Device with flexible communication structure, in particular automation device, for high data security real-time

By introducing flexible communication structures and encryption accelerators into automated equipment, the problems of flexibility and security in data communication and synchronization in automated systems are solved, achieving efficient data processing and transmission, supporting transmission rates up to 1 Gbps and multi-protocol communication requirements.

CN120981806APending Publication Date: 2025-11-18HILSCHER AUTOMATION SYST CO LTD +1
View PDF 18 Cites 0 Cited by

Patent Information

Application Number
CN202480023246.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2023-04-06
Filing Date
2024-03-27
Publication Date
2025-11-18

AI Technical Summary

Technical Problem

Existing technologies struggle to achieve flexible and efficient data communication and synchronization in automation systems, especially in industrial networks with high data security and real-time requirements. The increase in sensors and actuators leads to wiring complexity and maintenance difficulties, while existing equipment struggles to support transmission rates up to 1 Gbps and the need for multi-protocol communication.

Method used

The device and method employ a flexible communication architecture, including a communication processor, data controller, dual-port RAM memory, secure enclave, and host interface. Through a programmable processor core and cryptographic accelerator, it supports data stream processing, filtering, and distribution in the range of 10 Mbps to 1 Gbps, and integrates a switchable physical interface to achieve high data security and real-time performance.

Benefits of technology

It enables efficient and flexible data communication and synchronization in automated equipment, supports multiple communication protocols, reduces system latency and improves real-time capabilities, and meets the network application requirements for high data security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120981806A_ABST
    Figure CN120981806A_ABST
Patent Text Reader

Abstract

The invention relates to a device, in particular an automation device, having a flexible communication structure for real-time network applications with high data security, and to a method for configuring the device. In order to support all market-related communication protocols used in automation engineering, the device (AG) has a communication processor (KP) having: at least one freely programmable communication controller (KC), at least one freely programmable data controller (DC) and at least one interactive dual-port RAM memory (DPM), wherein the communication processor (KP) cooperates with a higher-level control system via the host interface (HS), whereby the higher-level control system is exchangeable,-at least one flexible communication fabric integrated in the communication controller (KC), by means of a processor core (gMAC: RPU, TPU; gPEC), at least one flexible data processing structure integrated in the data controller (DC) and having a cryptographic accelerator (KB), and an exchangeable physical interface (PYS) arranged in the device (AG) and connected via a signal line to a communication controller (KC) arranged in the communication processor (KP) for transmitting the identification code (ID), the control data (ST), the reception data (ED) and the transmission data (SD), therefore, processing, filtering and distribution of the data streams within the transmission rate range of 10 Mbps to 1 Gbps are realized. 2.2 The invention is applicable to the field of equipment with a flexible communication structure, in particular to automation equipment.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] According to claim 1, the present invention relates to a device, and according to claim 7, to a method of configuring the device. Background Technology

[0002] In control and automation technologies, fieldbuses and Ethernet, especially extensions of real-time Ethernet, are known to be used for data communication between various units involved in process control. Examples of classic fieldbuses include CANopen, PROFIBUS, Modbus, DeviceNet, or CC-Link. Well-known examples of real-time Ethernet systems include PROFINET, EtherNet / IP, EtherCAT, Sercos, POWERLINK, and CC-Link IE. Future examples supporting gigabit real-time Ethernet systems include PROFINET over TSN, EtherCAT-G, and OPC UA over TSN. Communication between units occurs over fieldbuses / Ethernets using specified protocols. To meet the demand for open networking systems, simple and cost-effective communication mechanisms are needed to enable networking capabilities in industrial equipment. This requirement is particularly important in the coupling of drive components, such as the coupling between drive controls, power units, and encoders in CNC machine tools and robots where multiple interpolation axes must operate synchronously. With the increasing networking of various technology systems, the industrial sector has a growing demand for standardized structures.

[0003] In distributed automation systems, such as in the field of drive technology, certain data must arrive at designated participants (i.e., real-time critical data) at specific times and be processed by the receiver. According to IEC 61491 and EN 61491 SERCOS Interface – Technical Overview, the successful transmission of such real-time critical data in distributed automation systems can be ensured. Furthermore, synchronous clock communication systems with equidistant characteristics are known in automation technology; for example, a system and method for transmitting data between data networks is described in DE 101 40 861 A1.

[0004] To design a method and apparatus for data communication and configuration of bus participants in an open automation system, enabling any bus participant to connect via separate interactive communication and interchangeability of device parts, the applicant discloses a method for data communication in EP1894113B1 for coupling bus subscribers in an open automation system with distributed control. These subscribers communicate with each other via a serial data bus, and interact with higher-level control devices via at least two communication controllers, wherein:

[0005] - Each communication controller includes at least three freely programmable communication ALUs, namely the first communication ALU, the second communication ALU, and the third communication ALU.

[0006] - Encode multiple commands for each communication controller of the first and second communication ALUs, wherein the method is characterized by:

[0007] For each communication controller:

[0008] - The logic function blocks are arranged in parallel with each other in the first and second communication ALUs, and simultaneously process the command code that performs the communication function.

[0009] - The First Communication ALU performs the reception and decoding of bit- or half-byte-oriented serial data streams and the serial / parallel conversion of data represented in bytes, words, or double words.

[0010] - The second communication ALU performs the conversion of byte, word, or double-word representations into bit-oriented or half-byte serial data, and encodes and transmits this serial data stream; and the third communication ALU has monitoring logic that monitors multiple events simultaneously, and when an event occurs, it starts associated program code within the system clock, wherein multiple commands are executed within one system clock cycle, and

[0011] - The third communication ALU controls the transmission and reception of associated data packets.

[0012] Therefore, the communication function is not permanently predefined, but is formed by means of freely programmable communication ALUs, in which each communication controller is properly configured by reading the identification code during the startup phase, and subsequently each associated communication ALU is properly configured, and thus, the switching between networks is achieved by means of higher-level control devices and each communication controller.

[0013] For each communication controller, a higher-level control device is integrated in a circuit along with one or more communication ALUs. This circuit contains a dual-port memory for coupling to an external control device (host system), or the higher-level control device of this circuit executes the entire application, which then exposes an internal system bus as an extension bus for connecting external memory and peripheral components. Both operating modes use the same signals, and these are switched via software.

[0014] Furthermore, the applicant discloses a device for data communication in EP1894113B1, for coupling bus subscribers of an open automation system with distributed control, the bus subscribers communicating with each other via a serial data bus, the device having:

[0015] - At least two communication controllers that interact with higher-level control devices and include at least three freely programmable communication ALUs, namely a first communication ALU, a second communication ALU, and a third communication ALU.

[0016] The command code encodes multiple commands, and the device has the following characteristics:

[0017] At least two logical function blocks are arranged in parallel, which simultaneously process the command code into first and second parts.

[0018] The second communication ALU performs communication functions.

[0019] The first communication ALU performs the reception and decoding of bit-oriented or half-byte-oriented serial data streams, and converts them serially / parallel into byte, word, or double-word representations.

[0020] The second communication ALU performs the conversion of byte, word, or double-word representations into bit-oriented or half-byte serial data, and encodes and transmits this serial data stream.

