Method and terminal for encryption-protected transmission of data in communication system
By generating key pairs and certificate applications locally on terminal devices, the problems of private key theft and certificate management difficulties in the existing technology are solved, and low-cost and secure terminal device certificate management is achieved, which is suitable for encrypted protection of data transmission in industrial automation systems.
Patent Information
- Application Number
- CN202480010116.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2023-01-31
- Filing Date
- 2024-01-12
- Publication Date
- 2025-09-12
AI Technical Summary
In industrial automation systems, existing technologies make it difficult to cost-effectively and securely provide key materials and certificates to a large number of terminal devices, especially to prevent the eavesdropping of private keys and irregular updates of certificates during time-critical data transmission.
A key pair and certificate application are generated locally in the terminal device, processed by the local authentication instance and transmitted to the superior authentication instance within a protected operating environment. The terminal device locally signs the certificate of the second key pair to ensure that the private key is not leaked, and the validity of the certificate is verified by the superior authentication instance.
It provides key materials and certificates to terminal devices at low cost and with high security, prevents the theft of private keys, simplifies certificate management, and is a scalable security solution suitable for industrial automation systems.
Smart Images

Figure CN120642299A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to a method for the encrypted and protected transmission of data within a communication system, in particular for the encrypted and protected transmission of time-critical data within a communication system for an industrial automation system, and a terminal for carrying out the method. Background Art
[0002] Industrial automation systems typically include multiple automation devices interconnected via an industrial communication network and are used to control or regulate facilities, machines, or equipment within the scope of manufacturing or process automation. Due to the time-critical framework conditions in industrial automation systems, real-time communication protocols such as PROFINET, PROFIBUS, Real-Time Ethernet, or Time-Sensitive Networking (TSN) are primarily used for communication between the automation devices. In particular, control services or control applications can be distributed automatically and according to availability across the currently available servers or virtual machines in the industrial automation system.
[0003] EP 3 646 559 B1 discloses a method for checking datagrams transmitted within an industrial automation system comprising multiple automation units. Datagrams to be checked from the automation units are transmitted to a firewall system via corresponding firewall interfaces for inspection and are checked there based on rules. The firewall system comprises at least one virtual machine provided within a data processing system comprising multiple computing units. To transmit the datagrams to be checked, a protection layer tunnel is established between the corresponding firewall interface and the firewall system. Within the corresponding protection layer tunnel, both the datagrams to be checked and at least the successfully checked datagrams are transmitted.
[0004] EP 3 975 502 A1 describes a method for providing time-critical services using a process control environment. At least one server component is provided for each service, the server component being constructed from process control components that can be loaded into the process control environment and implemented there. A configuration unit for at least one gateway component of a subnet comprising the process control environment determines globally valid access information assigned to the server component, addressing information valid within the subnet. Depending on the operating mode predefined by the configuration unit, one or more gateway components connected in parallel or in series are used. The at least one gateway component forwards service access requests to the server component based on forwarding rules or filtering rules reflecting the access information and the operating mode.
[0005] The previous European patent application EP 4 283 925 A1 relates to the protected transmission of time-critical data within a communication system, which comprises a plurality of local networks, in which data is transmitted by means of switching, at least one network overlapping with respect to the local networks, and a gateway system for connecting the communication system to at least one unprotected external network. Network layer communications via the overlapping network are only authorized between authenticated system components. The switches authenticate the connected terminal devices individually and assign these terminal devices to physical or logical local networks based on the corresponding terminal device identities. Within the local networks, protected layer communications are implicitly authorized due to the assignment of the individual terminal devices to the same local network. Communications on OSI layers 3-7 between terminal devices in different local networks or with terminal devices in unprotected external networks are authorized with the aid of zero-trust proxies, which are respectively assigned to the local networks.
[0006] US 2018 / 323977 A1 discloses a method comprising receiving a certificate request and a first digital certificate from a device to a certification authority. The device digitally signs the certificate request and transmits it to the certification authority. Furthermore, the first digital certificate is stored in the device. The certification authority verifies the first digital certificate using a second digital certificate from another certification authority. The digital signature of the certificate request is verified using the first digital certificate. Finally, after verifying the first digital certificate and digital signature, the second digital certificate is transmitted to the device.
[0007] Industrial automation devices or terminals that exchange time-critical data with communication partners for the purpose of controlling machines or equipment must be particularly sensitive to tampering and eavesdropping. One protective measure involves encrypting communications to and from these devices. For this purpose, encryption protocols such as TLS (Transport Layer Security) or SSL (Secure Sockets Layer) are commonly used, which provide each device with a key pair and a certificate based on the public key of the key pair.
