Method for secure transmission of time critical data within a communication system, communication system and adapter for a terminal device

By employing software-defined networking and zero-trust adapters in industrial automation systems to acquire and evaluate terminal device status information, the challenge of integrating zero-trust solutions into existing hardware is solved, achieving secure and deterministic data transmission and ensuring that system functions are not affected.

CN119404474BActive Publication Date: 2026-01-27SIEMENS AG
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202380050745.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2022-06-29
Filing Date
2023-05-26
Publication Date
2026-01-27
Estimated Expiration
2043-05-26

AI Technical Summary

Technical Problem

In industrial automation systems, existing zero-trust solutions are difficult to integrate efficiently into existing hardware components, and existing security protocols are difficult to adapt to zero-trust solutions, making it difficult to simultaneously guarantee determinism and security in data transmission and processing.

Method used

Software-defined networking (SDN) is used to separate the control unit and the local area network. The status information of the terminal device is obtained through the zero-trust adapter and forwarded to the control unit for evaluation. Communication rules are determined based on trust scores. The control unit is used to realize the low-cost integration of the zero-trust solution, ensuring data security and determinism.

Benefits of technology

It achieves low-cost integration of a zero-trust solution into existing industrial communication systems, ensuring data security and deterministic transmission, and avoiding impact on the functions and behavior of existing systems.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119404474B_ABST
    Figure CN119404474B_ABST
Patent Text Reader

Abstract

The invention relates to the secure transmission of time-critical data within a communication system, the communication system comprising a plurality of local area networks (100), each of which comprises at least one switch (101) and a plurality of terminal devices (102-105), the communication system comprising a control unit (202), which controls the functions of the plurality of switches and terminal devices, and a control network (200), which is assigned to the control unit and is separate from the local area networks. Communication within a local area network is implicitly authorized on the basis of the allocation of the respective terminal device to the same local area network. Each terminal device is assigned a zero trust adapter (121, 131, 141, 151), which acquires status information about the terminal device, forwards the status information to the control unit via the control network for evaluation, and authenticates the terminal device to the control unit and / or a communication partner. The control unit determines a trust score for the terminal device on the basis of the status information and uses rules depending on the trust score for the configuration or permitted communication relationships of the terminal device, respectively.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a method for securely transmitting time-critical data within a communication system, particularly a communication system for industrial automation systems, a communication system for performing the method, and an adapter for a terminal device of the communication system. Background Technology

[0002] Industrial automation systems typically comprise multiple automated devices networked together via industrial communication networks and are used to control or regulate facilities, machines, or equipment within the scope of manufacturing or process automation. Due to the time-critical framework of industrial automation systems, real-time communication protocols such as PROFINET, PROFIBUS, real-time Ethernet, or Time-Sensitive Networking (TSN) are primarily used for communication between automated devices. Control services or applications can be automatically and in a utilization-dependent manner distributed across currently available servers or virtual machines within the industrial automation system.

[0003] A method for inspecting datagrams transmitted within an industrial automation system having multiple automation units is known from EP 3 646 559 B1, wherein datagrams to be inspected from the automation units are transmitted to a firewall system via corresponding firewall interfaces for inspection, and are inspected thereon based on rules. The firewall system comprises at least one virtual machine, which is provided within a data processing system including multiple computing units. For transmitting the datagrams to be inspected, protection layer tunnels are established between each firewall interface and the firewall system. Within each protection layer tunnel, not only the datagrams to be inspected but also at least successfully inspected datagrams are transmitted.

[0004] Document WO 2020 / 182627 A1 describes a method for monitoring the integrity of an industrial cyber-physical system, wherein measurement data or control data is provided or measured, the measurement data being detected using different sensors within the cyber-physical system, and the control data being used for different actuators within the cyber-physical system. Furthermore, at least one measurement data association parameter is determined between the measurement data detected using different sensors, or at least one control data association parameter is determined between the control data determined for different actuators. The at least one measurement data association parameter is compared to a measurement data association reference, or the at least one control data association parameter is compared to a control data association reference. Based on this comparison, the integrity of the cyber-physical system to be monitored is determined.