[0021] The third communication ALU has monitoring logic that monitors multiple events simultaneously. When an event occurs, it starts associated program code within the system clock, executing multiple commands within the system clock. The third communication ALU also controls the transmission and reception of associated data packets.

[0022] Therefore, the communication function is not permanently predefined, but is formed by means of freely programmable communication ALUs, in which each communication controller is properly configured by reading the identification code during the startup phase, and subsequently each associated communication ALU is properly configured, and thus, the switching between networks is achieved by means of a higher-level control device and two communication controllers.

[0023] Compared to building dedicated communication controllers (which also correspond to hard-wired logic) using programmable FPGAs (Field-Programmable Gate Arrays) or their components according to existing technologies, the subject matter of the applicant's EP1894113B1 enables the construction of "quasi-dedicated" communication controllers in a simple manner, namely by constructing them as one or more freely programmable communication ALUs (Arithmetic and Logic Units) with instruction sets and hardware architectures optimized for communication tasks. This solution offers the following advantages:

[0024] - The development, production, and distribution of this type of circuit can be carried out independently of a specific fieldbus system / Ethernet.

[0025] - Implementations of extended or entirely new fieldbus systems within the Fieldbus / Ethernet and Real-Time Ethernet specifications can be done via software updates without requiring new circuitry.

[0026] - Especially when there are two or more communication interfaces in the circuit, the corresponding fieldbus / Ethernet system is defined by loading software and can therefore be combined in a completely flexible manner.

[0027] Furthermore, in the subject matter of the applicant's EP1894113B1, instructions are executed in parallel within a single loop, unlike conventional ALUs. To this end, corresponding logic function blocks within the ALU are arranged in parallel and can process instruction codes simultaneously, meaning that necessary functionality can be achieved even at high baud rates (e.g., 100 / 1000 Mbps Ethernet). For each communication controller, a switchable physical interface is provided. This physical interface, without its own intelligence or controller functionality, is connected to the communication controller via four signal line groups for transmitting identification codes, control data, receiving data, and transmitting data. During the startup phase, this interface registers itself with the freely programmable communication controller using an identification code, making the physical interface switchable and allowing for expansion within the fieldbus specification or implementation of entirely new fieldbus systems via software updates. Finally, for each communication controller, the physical interface is designed as a connector with a communication network or a printed circuit board with a communication network as an integrated unit, and the communication processor handles both the application and the transmission protocol.

[0028] Furthermore, the applicant discloses a method and apparatus for synchronizing bus participants in an open automation system in EP2110754B1. The method for synchronizing bus participants communicating with each other via a serial data bus in an open automation system with distributed control is designed to enable automatic and highly accurate synchronization via one of the bus participants having at least one communication controller; the communication controller (hereinafter referred to as the communication controller) has three freely programmable communication ALUs, namely a first communication ALU, a second communication ALU, and a third communication ALU, and cooperates with downstream control devices; and the method includes the following steps:

[0029] - The communication controller detects the occurrence of a specific date or event.

[0030] - The communication-ALU autonomously and without requiring the downstream control device to perform fully deterministic synchronization control functions, thereby the first communication-ALU decodes and converts the received bit or half-byte serial data stream into a parallel representation according to the transmission rate; the second communication-ALU encodes the data from the parallel representation into a bit or half-byte serial data stream and applies it to the line at the correct transmission rate; and the third communication-ALU controls the transmission and reception history of relevant data packets, and

[0031] Between synchronization times, the communication controller (KC) and the control device (CPU) exchange measurement and control values, thereby adapting the communication controller (KC), the three communication ALUs (RPA, TPA, PEA) and the control device (CPU) so that the interruption delay period of the downstream control device (CPU) does not affect synchronization.

[0032] Alternatively, a method is known from the applicant's EP 2110754B1, wherein the method is characterized in that one of the bus participants has at least one communication controller, and one of the at least one communication controllers (hereinafter referred to as the communication controller) cooperates with a downstream control device via three freely programmable communication ALUs, referred to as a first communication ALU, a second communication ALU, and a third communication ALU, and the method includes the following steps:

[0033] - The communication-ALU autonomously and without requiring the downstream control device to perform fully deterministic synchronization control functions, thereby the first communication-ALU decodes and converts the received bit or half-byte serial data stream into a parallel representation according to the transmission rate; the second communication-ALU encodes the data from the parallel representation into a bit or half-byte serial data stream and applies it to the line at the correct transmission rate; and the third communication-ALU controls the transmission and reception history of relevant data packets.

[0034] - Because the control function is cyclic and has a cycle time, the synchronized local time is stored in a latch at the starting point of the cyclic control function.

[0035] - The cycle time is measured by taking the difference between the local time relative to the local clock and the synchronized local time stored at the previous starting point, and by means of the control device, the current cycle time is increased or decreased to keep the current cycle time constant and maintain a fixed phase relationship with the local time.

[0036] - The entire cycle is synchronized with the local time in terms of cycle time and phase, thereby adapting the communication controller, the three communication ALUs and the control device so that the interruption delay period of the downstream control device does not affect the synchronization.

[0037] Compared to the method first mentioned in the applicant's EP2110754B1, which uses a "quasi-dedicated" communication controller for direct synchronization of control functions without the need for downstream control equipment, the synchronization in the alternative method is performed based on a stored local time each time the control function is started, which requires slightly higher hardware expenditure to maintain the local time.

[0038] Furthermore, a device for automatic and high-precision synchronization is known from the applicant's EP 2110754B1, characterized in that one of the bus subscribers has a communication processor with at least one communication controller, wherein one of the communication controllers is designated as a subsequent communication controller and has a downstream control device, wherein the communication controller has three freely programmable communication ALUs, namely designated as a first communication ALU, a second communication ALU, and a third communication ALU, wherein the communication ALUs are adapted to perform a fully deterministic synchronization control function without the control device, whereby the first communication ALU operates based on received bits or nibbles of serial data. The transmission rate of the stream is decoded and converted into a parallel representation. The second communication-ALU encodes the data from the parallel representation into a bit or half-byte serial data stream and applies it to the line at the correct transmission rate. The third communication-ALU controls the transmission and reception history of relevant data packets. The communication controller is adapted to detect the occurrence of a specific date or event. The device has a logic function block of a communication processor with means for measuring time and storing time in the communication-ALU. The communication controller, the three communication-ALUs, and the control device are adapted such that interruption delays of downstream control devices do not affect synchronization.

[0039] As demonstrated in the prior art assessment above, an apparatus for data communication and for coupling distributed control of bus participants in an open automation system is known from applicant EP1894113B1, these participants communicating with each other via a serial data bus. Furthermore, a method and apparatus for automatic and high-precision synchronization are disclosed in applicant EP2110754B1, wherein interruption delays of the control equipment do not affect synchronization.

[0040] The continuous advancement of networked production means that machines will be equipped with more and more sensors. However, the increase in sensors and actuators, and the resulting increase in wiring, makes the maintenance, fault analysis, and installation of wired sensors increasingly complex. With the introduction of Industry 4.0, the collection of equipment and sensor data and its transmission to cloud platforms are becoming increasingly important.