[0008] To ensure reliable communication, all communication partners must trust the device's certificate. Using self-signed certificates generated by the device is generally unsuitable, particularly due to potential "man-in-the-middle" attacks and problematic authenticity verification. Generating key pairs and certificates externally via a certification authority (CA) within a public key infrastructure (PKI) is also not entirely problem-free, as the private key of such a key pair could be eavesdropped on during transmission to the respective device. Furthermore, TLS certificates, in particular, must be regularly updated for security reasons. Therefore, the key pairs and certificates generated by the certification authority are regularly transmitted to the device. In industrial automation systems, this involves a large number of devices. Summary of the Invention
[0009] The object of the present invention is therefore to provide a method for transmitting, in particular, time-critical data in an encrypted and protected manner within a communication system, which method enables the cost-effective, efficient and nevertheless secure provision of key material and certificates to terminal devices of the communication system, and to specify a suitable device for technically implementing this method.
[0010] This object is achieved according to the invention by a method having the features specified in claim 1 and by a terminal having the features specified in claim 12. Advantageous developments of the invention are specified in the dependent claims.
[0011] According to the method according to the invention for transmitting, in particular, time-critical data in an encrypted and protected manner within a communication system, the communication system comprises at least one switch or router and a plurality of terminal devices, which exchange, in particular, time-critical data for controlling a machine or device. The terminal devices, in particular embedded systems or embedded systems, each comprise a local authentication instance, which, when the respective terminal device is put into operation, generates a first key pair for the terminal device and a request for creating a certificate assigned to the first key pair and transmits this request to a higher-level authentication instance within the scope of the protected operation of the terminal device. The request generated by the local authentication instance is preferably a certificate signing request (CSR), which in particular includes the serial number of the respective terminal device.
[0012] The communication system can in particular be comprised by an industrial automation system. Advantageously, the superior authentication instance and the local authentication instance each comprise the functionality of a certification authority (CA). Furthermore, the local authentication instance preferably each comprises the functionality of a registration authority (RA) assigned to the superior authentication instance.
[0013] According to the present invention, a superior authentication instance checks the application of a local authentication instance of a terminal device. If the check is successful, the superior authentication instance creates a certificate assigned to the corresponding first key pair and transmits the certificate to the corresponding local authentication instance. The certificate generated by the superior authentication instance is preferably a distribution certificate, a TLS or SSL client certificate, or a TLS or SSL server certificate.
[0014] According to the present invention, the terminal device terminates the protected operation after receiving the certificate generated by the superior authentication instance. After the protected operation is terminated, the local authentication instance generates at least one second key pair and a certificate for the second key pair for the cryptographically protected exchange of data, in particular time-critical data, from or to the terminal device. The certificate for the second key pair is signed using the private key included in the first key pair. Preferably, the exchange of data, in particular time-critical data, from or to the terminal device is cryptographically protected using the second key pair. The certificate for the second key pair can be easily verified by the communication partner of the respective terminal device when exchanging data, in particular time-critical data, using the root certificate of the superior authentication instance.
[0015] Compared to previous methods, the method according to the present invention is more secure because the private key or the information required for key generation is generated in the terminal device itself and therefore does not leave the terminal device. This eliminates the possibility of eavesdropping on the private key during key transmission. Furthermore, when using TLS certificates, the previously required distribution of these certificates is eliminated because the certificate for the second key pair can be generated by the terminal device itself as needed, starting from the certificate generated once for the first key pair by the higher-level authentication instance. Furthermore, the present invention enables a simple and scalable security solution for industrial automation systems because the implementation effort on the higher-level authentication instance side is largely independent of the number of terminal devices that generate their own certificates for cryptographically protected communication.
[0016] According to the present invention, during protected operation of a terminal device, communication is only possible between each local authentication instance and a superior authentication instance. For example, a predefined default gateway configuration or predefined firewall settings can be activated for each terminal device for protected operation. Alternatively or additionally, the terminal device and the superior authentication instance can each connect to each other within an environment that is at least virtually isolated from other terminal devices during protected operation of the terminal device.