[0005] A prior European patent application with application number 22175490.6 relates to the secure transmission of time-critical data within a communication system comprising multiple local area networks (LANs) in which data is transmitted via switching. The communication system includes at least one network superimposed on the LANs, in which data is transmitted via routing. The communication system also includes a gateway system for connecting the communication system to at least one unprotected external network. Network layer communication via this superimposed network is authorized only between authenticated system components. The switches authenticate connected terminal devices and assign them to physical or logical LANs based on their respective identities. The assignment of the respective terminal devices to the same LAN implicitly authorizes protection layer communication within the LAN. Communication at OSI layers 3-7 between terminal devices in different LANs or with terminal devices in unprotected external networks is authorized via zero-trust proxies, which are individually assigned to the LANs.

[0006] Zero-trust schemes stipulate that users or devices are authenticated relative to communication partners or when accessing protected resources, independent of their respective locations or environments, so that, upon successful authentication, they can access, for example, the desired data or applications. In industrial automation systems, a problem with the application of zero-trust schemes is that not every user or every device can perform authentication, especially from an economic perspective. The application of zero-trust schemes typically requires additional encryption capabilities (e.g., trust anchors) and key materials (e.g., device certificates) or computing power, which are not always freely available in existing hardware components. Furthermore, existing security or communication protocols in industrial automation systems cannot be easily adapted or replaced to implement zero-trust schemes.

[0007] Besides data security, deterministic data transmission and processing must also be ensured in the communication networks of industrial automation systems. In industrial automation systems, deterministic behavior is particularly necessary to ensure functional safety. However, the mutual authentication required by corresponding zero-trust schemes of communication partners makes deterministic data transmission and processing difficult. Summary of the Invention

[0008] Therefore, the basic objective of this invention is to provide a method for securely transmitting time-critical data that can be easily integrated into existing communication systems, particularly in industrial automation systems, to simultaneously ensure data security and decisiveness, and to provide a suitable apparatus for technically implementing this method.

[0009] According to the method for securely transmitting time-critical data within a communication system based on the present invention, the communication system includes multiple local area networks (LANs), a control unit, and a control network associated with the control unit, the control network being separate from the LANs. Each LAN includes at least one switch and multiple terminal devices, wherein the control unit controls the functions of the multiple switches and terminal devices. Communication within the LAN is implicitly authorized based on the allocation of corresponding terminal devices to the same LAN.

[0010] Local area network (LAN) switches are preferably assigned to software-defined networking (SDN), which includes a communication control plane called the control plane and a data transmission plane called the data plane. Here, control units are assigned to the control plane, while switches are assigned to the data plane. Specifically, flow tables can be pre-defined through these control units, from which routing tables or forwarding tables for network infrastructure devices associated with the control units can be derived. These network infrastructure devices include, for example, routers or switches.

[0011] According to the present invention, a zero-trust adapter is assigned to each terminal device. This zero-trust adapter acquires the status information of the terminal device, forwards the status information to the control unit via a control network for evaluation, and authenticates the terminal device relative to the control unit or a communication partner. The zero-trust adapter can be integrated into the respective terminal device as a hardware component and / or software component, for example. According to optional embodiments, each zero-trust adapter includes a zero-trust proxy integrated into each terminal device for acquiring status information and a zero-trust interface device for authenticating the terminal device, separate from each terminal device. Alternatively, zero-trust adapters for multiple terminal devices can be integrated into a common zero-trust proxy.

[0012] According to the present invention, the control unit determines a trust score (e.g., a trust rating) for each terminal device based on status information and applies rules dependent on the trust score to the configuration of the terminal device or the permitted communication relationships. For example, based on the rules applied by the control unit, the control unit authorizes the communication relationships between the terminal device and its corresponding communication partner outside the local area network. In particular, the functions of the terminal device or switch can be controlled according to the rules applied by the control unit. Preferably, the application of rules dependent on the trust score is performed only after successful authentication of the corresponding terminal device. In the event of terminal device authentication failure, warnings are advantageously issued separately.