[0041] To enable the transmission of cryptographically protected data in a first network to a less secure second network for evaluation, DE102015200279 A1 discloses an apparatus for performing cryptographically protected communication and a method for non-reactively acquiring data transmitted cryptographically between devices in a first network and monitored by a unidirectional transmission device in the second network. The method includes the steps of: negotiating at least one cryptographic parameter between the communicating devices in the first network for subsequent communication; generating a transmission structure in at least one device that at least partially contains the negotiated cryptographic parameters and transmitting the transmission structure within the first network; and monitoring and transmitting the transmission data structure to the second network by the unidirectional transmission device in a subsequent processing step. In an advantageous embodiment of the method, the transmission data structure is protected by a configurable cryptographic transmission key. This specifically ensures that the cryptographic parameters can only be read by authorized personnel with whom the transmission key has been negotiated. The apparatus for cryptographically protected communication provided in the subject matter of DE102015200279 A1 includes a negotiation unit designed to negotiate cryptographic parameters for cryptographically protected communication with a communication partner. The device also includes a generation unit designed to generate a transmission data structure containing at least a portion of negotiated cryptographic parameters and transmit it to the first network. Furthermore, the device may have a generation device that generates a configurable cryptographic transmission key and is designed to output the transmission data structure protected by the cryptographic transmission key to the first network. This ensures that only authorized personnel can evaluate the transmission data structure and use it to decrypt data transmitted in the first network. This also allows you to configure who can evaluate which messages. For example, cryptographic parameters for control messages can be encrypted using the first cryptographic transmission key, and cryptographic parameters for encrypting diagnostic data can be encrypted using a second transmission key, for example. If the first transmission key is known only to the evaluation unit, then the first one-way transmission unit can send messages to the controller but cannot decrypt diagnostic data. Additionally, a monitoring unit designed to listen for cryptographic parameters between devices in the first network and a storage unit designed to store the cryptographic parameters and transmit them to the second network may be provided. The one-way transmission device may include a decryption unit configured to decrypt cryptographically protected data transmitted from the first network using the cryptographic parameters. Furthermore, the decryption device may be designed such that only intercepted data that has successfully passed cryptographic verification is forwarded to the second network.

[0042] To provide a better overview of fieldbus networks and their components in terms of the framework application aspect, a framework application for device access software is known from DE102016120972A1. This framework application can be installed on a host, thereby allowing at least one driver to be integrated into the framework application, which is designed to access associated fieldbus components of the fieldbus network. The framework application has at least one standard interface for each integrated driver, through which data can be exchanged between the driver and the framework application. In addition to the at least one standard interface, the framework application also has one or more proprietary interfaces for at least some integrated drivers, through which data can be exchanged between the individual drivers and the framework application, wherein information on additional functions supported by the driver or associated fieldbus component can be transferred from the driver to the framework application via at least one proprietary interface. In addition to the at least one standard interface, one or more proprietary interfaces are also provided between the framework application and at least some integrated drivers. For example, if the framework application can connect to the cloud, it is particularly advantageous to incorporate information on additional functions on the framework application side. For example, information on supported additional functions can be uploaded to the cloud along with other data, making a complete overview of the system available from the cloud. For example, additional functions can also be activated from the cloud. This means that activating additional functions from the cloud can replace the time-consuming process of activating them in the field (i.e., at the location of the field device). To correctly address the various components of a fieldbus network, device access software requires information about the attributes and parameters of the field devices, gateways, remote I / O, etc., of the fieldbus network. This information is typically provided by the manufacturers of various devices in the form of device description files or device drivers. For device descriptions of non-cyclic data exchange, the fieldbus protocols PROFIBUS-DP, PROFIBUS-PA, the Fieldbus Foundation, and HART use device descriptions based on DTM (Device Type Manager), DD (Device Description), EDD (Enhanced Device Description), and FDI device packages. Specifically, the EDD and DTM standards, in addition to specifying device parameters, device functions, and address space allocation, also specify graphical features and graphical user interfaces designed to facilitate the parameterization and configuration of the corresponding field devices. To create these graphical interfaces, the EDD standard provides special graphical commands that are processed in an interpreted language. In the FDT / DTM standards, the DTM (Device Type Manager) is provided in the form of dynamically loadable libraries (DLLs) or executables. DTMs also include the aforementioned graphical features. Various DTMs for different components of fieldbus networks are integrated into a common FDT framework application, where FDT stands for "Field Device Tool".

[0043] This provides a universal framework application that can integrate DTMs from different devices and manufacturers. The FDT standard is increasingly being supplemented and may be superseded by the FDI device package standard. In addition to the previously discussed fieldbus protocols Profibus, the Fieldbus Foundation, and HART, so-called Industrial Ethernet protocols are becoming increasingly important, including fieldbus protocols EtherNet / IP, ProfiNet, and EtherCAT. The EtherNet / IP fieldbus protocol provides device description files based on the EDS (Electronic Data Sheet) standard for describing cyclic and non-cyclic data exchange. The first possible additional feature that can be activated for a fee is cloud connectivity, also known as the "Internet of Things," or simply IoT. This feature enables data to be uploaded from the DTM to the cloud via FDT framework applications. There, the data can be archived and linked to other data. For example, flow measurement data can be uploaded to the cloud and used as the basis for reordering and inventory management. The DTM will enable the use of IoT connectivity. Another additional feature that can be unlocked is the ability to perform device functional tests and self-tests.

[0044] Furthermore, DE102016215742 A1 discloses a gateway and a method for connecting a data source system to an IT system, wherein the gateway has real-time middleware and non-real-time middleware on a general-purpose operating system. The non-real-time middleware runs applications that communicate via network protocols such as TCP / IP, OPC-UA, or HTTP(s), and includes a framework. Real-time capability means that each computational step is completed within a defined time period. In a real-time environment, computational results are guaranteed to be available in a timely manner, allowing the movement of different units (especially in industrial machines) to also run synchronously. The subject matter of DE102016215742 A1 relates to a data source system comprising at least one data source, such as a computing unit (e.g., a programmable logic controller (PLC), numerical control (NC), or CNC (computerized numerical control)) or sensor, especially an existing data source that can be "Internet-enabled" in an extremely simple way. This is a scalable approach that allows for the transformation of existing machines without programming, using only web-based configuration. The solution provides modular scalability through the addition of sensors, logic, and providers, and automatically feeds in associated web-based interfaces. Existing PLCs in the data source system can be connected as add-ons via a gateway. This allows for easy subsequent connections without modifying the existing data source system. In this case, PLC functionality does not need to be present on the gateway, but can be provided as an add-on to allow any other components of the data source system to be directly connected to the gateway. For entirely new data source systems, the gateway can function as a PLC from the outset, enabling the provision of initial connectivity between the data source system and the IT system.

[0045] Furthermore, as described in US 8,775,757 B2, a trust zone with a security enclave processor (SEP) supports system-on-chip (SoC) architecture. This SoC implements the security enclave processor (SEP). The SEP may contain a processor and one or more secure peripheral devices. The SEP may be decoupled from the rest of the SoC (e.g., one or more central processing units (CPUs) or application processors (APs) within the SoC). Access to the security enclave processor (SEP) can be strictly controlled by hardware. For example, a mechanism is described where the CPU or AP can only access one mailbox within the security enclave processor (SEP). The CPU / AP can write messages to the mailbox, and the security enclave processor (SEP) can read and respond to those messages. In some embodiments, the SEP may include one or more of the following components: secure key management using a packaging key, SEP control for booting and / or power management, and a separate trust zone in memory.

