorized company, in particular represents the property of at least one authorized person or at least one authorized company, and, in the event that this is the case, a publicly trusted certificate C for the at least one component G to request.
- the registration authority RA is able to validate a legally binding customer assignment on the basis of transmitted unique component characteristics K.
- an embodiment of the method according to the invention for issuing publicly trusted certificates C for system components G of a technical system can be carried out.
- the certification module ZM queries the controller G, which is to receive a publicly trusted certificate, at least one preferably unique component identifier, in the present case the device certificate K.
- the certification module ZM which in the present case is integrated into the engineering system of the plant, has direct access to the controller G, so that this query is possible without any problems.
- the engineering system G is a participant in the closed system network, so that it - and thus the integrated certification module ZM - has access to the controller G.
- the certification module ZM can also generate at least one preferably unique component identifier for the controller G, which is to receive a publicly trusted certificate, in the present case a (possibly temporary) device certificate .
- At least one component for example the controller G
- the generation of at least one unique identifier K by the certification module ZM makes the components clearly identifiable.
- Publicly trusted certificates C can then already be requested and generated in advance and held internally in the certification module ZM for the projected component G. Later during commissioning, the certification module ZM then preferably ensures that the at least one component identifier K is actually present or can be introduced in a forgery-proof manner. If this has been ensured, the publicly trustee certificate C can also be transferred there.
- the certification module ZM transmits this together with a certificate request CSR for a publicly trusted certificate C for the controller G to a registration authority RA.
- the certificate application CSR which the certification module ZM transmits to the registration authority RA, can be or have been made by the certification module ZM or also by the controller G.
- the registration authority RA uses the device certificate K to check whether the at least one controller G belonging to the component K is assigned to at least one authorized person or at least one authorized company in whose or whose responsibility the controller is.
- this check is carried out in that the registration authority RA stores the database D in which the component identifiers K, including device certificates K, together with associated authorized persons and / or companies who represent the owners of components G belonging to the component identifiers K. are, after at least one entry for the together with the certificate katsfrage CSR transmitted component identifier, in this case the device certificate K of the controller G, searches.
- the CSR certificate application is approved / validated by the registration authority RA.
- the registration authority RA requests the publicly trusted certificate C from the certification authority CA, in particular by forwarding the CSR certificate request to the certification authority CA.
- the certification authority CA then creates or procures the requested publicly trustworthy certificate C for the control G.
- the certification authority CA which is part of the backend BE, contacts another, central certification authority zCA in the example described here, which has a trusted root certificate TRC disposes. Since the zCA has a relationship of trust with the CA, it executes the CSR directly.
- a certificate C is created by or in the registration authority CA or zCA of the backend BE.
- the certificate C is forwarded together with the associated key material to the deployment unit DE of the certification module ZM, stored there or at another point in the engineering system ES in a protected area that cannot be read or changed from the outside.
- the certificate C and associated key material are also “deployed” by the deployment unit, that is to say introduced into the control G, specifically stored securely in the certificate store CS. This is indicated again in FIG. 1 by corresponding arrows.
- the certificate C (can also be referred to as a customer certificate or, in English, customer certificate) points to an intermediate certificate zC from the CA, which in turn refers to the trusted root certificate TRC from the zCA.
- this certificate chain is indicated by arrows with a dashed line.
- these arrows indicate the "trust", i.e. the trust between the bodies or certificates.
- the TRC is the end of the certificate chain.
- the (customer) certificate C in component G must be above the whole chain up to the TRC of the zCA will be valid.
- a central certification authority zCA is provided and that the CA can be contacted, but does not have to be.
- the CA it is also possible for the CA to issue certificates C directly without having to rely on external cooperation from another CA. This is particularly the case if the CA has valid key material.
- the unique identifier K is now queried from component G and sent to the backend BE transmitted back. There the provisional identifier can now be replaced with the actual one. (If the ES has generated a unique identifier K in advance and this could be incorporated into component G, there is no return transmission, or other identifiers, such as the serial number, are transferred to database D for correct assignment.)
- the engineering system ES with the certification module ZM can support the following three variants:
- the components / servers are already installed in the system.