[0017] According to another advantageous embodiment of the present invention, the application for the local authentication instance includes the identifier of the corresponding terminal device, in particular the IDevID certificate (initial device identifier), or includes a signature created by the corresponding local authentication instance. In this case, checking the application by the superior authentication instance includes checking the validity of the identifier of the corresponding terminal device or the signature created by the corresponding local authentication instance. This enables efficient and reliable certificate checking.
[0018] The IDevID certificate is preferably stored in the terminal device according to IEEE 802.1AR when the device is manufactured, and the terminal device includes a private key assigned to the corresponding IDevID certificate. Here, the IDevID certificate includes the serial number of the corresponding terminal device and is signed by the corresponding manufacturer. In contrast to the respectively assigned private key, the IDevID certificate can be read after the device is manufactured. The identity of the terminal device can thus be checked, wherein the IDevID certificate is read and the validity is checked based on the root certificate of the corresponding manufacturer. In particular, when checking the identity of the terminal device, the consistency of the serial number included in the certificate signing request and the serial number included in the IDevID certificate is compared. In addition, the terminal device proves that it has access to the private key assigned to the IDevID certificate by means of a challenge-response method or by signing a random number sent to the terminal device with the help of the private key.
[0019] The terminal device according to the present invention for cryptographically protected transmission of particularly time-critical data within a communication system is particularly designed and configured to carry out the method according to the aforementioned embodiments. According to the present invention, the terminal device is designed and configured to exchange particularly time-critical data within the communication system for the purpose of controlling a machine or device. Furthermore, the terminal device includes a local authentication instance, which is designed and configured to generate a first key pair for the terminal device and a request for creating a certificate assigned to the first key pair when the terminal device is put into operation, and to transmit this request to a higher-level authentication instance within the scope of protected operation of the terminal device.
[0020] Furthermore, the terminal device according to the present invention is designed and configured to terminate the protected operation after receiving the certificate generated for the first key pair by the superior authentication instance. Furthermore, the local authentication instance is designed and configured to generate at least one second key pair and a certificate for the second key pair after the protected operation for the cryptographically protected exchange of, in particular, time-critical, data from or to the terminal device has concluded. The certificate is signed using the private key included in the first key pair. BRIEF DESCRIPTION OF THE DRAWINGS
[0021] The present invention will be described in more detail below with reference to the accompanying drawings.
[0022] Figure 1 An industrial automation system is shown, which comprises a plurality of automation devices and a superordinate authentication instance and in which, in particular, time-critical data are transmitted in an encrypted and protected manner from or to the automation devices.
[0023] Figure 2The diagram shows the process flow of a method for verifying a certificate provided for cryptographically protected data transmission. DETAILED DESCRIPTION
[0024] exist Figure 1 The industrial automation system shown in FIG has a superordinate authentication instance 100 , a plurality of automation devices 101 - 102 and a switch 103 , which interconnects the superordinate authentication instance 100 and the automation devices 101 - 102 . The automation devices 101 - 102 exchange data, in particular time-critical data 116 , 126 , for controlling a machine or system 110 .
[0025] Automation devices 101 - 102 can be physical or virtual hosts that provide data or resources to other hosts. The data or resources can be allocated, for example, to services or control and monitoring applications of an industrial automation system, which are instances of time-critical services or applications.
[0026] In this embodiment, automation devices 101-102 implement the functionality of control devices, such as programmable logic controllers or machine controllers, or field devices, such as sensors or actuators, in an industrial automation system. Automation devices 101-102 are used to exchange control variables and measured variables with a machine or device 110 controlled by the control device. In particular, the control device is configured to derive appropriate control variables from detected measured variables.
[0027] Alternatively or additionally, the automation devices 101-102 can each implement an operator station and an observer station and be used to process data or measured and controlled variables processed or captured by the control device or other automation devices. In particular, the operator station and the observer station can be used to display the values of control loops and to change control parameters or programs.
[0028] To transmit time-critical data 116, 126 in an encrypted and protected manner within an industrial automation system, the automation devices each include a local authentication instance 111, 121. When the respective automation device is put into operation, the local authentication instance generates a first key pair for the respective automation device 101-102 and a request 114, 124 for creating a certificate assigned to the first key pair. The first key pair is preferably stored in a specially protected key memory 112, 122 of the respective automation device 101-102. For example, a separate certificate memory 113, 123 is provided for each certificate.
[0029] Within the scope of protected operation of the respective automation devices 101-102, in particular during the onboarding process, the applications 114, 124 are transmitted to the superordinate authentication instance 100. In this exemplary embodiment, the superordinate authentication instance 100 and the local authentication instances 111, 121 each include the functionality of a certification authority (CA). Furthermore, the local authentication instances 111, 121 each include the functionality of a registration authority (RA) assigned to the superordinate authentication instance 100.