[0046] Building upon this, US 9,747,435 B2 includes various embodiments for authentication and control of known encryption keys. Generally, the device may include secure circuitry, a processor, and an interface controller. The secure circuitry may be configured to generate a key. The processor may be configured to determine one or more policies applied to the use of the key and generate a policy value. The policy value may contain one or more data bits specifying a particular policy. The interface controller may be configured to generate a message containing the key and the policy value. The interface controller may also be configured to send the message. In another embodiment, the one or more policies may include indications of one or more functional units of a plurality of functional units that allow the use of the key. In another embodiment, the one or more policies may include a allowed size for the key. In another embodiment, the one or more policies may include indications that the key can be used to encrypt data and indications that the key can be used to decrypt data. In another embodiment, the one or more policies include indications of the length of time the key can be used. In one embodiment, the secure circuitry may also be configured to encrypt the key. In another embodiment, the one or more policies may include indications of one or more additional operations to be performed on the message to decrypt the key.

[0047] Modern processor architectures now feature secure enclaves, which perform security-related tasks throughout the product lifecycle. An example of a product lifecycle is:

[0048] During chip manufacturing, it is essential to be able to fully test the chip. As the chip leaves the factory, its lifecycle is switched "forward," and the interfaces used for testing the chip's internals are disabled. Similarly, when finished devices are installed in the facility, the interfaces required for developing the device software are closed. Software running on automated equipment enables the use of additional security features in the final application, such as secure boot, key management, and certificate handling.

[0049] Real-time Ethernet used in automation differs from conventional Ethernet used in other industries. Therefore, new concepts must be developed that do not exist in traditional processor architectures.

[0050] In automation technology, real-time Ethernet refers to cyclic data communication between devices. In the future, for devices with a transmission rate of 1 Gbps, the cycle time will be in the microsecond range. Data will no longer be transmitted in plain text, but will be encrypted.

[0051] In this context, cryptographic acceleration is important. Edge networks can be implemented as any type of network, as long as they provide edge computing and / or storage resources located near a radio access network or access point. Endpoint devices supporting the RAN (e.g., mobile computing devices, Internet of Things (IoT) devices, smart devices, etc.) are also considered. A method and apparatus for providing dynamic selection of edge and local accelerator resources are known from DE102019130686 A1, wherein the apparatus includes a circuitry system for identifying the application to be accelerated, determining one or more attributes of the accelerator resources available at the network edge where the device is located, and determining one or more attributes of the accelerator resources available in the device. So-called edge devices, in some respects similar to industrial PCs, extend their functionality to include local accelerators for various tasks such as artificial intelligence, cryptography, FPGAs, etc. Expansion is achieved via I / O cards, for example, via PCIe (Rapid Peripheral Component Interconnect, often abbreviated as PCIe, a bus standard for connecting peripheral devices to a processor chipset) expansion card slot. Therefore, an accelerator device is a form of device expansion, similar to how a desktop PC uses slots in the motherboard for expansion, such as inserting a graphics card or network card. Windows, as an operating system, can identify cards, install drivers, and make them usable for applications.

[0052] Furthermore, a method and system for key management for secure data transmission are known from DE60314060 T2. This secure data transmission system includes:

[0053] - A secure channel established via at least one data channel.

[0054] - A host processor connected to the network, used to communicate with user applications running on other processors connected to the network.

[0055] - A main security module connected to the host processor is used to send an encrypted private key and a public key encryption scheme, wherein the private key has been encrypted using at least one key encryption key, wherein the main security module is also configured to send the encrypted private key via a data channel and the key encryption key via a secure channel, and wherein the main security module includes a security module configured to control key generation operations and associated data storage.

[0056] Specifically, the secure data transmission system according to DE60314060T2 is characterized by:

[0057] - At least one satellite module connected to the host processor is used to receive at least one key encryption key after transmission through a secure channel, to receive an encrypted private key after transmission through a data channel, to decrypt the private key using the received key encryption key, and to encrypt or decrypt data using the decrypted private key. The satellite security module includes an encryption accelerator having a key manager, an initial parsing unit (IPU), a cryptographic engine, and a non-volatile data memory EEPROM.

[0058] Furthermore, the secure data transmission system according to DE60314060T2 is characterized in that the secure channel is established by the host processor and is designed to initialize and control at least one satellite security module, and to facilitate the secure transmission of key encryption keys and management information. The encryption accelerator of the secure data transmission system according to DE60314060T2 includes one or more Initial Parsing Units (IPUs), a cryptographic machine, and a key manager. The IPU parses (analyzes) security association data from encrypted / unencrypted data packets to decrypt the encrypted security association. The encryption engine is a processor that decrypts encrypted data packets and / or encrypts unencrypted data packets. In this embodiment, the cryptographic engine is a dedicated processor that uses the decrypted security association from the IPU to encrypt or decrypt data packets. The key manager manages the key encryption keys (KEKs) used to decrypt the security association. The encryption accelerator can provide on-chip memory for caching, one for each MCR type (e.g., 96 bytes for MCR1 and 648 bytes for MCR2, sufficient to hold an AES 256-bit key IPsec context or an RSA 2048-bit private key context). Cryptographic accelerators can include additional instruction code for loading and decrypting instruction contexts. The cache and KEK to be used will be determined by the MCR that issues the instruction. The cached instruction context can be invoked using a packet descriptor with a null instruction context pointer.

[0059] Furthermore, an apparatus and method for handling key encryption are known from US 11,070,375B2. The apparatus includes an encryption key generator for generating a media encryption key for encrypting data in multiple storage components. The encryption key generator is configured to package the media encryption key to generate an encrypted media encryption key. The encrypted media encryption key is stored in non-volatile memory. The apparatus includes firmware with instructions for transitioning the device to a secure state and exiting the secure state using the encrypted media encryption key. The solution known from US 11,070,375B2 broadly describes an inline encryption for storage. It involves storing data or program code in encrypted form on a storage medium, i.e., encrypting the data when written to memory and decrypting the data when read from memory. It primarily relates to the application of memory chips. For example, a memory chip is connected to a communication processor. This is intended to prevent third parties from reading the contents of the memory, thereby preventing the leakage of confidential information.

[0060] Finally, a cost-effective encryption accelerator is known from DE102017215331 A1. The system includes:

[0061] - Central Processing Unit (CPU);

[0062] - A memory that stores instructions that, when executed by the CPU, cause the CPU to perform operations, including: obtaining cryptographic data that identifies a specific cryptographic process to be performed on the cryptographic data;

[0063] - Perform the first cryptographic operation on the cryptographic data according to the cryptographic process;

[0064] - Sending cryptographic data to the hardware accelerator; and receiving from the hardware accelerator cryptographic data generated by the hardware accelerator using a second cryptographic operation according to a cryptographic process different from the first cryptographic operation.

