Device for cryptographically protecting communication equipment of industrial automation system
By introducing Ethernet plug-in connectors and cryptographic modules into industrial automation systems, the problem of low-cost cryptographic protection is solved, enabling reliable encryption and decryption of communication devices. This technology is suitable for PROFINET secure networks and zero-trust environments.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-07-10
- Publication Date
- 2026-04-14
Smart Images

Figure CN121866746A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to a device for cryptographically protecting communication equipment in industrial automation systems, particularly equipment without cryptographic capabilities. Background Technology
[0002] Industrial automation systems typically comprise a large number of automated devices connected to the Internet via industrial communication networks and are used within the framework of manufacturing automation or process automation for open-loop or closed-loop control of equipment, machines, or systems. Due to the time-critical nature of industrial automation systems, real-time communication protocols (such as PROFINET, PROFIBUS, real-time Ethernet, or Time-Sensitive Networking (TSN)) are primarily used for communication between automated devices.
[0003] Because they are used for typically very different applications, problems can arise in Ethernet-based communication networks, for example, if network resources compete for the transmission of data streams or frames with real-time requirements and for the transmission of data frames with substantial valid data content but no specific quality of service requirements. This can cause data streams or frames with real-time requirements to fail to be transmitted at the requested or required quality of service.
[0004] EP 3 270 560 B1 describes a method for establishing a protected communication connection to an industrial automation system. In this method, a connection management facility, upon a positive authorization verification result, provides access control information to a first communication device requesting a user and a selected second communication device for establishing an encrypted communication connection. The connection management facility consists of a server instance running on a firewall system. Data packets transmitted via the encrypted communication connection between the first communication device requesting the user and the selected second communication device are decrypted by the firewall system for verification based on established security rules, and, upon successful verification, are encrypted and forwarded to either the first communication device requesting the user or the selected second communication device.
[0005] An earlier European patent application, EP 4 283 925 A1, relates to the protected transmission of time-critical data within a communication system comprising multiple local area networks (LANs) in which data is transmitted via switching, at least one network superimposed on the LANs in which data is transmitted via routing, and a gateway system for connecting the communication system to at least one unprotected external network. Network layer communication via the superimposed network is authorized only between authenticated system components. Each switch authenticates the connected terminal devices and assigns them to physical or logical LANs based on their respective terminal device identities. Security layer communication within a LAN is implicitly authorized because the corresponding terminal devices are assigned to the same LAN. Communication at OSI layers 3-7 between terminal devices in different LANs or with terminal devices in an unprotected external network is authorized via zero-trust proxies assigned to a LAN respectively.
[0006] A method for protected transmission of time-critical data within a communication system is known from an earlier European patent application, EP 4 300 882 A1. This communication system includes multiple local area networks (LANs), each LAN comprising at least one switch and multiple terminal devices, a control unit (which controls the functions of the multiple switches and terminal devices), and a control network separate from the LANs and assigned to the control unit. Communication within the LANs is implicitly authorized because the corresponding terminal devices are assigned to the same LAN. Each terminal device is assigned a zero-trust adapter that collects the terminal device's status information, forwards this status information to the control unit via the control network for evaluation, and authenticates the terminal device relative to the control unit or a communication partner. For each terminal device, the control unit determines a confidence index based on the status information and applies rules for configuring or allowing communication relationships for the terminal device according to this confidence index.
[0007] US 2022 / 067221 A1 describes a method for implementing secure operation in an input / output (I / O) device. The I / O device includes I / O ports, a host bus connected to a host, a data processing pipeline within the I / O device coupled to the I / O ports and the host bus, and a hardware security module. The hardware security module is also connected to the host bus and the data processing pipeline and includes a cryptographic engine capable of encrypting and decrypting data in the data processing pipeline. Furthermore, the hardware security module includes a security key memory that stores encryption keys used to encrypt and decrypt data packets. These keys, encrypted by the hardware security module, are stored in the security key memory and are accessible through it.
[0008] Specifically, the zero-trust concept stipulates that users or devices, regardless of their location or environment, should authenticate with communication partners or when accessing protected resources to gain access to desired data or applications upon successful authentication. However, in some application areas, the limitation to meeting network security requirements lies in the fact that not every user or device can afford to guarantee secure authentication, encryption and decryption, or the storage of encryption keys. This is often a problem, especially in industrial automation systems with long-used inventory components. Summary of the Invention
[0009] Therefore, the object of this invention is to create a solution that can be integrated into existing environments at low cost for cryptographic protection of communication devices, especially within industrial automation systems.
[0010] This objective is achieved according to the invention by means of a device having the features described in claim 1. Advantageous further developments of the invention are given in the dependent claims.
[0011] The apparatus of the present invention for cryptographically protecting communication equipment in an industrial automation system includes a first Ethernet plug-in connection element for connecting to a communication network in which messages are transmitted in a cryptographically protected manner (particularly encrypted), a second Ethernet plug-in connection element for connecting to the communication equipment, and a cryptographic module. For example, the first Ethernet plug-in connection element can be an RJ45 connector or an M12 connector, and the second Ethernet plug-in connection element can be an RJ45 connector or an M12 connector.