[0030] During protected operation of the automation devices 101-102, it can be provided, for example, that communication is essentially only possible between the respective local authentication instances 111, 121 and the superordinate authentication instance 100. Furthermore, a predefined default gateway configuration or predefined firewall settings can be activated for the protected operation of the automation devices 101-102. In particular, during protected operation of the automation devices 101-102, the automation devices 101-102 and the superordinate authentication instance 100 can each be connected to one another within an environment that is at least virtually isolated from other automation devices or end devices.
[0031] The superordinate authentication instance 100 checks the applications 114, 124 of the local authentication instances 111, 121 of the automation devices 101-102, respectively. If the check is successful, the superordinate authentication instance 100 creates a certificate 115, 125 assigned to the respective first key pair and transfers this certificate to the respective local authentication instance 111, 121. The application 114, 124 created by the local authentication instance 111, 121 is preferably a certificate signing request (CSR) and includes, for example, the serial number of the respective automation device 101-102.
[0032] Advantageously, the applications 114, 124 of the local authentication instances 111, 121 each include an IDevID (Initial Device Identifier) certificate as the identifier of the respective automation device 101-102. Alternatively or additionally, the applications 114, 124 can include a signature generated by the respective local authentication instance 111, 121. Accordingly, checking the applications 114, 124 by the superior authentication instance 100 includes checking the validity of the identifier of the respective automation device 101-102 or the signature generated by the respective local authentication instance 111, 121.
[0033] When devices are manufactured in accordance with IEEE 802.1AR, an IDevID certificate is preferably stored in the key memory 112, 122 or certificate memory 113, 123 of the respective automation device 101-102, along with the private key assigned to the respective IDevID certificate. In particular, the IDevID certificate includes the serial number of the respective automation device 101-102 and is signed by the respective manufacturer. In contrast to the private key assigned to each, and in particular protected in the key memory 112, 122, the IDevID certificate can be read after the device is manufactured. This allows the identity of the automation device 101-102 to be verified by reading the IDevID certificate and checking its validity using the root certificate from the respective manufacturer.
[0034] In this embodiment, when checking the identity of the automation devices 101-102, the superior authentication instance 100 compares the serial number included in the certificate signing request with the serial number included in the IDevID certificate. Furthermore, the automation devices 101-102 demonstrate access to the private key assigned to the IDevID certificate using a challenge-response method or by signing a random number sent to the automation devices 101-102 by the superior authentication instance 100 using the private key.
[0035] After receiving the certificates 115 , 125 generated by the superordinate authentication instance 100 , the automation devices 101 - 102 each terminate protected operation.
[0036] The certificate generated by the superior authentication instance 100 is preferably an issuing certificate. In principle, the superior authentication instance 100 can also create a TLS or SSL client certificate or a TLS or SSL server certificate.
[0037] After the protected operation is completed, the local authentication instances 111, 121 each generate at least one second key pair and a certificate for the second key pair for the encrypted and protected exchange of time-critical data 116, 126 from or to the automation devices 101-102. The certificate is signed using the private key included in the first key pair and stored in the certificate memory 113, 123.
[0038] The data exchanged from or to the automation devices 101-102, in particular the time-critical data 116, 126, is encrypted and protected by means of a second key pair. Figure 2 In step 201 of the method flow shown in FIG, the superior authentication instance 100 uses the certificate for the first key pair to authenticate the local authentication instances 111 and 121. According to step 202, the local authentication instances 111 and 121 in turn authenticate the certificate 117 for the second key pair generated by themselves.
[0039] According to step 203, the communication partner 200 of the automation device 101-102 can retrieve the root certificate from the certificate memory 104 of the superordinate authentication instance 100. Finally, according to step 204, the communication partner 200 verifies the certificate for the second key pair, which is signed with the private key included in the first key pair, using the root certificate of the superordinate authentication instance 100.
[0040] In this embodiment, automation devices 101-102 each automatically generate a new second key pair and a certificate for the new second key pair if the certificate for the second key pair loses validity due to a configuration change. For example, if a TLS certificate has already been created for a selected IP address, the TLS certificate loses its validity after the IP address changes. Therefore, encrypted communication continues even after such a configuration change.