[0065] Encryption accelerators include:

[0066] - An interface is configured to receive cryptographic data, wherein the cryptographic data identifies a specific cryptographic process to be performed on the cryptographic data;

[0067] - Transformation logic, configured to perform cryptographic operations on cryptographic data according to a cryptographic process, wherein the transformation logic includes logic for performing cryptographic operations on multiple different cryptographic processes; and

[0068] - The status register is configured to store the results of cryptographic operations.

[0069] In the future, secure communication between terminal devices in automation technology will become increasingly separated from other industries. Secure enclaves form the foundation for establishing secure communication. To realize intelligent devices with flexible communication structures for real-time network applications with high data security, especially for automation devices with transmission rates in the range of 10 Mbps to 1 Gbps, further development of solution concepts known from existing technologies is needed.

[0070] To design an automated device with a network analysis module and a cloud connectivity module, eliminating the need for a dedicated gateway, applicant DE102018008674 A1 describes an automated device designed to integrate the analysis and cloud units as independent modules into the automated device's ASIC, and / or to connect an Ethernet network controller to the analysis and cloud units. This Ethernet network controller has an interface for lossless reading of all received network data from the internal side of the Ethernet transmitter on all existing Ethernet ports. Alternatively, the analysis and cloud units are integrated as independent modules into the automated device, and / or the Ethernet controller is designed with interfaces such as UART, SPI, SDIO, MAC, PCIe, dual-port memory, FIFO, or similar types for exchanging Ethernet frames with the automated device and / or the network controller's internal Ethernet switch.

[0071] To design a device and method with a flexible communication and control structure, allowing parts of the device to be interchanged, applicant DE102006019451 A1 discloses a device with a flexible communication and control structure for coupling to other devices or higher-level control devices in an automation system via a serial data bus, which has:

[0072] - At least two or more communication interfaces, and

[0073] - At least one programmable logic controller

[0074] This allows the programmable logic controller to be designed as an interchangeable unit, and data to be transmitted between communication interfaces and / or further processed via the internal programmable logic controller in a completely transparent manner.

[0075] In the method for configuring a device having two or more communication interfaces and a programmable logic controller described in the applicant's DE102006019451 A1,

[0076] - The interchangeable communication interface is extended through PLC functionality to couple devices in an automation system that communicate with each other via a serial data bus, and

[0077] - It is integrated into the communication path and works completely transparently to both the device and higher-level control equipment.

[0078] Furthermore, EP0982641 B1 discloses a bus connection comprising a memory region merged into a single module, a communication module, and functional units having their own program memory spaces, all accessing the same memory region, wherein blocks of variable size can be formed within the memory region. As the size of the first block increases, the size of the second block decreases, and vice versa, thereby allowing a communication buffer to be established within the variable-sized second block. Specifically, the first block is characterized by the ability to explicitly switch to the program memory space of the functional unit. Physical units with asynchronous and synchronous interfaces are provided for physical connection to the bus.

[0079] To specify a communication module for modularly constructed automation systems, which alleviates the burden on the central control unit of the automation system and is particularly suitable for transferring and programming user programs directly from the central unit connected to the communication module into the communication module, a communication module known from DE102009008957 A1 includes a processing unit (preferably designed as a microprocessor), a zero-voltage safe memory unit interacting with it for storing user programs, and at least two independent, configurable, and electrically isolated serial interfaces. The serial interfaces can be configured using the user programs stored in the memory unit and are designed to take over the functionality of the interface connected to the central control unit of the communication module when its functionality is insufficient.

[0080] Finally, DE102004035843 A1 discloses a network processor having multiple programmable processor elements, wherein:

[0081] - Each of the multiple processor elements is configured to provide basic communication network protocol functions;

[0082] - The first portion of a plurality of processor elements is configured as a communication network-processor element; and

[0083] - A second portion of the plurality of processor elements is configured as an interface processor element, which is configured to provide an output communication interface and / or an input communication interface to the network processor in accordance with a communication protocol. Summary of the Invention

[0084] The object of this invention is to further develop an apparatus and method based on solutions known from the applicant’s EP 1 894 113 B1 and EP 2 HO 754 B1, which supports all market-relevant communication protocols in automation technology and enables the preprocessing, protection and forwarding of high-priority real-time data in the range of up to 1 Gbps.

[0085] According to claim 1, this objective is achieved by a device with a flexible communication structure for real-time network applications with high data security, the device comprising a communication processor having:

[0086] - At least one freely programmable communication controller, at least one freely programmable data controller, and at least one interactive dual-port RAM memory, wherein the communication processor collaborates with higher-level control devices via a host interface, thereby allowing the higher-level control devices to be interchanged.

[0087] - At least one flexible communication architecture integrated in the communication controller, consisting of a processor core programmable according to the application.

[0088] - At least one flexible data processing architecture integrated into the data controller and featuring an encryption accelerator.

[0089] It also includes a switchable physical interface, which is arranged in the device and connected via signal lines to a communication controller arranged in the communication processor for transmitting identification codes, control data, receiving data, and transmitting data, enabling the processing, filtering, and distribution of data streams at transmission rates ranging from 10 Mbps to 1 Gbps.

[0090] Furthermore, according to claim 7, this objective is achieved by a method for configuring a device with a flexible communication architecture for real-time network applications with high data security, the device having a communication controller, a data controller, a dual-port RAM memory, a secure enclave, and a host interface arranged in a communication processor, wherein:

[0091] - The communication controller and data controller can be freely programmed.

[0092] The communication controller and data controller collaborate with higher-level control devices via a host interface, enabling interchangeability between these higher-level control devices.

[0093] - To process, filter, and distribute data streams with transmission rates ranging from 10 Mbps to 1 Gbps, at least one flexible communication architecture is integrated into the communication controller, which consists of an application-specific programmable processor core.

[0094] - To preprocess, protect, and forward high-priority real-time data, at least one flexible data processing architecture is provided. This architecture features an encryption accelerator integrated into the data controller and consists of an application-specific programmable processor core.

[0095] - The device includes a replaceable physical interface for connecting to the communication controller, and

[0096] - Secure enclaves undertake security-related tasks according to the corresponding product lifecycle and provide additional security functions for the end application, including secure boot, key management and certificate disposal.

[0097] The device according to the invention, particularly the automation device, supports all market-relevant communication protocols of automation technology in a surprisingly simple manner due to the system's multi-protocol capabilities and workload distribution.

[0098] In a further development of the invention, according to claim 2, the data controller includes:

[0099] - Application-specific processor cores designed specifically for handling high-priority real-time data.

[0100] - Low-latency, tightly coupled memory, divided into program memory and data memory.

[0101] - An encryption accelerator for hash functions, authentication, and data encryption and decryption, and

[0102] - Direct memory access controller for interactive data transfer to reduce the burden on the processor core.

[0103] The advantage of this development is that its performance optimization stems from size and speed optimized for the specific application. By enabling optimal single-loop access, latency is kept low, system response becomes more deterministic, and the real-time capability of the entire system is improved.

[0104] In a preferred embodiment of the invention, according to claim 3, the communication processor has a secure enclave, also known as a Secure Enclave, which has a secure enclave processor and a secure non-volatile memory connected thereto via an internal bus, wherein the secure enclave takes over security-related tasks according to the corresponding product lifecycle and makes further security functions available for the end application, including secure boot, key management, and certificate handling.