[0012] According to the present invention, the cryptographic module is designed to store cryptographic keys or certificates assigned to a communication device or its user, for encrypting messages sent by the communication device and decrypting messages sent to the communication device. Preferably, the cryptographic module is also designed to verify the certificates of the communication device or the communication partner of the user of the communication device.
[0013] According to the present invention, a security sensor is provided at the second Ethernet plug-in connection element for monitoring the disconnection from the communication device. This security sensor is configured to trigger the locking of the cryptographic key, certificate, or cryptographic module when the connection to the communication device is lost. The present invention thus enables devices, especially those without PROFINET security functions, to connect to the PROFINET security network and thereby participate in cryptographically protected network communications. Therefore, no device replacement is required.
[0014] According to the present invention, the cryptographic module includes a processor, such as an FPGA or ASIC, designed for encrypting and decrypting messages. Furthermore, the functionality of the cryptographic module can be controlled by engineering tools via an encrypted connection or via a dedicated configuration interface of the device. Additionally, a security sensor for monitoring disconnections between the device and the communication equipment can be activated or deactivated by engineering tools via an encrypted connection or via a dedicated configuration interface.
[0015] An encrypted connection for controlling the functions of the cryptographic module can be established, for example, via a first Ethernet plug-in connection element. Furthermore, a dedicated configuration interface can be advantageously implemented using a USB interface, serial interface, NFC interface, Bluetooth interface, or WLAN.
[0016] According to a particularly preferred embodiment of the invention, a security sensor is implemented on the plug neck of the device or on the plug-in contact surface by means of a mechanical button, a capacitive or resistive sensor element, a reed contact, an ultrasonic sensor element, or a photoelectric sensor unit. Therefore, reliable locking of the cryptographic key or certificate or cryptographic module is always ensured when a mechanical disconnection occurs between the device according to the invention and the communication device to be protected. Advantageously, the security sensor is also configured to be activated when a connection is established with the communication device at the second Ethernet plug-in connection element.
[0017] When implementing a security sensor based on a photoelectric sensor unit, the photoelectric sensor unit advantageously includes a light-emitting diode (LED) and a phototransistor. Based on the amount or intensity of light incident from the LED into the phototransistor, a break in the connection between the device and the communication equipment can be reliably detected. Furthermore, the LED can be controlled to emit a signal in the form of coded pulses, and the pulse pattern of this signal received by the phototransistor can be compared for consistency with a reference pattern. Attached Figure Description
[0018] The present invention will be further illustrated by way of embodiments and with reference to the accompanying drawings. The drawings show: Figure 1 A schematic diagram of a device for cryptographically protecting communication equipment in an industrial automation system is shown. Figure 2 Showing according to Figure 1 A three-dimensional view of the device and the communication equipment to be protected in a connected state. Figure 3 Showing according to Figure 2 A view of the device and the communication equipment to be protected in the disconnected state. Detailed Implementation
[0019] exist Figure 1The device 1 shown is used for cryptographic protection of communication equipment in an industrial automation system. Such communication equipment can be, for example, a PROFINET device that does not itself have PROFINET security features enabled but needs to operate within a PROFINET secure environment. In another application scenario, the communication device can be a device without encryption capabilities but needs to operate in a zero-trust environment.
[0020] The device includes a first Ethernet plug-in connection element 11 for connecting to a communication network within which messages are transmitted in a cryptographically protected manner. Additionally, a second Ethernet plug-in connection element 12 is provided for connecting to a communication device. In this embodiment, the first Ethernet plug-in connection element 11 is an RJ45 socket, and the second Ethernet plug-in connection element 12 is an RJ45 plug. According to an alternative embodiment, the first Ethernet plug-in connection element 11 can be an M12 socket, and the second Ethernet plug-in connection element 12 can be an M12 plug. Furthermore, the first Ethernet plug-in connection element 11 can also be a plug, and the second Ethernet plug-in connection element 12 can be a socket. In principle, plug-to-plug or socket-to-socket combinations are also possible.
[0021] Furthermore, device 1 includes a cryptographic module 13 designed to store cryptographic keys or certificates assigned to the communication device or its user. The cryptographic module 13 is also designed to decrypt encrypted messages 101 sent to the communication device and to encrypt unencrypted messages 102 sent by the communication device. Specifically, the cryptographic module 13 is designed to verify the certificates of the communication device or its user's communication partner.
[0022] The cryptographic module 13 preferably includes a processor, FPGA, or ASIC designed for encrypting and decrypting messages. Advantageously, the functionality of the cryptographic module 13 can be controlled by engineering tools via an encrypted connection or via a dedicated configuration interface 131 of the device. This dedicated configuration interface can be implemented, for example, via a USB interface, serial interface, NFC interface, Bluetooth interface, or via WLAN. If the dedicated configuration interface 131 is not provided, an encrypted connection for controlling the functionality of the cryptographic module 13 can be established via a first Ethernet plug-in connection element 11.