[0013] The present invention enables low-cost integration of zero-trust solutions into industrial communication or automation systems, particularly through zero-trust adapters. This is especially advantageous in existing infrastructures where components cannot be easily replaced. Further simplified integration is achieved if each zero-trust adapter includes a trust anchor for storing adapter-specific or end-device-specific key material. Furthermore, implementing zero-trust control functions within a separate control network ensures that the functionality and behavior of existing industrial communication or automation systems are not adversely affected or altered. Preferably, end devices are connected to the zero-trust interface device or control network via dedicated ports.

[0014] According to a preferred embodiment of the invention, the status information is preprocessed by various zero-trust adapters for the control unit. Advantageously, only the preprocessed status information or metadata extracted from the status information is forwarded to the control unit for evaluation. The status information may, in particular, include log files, which are collected, preprocessed, and forwarded to the control unit via the various zero-trust adapters. In this way, the security status or potential security risks of the terminal device can be evaluated more accurately again.

[0015] Preferably, security policies are used to pre-define rules applied by the control unit based on trust scores. These security policies define which terminal devices or users need to access which data and / or resources. This allows for selective and efficient access control. Advantageously, status information is evaluated based on the security policies through Policy Decision Points (PDPs) associated with the control device. Preferably, the security policies are enforced by the control device as the policy enforcement point.

[0016] The communication system according to the present invention is configured to execute the method according to the foregoing embodiments and includes multiple local area networks (LANs), a control unit, and a control network associated with the control unit. Each LAN includes at least one switch and multiple terminal devices. The control unit controls the functions of the multiple switches and terminal devices. The control network is separate from the LANs. Here, each LAN implements and configures communication within the LAN implicitly authorized based on the allocation of corresponding terminal devices to the same LAN.

[0017] In the communication system according to the present invention, each terminal device is assigned a zero-trust adapter. This zero-trust adapter is implemented and configured to acquire the terminal device's status information, forward the status information to the control unit via a control network for evaluation, and authenticate the terminal device against the control unit or a communication partner. Conversely, the control unit is implemented and configured to determine a trust score for each terminal device based on the status information and apply rules dependent on the trust score to the terminal device's configuration or permitted communication relationships. Preferably, the communication system is implemented and configured to authorize communication relationships between the terminal device and its corresponding external communication partner according to the rules applied by the control unit. Attached Figure Description

[0018] The invention will now be described in more detail with reference to the accompanying drawings and embodiments. The drawings show:

[0019] Figure 1 The diagram illustrates a communication system comprising a local area network (LAN) including switches and multiple terminal devices, a control network, a control unit, and a zero-trust adapter integrated into the terminal devices.

[0020] Figure 2 Showing according to Figure 1 An alternative implementation of the communication system, which has a zero-trust adapter not fully integrated into the terminal device,

[0021] Figure 3 Show Figure 2 The diagram shows a detailed view of the terminal equipment and associated zero-trust interface device of the communication system.

[0022] Figure 4 This illustration shows an example of determining trust scores for multiple terminal devices using status information.

[0023] Figure 5 This illustrates an example of a trust score-related rule applied by the control unit. Detailed Implementation

[0024] exist Figure 1 The communication system shown in the diagram generally comprises multiple local area networks (LANs) 100, a control unit 202, and a control network 200 associated with the control unit 202. Each LAN includes a switch 101 and multiple terminal devices 102-105 connected to that switch. In this embodiment, communication within the LAN 100 is implicitly authorized based on the allocation of corresponding terminal devices 102-105 to the same LAN. To make it clearer, in Figure 1 The example shown is of only one local area network 100.

[0025] Control network 200 is advantageously completely isolated from local area network 100. For this purpose, terminal devices 102-105 are connected to control network 200 via dedicated ports 122, 132, 142, and 152, respectively. Similarly, switch 101 of local area network 100 is connected to control unit 202 included in control network 200 via dedicated ports.

[0026] Terminal devices 102-105 are, in particular, physical or virtual hosts that can provide data and resources to other hosts. Data or resources can, for example, be allocated to services or control and monitoring applications within an industrial automation system, such as time-critical services or applications.