[0105] This embodiment of the invention has the following advantages: only the secure enclave can access the secure non-volatile memory via the bus. All keys used to encrypt user data originate from entropy stored in the non-volatile memory of the secure enclave. The secure enclave lays the foundation for secure communication by managing secret keys. Using these keys and special certificates, devices negotiate session keys and encrypt and decrypt cyclic data based on said session keys. Generally, the session key is valid as long as the connection is active. In automation, in a cyclic context, the connection is maintained as long as the system is running. Therefore, according to the invention, the negotiated session key can be updated during an active connection. Attached Figure Description

[0106] Further advantages and details can be found in the following description of preferred embodiments of the invention with reference to the accompanying drawings. The drawings show:

[0107] Figure 1 A block diagram of a communication processor with a freely programmable communication controller, based on the applicant's EP1894113 B1 and EP2110754 B, is shown.

[0108] Figure 2 A block diagram of a data controller according to the present invention is shown, and

[0109] Figure 3 Detailed illustration of having according to Figure 1 The data stream in the device according to the invention has a flexible communication structure. Detailed Implementation

[0110] Figure 1 The device with a flexible communication structure according to the invention shown herein, particularly a solution for automated devices, is a further development of the data communication methods and devices described by the applicant in EP1894113 B1 and EP2110754 B1, for coupling bus participants in an open automated system with distributed control, which communicate with each other via a serial data bus. The same reference numerals are used herein such that, by referring to these numerals, a detailed description of the components and their interconnections can be declared as part of the description of further developments according to the invention in this patent application.

[0111] Intelligent systems refer to machines with embedded, internet-connected computers capable of collecting and analyzing data and communicating with other systems. The next stage of evolution is connecting automated equipment to what is known as a higher level of cloud. Diagnostic data recorded by the equipment about itself or its environment can be used for topics such as predictive maintenance. Using the equipment as a digital twin representation in the cloud makes it possible, for example, to optimize processes in a production plant. The cloud can be on-premises or remote. Plant operators can also access the cloud on-site at the plant without an internet connection. The automated equipment AG of this invention is now referred to in technical terms as an intelligent device or a device called an intelligent device. The term "freely programmable" used by the applicant in EP1894113 B1 and EP2110754 B1 is intended to distinguish it from devices with a fixed programming scope achieved through functions or scripts. Using a programming language, application-specific tasks and functions can be freely implemented.

[0112] For example, there exists an Ethernet MAC (the abbreviation MAC stands for Media Access Controller and refers to the unique identifier and access control of electronic media within a network (Ethernet, Token Ring, Bluetooth, or WLAN)). A MAC address is a specific physical address of a network adapter with a fixed range of functions; colloquially, it is programmed via registers. Ultimately, this is primarily a configuration issue. It does not allow for multi-protocol support. In the solution according to the invention, the MAC (Media Access Controller) is programmable in the communication controller KC to support, for example, different real-time Ethernet protocols by installing different software.

[0113] Figure 1 The block diagram shown illustrates a device (hereinafter referred to as the automation device AG) with a flexible communication architecture for real-time network applications requiring high data security. The automation device AG includes a communication processor KP, which has:

[0114] - At least one freely programmable communication controller KC, at least one freely programmable data controller DC, and at least one interactive dual-port RAM memory DPM, wherein the communication processor KP collaborates with higher-level control devices via a host interface HS, thereby allowing the higher-level control devices to be interchanged.

[0115] - At least one flexible communication architecture integrated in the communication controller KC, consisting of an application-dependent programmable processor core PK (RPA, TPA, PEA, see applicant's EP 1 894 113 B1 and EP 2 110754 B1), and hereinafter referred to as gMAC: RPU, TPU, and

[0116] - At least one flexible data processing architecture with an encryption accelerator KB integrated in the data controller DC.

[0117] In addition, the automation equipment AG includes signal lines or signal line groups for transmitting identification code ID, control data ST, receive data ED, and transmit data SD. These are connected to the switchable physical interface PYS arranged in the communication processor KP, enabling the processing, filtering, and distribution of data streams with transmission rates ranging from 10 Mbps to 1 Gbps.

[0118] Figure 2 The block diagram shown illustrates a data controller DC, which has:

[0119] - At least one application-specific programmable processor core (PK) dedicated to processing high-priority real-time data.

[0120] - The low-latency, tightly coupled memory is divided into program memory (PS) and data memory (DS).

[0121] - Encryption Accelerator KB for hash functions, authentication, and data encryption and decryption.

[0122] - Direct Memory Access (DMA) controller for interactive data transfer to reduce the burden on the processor core PK.

[0123] Many modern processor architectures are now referred to as heterogeneous multi-core processor systems. The CPU (CPU stands for Central Processing Unit), acting as the main processor, is the central unit that interacts with distributed systems (also known as subsystems). To distinguish it from the CPU, the processor core PK of a subsystem is referred to below as the application-specific processor core PK.

[0124] In microcomputer technology, the processor core mainly consists of a control unit, an arithmetic unit, and registers. The arithmetic unit is also known as the arithmetic and logic unit (ALU).

[0125] Application-specific processor cores (PK) are equipped with tightly-coupled memory (TCM) for real-time execution of program code.

[0126] The technical term for "tightly coupled" memory is TCM (Tightly Coupled Memory), defined by the architecture of the processor core PK used. Ultimately, it optimizes performance to address the physical constraints imposed by the semiconductor process and the chip's system architecture. The processor core PK has, among other things, a system interface and a dedicated TCM interface, divided into a data bus and a program bus. Physically, in the chip layout, the TCM is placed near and directly connected to the processor core PK. For this purpose, high-speed memory cells are used, which typically have higher power consumption. The balance between size and speed optimized for the specific application determines the performance. The design goal is to minimize latency, ideally enabling single-cycle access. This makes the system response deterministic and improves the real-time capability of the entire system. In hard real-time, exceeding a fixed response time will be considered a fault by the application-specific programmable processor core PK.

[0127] This is referred to as low-latency, tightly coupled memory compared to traditional memory access in a system. Higher latency can occur if one of the data controllers (DCs) accesses system memory (external to the DC) via the system bus, depending on several factors such as the number of bus participants operating on system memory, the corresponding data flow on the system bus, and the internal synchronization level; that is, latency measured in processor clock cycles can be in the double-digit range. During this time, the application-associated programmable core (PK) does nothing but wait for data access. A DMA (Direct Memory Access) controller is used to offload the load on the application-associated programmable processor core (PK). The DMA controller performs memory accesses in the system. Instead of wasting clock cycles waiting, the application-associated programmable processor core (PK) executes program instructions.

[0128] As part of further development of the solution based on EP1894113 B1, the applicant has extended the communication controller KC to meet future communication protocol requirements and network transmission requirements, as shown below and as follows. Figure 3 As shown in detail below:

[0129] Each communication controller KC consists of several (especially ten or more) application-specific programmable key controllers (PKs) with communication ALUs.

[0130] The parallel processor cores PK, known as RPU (Receive Processing Unit) and TPU (Transmit Processing Unit), form gMAC (Gigabit MAC).