[0023] In addition, such as Figure 1 As shown, device 1 includes an optional power terminal 132. Alternatively, device 1 can also be powered, for example, via Ethernet.
[0024] A security sensor 121 is provided at the second Ethernet plug-in connector 12 for monitoring... Figure 2 The connection to communication device 2 is disconnected, as shown in the diagram. Security sensor 121 is configured to... Figure 3 In the event of a disconnection from the communication device 2, as shown, a lock is triggered on the cryptographic key or certificate or the cryptographic module 13. Advantageously, the security sensor 121 is disposed at the plug neck or plug-in contact surface of the housing 14 of the second Ethernet plug-in connection element 12 or the device 1 containing the cryptographic module 13.
[0025] The safety sensor 121 can be implemented, for example, by means of a mechanical button, a capacitive or resistive sensor element, a reed contact, an ultrasonic sensor element, or a photoelectric sensor unit. In the case of implementation using a photoelectric sensor unit, the photoelectric sensor unit includes a light-emitting diode (LED) and a phototransistor. Based on the amount or intensity of light emitted from the LED into the phototransistor, the disconnection of the connection between the device 1 and the communication device 2 can be reliably detected. Furthermore, the LED can be driven to emit a predetermined or random pulse sequence. Signals received at the phototransistor can then be compared to determine whether they match the pulse sequence.
[0026] According to a preferred embodiment, in order to monitor the disconnection of the connection between the monitoring device 1 and the communication device 2, the security sensor 121 can be activated or deactivated by an engineering tool via an encrypted connection or via a dedicated configuration interface 131. Alternatively or additionally, the security sensor 121 can be activated when a connection to the communication device 2 is established at the second Ethernet plug-in connection element 12.
Claims
1. A device for cryptographically protecting communication equipment in an industrial automation system, wherein, The device includes: - A first Ethernet plug-in connector (11) is used to connect to a communication network, within which messages are transmitted in a cryptographically protected manner. - A second Ethernet plug-in connector (12) for connecting to the communication device (2), and - Cryptographic module (13), the cryptographic module is designed to store cryptographic keys and / or certificates assigned to the communication device and / or the user of the communication device for encrypting messages (102) sent by the communication device and decrypting messages (101) sent to the communication device. -The cryptographic module (13) includes a processor designed to encrypt and decrypt messages and capable of controlling the functionality of the cryptographic module via engineering tools through a dedicated configuration interface (131) of the device (1) and / or via an encrypted connection. -The second Ethernet plug-in connection element is provided with a security sensor (121) for monitoring the disconnection of the connection with the communication device. The security sensor is designed to trigger the locking of the cryptographic key and / or certificate and / or the cryptographic module when the connection with the communication device is disconnected. -In order to monitor the disconnection of the connection between the device (1) and the communication device (2), the security sensor (121) can be activated and / or deactivated by the engineering tool via the encrypted connection and / or via the dedicated configuration interface (131).
2. The apparatus according to claim 1, wherein, The cryptographic module (13) is designed to check the certificates of the communication device (2) and / or the communication partners of the user of the communication device.
3. The apparatus according to any one of claims 1 or 2, wherein, The encrypted connection for controlling the function of the cryptographic module (13) is constructed via the first Ethernet plug-in connection element (11).
4. The apparatus according to claim 3, wherein, The dedicated configuration interface (131) is implemented via a USB interface, serial interface, NFC interface, Bluetooth interface or WLAN.
5. The apparatus according to any one of claims 1 to 4, wherein, The safety sensor (121) is implemented on the plug neck and / or on the plug connection contact surface of the device by means of a mechanical button, a capacitive or resistive sensor element, a reed contact, an ultrasonic sensor element, or a photoelectric sensor unit.
6. The apparatus according to claim 5, wherein, The photoelectric sensor unit includes a light-emitting diode and a phototransistor, and wherein the disconnection of the connection between the device (1) and the communication device (2) can be detected based on the amount and / or intensity of light incident from the light-emitting diode into the phototransistor.
7. The apparatus according to any one of claims 5 or 6, wherein, The security sensor (121) is designed to be activated when a connection to the communication device (2) is established at the second Ethernet plug-in connection element (12).
8. The apparatus according to any one of claims 1 to 9, wherein, The first Ethernet plug-in connection element (11) is an RJ45 connector or an M12 connector, and the second Ethernet plug-in connection element (12) is an RJ45 connector or an M12 connector.
Citation Information
Patent Citations
Method for establishing secure communication links to an industrial automation system and firewall system
EP3270560B1
Method for secure transmission of time-critical data within a communication system and communication system
EP4283925A1
Method for secure transmission of time-critical data within a communication system, communication system and adapter for end device
EP4300882A1
Method and system for implementing security operations in an input / output device
US20220067221A1