IP Library › Granted Patent US 12,524,516
Granted Patent B2
US 12,524,516 · App. 17/705,838 · Granted Jan 13, 2026

Multi-factor authentication of industrial assets

Inventor: James Redmond (Richmond, CA)
Assignee: SCHNEIDER ELECTRIC SYSTEMS USA, INC.
G06F21/40G06F21/32
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,524,516
App. No.
17/705,838
Granted
Jan 13, 2026
Kind
B2
Abstract

A multi-factor authentication method and system enabling secure access to an industrial asset. A higher level of authentication to access a selected privileged operation of the industrial asset requires verification of two or more multi-factor access credentials.

Claims (32)

1 . A multi-factor authentication method for enabling secure access to an industrial asset, comprising:

determining a level of authentication required to access a selected operation of the industrial asset;

requesting two or more access credentials based on the determined level of authentication;

in response to receiving the requested access credentials, verifying the requested access credentials to determine if the requested access credentials match credentials required to access the selected operation, wherein verifying the requested access credentials comprises:

authenticating a user by a human-machine interface (HMI) using a first access credential, wherein the HMI is associated with the industrial asset, and wherein the HMI and the industrial asset are located remotely from each other; and

authenticating the user by the industrial asset using a second access credential:

in response to the requested access credentials matching the credentials required to access the selected operation, enabling access to the selected operation by the user, wherein enabling access by the user to the selected operation comprises enabling secure access to a non-privileged portion of the selected operation in response to verifying a first access credential and enabling secure access to a privileged portion of the selected operation in response to verifying the first access credential and a second access credential; and

in response to the requested access credentials not matching the credentials required to access the privileged portion of the selected operation, denying access by the user to the privileged portion of the selected operation;

wherein the industrial asset includes a run-time mode of operation and a privileged mode of operation, the run-time mode allowing deployment of application content via local certificate, and the privileged mode allowing integrator certificate deployment via local access;

wherein running services of the industrial asset are dynamically restricted when the industrial asset is not in the privileged mode; and

wherein services requiring physical presence at the industrial asset are enabled when the industrial asset is in the privileged mode.

2 . The method of claim 1 , wherein the level of authentication required to access the selected operation of the industrial asset is customizable based on one or more of the following: customer preferences, firmware/software upgrades, or communication availability.

3 . The method of claim 1 , wherein the industrial asset includes at least one of: a remote terminal unit (RTU), a programmable logic controller (PLC), a multivariable transmitter (MVT), or a sensor.

4 . The method of claim 1 , further comprising receiving at least one of the requested access credentials via physical storage media.

5 . The method of claim 1 , wherein verifying the requested access credentials comprises executing a multi-factor authentication system.

6 . The method of claim 1 , wherein requesting the access credentials comprises requesting and validating a first access credential before requesting a second access credential.

7 . The method of claim 1 , wherein the selected operation includes the privileged mode of operation associated with the industrial asset.

8 . The method of claim 1 , further comprising receiving, via the HMI, a request to access the selected operation of the industrial asset, wherein requesting the access credentials is responsive to the request to access the selected operation.

9 . The method of claim 1 , further comprising, in response to the requested access credentials not matching the credentials required to accessing the selected operation, logging an instance of denying access to the selected operation by the user and generating a report representative thereof.

10 . A system for enabling secure access to a selected operation of an industrial asset, comprising:

an industrial asset having a privileged operational mode and a run-time operational mode, the privileged operational mode requiring a higher level of authentication than the run-time operational mode, wherein the run-time operational mode allows deployment of application content with local certificate authentication and the privileged operational mode allows integrator certificate deployment via local access; and

a computing device communicatively coupled to the industrial asset, the computing device configured to enable secure access to a portion of the selected operation in response to verifying a first access credential for performing one or more functionalities associated with the run-time operational mode and to enable secure access to another portion of the selected operation in response to verifying a second access credential for performing one or more functionalities associated with the privileged operational mode in response to verification of two or more access credentials;

wherein the computing device comprises a human-machine interface (HMI) associated with the industrial asset, wherein the HMI is configured to authenticate a user using the first access credential, wherein the industrial asset is configured to authenticate the user using the second access credential, and wherein the HMI and the industrial asset are located remotely from each other;

wherein running services of the industrial asset are dynamically restricted when the industrial asset is not in the privileged operational mode; and

wherein services requiring physical presence at the industrial asset are enabled when the industrial asset is in the privileged operational mode.

11 . The system of claim 10 , wherein the level of authentication required to access the privileged operational mode of the industrial asset is customizable based on one or more of the following: customer preferences, firmware/software upgrades, or communication availability.

12 . The system of claim 10 , wherein the industrial asset includes at least one of: a remote terminal unit (RTU), a programmable logic controller (PLC), a multivariable transmitter (MVT), or a sensor.

13 . The system of claim 10 , further comprising an external physical storage media storing at least one of the access credentials.

14 . The system of claim 10 , further comprising a multi-factor authentication system communicatively coupled to the industrial asset and the computing device for distributing at least one of the access credentials.

15 . The system of claim 10 , wherein the industrial asset includes an embedded processing device configured to access a selected operation of the privileged operational mode via at least one of a wired protocol, a wireless protocol, or a human machine interface.

16 . The system of claim 10 , further comprising a biometric data reader configured to receive biometric data from a user and to generate at least one of the access credentials based thereon.

17 . The system of claim 16 , wherein the biometric data reader is a fingerprint reader.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 20, 2022
From: REDMOND, JAMES
To: SCHNEIDER ELECTRIC SYSTEMS USA, INC.
Reel/Frame 060754/0472 →
Continuity (1)
Related Publication 20230306099A1 · Sep 28, 2023
References Cited (18)
US 11244034B1 · Nagappan · 2022 [cited by examiner]
US 20070011452A1 · Marquet · 2007 [cited by examiner]
US 20090193151A1 · Adams · 2009 [cited by examiner]
US 20130036462A1 · Krishnamurthi · 2013 [cited by examiner]
US 20150046697A1 · Galpin · 2015 [cited by examiner]
US 20150227732A1 · Doctor · 2015 [cited by examiner]
US 20150281279A1 · Smith · 2015 [cited by examiner]
US 20180026954A1 · Toepke et al. · 2018 [cited by applicant]
US 20180316671A1 · Brown · 2018 [cited by examiner]
US 20190147153A1 · Bai · 2019 [cited by examiner]
US 20200082108A1 · Griffin · 2020 [cited by examiner]
US 20210288805A1 · Lev · 2021 [cited by examiner]
US 20210377018A1 · Lawrence · 2021 [cited by examiner]
US 20220094686A1 · Jain · 2022 [cited by examiner]
WO 2019191394A1 · 2019 [cited by applicant]
Stouffer et al., Guide to Industrial Control Systems (ICS) Security, NIST Revision 2 (Year: 2015). [cited by examiner]
Stouffer et al., “Guide to Industrial Control Systems (ICS) Security, Revision2”, National Institute of Technology, May 1, 2025, pp. 1-247. [cited by applicant]
Extended European Search Report from EP Application No. 23161043.7, dated Aug. 28, 2023, 11 pages. [cited by applicant]