Claims
1. A method for transmitting data in an encrypted and protected manner within a communication system, wherein: - the communication system comprises at least one switch (103) or router and a plurality of terminal devices (101-102) which exchange data to control a machine or device (110), - the terminal devices (101-102) each comprise a local authentication instance (111, 121), which generates a first key pair for the terminal device and a request (114, 124) for creating a certificate assigned to the first key pair when the corresponding terminal device is put into operation, and which transmits the request to a superior authentication instance (100) during protected operation of the terminal device, wherein only communication between the respective local authentication instance (111, 121) and the superior authentication instance (100) is possible during protected operation of the terminal device (101-102), - the superior authentication instance (100) checks the application (114, 124) of the local authentication instance of the terminal device respectively, and if the check is successful, the superior authentication instance creates a certificate (115, 125) assigned to the corresponding first key pair and transmits the certificate to the corresponding local authentication instance (111, 121), - the terminal devices (101-102) each terminate the protected operation after receiving the certificate generated by the superior authentication instance, - After the protected operation is terminated, the local authentication instance (111, 121) generates at least a second key pair and a certificate for the second key pair for exchanging data (116, 126) from and to the terminal device in an encrypted and protected manner, wherein the certificate is signed with the help of a private key included in the first key pair.
2. The method according to claim 1, wherein For the protected operation of the terminal, a predetermined default gateway configuration and / or predetermined firewall settings are respectively activated.
3. The method according to any one of claims 1 to 2, wherein During the protected operation of the terminal device, the terminal device and the superior authentication instance are respectively connected to each other in an environment isolated from other terminal devices.
4. The method according to any one of claims 1 to 3, wherein The applications of the local authentication instance respectively include the identifier of the corresponding terminal device and / or the signature created by the corresponding local authentication instance, and wherein the check of the application performed by the superior authentication instance respectively includes checking the validity of the identifier of the corresponding terminal device and / or the validity of the signature created by the corresponding local authentication instance.
5. The method according to any one of claims 1 to 4, wherein The exchange of data from and / or to the terminal is each cryptographically protected using the second key pair.
6. The method according to claim 5, wherein: During the data exchange, the certificate for the second key pair, signed by means of the private key included in the first key pair, is verified by the communication partner of the respective terminal using the root certificate of the superior authentication instance.
7. The method according to any one of claims 1 to 6, wherein The request created by the local authentication instance is a certificate signing request, and wherein the certificate generated by the superior authentication instance is an issuing certificate, a TLS or SSL client certificate and / or a TLS or SSL server certificate.
8. The method according to any one of claims 1 to 7, wherein The superior authentication instance and the local authentication instance respectively include authentication and authorization functions.
9. The method according to claim 8, wherein The local authentication instances each include a function of registration authorization assigned to the superior authentication instance.
10. The method according to any one of claims 1 to 9, wherein The communication system is comprised by an industrial automation system.
11. The method according to any one of claims 1 to 10, wherein In the event of a loss of validity of the certificate for the second key pair due to a configuration change, the terminal device automatically generates a new second key pair and a certificate for the new second key pair.
12. A terminal device for transmitting data in an encrypted and protected manner within a communication system, wherein: - the terminal device is designed and arranged to exchange data (116, 126) within the communication system for controlling a machine and / or device (100), the terminal device comprises a local authentication instance (111, 121) which is designed and arranged to generate a first key pair for the terminal device and a request (114, 124) for creating a certificate assigned to the first key pair when the terminal device is put into operation, and to transmit the request to a superordinate authentication instance (100) during protected operation of the terminal device, the terminal device is further designed and arranged to terminate the protected operation after receiving the certificate generated by the superior authentication instance for the first key pair, -The local authentication instance (114, 124) is also designed and configured to, after the protected operation is terminated, generate at least a second key pair and a certificate for the second key pair for exchanging data from and / or to the terminal device in an encrypted and protected manner, wherein the certificate is signed with the aid of a private key included in the first key pair.
13. The terminal device according to claim 12, wherein: The terminal is designed and configured to execute the method according to any one of claims 1 to 12 .
Citation Information
Patent Citations
Method for inspecting datagrams transmitted within an industrial automation system and automation and / or communication device
EP3646559B1
Method and system for providing time-critical services by means of a process control environment
EP3975502A1
Method for secure transmission of time-critical data within a communication system and communication system
EP4283925A1
Data processing method, vehicle-mounted equipment and electronic equipment
CN108055236A
Methods of data sending and equipment
CN109639427A