[0131] The control of the transmission and reception of related data packets is performed by several, specifically four gPECs (Gigabit Protocol Execution Controllers).

[0132] The resulting flexible communication architecture is formed by an application-dependent programmable key with a communication ALU, and is not fixed.

[0133] The number of freely programmable communication controllers (KCs) depends on the expansion level of the device AG for the corresponding application:

[0134] 1) Terminal devices used for process automation sometimes have only one communication port (i.e., the communication controller KC is in use). This is usually due to a star network topology.

[0135] 2) Factory automation terminal equipment has at least two communication ports (i.e., two KC communication controllers are in use). This is usually due to a ring network topology.

[0136] 4) Devices used in the control system can have a maximum of 4 communication ports (i.e., four KC communication controllers in use). This is generally independent of the implementation of the corresponding network topology.

[0137] The data controller DC with an integrated encryption accelerator KB according to the present invention meets the requirements of a device with a transmission rate of 1 Gbps, wherein the cycle time is in the microsecond range and wherein the data is transmitted in encrypted form. There is a distinction between cyclically received data, cyclically transmitted data, and non-cyclic data.

[0138] The interconnect IC is a key component connecting various functional blocks. It manages the data flow between these components and ensures they work together efficiently and effectively. Therefore, this IC provides internal communication connections for data and control signals. There is a distinction between the initiator INT and the target TRG (see [link]). Figure 1 This means that the initiator INT can perform write and read accesses on the target TRG. Figure 3 The access path via the IC is shown from top to bottom. The Secure Enclave (SE) is a special feature because it is both the initiator (INT) and the target TRG. During the boot phase, the Secure Enclave (SE) accesses the Storage Service (SP) and external storage via the External Storage Interface (ES), for example, for secure boot. During runtime, the Secure Enclave (SE) provides special services to the parent system, such as key management.

[0139] The dual-port RAM DPM used for the host interface HS is a volatile memory with arbitration, triple buffering, and handshaking mechanisms for synchronization. This allows both parties to access the memory contents of the dual-port RAM DPM independently, enabling the exchange of cyclic and non-cyclic data. Therefore, it represents a physical separation between real-time protocol communication and the higher-level control device of the final application, which is connected to the external host interface EHS and is thus interchangeable.

[0140] Higher-level control devices with corresponding host applications can be any category of equipment used in factory or process automation, such as industrial PCs, machines, drives, actuators, I / O systems, sensors, etc.

[0141] In the case of an external host interface (EHS), the final application is implemented on a commercial microprocessor or microcontroller, or on an application-specific FPGA or ASIC solution (FPGA stands for Field Programmable Gate Array, and ASIC stands for Application-Specific Integrated Circuit). The control device of the final application (also known as the host system) interfaces with the communication processor (KP) using the host interface (HS).

[0142] In the case of the internal host interface (IHS), the communication processor KP is extended through a complete application system with a main processor, thus becoming a system-on-a-chip (SoC) that can be used as a single-chip solution for the end application.

[0143] Modern cryptography encompasses four main objectives for protecting information: confidentiality / access protection, integrity / alteration protection, authenticity / anti-forgery protection, and binding / non-repudiation. In modern cryptography, there are three main encryption methods:

[0144] • Symmetric cryptography. In symmetric cryptography, a single key is used to encrypt and decrypt messages.

[0145] • Asymmetric cryptography.

[0146] • Hybrid cryptography.

[0147] Within the scope of this invention, the following cryptographic algorithms can be used.

[0148] - Hash / HMAC

[0149] • MD5

[0150] • SHA1

[0151] • SHA2

[0152] • SHA-224

[0153] • SHA-256

[0154] • SHA-384

[0155] • SHA-512

[0156] -AES

[0157] o Key length

[0158] • AES-128

[0159] • AES-192

[0160] • AES-256

[0161] o Operation Mode

[0162] ECB

[0163] •CBC

[0164] •CTR

[0165] •GCM

[0166] -ChaCha20

[0167] o No authentication required

[0168] o combined with Poly 1305

[0169] o Poly1305 without ChaCha20

[0170] In terms of data encryption, AES (Advanced Encryption Standard) encryption remains one of the most secure and widely used systems in the world.

[0171] Other ciphers include: Salsa20 (also known as Snuffle 2005), a stream cipher developed by Daniel J. Bernstein in 2005, and belonging to the 256-bit stream cipher family. Salsa20 / 20 with 20 rounds is planned as the standard. XSalsa20 is a variant with extended random numbers (192 bits instead of 64 bits). ChaCha or Snuffle 2008 are variants of Salsa20. ChaCha20-Poly1305 is an Authentication Encryption Algorithm with Appendage Data (AEAD), which combines the ChaCha20 stream cipher with the Poly1305 message authentication code. Its use in the IETF protocol is standardized in RFC 8439. It features fast software performance and is generally faster than AES-GCM without hardware acceleration. The ChaCha20-Poly1305 algorithm, described in RFC 8439, takes a 256-bit key and a 96-bit random number as input, encrypting the plaintext using a 128-bit (tag-size) ciphertext extension. In the ChaCha20-Poly1305 construction, ChaCha20 is used in counter mode to derive the keystream for XORing with the plaintext. Then, a variant of Poly1305 is used to authenticate the ciphertext and associated data, which first encodes the two strings into a single string. The XChaCha20-Poly1305 construction is an extended 192-bit random number variant of the ChaCha20-Poly1305 construction, using XChaCha20 instead of ChaCha20. The XChaCha20-Poly1305 construction provides higher security than the original construction when randomly selecting random numbers.

[0172] The data processing structure of the data controller DC depends on the software executed by the processor core PK. The corresponding software is determined by the data model of a higher-level communication protocol, which may vary depending on the communication standard. This also applies, among other things, to the use of the corresponding encryption algorithm. For example, communication standard A specifies ASE as the algorithm, and communication standard B specifies ChaCha as the algorithm. Furthermore, the data controller DCs operate different task-specific data models from each other. There is a distinction between cyclic data reception, cyclic data transmission, and non-cyclic data. Therefore, in the solution according to the invention, several (at least three) data controller DCs are implemented in the system. A purely hardware-based encryption accelerator KB would be disadvantageous. This would fail to achieve the system's multi-protocol capability and distribute the workload. The algorithm is accelerated using a combination of software and hardware. The software executed by the processor core (PK) in the tightly coupled memory (TCM) ensures that the data in the tightly coupled memory is processed according to the data model using a hardware accelerator.

[0173] In summary, the method according to the present invention for configuring a device AG with a flexible communication structure, including a communication controller KC, a data controller DC, a dual-port RAM memory DPM, a secure enclave SE, and a host interface HS, for a real-time network application with high data security, is characterized by:

[0174] • The communication controller KC and the data controller DC can be freely programmed.

[0175] • The communication controller KC and data controller DC work with higher-level control devices via the host interface HS, enabling interchangeability between these higher-level control devices.

[0176] • To process, filter, and distribute data streams with transmission rates ranging from 10 Mbps to 1 Gbps, at least one flexible communication architecture is integrated into the communication controller KC. This communication architecture consists of an application-specific programmable processor core PK.

