Industrial automation system with certificate based cryptographic feature licensing
A system can include one or more memory devices storing instructions executed by one or more processors. The one or more processors can receive a public key of a device of an industrial automation system corresponding to a private key of the device. The one or more processors can receive a request to grant the device a license to enable a feature of the device or access a feature of the industrial automation system. The one or more processors can generate a certificate including the public key of the device and an indication of the license in a non-encrypted format. The one or more processors can transmit the certificate to the device to cause the device to enable the feature of the device or access the feature of the industrial automation system responsive to the device proving possession of the private key corresponding to the public key in the certificate.
1 . A system for licensing features to industrial devices employed in an industrial automation system, the system comprising:
one or more memory devices storing instructions thereon that, when executed by one or more processors, cause the one or more processors to:
receive a public key of a device of the industrial devices employed in the industrial automation system, the public key corresponding to a private key possessed by the device;
receive a request to grant the device a license, responsive to receiving the public key of the device, to enable a licensable feature of the device or access a licensable feature of the industrial automation system;
generate a certificate comprising the received public key of the device and an indication of the granted license in a non-encrypted format; and
transmit the generated certificate, including the indication of the granted license in the non-encrypted format, to the device to cause the device to effectively enable the feature of the device or access the feature of the industrial automation system responsive to the device proving possession of the private key corresponding to the public key in the certificate without requiring the certificate including the indication of the granted license to be encrypted and only readable by a recipient device possessing a corresponding decryption key.
2 . The system of claim 1 , wherein the instructions cause the one or more processors to:
generate a signature for the certificate by signing the certificate using a private key of the certificate authority corresponding to a public key of the certificate authority stored in a root certificate of the certificate authority; and
the system further comprising the device, the device comprising one or more processing circuits to validate the signature of the certificate using the public key of the certificate authority stored in the root certificate of the certificate authority.
3 . The system of claim 1 , wherein the instructions cause the one or more processors to:
generate a plurality of certificates comprising the public key, indications of different features of the device or access to different features of the industrial automation system, and different expiration times; and
transmit the plurality of certificates to the device to cause the device to enable the different features of the device or access the different features of the industrial automation system responsive to the device proving possession of the private key corresponding to the public key in the plurality of certificates.
4 . The system of claim 1 , wherein the instructions cause the one or more processors to:
transmit a request to the device for a vendor certificate installed on the device during device manufacturing, the vendor certificate including the public key;
receive the vendor certificate from the device responsive to the request; and
extract the public key of the device from the vendor certificate.
5 . The system of claim 1 , wherein:
the device is manufactured by a first manufacturer different than a second manufacturer of the industrial automation system; and
the instructions cause the one or more processors to:
transmit a prompt to the device to cause a trusted platform module of the device to generate a message applying for a certificate from a certificate authority, the message comprising the public key of the device;
receive, responsive to the prompt, the message applying for the certificate from the certificate authority; and
extract the public key from the message.
6 . The system of claim 1 , wherein the instructions cause the one or more processors to:
transmit, to the device, a request for an identity of a removable memory device installed at the device, the removable memory device storing the identity, wherein the private key possessed by the device is stored on the device or the removable memory device;
receive, responsive to the request, the identity from the device; and
cause the certificate to be generated using the identity.
7 . The system of claim 1 , further comprising the device, the device comprising one or more processing circuits to:
receive the certificate from the one or more processors;
transmit a request to one or more computing systems of the industrial automation system located remote from the device to execute the feature of the industrial automation system;
receive, from the one or more computing systems, a request to prove possession of the private key corresponding to the public key in the certificate; and
return a response to the one or more computing systems proving possession of the private key and causing the one or more computing systems to execute the feature of the industrial automation system.
8 . The system of claim 1 , wherein the instructions cause the one or more processors to:
receive a length of time for the license to remain valid; and
generate the certificate using the length of time to include an expiration time for the license to expire;
the system further comprising the device comprising one or more processing circuits to:
read the expiration time from the certificate; and
disable the feature of the device or access to the feature of the industrial automation system responsive to a determination that a current time has reached the expiration time.
9 . The system of claim 1 , wherein the instructions cause the one or more processors to:
receive a length of time for the license to remain valid; and
generate the certificate using the length of time to include an expiration time for the license to expire;
the system further comprising one or more computing systems to:
read the expiration time from the certificate;
receive a request from the device to perform the feature of the industrial automation system; and
decline the request from the device to perform the feature responsive to a determination that a current time has reached the expiration time.
10 . The system of claim 1 , where the instructions cause the one or more processors to:
receive a request to cancel access to the feature of the device or the feature of the industrial automation system; and
revoke the certificate responsive to reception of the request.