- the ES can read out features here, uniquely identify a component G (and ensure that there is no other entity with the same features) and securely transfer data and certificates C to the component G.
- the components / servers are not yet installed in the system, but this may still be configured.
- the engineering system ES may first generate the unique features required for the target component G (at least one component identifier K) (e.g. a machine certificate). Certificates C can then, however, be requested in advance and generated in the engineering system ES, specifically the certification module ZM internally for the configured component G. Later, during commissioning, the ES ensures that the unique features are actually available or can be incorporated in a forgery-proof manner.
- the engineering system ES has access to the components G to be validated at least at some point in time.
- the certificate C can be encrypted directly for the target component G with accompanying material. This ensures that certificate C is completely secured and can only be decrypted there.
- each project in the ES engineering system can be provided with a (customer) -specific key so that in the offline case the CA can secure the transport at least up to the ES.
- the material for the specific terminal G can in turn be encrypted in the respective project. Consistent protection is thus also possible.
- the engineering system ES in which the certification module ZM is integrated, or of which the certification module ZM forms a component, represents an exemplary embodiment of an engineering system according to the invention for a technical installation or for a technical installation.
- the technical system of which the controller G and the engineering system ES form a component, is also a Embodiment of a technical plant according to the invention ge.
- a certification module ZM or a system S according to the invention can be used for several components of a technical system (or also several technical systems).
- the backend BE of a system according to the invention can also represent a control center that communicates with several certification modules ZM and creates several certification modules ZM, possibly various systems, publicly trusted certificates C and transmits them to the several certification modules ZM.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Computing Systems (AREA)
- Computer Hardware Design (AREA)
- General Engineering & Computer Science (AREA)
- Health & Medical Sciences (AREA)
- General Health & Medical Sciences (AREA)
- Medical Informatics (AREA)
- Management, Administration, Business Operations System, And Electronic Commerce (AREA)
Abstract
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| EP19171566.3A EP3734902A1 (fr) | 2019-04-29 | 2019-04-29 | Procédé et système d'attribution de certificats de sécurité publics, système d'ingénierie ou de guidage et installation technique |
| PCT/EP2020/058794 WO2020221528A1 (fr) | 2019-04-29 | 2020-03-27 | Procédé et système pour émettre des certificats de clé publique, système d'ingénierie ou système de commande et installation technique |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| EP3932005A1 true EP3932005A1 (fr) | 2022-01-05 |
Family
ID=66397020
Family Applications (2)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| EP19171566.3A Withdrawn EP3734902A1 (fr) | 2019-04-29 | 2019-04-29 | Procédé et système d'attribution de certificats de sécurité publics, système d'ingénierie ou de guidage et installation technique |
| EP20718202.3A Pending EP3932005A1 (fr) | 2019-04-29 | 2020-03-27 | Procédé et système pour émettre des certificats de clé publique, système d'ingénierie ou système de commande et installation technique |
Family Applications Before (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| EP19171566.3A Withdrawn EP3734902A1 (fr) | 2019-04-29 | 2019-04-29 | Procédé et système d'attribution de certificats de sécurité publics, système d'ingénierie ou de guidage et installation technique |
