-
公开(公告)号:US10721223B2
公开(公告)日:2020-07-21
申请号:US15951464
申请日:2018-04-12
Applicant: Rockwell Automation Technologies, Inc.
Inventor: Taryl J. Jasper , Dukki Chung , Jack M. Visoky , Michael A. Bush
Abstract: A secure method for establishing communications to provision modules in an industrial control system generates a certificate signing request to obtain a signed security certificate. A mobile device is located proximate to the module with the certificate signing request, and the mobile device has previously established itself as a secure communication interface on the network. The mobile device establishes a first connection between the module and the mobile device via a short-range protocol and a s second connection between the mobile device and a signing server via a network. The mobile device retrieves the certificate signing request via the first connection and transmits the certificate signing request to the signing server via the second connection. Because the mobile device has previously established itself as a secure interface, the transmission of the certificate signing request to the signing server may be made via a secure connection.
-
22.
公开(公告)号:US10097585B2
公开(公告)日:2018-10-09
申请号:US15147667
申请日:2016-05-05
Applicant: Rockwell Automation Technologies, Inc.
Inventor: Michael A. Bush , Jack M. Visoky , Taryl J. Jasper
IPC: G06F17/00 , H04L29/06 , G05B19/042 , G05B19/418
Abstract: A model-based industrial security policy configuration system implements a plant-wide industrial asset security policy in accordance with security policy definitions provided by a user. The configuration system models the collection of industrial assets for which diverse security policies are to be implemented. An interface allows the user to define security policies for a plant environment at a high-level by grouping the industrial assets into security zones, and defining any additional communication permissions in terms of asset-to-asset, asset-to-zone, or zone-to-zone conduits. Based on the model and these policy definitions, the system generates asset-level security setting instructions configured to set appropriate security settings on one or more of the industrial assets, and deploys these instructions to the appropriate assets in order to implement the defined security policy.
-
公开(公告)号:US20180129793A1
公开(公告)日:2018-05-10
申请号:US15383908
申请日:2016-12-19
Applicant: Rockwell Automation Technologies, Inc.
Inventor: Dylan A. Ulis , Kevin A. Fonner , Derek P. Miller , James J. Kay , Douglas W. Reid , Jack M. Visoky , Richard M. Cherney , John E. Belcher , Taryl J. Jasper
CPC classification number: G06F21/12 , G06Q2220/165
Abstract: An industrial precompile and encrypt system facilitates secure distribution of a digital industrial asset to a target device in an industrial automation environment while permitting common, expected user workflows such as interfacing with the asset; replacing failed target devices; verifying and validating the asset and its usage; securely troubleshooting the asset, editing the asset, or replacing the asset in a running system.
-
公开(公告)号:US20130238886A1
公开(公告)日:2013-09-12
申请号:US13867246
申请日:2013-04-22
Applicant: ROCKWELL AUTOMATION TECHNOLOGIES, INC.
Inventor: Brian A. Batke , Jack M. Visoky , James J. Kay , Scott A. Mintz , William B. Cook
IPC: G06F21/44
CPC classification number: G06F21/572 , G05B19/058 , G06F8/61 , G06F9/4401 , G06F21/44 , G06F2221/033
Abstract: A method for installing embedded firmware is provided. The method includes generating one or more firmware file instances and generating one or more digital certificate instances that are separate instances from the firmware file instances. The method includes associating the one or more digital certificate instances with the one or more firmware file instances to facilitate updating signature-unaware modules with signature-aware firmware or to facilitate updating signature-aware modules with signature-unaware firmware.
-
-
-