[0027] In this embodiment, terminal devices 102-105 implement the functions of control devices for an industrial automation system, such as programmable logic controllers (PLCs) or field devices, such as sensors or actuators. Here, terminal devices 102-105 are used to exchange control and measurement parameters with machines or devices controlled by the control devices. The control devices are specifically configured to determine appropriate control parameters from the detected measurement parameters.

[0028] Optionally or additionally, terminal devices 102-105 may be implemented as operation and observation stations and used for visualizing process data or measurement and control parameters processed or detected by control equipment or other automation equipment. The operation and observation stations can be used in particular to display control loop values ​​and for changing adjustment parameters or procedures.

[0029] The switches 101 and terminal devices 102-105 of the local area network 100 are preferably assigned to a software-defined network (SDN), which includes a communication control plane, referred to as the control plane, and a data transmission plane, referred to as the data plane. Here, the control unit 202 includes an SDN controller 221 and is assigned to the control plane, while the switches 101 and terminal devices 102 are assigned to the data plane. In principle, other network infrastructure devices that act as switches, such as routers, can also be assigned to the data plane. The control unit 202 can preset flow tables, particularly for routers or switches, from which routing tables or forwarding tables for the network infrastructure devices associated with the control unit can be derived.

[0030] Typically, control unit 202 controls the functions of multiple switches 101, 201 and terminal devices 102-105. According to... Figure 1In the illustrated embodiment, the control unit 202 connects to terminal devices 102-105 or to zero-trust adapters 121, 131, 141, 151 via a switch 201 assigned to the control network 200 and via dedicated ports 122, 132, 142, 152. The zero-trust adapters are configured for each terminal device 102-105. Here, the zero-trust adapters 121, 131, 141, 151 are integrated into the respective terminal devices 102-105 as hardware components or software components, particularly as a combination of hardware and software components. Alternatively, zero-trust adapters 102-105 for multiple terminal devices can be combined in a common zero-trust proxy 110. This... Figure 1 The dashed lines represent the connection between the zero-trust proxy 110 and the dedicated ports 122, 132, 142, and 152 of the terminal devices 102-105.

[0031] Zero-trust adapters 121, 131, 141, and 151 respectively acquire the status information of their assigned terminal devices 102-105, forward the status information to the control unit 202 for evaluation via the control network 200, and authenticate the corresponding terminal devices 102-105 on behalf of the control unit 202 or a communication partner. The status information may in particular include log files collected and forwarded to the control unit 202 by the respective zero-trust adapters 121, 131, 141, and 151. Preferably, the status information is preprocessed by the respective zero-trust adapters 121, 131, 141, and 151 used by the control unit 202. In this case, only the preprocessed status information or the metadata extracted from the status information is forwarded to the control unit 202 for evaluation.

[0032] The control unit 202 determines a trust score for each of the terminal devices 102-105 based on status information and applies rules based on the trust score to configure the terminal devices or allow communication relationships. Specifically, based on the rules applied by the control unit 202, communication relationships between the terminal devices 102-105 and communication partners outside the corresponding local area network 100 of the terminal devices are authorized. Furthermore, the functions of the local area network 100 or the switch 101 of the terminal devices 102-105 are controlled according to the rules applied by the control unit 202. Preferably, the application of rules based on the trust score occurs only after successful authentication of the corresponding terminal device. Warnings can be issued, for example, in the event of terminal device authentication failure. Alternatively, in the event of terminal device authentication failure, the SDN controller 221 can interrupt the corresponding terminal device's communication via the data plane, i.e., actively intervene in the communication.

[0033] The rules applied by the control unit 202 are preset, in particular, through security policies. In this embodiment, these security policies manage and limit which terminal devices or users need to access which data or resources using a policy management point (PAP) 223 integrated in the control unit 202. Here, state information is evaluated based on the security policies through a policy decision point (PDP) 222 included in the control unit 202. The security policies are enforced by the SDN controller 221 as a policy enforcement point (PEP).

[0034] according to Figure 2 In the alternative embodiment shown, the control unit 202 is connected to the dedicated ports 122, 132, 142, 152 of the terminal devices 102-105 via the switch 201 of the control network 200 and via zero-trust interface devices 121b, 131b, 141b, 151b. In this embodiment, each zero-trust adapter includes a zero-trust agent 121a, 131a, 141a, 151a integrated into the respective terminal device 102-105 to obtain status information, and a zero-trust interface device 121b, 131b, 141b, 151b separate from the respective terminal device 102-105. The zero-trust interface device authenticates the terminal devices 102-105.

