IP Library › Granted Patent US 12,732,345
Granted Patent B2
US 12,732,345 · App. 18/574,446 · Granted Sep 8, 2026

Control system for a technical installation and method for transferring a certificate request of an installation component

Inventors: Anna Palmin (Karlsruhe, DE); Marwin Madsen (Karlsruhe, DE)
Assignee: Siemens Aktiengesellschaft
H04L9/0825H04L9/3268
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,732,345
App. No.
18/574,446
Granted
Sep 8, 2026
Kind
B2
Abstract

A control system for a technical installation, particularly a process or manufacturing facility, includes a computer-implemented registration service that is configured to receive a certificate request from a component of the technical installation that comprises information regarding the identity of the installation component, configured to extract from a first memory information about which certificates of the installation component have already been assigned, can be assigned or are to be assigned, using the information regarding the identity of the installation component and the information about certificates that can be assigned or are to be assigned, configured to determine what the certificate request type is and which registration authority or certification authority of the technical installation is responsible for the certificate request, and is configured to transfer the certificate request of the installation component with information about the type of certificate request to the responsible registration authority or the responsible certification authority.

Claims (39)

1 . A control system for a process installation, the control system comprising:

an engineering station server including a processor and memory;

an operator station server including a processor and memory;

functionalities for representing, operating and controlling the process installation; and

a computer-implemented registration service;

wherein the computer-implemented registration service is configured to automatically:

receive a certificate request from an installation component of the process installation, said certificate request comprising information regarding an identity of the installation component;

extract, from a first memory, information about which certificates of the installation component have already been assigned, are assignable and are to be assigned;

determine, based on a linking of the information regarding the identity of the installation component and the information, extracted from the first memory, about the certificates which are assignable or are to be assigned, a type of the certificate request and which registration authority or which certification authority of the process installation is responsible for the certificate request; and

transfer the certificate request of the installation component, with information about the type of the certificate request, to the responsible registration authority or the responsible certification authority, the registration service utilizing the information extracted from the first memory to transform the certificate request from a rudimentary format into a more comprehensive format which includes a type of the certificate request;

wherein the computer-implemented registration service routes an issued certificate to the requesting installation component of the process installation subsequent to a check and issuance of the certificate request.

2 . The control system as claimed in claim 1 , wherein the registration service is computer-implemented on a component of a public key infrastructure of the technical installation.

3 . The control system as claimed in claim 1 , wherein the registration service is computer-implemented on a terminal of the process installation.

4 . The control system as claimed in claim 2 , wherein the registration service is computer-implemented on a terminal of the process installation.

5 . The control system as claimed in claim 1 , wherein the registration service includes relationships of trust with the installation component and with at least one of (i) the registration authority and (ii) the certification authority of the process installation; and wherein the relationships of trust are certificate-based.

6 . The control system as claimed in claim 1 , wherein the registration service is configured to extract, from the first memory or a second memory, the information about which registration authority or which certification authority of the process installation is responsible for the certificate request.

7 . The control system as claimed in claim 6 , wherein the first memory or the second memory is implemented on a component of a public key infrastructure.

8 . The control system as claimed in claim 6 , wherein the first memory or the second memory is implemented on the engineering station server or on the operator station server of the control system.

9 . The control system as claimed in claim 6 , wherein the first memory or the second memory is implemented on a terminal of the process installation.

10 . The control system as claimed in claim 6 , wherein the process installation comprises a chemical, pharmaceutical, petrochemical installation, or an installation from the food and drinks industry.

11 . An automated method for transferring a certificate request from an installation component of a process installation, which includes a computer-implemented registration service, to a registration authority or a certification authority of the process installation, an engineering station server including a processor and memory and an operator station server including a processor and memory, said method comprising:

receiving, via the registration service, a certificate request from an installation component of the process installation, the certificate request comprising information regarding an identity of the installation component;

extracting, via the registration service, information from a first memory about which certificates of the installation component are assignable and are to be assigned;

determining, via the registration service, based on a linking of the information regarding the identity of the installation component and the information, extracted from the first memory, about the certificates which have already been assigned, are assignable or are to be assigned, the type of the certificate request, the type representing an initial certificate request or a request for certificate renewal, and which registration authority or which certification authority of the process installation is responsible for the certificate request;

transferring, via the registration service, the certificate request of the installation component together with information about the type of the certificate request to the responsible registration authority or the responsible certification authority, the registration service utilizing the information extracted from the first memory to transform the certificate request from a rudimentary format into a more comprehensive format which includes a type of the certificate request; and

routing an issued certificate to the requesting installation component of the process installation subsequent.

