IP Library Granted Patent US 12,609,840
Granted Patent B2
US 12,609,840 · App. 18/378,979 · Granted Apr 21, 2026

Control apparatus, control method, and computer-readable recording medium for automation system

Inventors: Takeshi Toinaga (Tokyo, JP); Vien Nguyen (Carrollton, TX); Andrew Keller (Carrollton, TX); Yoshitaka Yoshida (Tokyo, JP)
Assignee: Yokogawa Electric Corporation
H04L9/3268
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,609,840
App. No.
18/378,979
Granted
Apr 21, 2026
Kind
B2
Abstract

A control apparatus transmits a self-signed certificate to a management server, receives a certificate authority signature certificate generated by the management server according to the self-signed certificate, and executes data communication in the control system that executes control of a system on the basis of the certificate authority signature certificate.

Claims (36)

1 . A control apparatus, comprising:

a memory; and

a processor coupled to the memory, wherein the processor executes a process comprising:

transmitting, to a management server having a function of a certificate authority and having individual identification information set for a control apparatus registered therein, a self-signed certificate that is a digital certificate of the control apparatus generated using a public key and the identification information of the control apparatus, the control apparatus executing data communication in a control system of a plant including a plurality of field devices;

receiving, from the management server, a certificate authority signature certificate that is a digital certificate of the management server generated by the management server on condition that the identification information of the control apparatus that has transmitted the self-signed certificate is determined to be registered based on information obtained from the self-signed certificate; and

executing data communication in the control system on the basis of the certificate authority signature certificate, wherein

the transmitting transmits the self-signed certificate to the management server, when the control apparatus is connected to a communication network including the management server for the first time or when the control apparatus is connected to the communication network including the management server after a system configuration of a system to which the control apparatus belongs is changed, and

the executing executes data communication that is encrypted using encryption information obtained from the certificate authority signature certificate when executing the data communication in the control system after receiving the certificate authority signature certificate.

2 . The control apparatus according to claim 1 , wherein

the transmitting transmits the self-signed certificate to the management server using a registered Internet protocol address or host name of the management server,

the receiving receives the certificate authority signature certificate generated by the management server adding a certificate authority signature to the self-signed certificate, and

the executing executes data communication capable of verifying falsification or capable of verifying validity of the certificate authority signature certificate in the control system by using encryption information included in the certificate authority signature certificate.

3 . The control apparatus according to claim 2 , the process further comprising:

registering individual information including an Internet protocol address or a host name of the control apparatus in the management server by using the Internet protocol address or the host name of the management server.

4 . The control apparatus according to claim 2 , wherein

the receiving receives the certificate authority signature certificate generated by the management server in a case where individual information including the Internet protocol address or the host name of the control apparatus is registered.

5 . The control apparatus according to claim 1 , wherein

the transmitting transmits the self-signed certificate to the management server a predetermined time before an expiration date of the certificate authority signature certificate.

6 . The control apparatus according to claim 1 , wherein

the control system or the control apparatus conforms to Open Process Automation (OPA), Module Type Package (MTP), or NAMUR Open Architecture (NOA).

7 . The control apparatus according to claim 1 , wherein

the control system or the control apparatus conforms to Open Platform Communications Unified Architecture (OPC UA).

8 . The control apparatus according to claim 1 , wherein

the control system or the control apparatus executes control of a plant.

9 . A control method comprising, by a computer:

transmitting, to a management server having a function of a certificate authority and having individual identification information set for a control apparatus registered therein, a self-signed certificate that is a digital certificate of the control apparatus generated using a public key and the identification information of the control apparatus, the control apparatus executing data communication in a control system of a plant including a plurality of field devices;

receiving, from the management server, a certificate authority signature certificate that is a digital certificate of the management server generated by the management server on condition that the identification information of the control apparatus that has transmitted the self-signed certificate is determined to be registered based on information obtained from the self-signed certificate; and

executing data communication in the control system on the basis of the certificate authority signature certificate, wherein

the transmitting transmits the self-signed certificate to the management server, when the computer is connected to a communication network including the management server for the first time or when the computer is connected to the communication network including the management server after a system configuration of a system to which the computer belongs is changed, and

the executing executes data communication that is encrypted using encryption information obtained from the certificate authority signature certificate when executing the data communication in the control system after receiving the certificate authority signature certificate.

10 . A non-transitory computer-readable recording medium that records an control program for causing a computer to execute processing of:

transmitting, to a management server having a function of a certificate authority and having individual identification information set for a control apparatus registered therein, a self-signed certificate that is a digital certificate of the control apparatus generated using a public key and the identification information of the control apparatus, the control apparatus executing data communication in a control system of a plant including a plurality of field devices;

receiving, from the management server, a certificate authority signature certificate that is a digital certificate of the management server generated by the management server on condition that the identification information of the control apparatus that has transmitted the self-signed certificate is determined to be registered based on information obtained from the self-signed certificate; and

executing data communication in the control system on the basis of the certificate authority signature certificate, wherein

the transmitting transmits the self-signed certificate to the management server, when the computer is connected to a communication network including the management server for the first time or when the computer is connected to the communication network including the management server after a system configuration of a system to which the computer belongs is changed, and

the executing executes data communication that is encrypted using encryption information obtained from the certificate authority signature certificate when executing the data communication in the control system after receiving the certificate authority signature certificate.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 14, 2023
From: TOINAGA, TAKESHI; NGUYEN, VIEN; KELLER, ANDREW; YOSHIDA, YOSHITAKA
To: YOKOGAWA ELECTRIC CORPORATION
Reel/Frame 065559/0219 →
Continuity (1)
Related Publication 20250125977A1 · Apr 17, 2025
References Cited (22)
US 6826685B1 · Douglas · 2004 [cited by examiner]
US 7624264B2 · Aura · 2009 [cited by examiner]
US 8380992B2 · Park · 2013 [cited by examiner]
US 10277406B1 · Veladanda · 2019 [cited by examiner]
US 10411902B2 · Kalan · 2019 [cited by examiner]
US 10547605B2 · Ajitomi et al. · 2020 [cited by applicant]
US 20040230793A1 · Estrada · 2004 [cited by examiner]
US 20040250062A1 · Douglas · 2004 [cited by examiner]
US 20050005097A1 · Murakawa · 2005 [cited by examiner]
US 20060200857A1 · Yokota · 2006 [cited by examiner]
US 20080209208A1 · Parkinson · 2008 [cited by examiner]
US 20180322274A1 · Lutz · 2018 [cited by examiner]
US 20200137044A1 · Shimazawa · 2020 [cited by examiner]
US 20200274721A1 · Melo · 2020 [cited by examiner]
US 20220138303A1 · Lutz · 2022 [cited by examiner]
US 20220147029A1 · Hoernicke · 2022 [cited by examiner]
US 20240243925A1 · Ben-Yehezkel · 2024 [cited by examiner]
US 20240333529A1 · Metzger · 2024 [cited by examiner]
US 20250125977A1 · Toinaga · 2025 [cited by examiner]
EP 3993339A1 · 2022 [cited by applicant]
JP 202246438A · 2022 [cited by applicant]
Extended European Search Report (EESR) dated Nov. 29, 2024 issued in European patent application No. 24205187.8. [cited by applicant]