[0035] Figure 3 Exemplary details are shown according to Figure 2 The communication system includes a terminal device 102 and a zero-trust interface device 121b. In addition to a dedicated port 1211 for the associated terminal device 102, a dedicated port 1212 for controlling the network 200, and a control module 1213, the zero-trust interface device 121b also includes a trust anchor 1214 for storing adapter-specific or terminal device-specific key materials. This trust anchor can also be integrated into... Figure 1 The zero-trust adapters 121, 131, 141, and 151 of the communication system shown herein. In summary, the key material used for authenticating terminal devices 102-105 does not need to be stored there, but can be reliably managed by the correspondingly assigned zero-trust adapters 121, 131, 141, and 151 or the corresponding zero-trust interface devices 121b, 131b, 141b, and 151b.

[0036] To determine the trust score based on the status information of multiple example terminal devices, according to Figure 4On one hand, network configuration data, such as network adapter ID (identifier) ​​401 and IP (Internet Protocol) address 402, can be evaluated. On the other hand, software installation data, such as operating system 403, operating system version 404, software version 405 of each zero-trust adapter or zero-trust agent, installed virus scanner 406, and final scan results 407, can be evaluated. Trust scores 408 are calculated for each terminal device based on this data. In this embodiment, a relatively low trust score of 50 is calculated for the first terminal device based on an older operating system version, while a higher trust score of 85 is determined for the second terminal device with a newer operating system version. A higher trust score of 85 can also be calculated for the third terminal device, which has an older operating system version but has an installed virus scanner and positive final scan results. The method of calculating trust scores can, in principle, be adapted to individual application requirements.

[0037] Figure 5 Four rules, dependent on trust scores, are illustrated exemplarily, applied by the control unit. Here, attention is focused on rule ID 501, source IP address 502, destination IP address 503, destination port 504, the communication protocol permitted by the corresponding rule 505, and the trust score threshold 506. According to rule 1, terminal devices with a determined trust score of at least 80 are allowed to communicate with a terminal device having IP address 10.10.1.20 via the OPC UA communication protocol and destination port 4840. Conversely, according to rule 2, terminal devices with a determined trust score of at least 65 are allowed to communicate with a terminal device having IP address 10.10.1.20 only via the DCOM communication protocol and destination port 135.

[0038] According to Rule 3, a terminal device with a determined trust score of at least 70 is permitted to communicate with a terminal device with IP address 10.10.1.25 via the OPC UA communication protocol and target port 4840. Furthermore, Rule 4, for example, stipulates that if the calculated trust score for a terminal device with IP address 10.10.1.25 is at least 85, then communication is permitted between the terminal device with IP address 10.10.1.25 and the terminal device with IP address 10.10.1.30 via the OPC UA communication protocol and target port 4840.

[0039] According to the above rules, communication is generally blocked for terminal devices with a calculated trust score lower than the corresponding trust score threshold. To avoid conflicts between rules, their application is preferentially prioritized based on rule ID. Rules applied by the control unit can also, in principle, be adapted to individual application requirements.

Claims

1. A method for securely transmitting time-critical data within a communication system, wherein, The communication system includes multiple local area networks (100), each local area network including at least one switch (101) and multiple terminal devices (102-105). The communication system also includes a control unit (202) that controls the functions of the multiple switches and terminal devices. The communication system further includes a control network (200) that is associated with the control unit and separate from the local area networks. - The allocation of the corresponding terminal device to the same local area network implicitly authorizes communication within the local area network. - A zero-trust adapter (121, 131, 141, 151) is assigned to each terminal device. The zero-trust adapter acquires status information about the terminal device, forwards this status information to the control unit via the control network for evaluation, and authenticates the terminal device for the control unit and / or its communication partner. - Each control unit determines a trust score for the terminal device based on the status information and applies rules based on the trust score to the configuration of the terminal device and / or permitted communication relationships.

