IP Library › Granted Patent US 12,656,962
Granted Patent B2
US 12,656,962 · App. 18/974,050 · Granted Jun 16, 2026

Authentication server, authentication system, and authentication method

Inventor: Makoto Ikeda (Tokyo, JP)
Assignee: Hitachi Indusrty & Control Solutions, Ltd.
G06F3/0622G06F3/0655G06F3/0673
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,656,962
App. No.
18/974,050
Granted
Jun 16, 2026
Kind
B2
Abstract

An authentication server capable of accessing data in a memory of a control device is configured to: detect authentication input information being written into the memory by monitoring access to the memory and read, from the memory, the authentication input information written into the memory; check the authentication input information against account information registered in a user database to generate an authentication result for the authentication input information; and write the authentication result for the authentication input information into the memory of the control device, thereby to notify the control device of availability of control processing based on the authentication result.

Claims (29)

1 . An authentication server capable of accessing data in a memory of a programmable logic controller (PLC) that does not implement standard authentication protocols and that is connected to manufacturing equipment, the authentication server configured to:

detect authentication input information being written into the memory of the PLC by monitoring access to the memory of the PLC and read, from the memory of the PLC, the authentication input information written into the memory of the PLC;

check the authentication input information against account information registered in a user database to generate an authentication result for the authentication input information; and

write the authentication result for the authentication input information into the memory of the PLC, thereby to notify the PLC of availability of control processing for the manufacturing equipment based on the authentication result.

2 . The authentication server according to claim 1 ,

wherein the account information registered in the user database is associated with, in addition to the authentication input information, an identifier of the PLC, and

wherein the authentication server is further configured to, when the identifier of the PLC, in which the authentication server has detected the authentication input information, has been registered in the user database in addition to the authentication input information, generate the authentication result so as to indicate granting of authentication.

3 . The authentication server according to claim 1 ,

wherein the account information registered in the user database is associated with, in addition to the authentication input information, information on operation privileges for performing functions provided by the PLC, and

wherein the authentication server is further configured to, when writing the authentication result into the memory of the PLC, write information on the operation privileges into the memory as well, thereby to notify the PLC of the availability of control processing according to the operation privileges based on the authentication result.

4 . The authentication server according to claim 1 ,

wherein the authentication server is further configured to, when the authentication server writes the authentication result into the memory of the PLC and then receives a notification from the PLC that a forcible logout occurs due to no operation on the PLC having been performed for a predetermined time, delete the authentication result from the memory of the PLC.

5 . An authentication system comprising a programmable logic controller (PLC) that does not implement standard authentication protocols and that is connected to manufacturing equipment, an authentication server, and a directory server,

wherein the PLC is configured to write input authentication input information into a memory of the PLC,

wherein the authentication server is configured to detect the authentication input information being written into the memory by monitoring access to the memory, read, from the memory, the authentication input information written into the memory, and transmit an authentication request including the authentication input information to the directory server,

wherein the directory server is configured to check the authentication input information included in the authentication request against account information registered in a user database to generate an authentication result for the authentication input information and return the generated authentication result to the authentication server,

wherein the authentication server is further configured to write the authentication result for the authentication input information into the memory, and

wherein the PLC is further configured to read the authentication result written into the memory and determine availability of control processing for the manufacturing equipment based on the authentication result read from the memory.

6 . The authentication system according to claim 5 ,

wherein the authentication server is further configured to, when no response to the authentication request transmitted to the directory server is received for a predetermined time, write the authentication result into the memory so as to indicate a failure of authentication processing.

7 . The authentication system according to claim 5 ,

wherein the PLC is further configured to encrypt information to be written into the memory and write the encrypted information into the memory, and

wherein the authentication server is further configured to decrypt information read from the memory.

8 . The authentication server according to claim 1 , wherein the authentication input information comprises a user ID and a password.

9 . The authentication system according to claim 5 , wherein the authentication input information comprises a user ID and a password.

10 . An authentication method for an authentication server, the authentication server being capable of accessing data in a memory of a programmable logic controller (PLC) that does not implement standard authentication protocols and that is connected to manufacturing equipment, the authentication method comprising steps of, by the authentication server:

detecting authentication input information being written into the memory of the PLC by monitoring access to the memory of the PLC and reading, from the memory of the PLC, the authentication input information written into the memory of the PLC;

checking the authentication input information against account information registered in a user database to generate an authentication result for the authentication input information; and

writing the authentication result for the authentication input information into the memory of the PLC, thereby to notify the PLC of availability of control processing for the manufacturing equipment based on the authentication result.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 9, 2024
From: IKEDA, MAKOTO
To: HITACHI INDUSTRY & CONTROL SOLUTIONS, LTD.
Reel/Frame 069527/0367 →
Priority Claims (1)
JP 2024-005902 · Jan 18, 2024 · national
Continuity (1)
Related Publication 20250238148A1 · Jul 24, 2025
References Cited (3)
US 20020026582A1 · Futamura · 2002 [cited by examiner]
JP 2021096512A · 2021 [cited by applicant]
JP 7499426B1 · 2024 [cited by applicant]