IP Library Granted Patent US 11,533,304
Granted Patent B2
US 11,533,304 · App. 17/228,954 · Granted Dec 20, 2022

Securing sensitive historian configuration information

Inventors: Ryan B. Saldanha (Anaheim, CA); Vinay T. Kamath (Rancho Santa Margarita, CA); Peijen Lin (Irvine, CA); Abhijit Manushree (Laguna Niguel, CA)
Assignee: AVEVA SOFTWARE, LLC
H04L63/0823G06F21/6209G06F21/64H04L63/0442
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,533,304
App. No.
17/228,954
Granted
Dec 20, 2022
Kind
B2
Abstract

Systems and methods for securing configuration information for cloud-based services. A system comprises a data store and data sets including plant process information and configuration information. A memory device stores computer-executable instructions. When executed by a processor coupled to the cloud service, the instructions receive configuration information, store it in a data file, apply a generated certificate to the file, and deploy the resulting protected configuration data file to the cloud-based service. In addition, the protected configuration data file is made available by obtaining the file from the cloud-based service.

Claims (46)

1. A cloud-based computer system comprising:

one or more computers comprising one or more processors and one or more non-transitory computer readable media, the one or more non-transitory computer readable media storing computer-executable instructions that cause the one or more computers to:

transmit, by the one or more processors, time series data,

connect, by the one or more processors, to a cloud-based data store;

connect, by the one or more processors, to a cloud service,

connect, by the one or more processors, to a service role,

generate, by the one or more processors, a configuration data file,

generate, by the one or more processors, configuration data, and

generate, by the one or more processors, configuration settings;

wherein the time series data includes plant data representative of historical plant process information;

wherein the cloud-based data store is configured to receive and store the time series data and the configuration data file;

wherein the service role is configured to receive the configuration data and store the configuration data in the configuration data file;

wherein the configuration data comprises the configuration settings; and

wherein the cloud service is configured to read the configuration settings from the configuration data file in response to a query by the service role.

2. The system of claim 1 ,

the one or more non-transitory computer readable media storing computer-executable instructions that further cause the one or more computers to:

generate, by the one or more processors, a certificate,

apply, by the one or more processors, the certificate to the configuration data file to transform the configuration data file into a protected configuration data file,

generate, by the one or more processors, a private key associated with the certificate, and

deploy, by the one or more processors, the protected configuration data file for querying by the service role.

3. The system of claim 2 ,

wherein the protected configuration data file comprises encrypted configuration values as well as a thumbprint of the certificate stored in a service configuration file.

4. The system of claim 3 ,

wherein the thumbprint uniquely identifies the certificate.

5. The system of claim 4 ,

wherein said applying, by the one or more processors, the certificate to the configuration data file to transform the configuration data file into a protected configuration data file, includes a user pointing to the thumbprint of the certificate to begin an encryption process.

6. The system of claim 5 ,

wherein access to the private key is not required to begin the encryption process.

7. The system of claim 5 ,

wherein the thumbprint is provided by an out-of-band communication.

8. The system of claim 2 ,

the one or more non-transitory computer readable media storing computer-executable instructions that cause the one or more computers to:

enable, by the one or more processors, a user to access to the certificate without providing the user access to configuration information.

9. The system of claim 8 ,

wherein decoding the configuration information requires a use of the private key.

10. The system of claim 9 ,

wherein the configuration information is protected by three levels of protection.

11. The system of claim 10 ,

wherein the three levels of protection include a first level of protection; and

wherein the first level of protection requires a use of the private key to access the configuration information.

12. The system of claim 11 ,

wherein the three levels of protection include a second level of protection; and

wherein the second level of protection includes required knowledge of what configuration information to use that is contained in the configuration data file.

13. The system of claim 12 ,

wherein the three levels of protection include a third level of protection; and

wherein the third level of protection includes required access to physical hard drives to access the configuration information.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 21, 2021
From: SALDANHA, RYAN B.; KAMATH, VINAY T.; LIN, PEIJEN; MANUSHREE, ABHIJIT
To: INVENSYS SYSTEMS INC.
Reel/Frame 056606/0677 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 21, 2021
From: INVENSYS SYSTEMS, INC.
To: SCHNEIDER ELECTRIC SOFTWARE, LLC
Reel/Frame 056607/0299 →
CHANGE OF NAME Recorded Jun 21, 2021
From: SCHNEIDER ELECTRIC SOFTWARE, LLC
To: AVEVA SOFTWARE, LLC
Reel/Frame 056638/0485 →
Continuity (3)
Continuation 16249623 · Jan 16, 2019
Continuation 14638506 · Mar 4, 2015
Related Publication 20210306327A1 · Sep 30, 2021