US 12,229,242 B2
Securing access to privileged functionality in run-time mode on remote terminal unit
Philip Aubin, Kanata (CA); and Salih Utku Karaaslan, Ottawa (CA)
Assigned to SCHNEIDER ELECTRIC SYSTEMS USA, INC., Foxboro, MA (US)
Filed by Schneider Electric Systems, USA Inc., Foxborough, MA (US)
Filed on Dec. 21, 2021, as Appl. No. 17/557,364.
Claims priority of provisional application 63/271,863, filed on Oct. 26, 2021.
Prior Publication US 2023/0129749 A1, Apr. 27, 2023
Int. Cl. G06F 21/00 (2013.01); G06F 3/14 (2006.01); G06F 9/54 (2006.01); G06F 21/44 (2013.01); G06F 21/64 (2013.01)
CPC G06F 21/44 (2013.01) [G06F 3/1454 (2013.01); G06F 9/545 (2013.01); G06F 21/64 (2013.01)] 18 Claims
OG exemplary drawing
 
1. A method for selecting an operational mode on a remote terminal unit (RTU), comprising:
assigning a first state of a mode selector to a run-time operational mode of the RTU, wherein the mode selector is local to the RTU;
assigning a second state of the mode selector to a privileged operational mode of the RTU, wherein the second state is different than the first state;
in response to the mode selector being caused to physically move from the first state to the second state, deactivating the run-time operational mode of the RTU and activating the privileged operational mode of the RTU;
enabling, in the privileged operational mode, one or more functionalities associated with the privileged operational mode, wherein the functionalities associated with the privileged operational mode include deploying content to the RTU, and wherein authentication of the content by one or more integrator security certificates is required in the privileged operational mode;
subsequent to performing the one or more functionalities associated with the privileged operational mode, causing the mode selector of the RTU to physically move from the second state assigned to the privileged operational mode to the first state assigned to the run-time operational mode to deactivate the privileged operational mode and activate the run-time operational mode of the RTU;
preventing, in the run-time operational mode, access to the functionalities associated with the privileged operational mode; and
enabling, in the run-time operational mode, one or more functionalities associated with the run-time operational mode, wherein the functionalities associated with the run-time operational mode include deploying the content to the RTU, and wherein authentication of the content by one or more local security certificates is permitted in the run-time operational mode.