12 . The method as claimed in claim 11 , wherein the registration service is computer-implemented on a component of a public key infrastructure of the process installation.

13 . The method as claimed in claim 11 , wherein the registration service is computer-implemented on a terminal of the process installation.

14 . The method as claimed in claim 12 , wherein the registration service is computer-implemented on a terminal of the process installation.

15 . The method as claimed in claim 11 wherein the registration service includes relationships of trust with the installation component and with at least one of (i) the registration authority and (ii) the certification authority of the process installation; and

wherein the relationships of trust are certificate-based.

16 . The method as claimed in claim 12 , wherein the registration service includes relationships of trust with the installation component and with at least one of (i) the registration authority and (ii) the certification authority of the process installation; and

wherein the relationships of trust are certificate-based.

17 . The method as claimed in claim 13 , wherein the registration service includes relationships of trust with the installation component and with at least one of (i) the registration authority and (ii) the certification authority of the process installation; and wherein the relationships of trust are certificate-based.

18 . The method as claimed in claim 11 , wherein the registration service extracts, from the first memory or a second memory, the information about which registration authority or which certification authority of the process installation is responsible for the certificate request.

19 . The method as claimed in claim 11 , wherein the first memory or the second memory is implemented on a component of a public key infrastructure.

20 . The method as claimed in claim 11 , wherein the first memory or the second memory is implemented on the engineering station server or on the operator station server of the control system.

21 . The method as claimed in claim 11 , wherein the first memory or the second memory is implemented on a terminal of the process installation.

22 . The control system of claim 1 , wherein the control system operates the process installation.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 5, 2024
From: PALMIN, ANNA; MADSEN, MARWIN
To: SIEMENS AKTIENGESELLSCHAFT
Reel/Frame 068180/0122 →
Priority Claims (1)
EP 21182334 · Jun 29, 2021 · regional
Continuity (1)
Related Publication 20240323001A1 · Sep 26, 2024
References Cited (22)
US 5745574A · Muftic · 1998 [cited by applicant]
US 20050069136A1 · Thornton · 2005 [cited by examiner]
US 20090319783A1 · Thornton · 2009 [cited by examiner]
US 20110154024A1 · Ignaci · 2011 [cited by examiner]
US 20110213965A1 · Fu · 2011 [cited by examiner]
US 20110213966A1 · Fu · 2011 [cited by examiner]
US 20160112406A1 · Bugrov et al. · 2016 [cited by applicant]
US 20170366537A1 · Bose · 2017 [cited by examiner]
US 20180323977A1 · Hojsik · 2018 [cited by examiner]
US 20200044869A1 · Lutz · 2020 [cited by examiner]
US 20200092115A1 · Palmin · 2020 [cited by examiner]
US 20200204381A1 · Meyer · 2020 [cited by examiner]
US 20210067352A1 · Fynaardt · 2021 [cited by examiner]
US 20210226802A1 · Zhu · 2021 [cited by examiner]
EP 3258662 · 2017 [cited by applicant]
EP 3734478 · 2020 [cited by applicant]
JP H10105612 · 1998 [cited by applicant]
JP 2006270646 · 2006 [cited by applicant]
JP 2007328411 · 2007 [cited by applicant]
JP 2020022165 · 2020 [cited by applicant]
PCT International Search Report dated Sep. 29, 2022 based on PCT/EP2022/067750 filed Jun. 28, 2022. [cited by applicant]
Brockhaus, H. et al.“Certificate Management Protocol (CMP) Updates draft-ietf-lamps-cmp-updates-10; draft-ietf-lamps-cmp-updates-10.txt”; Certificate Management Protocol (CMP) Updates draft-ietf-lamps-cmp-updates-10; dr… [cited by applicant]