11 . The system of claim 1 , wherein the instructions cause the one or more processors to:
receive an identifier of the device;
lookup, using the identifier of the device, the public key from a database storing a plurality of identifiers of devices manufactured by a manufacturer of the industrial automation system and public keys corresponding to private keys stored on the devices; and
cause the certificate to be generated using the public key looked up from the database.
12 . The system of claim 1 , wherein the instructions cause the one or more processors to:
receive an indication of an event to trigger an end of the license; and
cause the certificate to be generated to include the indication of the event; and
the system further comprising the device comprising one or more processing circuits configured to:
monitor a plurality of operations performed by the one or more processing circuits or one or more computing systems of the industrial automation system remote from the device;
determine, based on the indication of the event of the certificate and the plurality of operations, that the event is triggered; and
request that a certificate authority revoke the certificate responsive to the determination that the event is triggered.
13 . The system of claim 12 , wherein the event is a predefined number of components being manufactured by the industrial automation system.
14 . The system of claim 12 , wherein the event is a predefined number of optimizations run by the one or more computing systems to optimize operation of the industrial automation system.
15 . A method of licensing features to industrial devices employed in an industrial automation system, the method comprising:
receiving, by one or more processing circuits, a public key of the industrial devices employed in a device of the industrial automation system, the public key corresponding to a private key possessed by the device;
receiving, by the one or more processing circuits, a request to grant the device a license, responsive to receiving the public key of the device, to enable a licensable feature of the device or access a licensable feature of the industrial automation system;
generating, by the one or more processing circuits, a certificate comprising the received public key of the device and an indication of the granted license in a non-encrypted format; and
transmitting, by the one or more processing circuits, the generated certificate, including the indication of the granted license in the non-encrypted format, to the device to cause the device to effectively enable the feature of the device or access the feature of the industrial automation system responsive to the device proving possession of the private key corresponding to the public key in the certificate without requiring the certificate including the indication of the granted license to be encrypted and only readable by a recipient device possessing a corresponding decryption key.
16 . The method of claim 15 , further comprising:
receiving, by the one or more processing circuits, an identifier of the device;
retrieving, by the one or more processing circuits, using the identifier of the device, the public key from a database storing a plurality of identifiers of devices manufactured by a manufacturer of the industrial automation system and public keys corresponding to private keys stored on the devices; and
causing, by the one or more processing circuits, the certificate to be generated using the public key looked up from the database.
17 . The method of claim 15 , further comprising:
receiving, by the one or more processing circuits, an indication of an event to trigger an end of the license;
generating, by the one or more processing circuits, the certificate to include the indication of the event;
monitoring, by the device, a plurality of operations performed by the one or more processing circuits or one or more computing systems of the industrial automation system remote from the device;
determining, by the device, based on the indication of the event of the certificate and the plurality of operations, that the event is triggered; and
requesting, by the device, that a certificate authority revoke the certificate responsive to the determination that the event is triggered.
18 . The method of claim 15 , further comprising:
sending, by a remote system, a request to the one or more processing circuits to verify that the certificate license has not been revoked; and
verifying, by the remote system, that the certificate was issued by a certificate authority.
19 . An industrial device of an industrial automation system, the industrial device comprising:
one or more processing circuits to:
transmit a public key of the industrial device employed in the industrial automation system to one or more computing systems, the public key corresponding to a private key possessed by the industrial device;
responsive to transmitting the public key to the one or more computing systems, transmitting a request to grant the industrial device a license to enable a licensable feature of the industrial device or access a licensable feature of the industrial automation system;
receive, from the one or more computing systems, a certificate comprising the transmitted public key of the industrial device and an indication of a license in a non-encrypted format, the license to enable the licensable feature of the industrial device or access the licensable feature of the industrial automation system;
prove possession of the private key corresponding to the transmitted public key in the certificate including the indication of the granted license in the non-encrypted format; and
perform the licensable feature or access the licensable feature of the industrial automation system responsive to proving possession of the private key without requiring the certificate including the indication of the granted license to be encrypted and only readable by a recipient device possessing a corresponding decryption key.
20 . The industrial device of claim 19 , wherein the one or more processing circuits are configured to:
transmit a request to one or more external computing systems of the industrial automation system located remote from the industrial device to execute the feature of the industrial automation system;
receive, from the one or more external computing systems, a request to prove possession of the private key corresponding to the public key in the certificate; and
return a response to the one or more external computing systems proving possession of the private key and causing the one or more external computing systems to execute the feature of the industrial automation system.