IP Library Granted Patent US 11,005,857
Granted Patent B2
US 11,005,857 · App. 16/169,935 · Granted May 11, 2021

Systems and methods for securing industrial data streams with a fog root of trust

Inventors: Ruchir Tewari (Mountain View, CA); Thushar Gowda (Pleasanton, CA); Pankaj Bhagra (Fremont, CA); Thiru Narayanan (Fremont, CA); Palani Chinnakannan (San Jose, CA)
Assignee: NEBBIOLO TECHNOLOGIES, INC.
H04L63/126H04L9/0877H04L9/3213H04L9/3234H04L9/3297
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,005,857
App. No.
16/169,935
Granted
May 11, 2021
Kind
B2
Abstract

Systems and methods for security of industrial data streams are provided herein. Methods according to various embodiments include provisioning a fogNode that is communicatively coupled with a fog cloud manager through a forwarder of the fogNode and providing a fogLet within the fogNode, the fogLet communicating with a plurality of operational technology devices. Embodiments include providing fogLet identification information using hardware root of trust of the fogNode, the hardware root of trust of the fogNode being a Trusted Platform Module (TPM) of the fogNode. Embodiments further comprise communicating operational device authentication information with fogLet identification information to a third party tenant application, the third party tenant application validating industrial data streams from the operational technology devices by communicating the operational device authentication information with the fogLet identification information to a third party cloud application.

Claims (27)

1. A method for security of industrial data streams arising from industrial applications and devices, comprising:

provisioning a fog Node that is communicatively coupled with a fog cloud manager through a forwarder of the fog Node;

providing a foglet within the fog Node, the foglet communicating with a plurality of operational technology devices;

providing foglet identification information using a root of trust of the fog Node, the root of trust of the fog Node being located in the fog Node;

providing foglet encryption information using the root of trust of the fog Node;

communicating the foglet identification information and the foglet encryption information to the fog cloud manager;

transferring the foglet identification information and the foglet encryption information to a third party cloud application for validation of industrial data streams from the plurality of operational technology devices;

receiving operational device authentication information from a third party tenant application, the third party tenant application communicating with the plurality of operational technology devices;

providing the operational device authentication information with foglet identification information using the root of trust of the fog Node; and

communicating the operational device authentication information with the foglet identification information to the third party tenant application, the third party tenant application communicating the operational device authentication information with the foglet identification information to the third party cloud application, the third party cloud application validating the industrial data streams from the plurality of operational technology devices using the operational device authentication information and the foglet identification information.

2. The method of claim 1 , further comprising:

an offline policy engine, the offline policy engine conditionally elevating security based on analysis of the industrial data streams from the plurality of operational technology devices using a threshold for at least one of data volume of the industrial data streams, frequency of the industrial data streams, and a machine learning filter of the industrial data streams.

3. The method of claim 1 , wherein the operational device authentication information comprises manufacturer identification information of the plurality of operational technology devices.

4. The method of claim 3 , further comprising:

grouping of the industrial data streams from the plurality of operational technology devices based on the manufacturer identification information of the plurality of operational technology devices.

5. The method of claim 1 , wherein the root of trust of the fog Node is a hardware root of trust, the hardware root of trust being a Trusted Platform Module of the fog Node.

6. The method of claim 1 , wherein the root of trust of the fog Node is a hardware root of trust, the hardware root of trust being a Trusted Platform Module located in the foglet.

7. The method of claim 5 , wherein the providing of the foglet encryption information comprises the fog Node generating a private signing key with the Trusted Platform Module of the fog Node.

8. The method of claim 7 , wherein the providing of the foglet encryption information further comprises the Trusted Platform Module of the fog Node returning a public key to a virtual machine of the fog Node.

9. The method of claim 1 , wherein the operational device authentication information from the third party tenant application comprises a signed authentication cookie.

10. The method of claim 1 , wherein the providing of the foglet encryption information comprises the fog Node providing a private signing key with the Trusted Platform Module of the fog Node.

11. The method of claim 1 , wherein the foglet identification information using the root of trust of the fog Node comprises a time limited, client server specific signed token.

12. The method of claim 11 , wherein the validation of the industrial data streams from the plurality of operational technology devices comprises validation of the time limited, client server specific signed token by a token validator of the fog cloud manager.

13. The method of claim 1 , wherein the foglet identification information using the root of trust of the fog Node comprises:

a first time limited, client server specific signed identity token, the identity token comprising foglet identification information for the validating of the industrial data streams from the plurality of operational technology devices; and

a second time limited, client server specific signed access control token, the access control token comprising a timestamp and metadata attributes.

14. The method of claim 13 , wherein the validation of the industrial data streams from the plurality of operational technology devices comprises validation of the first time limited, client server specific signed identity token and the second time limited, client server specific signed access control token by a token validator of the fog cloud manager.

Assignments (4)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 19, 2025
From: TTTECH INDUSTRIAL AUTOMATION AG
To: TTTECH COMPUTERTECHNIK AG
Reel/Frame 072315/0115 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 9, 2021
From: NEBBIOLO TECHNOLOGIES, INC.
To: TTTECH INDUSTRIAL NORTH AMERICA, INC.
Reel/Frame 058053/0763 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 9, 2021
From: TTTECH INDUSTRIAL NORTH AMERICA, INC.
To: TTTECH INDUSTRIAL AUTOMATION AG
Reel/Frame 058053/0801 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 26, 2018
From: TEWARI, RUCHIR; GOWDA, THUSHAR; BHAGRA, PANKAJ; NARAYANAN, THIRU; CHINNAKANNAN, PALANI
To: NEBBIOLO TECHNOLOGIES, INC.
Reel/Frame 047330/0627 →
Continuity (1)
Related Publication 20200137078A1 · Apr 30, 2020