IP Library Granted Patent US 12,437,114
Granted Patent B2
US 12,437,114 · App. 18/849,595 · Granted Oct 7, 2025

Method and system for granting access rights to control applications of an industrial automation system

Inventors: Peter Kob (Heroldsberg, DE); Maximilian Hoch (Adelsdorf, DE)
Assignee: Siemens Aktiengesellschaft
G06F21/629G06F9/45558G06F2009/45562G06F2009/4557
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,437,114
App. No.
18/849,595
Granted
Oct 7, 2025
Kind
B2
Abstract

System and method for granting access rights to control applications of an industrial automation system, wherein first control applications are initially provided via software containers that are loaded into a container runtime environment installed on a host operating system, and executed there, the first control applications are monitored and configured via an application management system, additionally the first control applications are authenticated via the application management system, second control applications are executed and cryptographically authenticated directly on a host operating system, and data traffic from the first and second control applications to target devices and/or applications are each authorized after successful authentication via an at least temporarily valid access key inserted into the data traffic.

Claims (29)

1. A method of granting access rights to control applications of an industrial automation system, the method comprising:

providing first control applications via software containers which are loaded into and executed in a container runtime environment installed on a host operating system, the software containers for the first control applications each being at least one of (i) migratable from one automation device having a container runtime environment to another automation device having a container runtime environment for execution there and (ii) executable simultaneously on a plurality of automation devices having a container runtime environment;

monitoring and configuring the first control applications via an application management system;

detecting, by the application management system, at least one of creation, deletion and modification of the software containers, and registering, by the application management system, the software containers with their respective execution status, at least one of the creation, deletion and modification of the software containers each comprising allocating or releasing resources in a respective automation device having a container runtime environment;

authenticating the first control applications via the application management system;

executing and cryptographically authenticating second control applications directly on a host operating system; and

authorizing data traffic from at least one of (i) the first and the second control applications to target devices and (ii) target applications following successful authentication in each case via an at least temporarily valid access key inserted into the data traffic;

wherein the first and second control applications are installed on automation devices which comprise a secured subnetwork which is assigned to the industrial automation system; and

wherein the first and the second control applications are accessed from outside the secured subnetwork only following authorization by the application management system.

2. The method as claimed in claim 1 , wherein the data traffic is authorized only for trusted first control applications and second control applications which are provided at least one of via a trusted path and by a trusted instance.

3. The method as claimed in claim 2 , wherein access keys are each inserted into the respective data traffic by an assigned injector component separated from the first control applications and the second control applications; and wherein the first and the second control applications are authenticated to the respective assigned injector component.

4. The method as claimed in claim 2 , wherein the second control applications are cryptographically authenticated via at least one of digital signatures, computing process identifiers and the operating system itself.

5. The method as claimed in claim 1 , wherein access keys are each inserted into the respective data traffic by an assigned injector component separated from the first control applications and the second control applications; and wherein the first and the second control applications are authenticated to the respective assigned injector component.

6. The method as claimed in claim 5 , wherein the second control applications are cryptographically authenticated via at least one of digital signatures, computing process identifiers and the operating system itself.

7. The method as claimed in claim 1 , wherein the second control applications are cryptographically authenticated via at least one of digital signatures, computing process identifiers and the operating system itself.

8. The method as claimed in claim 7 , wherein root keys are transferred onto the respective automation device for authentication during commissioning processes of automation devices upon which the second control applications are installed; and wherein a root key is required on each respective automation device for a successful authentication of a second control application.

9. The method as claimed in claim 8 , wherein the root keys are each continuously exchanged during operation of the automation devices.

10. The method as claimed in claim 1 , wherein the first and the second control applications each have and/or perform no authentication functions.

11. The method as claimed in claim 1 , wherein the first and second control applications are authenticated to an injector component assigned to the application management system for accessing a cloud computing system outside the secured subnetwork;

wherein, following successful authentication, the injector component assigned to the application management system in each case inserts at least temporarily valid access keys into data traffic from the first and the second control applications to the cloud computing system; and

wherein access by the first and the second control applications to the cloud computing system is subsequently authorized securely and efficiently via the at least temporarily valid access keys.

12. A system comprising:

a plurality of automation devices which are configured to provide first control applications via software containers which are loadable into and executable in a container runtime environment installed on a host operating system, selected automation devices being configured to execute and cryptographically authenticate second control applications directly on a host operating system;

an application management system which is configured to monitor, configure and authenticate the first control applications;

wherein the software containers for the first control applications are each at least one of (i) migratable from one automation device having a container runtime environment to another automation device having a container runtime environment for execution there and (ii) executable simultaneously on a plurality of automation devices having a container runtime environment;

wherein the application management system is configured to detect at least one of creation, deletion and modification of the software containers and to register the software containers with their respective execution status, at least one of the creation, deletion and modification of the software containers each comprising allocating or releasing resources in the respective automation device having a container runtime environment;

wherein the system is configured to authorize data traffic from the first and the second control applications to at least one of (i) target devices and (ii) target applications following successful authentication in each case via an at least temporarily valid access key inserted into the data traffic;

wherein the first and second control applications are installed on automation devices which comprise a secured subnetwork which is assigned to the industrial automation system; and

wherein the first and the second control applications are accessed from outside the secured subnetwork only following authorization by the application management system.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 19, 2025
From: KOB, PETER; HOCH, MAXIMILIAN
To: SIEMENS AKTIENGESELLSCHAFT
Reel/Frame 070262/0735 →
Priority Claims (1)
EP 22164332 · Mar 25, 2022 · regional
Continuity (1)
Related Publication 20250165653A1 · May 22, 2025
References Cited (18)
US 10922090B1 · Lieberman et al. · 2021 [cited by applicant]
US 20050240906A1 · Kinderknecht · 2005 [cited by examiner]
US 20050283830A1 · Guthery · 2005 [cited by examiner]
US 20150281233A1 · Asenjo et al. · 2015 [cited by applicant]
US 20160164673A1 · Grimault · 2016 [cited by examiner]
US 20180268156A1 · Luo et al. · 2018 [cited by applicant]
US 20180367528A1 · Schwarz et al. · 2018 [cited by applicant]
US 20190182295A1 · Pulapaka · 2019 [cited by examiner]
US 20210019416A1 · Höfele et al. · 2021 [cited by applicant]
US 20250090964A1 · Grimm · 2025 [cited by examiner]
CN 110383240 · 2019 [cited by applicant]
CN 112241533 · 2021 [cited by applicant]
CN 112988333 · 2021 [cited by applicant]
CN 114598463B · 2024 [cited by examiner]
CN 114154173B · 2024 [cited by examiner]
EP 4194973 · 2023 [cited by applicant]
WO 2021104632 · 2021 [cited by applicant]
PCT International Search Report dated Jun. 15, 2023 based on PCT/EP2023/054785 filed Feb. 27, 2023. [cited by applicant]