Secure provisioning of devices in industrial automation systems

US12362912B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-12362912-B2
Application numberUS-202217974693-A
CountryUS
Kind codeB2
Filing dateOct 27, 2022
Priority dateOct 27, 2021
Publication dateJul 15, 2025
Grant dateJul 15, 2025

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

A method for securely supplying data to be used in parameterizing a device for an industrial automation system includes a first party supplying a second party with a machine-readable standardized container for the exchange of device parameters in industrial automation systems, wherein the supplying comprises writing into the container an encrypted primary security credential to be used by the device for establishing trust with the industrial automation system. In another aspect, a method for securely obtaining data to be used in parameterizing a device for an industrial automation system includes obtaining, from a first party, by a second party, a machine-readable standardized container for the exchange of device parameters in industrial automation systems, the container comprising an encrypted primary security credential to be used by the device for establishing trust with the industrial automation system.

First claim

Opening claim text (preview).

What is claimed is: 1. A method for securely supplying data to be used in parameterizing a device for an industrial automation system, the method comprising: a first party supplying a second party with a machine-readable standardized container for the exchange of device parameters in industrial automation systems, wherein the supplying comprises writing into the container an encrypted primary security credential to be used by the device for establishing trust with the industrial automation system, wherein the machine-readable standardized container supplied by the first party or obtained by the second party comprises further device parameters for parameterizing the device, wherein parameterizing the device comprises extracting, by the device, the encrypted primary security credential and decrypting the encrypted primary security credential, wherein the machine-readable standardized container comprises configuration data including functional data for parametrizing the device, the machine-readable standardized container comprising a device configuration sub model and an encrypted security sub model, wherein the configuration data is stored in the device configuration sub model that is integrated in the machine-readable standardized container, the primary security credential being integrated into the encrypted security sub model. 2. A method for securely obtaining data to be used in parameterizing a device for an industrial automation system, the method comprising: obtaining, from a first party, by a second party, a machine-readable standardized container for the exchange of device properties in industrial automation systems, the container comprising an encrypted primary security credential to be used by the device for establishing trust with the industrial automation system, wherein the machine-readable standardized container supplied by the first party or obtained by the second party comprises further device parameters for parameterizing the device, wherein parameterizing the device comprises extracting, by the device, the encrypted primary security credential and decrypting the encrypted primary security credential, wherein the machine-readable standardized container comprises configuration data including functional data for parametrizing the device, the machine-readable standardized container comprising a device configuration sub model and an encrypted security sub model, wherein the configuration data is stored in the device configuration sub model that is integrated in the machine-readable standardized container, the primary security credential being integrated into the encrypted security sub model. 3. The method of claim 1 , wherein the first party writes the primary security credential into the container using a secure local work environment, before supplying the second party with the container by transmitting the container to the second party over a public or private network. 4. The method of claim 1 , wherein the first party writes the primary security credential into the container by using a secondary security credential received from the second party to establish a secure channel to a remote work environment of the second party in which the container is stored, before writing the primary security credential into the container stored in the remote work environment. 5. The method of claim 4 , wherein the secondary security credential is transmitted from the second party to the first party by embedding it in the said container and transmitting the container. 6. The method of claim 1 , further comprising commissioning the parameterized device for use in the industrial automation system, wherein the commissioning comprises the device using the primary security credential to establish trust with the industrial automation system. 7. A method for parameterizing a device for an industrial automation system, the method comprising: obtaining a machine-readable standardized container for the exchange of device properties in industrial automation systems, the container comprising an encrypted primary security credential to be used by the device for establishing trust with the industrial automation system, along with further device parameters for parameterizing the device; and parameterizing the device using the device parameters from the container, wherein the parameterizing comprises the device extracting the primary security credential from the container and decrypting the primary security credential, wherein the machine-readable standardized container comprises configuration data including functional data for parametrizing the device, the machine-readable standardized container comprising a device configuration sub model and an encrypted security sub model, wherein the configuration data is stored in the device configuration sub model that is integrated in the machine-readable standardized container, the primary security credential being integrated into the encrypted security sub model. 8. The method of claim 7 , wherein the parameterizing is performed locally by downloading the container to the device from a secure local work environment in which the container is stored. 9. The method of claim 7 , wherein the parameterizing is performed remotely by accessing a remote work environment in which the container is stored, and downloading the container to the device from the remote work environment. 10. The method of claim 9 , wherein the device itself accesses the remote work environment according to predefined power-on behavior programmed into the device. 11. The method of claim 10 , wherein the predefined power-on behavior is input to the device by way of the said container. 12. The method of claim 7 , further comprising commissioning the parameterized device for use in the industrial automation system, wherein the commissioning comprises the device using the primary security credential to establish trust with the industrial automation system.

Assignees

Inventors

Classifications

  • wherein the data content is protected, e.g. by encrypting or encapsulating the payload · CPC title

  • using certificates (cryptographic mechanisms or cryptographic arrangements for entity authentication involving certificates H04L9/3263) · CPC title

  • Entity profiles · CPC title

  • H04L9/0816Primary

    Key establishment, i.e. cryptographic processes or cryptographic protocols whereby a shared secret becomes available to two or more parties, for subsequent use · CPC title

  • H04L63/08Primary

    for authentication of entities (cryptographic mechanisms or cryptographic arrangements for entity authentication H04L9/32) · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US12362912B2 cover?
A method for securely supplying data to be used in parameterizing a device for an industrial automation system includes a first party supplying a second party with a machine-readable standardized container for the exchange of device parameters in industrial automation systems, wherein the supplying comprises writing into the container an encrypted primary security credential to be used by the d…
Who is the assignee on this patent?
Abb Schweiz Ag
What technology area does this patent fall under?
Primary CPC classification H04L9/0816. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Jul 15 2025 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 2 related publications on this page (citations in our corpus or others sharing the same primary CPC).