IP Library Granted Patent US 12,019,418
Granted Patent B2
US 12,019,418 · App. 17/231,682 · Granted Jun 25, 2024

Access control within a modular automation system

Inventor: Björn Leander (Västerås, SE)
Assignee: ABB Schweiz AG
G05B19/0421G05B19/0426G05B19/048G05B2219/13108G05B2219/2222G05B2219/2642
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,019,418
App. No.
17/231,682
Filed
Apr 15, 2021
Granted
Jun 25, 2024
Kind
B2
Art Unit
2119
USPC
700/19
Abstract

A method for managing access control within a modular automation system including at least two automation modules. Each automation module is associated with an operation or a set of operations for carrying out a specific task. The method includes: receiving a schema of a common process including at least the order of processing steps of the modular automation system, wherein each processing step includes one or more of the specific tasks of the automation modules; generating privilege associations for each processing step with one or more automation modules, based on the schema; and generating an access control policy for the automation modules based on the privilege associations.

Claims (32)

1. A method for managing access control within a modular automation system including at least two automation modules, wherein each automation module is associated with an operation or a set of operations for carrying out a specific task, the method comprising:

receiving a schema of a common process including at least the order of processing steps of the modular automation system, each processing step having one or more of the specific tasks of the automation modules;

generating privilege associations for each processing step with one or more automation modules, based on said schema;

generating an access control policy for the automation modules based on the privilege associations, such that access is only allowed based on the privileged associations.

2. The method according to claim 1 , wherein the modular automation system comprises a central operating unit configured to communicate with each one of the automation modules, and wherein the method further includes the step of:

executing the schema by the central operating unit in accordance with the generated access control policy.

3. The method according to claim 2 , wherein the step of executing the schema by the central operating unit includes applying the principle of least privilege in the access control for the automation modules.

4. The method according to claim 1 , wherein the access control policy is based on an attribute-based access control, ABAC.

5. The method according to claim 1 , wherein the schema is a sequential function chart, SFC.

6. The method according to claim 1 , further comprising the steps:

deactivating a schema:

remove the privilege associations for the deactivated schema.

7. The method according to claim 1 , wherein the generated access control policy is based on next generation access control, NGAC or eXtensible Access Control Markup Language, XACML.

8. The method according to claim 1 , wherein the automation modules may be rearranged in order to perform different common processes.

9. The method according to claim 8 , wherein said common process is a first common process and said schema is a first schema, and the at least two automation modules are operable according to a second common process corresponding to a second schema different to said first schema, wherein the method further comprises:

generating updated privilege associations for each processing step with one or more automation modules, based on said second schema;

generating an updated access control policy for the automation modules based on the updated privilege associations.

10. An automation security system for a modular automation system including at least two automation modules, each automation module being associated with an operation or a set of operations for carrying out a specific task, the system comprising:

means for receiving a schema of a common process including at least the order of processing steps of the modular automation system, each processing step having one or more of the specific tasks of the automation modules;

a data unit configured to generate privilege associations for each processing step with one or more automation modules, based on said schema, and to generate an access control policy for the automation modules based on the privilege associations, such that access is only allowed based on the privileged associations.

11. The system according to claim 10 further comprising:

a central operating unit configured to communicate with each one of the automation modules and to execute the schema;

a policy data unit including the access control policy,

wherein the central operating unit is adapted to execute the schema in accordance with access control policy.

12. The system according to claim 10 , wherein the access control to the automation modules is based on an attribute-based access control, ABAC.

13. The system according to claim 10 , wherein the schema is a sequential function chart, SFC, and the central operating unit is configured execute the SFC, and/or wherein the access control policy is based on next generation access control, NGAC or eXtensible Access Control Markup Language, XACML.

14. The system according to claim 10 , wherein the system is configured to upon deactivation of a schema, remove the privilege associations related to the deactivated schema.

15. The system according to claim 10 , wherein said common process is a first common process and said schema is a first schema, and the at least two automation modules are operable according to a second common process corresponding to a second schema different to said first schema, and wherein the data unit is adapted to generate updated privilege associations for each processing step with one or more automation modules based on the second schema, and to generate an updated access control policy for the automation modules based on the updated privilege associations.

16. The system according to claim 10 , wherein the system is configured to carry out a method including the steps of:

receiving a schema of a common process including at least the order of processing steps of the modular automation system, each processing step including one or more of the specific tasks of the automation modules;

generating privilege associations for each processing step with one or more automation modules, based on said schema; and

generating an access control policy for the automation modules based on the privilege associations.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 27, 2021
From: LEANDER, BJÖRN
To: ABB SCHWEIZ AG
Reel/Frame 056050/0590 →
Priority Claims (1)
EP 20171980 · Apr 29, 2020 · regional
Continuity (1)
Related Publication 20210341894A1 · Nov 4, 2021