2. The method according to claim 1, wherein, According to the rules applied by the control unit (202), the terminal device (102-105) is authorized to establish communication relationships with communication partners outside the corresponding local area network (100) of the terminal device.

3. The method according to claim 1 or 2, wherein, The state information is preprocessed by the corresponding zero-trust adapter (121, 131, 141, 151) for the control unit, wherein only the preprocessed state information and / or the metadata extracted from the state information are forwarded to the control unit for evaluation.

4. The method according to claim 1 or 2, wherein, The terminal devices (102-105) are each connected to the zero-trust interface device (121b, 131b, 141b, 151b) and / or the control network (200) via dedicated ports (122, 132, 142, 152).

5. The method according to claim 1 or 2, wherein, The zero-trust adapters (121, 131, 141, 151) are each integrated as hardware components and / or software components into the corresponding terminal devices (102-105).

6. The method according to claim 1 or 2, wherein, Each of the zero-trust adapters includes a zero-trust agent (121a, 131a, 141a, 151a) integrated into the respective terminal device (102-105) for acquiring the status information, and a zero-trust interface device (121b, 131b, 141b, 151b) separate from the respective terminal device for authenticating the terminal device.

7. The method according to claim 1 or 2, wherein, The zero-trust adapters for multiple end devices (102-105) are combined in a common zero-trust agent (110).

8. The method according to claim 1 or 2, wherein, Each of the zero-trust adapters includes a trust anchor for storing adapter-specific and / or terminal device-specific key material.

9. The method according to claim 1 or 2, wherein, The security policy presets the rules, which restricts which terminal devices and / or users can access which data and / or resources.

10. The method according to claim 9, wherein, The state information is evaluated based on the security policy through a policy decision point associated with the control device, wherein the security policy is executed by the control device as a policy execution point.

11. The method according to claim 1 or 2, wherein, The functions of the terminal device and / or switch are controlled according to the rules applied by the control unit.

12. The method according to claim 1 or 2, wherein, The rules, which depend on the trust score, are applied only after the terminal device authentication is successful, and warnings are issued in case of terminal device authentication failure.

13. The method according to claim 1 or 2, wherein, The switch (101) of the local area network (100) is assigned to a software-defined network, which includes a communication control plane called the control plane and a data transmission plane called the data plane, wherein the control unit (202) is assigned to the control plane and wherein the switch (101) is assigned to the data plane.

14. The method according to claim 13, wherein, The control unit (202) can preset flow tables and derive routing tables and / or forwarding tables for network infrastructure devices belonging to the control unit from the flow tables, wherein the network infrastructure devices include routers and / or switches.

15. A communication system for securely transmitting time-critical data, comprising: - Multiple local area networks (100), each including at least one switch (101) and multiple terminal devices (102-105), a control unit (202) for controlling the functions of the multiple switches and terminal devices, and a control network (200) belonging to the control unit and separate from the local area networks. - in, Each of the local area networks (LANs) implements and configures itself to ensure that the allocation of the corresponding terminal device to the same LAN implicitly authorizes communication within the corresponding LAN. - Each of the terminal devices is assigned to a zero-trust adapter (121, 131, 141, 151), which is configured to: acquire status information about the terminal device; forward the status information to the control unit via the control network for evaluation; and authenticate the terminal device for the control unit and / or its communication partner. - Each of the control units implements and is configured to determine a trust score for the terminal device based on the status information and apply rules depending on the trust score to the configuration and / or permitted communication relationships of the terminal device.

16. An adapter for a terminal device in a communication system according to claim 15, - in, The adapter implementation and settings are configured to be assigned to the terminal device as a zero-trust adapter, and - in, The adapter is also configured to acquire status information about the terminal device, forward the status information about the terminal device to the control unit via the control network for evaluation, and authenticate the terminal device for the control unit and / or communication partner.

Citation Information

Patent Citations

  • Method for inspecting datagrams transmitted within an industrial automation system and automation and / or communication device

    EP3646559B1

  • Method and system for monitoring the integrity of an automation system

    WO2020182627A1

  • Zero-trust power Internet of Things equipment and user real-time trust degree evaluation method

    CN112055029A