Country Status (4)
| Country | Link |
|---|---|
| US (1) | US12126611B2 (fr) |
| EP (2) | EP3734902A1 (fr) |
| CN (1) | CN113748641B (fr) |
| WO (1) | WO2020221528A1 (fr) |
Families Citing this family (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US12143506B2 (en) * | 2022-01-26 | 2024-11-12 | Microsoft Technology Licensing, Llc | Establishing PKI chain of trust in air gapped cloud |
| EP4243343A1 (fr) * | 2022-03-10 | 2023-09-13 | Siemens Aktiengesellschaft | Procédé de délivrance d'un certificat et point d'enregistrement mis en uvre par ordinateur |
| EP4412153A1 (fr) * | 2023-01-31 | 2024-08-07 | Siemens Aktiengesellschaft | Procédé et terminal pour la transmission sécurisée cryptographique de données dans un système de communication |
Family Cites Families (17)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US6980660B1 (en) * | 1999-05-21 | 2005-12-27 | International Business Machines Corporation | Method and apparatus for efficiently initializing mobile wireless devices |
| JP2001320356A (ja) * | 2000-02-29 | 2001-11-16 | Sony Corp | 公開鍵系暗号を使用したデータ通信システムおよびデータ通信システム構築方法 |
| US20030074555A1 (en) * | 2001-10-17 | 2003-04-17 | Fahn Paul Neil | URL-based certificate in a PKI |
| ITRM20020335A1 (it) * | 2002-06-14 | 2003-12-15 | Telecom Italia Mobile Spa | Metodo di autoregistrazione e rilascio automatizzato di certificati digitali e relativa architettura di rete che lo implementa. |
| US20050229004A1 (en) * | 2004-03-31 | 2005-10-13 | Callaghan David M | Digital rights management system and method |
| US20060136274A1 (en) * | 2004-09-10 | 2006-06-22 | Olivier Lyle E | System, method, and apparatus for providing a single-entry and multiple company interface (SEMCI) for insurance applications and underwriting and management thereof |
| CN102971485B (zh) * | 2010-04-30 | 2016-01-13 | S.P.M.流量控制股份有限公司 | 测试和认证石油和天然气设备的机器、系统、计算机实施的方法 |
| EP4598067A3 (fr) * | 2011-10-25 | 2025-11-05 | Salesforce, Inc. | Systèmes et procédés d'authentification à deux facteurs |
| US9130837B2 (en) * | 2012-05-22 | 2015-09-08 | Cisco Technology, Inc. | System and method for enabling unconfigured devices to join an autonomic network in a secure manner |
| CN103986687B (zh) | 2013-02-07 | 2017-09-15 | 电信科学技术研究院 | 一种实现车联网设备授权管理的方法、设备及系统 |
| JP6425984B2 (ja) * | 2014-07-07 | 2018-11-21 | ベドロック・オートメーション・プラットフォームズ・インコーポレーテッド | 産業用制御システム冗長通信/制御モジュール認証 |
| KR20160038091A (ko) | 2014-09-24 | 2016-04-07 | 현대자동차주식회사 | V2x 통신을 위한 csr 인증서 발급 방법 및 시스템 |
| US9560018B2 (en) * | 2014-12-08 | 2017-01-31 | Cisco Technology, Inc. | Autonomic locator/identifier separation protocol for secure hybrid cloud extension |
| US20160360403A1 (en) * | 2015-01-05 | 2016-12-08 | Ebid,Products & Solutions, S.L. | Procedure for generating a digital identity of a user of a mobile device, digital identity of the user, and authentication procedure using said digital identity of the user |
| US11218465B2 (en) * | 2017-01-29 | 2022-01-04 | Beame.io Ltd. | Establishing an AD-HOC secure connection between two electronic computing devices using a self-expiring locally transmitted information packet |
| US10749692B2 (en) * | 2017-05-05 | 2020-08-18 | Honeywell International Inc. | Automated certificate enrollment for devices in industrial control systems or other systems |
| CN107959686B (zh) * | 2017-12-13 | 2019-06-07 | 恒宝股份有限公司 | 一种物联网安全认证系统及认证方法 |
-
2019
- 2019-04-29 EP EP19171566.3A patent/EP3734902A1/fr not_active Withdrawn
-
2020
- 2020-03-27 US US17/607,083 patent/US12126611B2/en active Active
- 2020-03-27 EP EP20718202.3A patent/EP3932005A1/fr active Pending
- 2020-03-27 CN CN202080032234.8A patent/CN113748641B/zh active Active
- 2020-03-27 WO PCT/EP2020/058794 patent/WO2020221528A1/fr not_active Ceased
Also Published As
| Publication number | Publication date |
|---|---|
| US20220239641A1 (en) | 2022-07-28 |
| US12126611B2 (en) | 2024-10-22 |
| EP3734902A1 (fr) | 2020-11-04 |
| CN113748641B (zh) | 2025-01-14 |
| WO2020221528A1 (fr) | 2020-11-05 |