[0177] • To process, protect, and forward high-priority real-time data, at least one flexible data processing architecture is integrated into the data controller (DC). This data processing architecture includes an encryption accelerator (KB) consisting of an application-specific programmable processor core (PK).

[0178] • The device AG, which is connected to the communication controller KC, has a switchable physical interface PYS, and

[0179] • Secure Enclaves (SEs) undertake security-related tasks according to the corresponding product lifecycle and provide additional security features for the end application, including secure boot, key management, and certificate handling.

[0180] Preferably, the secure enclave (SE) manages secret keys used to negotiate session keys between devices using these keys and special certificates, and to encrypt and decrypt cyclic data based on these session keys. The session keys remain valid as long as the connection is active; in particular, the negotiated session keys can be updated during active connections.

[0181] Furthermore, according to the present invention, the software structure of the encryption accelerator KB is modified to implement the multi-protocol capability of the device AG and allocate workload based on the cryptographic algorithm determined for the data model of a higher-level communication protocol.

[0182] This invention is not limited to the embodiments shown and described, but also includes all embodiments that have the same effect within the meaning of this invention, and is limited only by the patent claims.

[0183] Reference symbol list:

[0184] AG: Automated Equipment

[0185] CPU: Central Processing Unit

[0186] DC: Data Controller

[0187] DPM: Dual-port RAM

[0188] DS: Data Storage

[0189] DMA: Direct Memory Access Controller

[0190] ED: Receive data

[0191] EHS: External Host System

[0192] ES: External Storage Interface

[0193] FIFO: First-In-First-Out Data Buffer

[0194] gMAC: Gigabit Media Access Controller

[0195] HS: Host Interface

[0196] ID: Identification code

[0197] IC: Interconnect

[0198] IHS: Internal Mainframe System

[0199] INT: Initiator

[0200] KB: Encryption Accelerator

[0201] KC: Communication Controller

[0202] KP: Communication Processor

[0203] PE: Peripheral Equipment

[0204] PK: Processor Core

[0205] PS: Physical interface

[0206] PSP: Program Memory

[0207] RPU: Receive Processing Unit

[0208] SD: Broadcast Data

[0209] SE: Safe Enclave

[0210] SP: Memory

[0211] SR: Shared Register

[0212] ST: Control Data

[0213] TPU: Transmission Processing Unit

[0214] TRG: Target

Claims

1. A device (AG) with a flexible communication structure for real-time network applications with high data security, the device comprising: Communication processor (KP), the communication processor having: - At least one freely programmable communication controller (KC), at least one freely programmable data controller (DC), and at least one interactive dual-port RAM memory (DPM), wherein the communication processor (KP) collaborates with higher-level control devices via a host interface (HS), thereby enabling the higher-level control devices to be interchanged. - At least one flexible communication architecture integrated in the communication controller (KC), consisting of application-programmable processor cores (gMAC: RPU, TPU; gPEC). - At least one flexible data processing architecture integrated into the data controller (DC) and featuring an encryption accelerator (KB). And a switchable physical interface (PYS), which is arranged in the device (AG) and connected via signal lines to a communication controller (KC) arranged in the communication processor (KP) for transmitting identification codes (ID), control data (ST), receive data (ED), and transmit data (SD), enabling the processing, filtering, and distribution of data streams at transmission rates ranging from 10 Mbps to 1 Gbps.

2. The device (AG) of claim 1, wherein the data controller (DC) comprises: - At least one application-specific programmable processor core (PK) dedicated to processing high-priority real-time data. - Tightly coupled low-latency memory is divided into program memory (PS) and data memory (DS). - Encryption Accelerator (KB) for hash functions, authentication, and the encryption and decryption of data, and - Direct Memory Access (DMA) controller for interactive data transfer to reduce the load on the processor core (PK).

3. The device (AG) according to claim 1 or 2, wherein the communication processor (KP) has a secure enclave (SE), also known as a secure enclave, the secure enclave having a secure enclave processor and a secure non-volatile memory connected thereto via an internal bus, wherein the secure enclave (SE) takes over security-related tasks according to the corresponding product lifecycle and enables further security functions for the end application, including secure boot, key management, and certificate handling.

4. The device (AG) of claim 1, wherein in a ring embodiment of the network topology, the device for factory automation has at least two communication controllers (KC), and regardless of the network topology, the device has up to four communication controllers (KC).

5. The device (AG) according to claim 2, wherein the communication processor (KP) has at least three data controllers (DCs) for distinguishing between cyclically received data, cyclically transmitted data, and non-cyclic data.

6. The device (AG) according to claim 1 or 2, wherein each communication controller (KC) comprises a plurality of application-dependent programmable processor cores (PK) having a communication ALU (arithmetic and logic unit). The parallel processor cores (PK), known as RPU (Receive Processing Unit) and TPU (Transmission Processing Unit), form gMAC (Gigabit Media Access Controller). The transmission and reception of associated data packets are controlled by several gPECs (gigabit protocol execution controllers). This allows for the formation of an integrated, flexible communication architecture using an application-specific programmable processor core (PK) with a communication ALU.

7. A method for configuring a device (AG) with a flexible communication architecture for real-time network applications with high data security, said device having a communication controller (KC), a data controller (DC), a dual-port RAM memory (DPM), a secure enclave (SE), and a host interface (HS) arranged in a communication processor (KP), wherein: The communication controller (KC) and data controller (DC) are freely programmable. The communication controller (KC) and data controller (DC) collaborate with higher-level control devices via a host interface (HS), allowing these higher-level control devices to be interchanged. To process, filter, and distribute data streams with transmission rates ranging from 10 Mbps to 1 Gbps, at least one flexible communication architecture is integrated within the communication controller (KC), which consists of an application-specific programmable processor core (PK). To preprocess, protect, and forward high-priority real-time data, at least one flexible data processing architecture is integrated into the data controller (DC). This data processing architecture includes a cryptographic accelerator (KB), which comprises an application-specific programmable processor core. The device (AG) is equipped with a physical interface (PYS) for exchanging signals, which is connected to the communication controller (KC). Secure enclaves (SEs) undertake security-related tasks according to the corresponding product lifecycle and make additional security features available for end applications, including comprehensive secure boot, key management and certificate disposal.

8. The method of claim 7, wherein for cyclic data communication, the data controller (DC) distinguishes between cyclically received data, cyclically transmitted data, and non-cyclic data.

9. The method of claim 7 and / or 8, wherein the secure enclave (SE) manages secret keys, uses these keys and special certificates to negotiate session keys between devices, encrypts and decrypts cyclic data based on the session keys, the session keys are valid as long as the connection is active, and the negotiated session keys can be updated during active connections.

10. The method according to one or more of claims 7 to 9, wherein, for cryptographic algorithms determined by a data model of a higher-level communication protocol, the software architecture of the application for the cryptographic accelerator (KB) is modified to enable multi-protocol capabilities of the device (AG) and to partition the workload.

Citation Information

Patent Citations

  • method and system for coupling data networks

    DE10140861A1

  • router network processor

    DE102004035843A1

  • interchangeable communication and control device for transparent processing of data during ongoing data exchange

    DE102006019451A1

  • Communication module for an automation system

    DE102009008957A1

  • One-way transmission device, device and method for the non-reactive acquisition of data

    DE102015200279A1