| CN113748641A (zh) | 2021-12-03 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| EP3985532B1 (fr) | Gestion des certificats pour installations techniques | |
| EP3488555B1 (fr) | Traitement sécurisé d'une demande d'attestation d'autorisation | |
| DE102011081804B4 (de) | Verfahren und System zum Bereitstellen von gerätespezifischen Betreiberdaten, welche an ein Authentisierungs-Credential gebunden werden, für ein Automatisierungsgerät einer Automatisierungsanlage | |
| EP3673623A1 (fr) | Procédé et système de commande destinés à la commande et/ou à la surveillance d'appareils | |
| EP3605253B1 (fr) | Initialisation automatisée des infrastructures à clé publique | |
| EP3932005A1 (fr) | Procédé et système pour émettre des certificats de clé publique, système d'ingénierie ou système de commande et installation technique | |
| EP3714575B1 (fr) | Procédé et système de contrôle pour le contrôle et/ou la surveillance d'appareils | |
| EP3763089B1 (fr) | Procédé et système de contrôle pour le contrôle et/ou la surveillance d'appareils | |
| EP4154070A1 (fr) | Commande de processus basée sur un jumeau numérique dans un réseau ido | |
| EP3718263B1 (fr) | Procédé et système de contrôle pour le contrôle et/ou la surveillance d'appareils | |
| EP3762845B1 (fr) | Gestion des certificats relatif à un projet | |
| EP3993339B1 (fr) | Gestion des certificats dans une installation technique | |
| WO2020207717A1 (fr) | Procédé et système de commande pour la commande d'une exécution de transactions | |
| WO2024110524A1 (fr) | Module technique sécurisé | |
| WO2022022997A1 (fr) | Communication basée sur des canaux dans un réseau ido | |
| EP4032243A1 (fr) | Système et procédé de gestion de données d'un appareil de terrain de la technique d'automatisation de manière sécurisée contre la manipulation | |
| WO2020221523A1 (fr) | Procédé d'attribution de certificats, système de guidage, utilisation d'un tel système, installation technique, composants d'installation et utilisation d'un fournisseur d'identité | |
| EP4254233A1 (fr) | Procédé et système de mise en oeuvre sécurisée d'applications de commande, hôte | |
| EP3681099A1 (fr) | Procédé de fonctionnement d'un système informatique pour une installation d'automatisation et / ou installation de fabrication ainsi que système informatique | |
| BE1027181B1 (de) | Verfahren und System zum sicheren Bereitstellen von Daten eines Gegenstands über dessen gesamten Lebenszyklus | |
| WO2020193044A1 (fr) | Procédé et système de commande pour la commande d'une exécution de transactions | |
| DE102023201458B4 (de) | Verfahren zur Integration einer Anlagenkomponente in ein Kommunikationsnetzwerk einer technischen Anlage | |
| EP4432602A1 (fr) | Procédé de présentation d'un certificat et site d'enregistrement mis en uvre par ordinateur | |
| WO2018114101A1 (fr) | Procédé de vérification d'une attribution à un mandant, produit programme informatique et système d'automatisation comportant des appareils de terrain | |
| EP3944108A1 (fr) | Révocation de certificats dans une installation technique |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: UNKNOWN |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: THE INTERNATIONAL PUBLICATION HAS BEEN MADE |
|
| PUAI | Public reference made under article 153(3) epc to a published international application that has entered the european phase |
Free format text: ORIGINAL CODE: 0009012 |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: REQUEST FOR EXAMINATION WAS MADE |
|
| 17P | Request for examination filed |
Effective date: 20210930 |
|
| AK | Designated contracting states |
Kind code of ref document: A1 Designated state(s): AL AT BE BG CH CY CZ DE DK EE ES FI FR GB GR HR HU IE IS IT LI LT LU LV MC MK MT NL NO PL PT RO RS SE SI SK SM TR |
|
| DAV | Request for validation of the european patent (deleted) | ||
| DAX | Request for extension of the european patent (deleted) | ||
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: EXAMINATION IS IN PROGRESS |
|
| 17Q | First examination report despatched |
Effective date: 20250221 |