DATA TRANSFER DEVICE

DE502020012480D1Active Publication Date: 2026-01-15SIEMENS MOBILITY GMBH
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
DE502020012480
Authority / Receiving Office
DE · DE
Patent Type
Patents
Current Assignee / Owner
Priority Date
2019-07-30
Filing Date
2020-07-22
Publication Date
2026-01-15
Estimated Expiration
2040-07-22

AI Technical Summary

Technical Problem

Existing bidirectional network guards for secure communication between networks with different security levels are vulnerable to manipulation and errors, lacking effective fault detection and localization mechanisms.

Method used

A transmission device with independently operating communication and one-way communication devices that can detect, identify, and locate faults within or between components by evaluating operating states using test messages with identification and security information, and employing cryptographic checks.

Benefits of technology

Enhances security and reliability by enabling self-checks to verify correct operation, reduces troubleshooting time, and logs error data for user-friendly error correction, ensuring secure and stable data transmission.

✦ Generated by Eureka AI based on patent content.
Patent Text Reader
Need to check novelty before this filing date? Find Prior Art

Description

[0001] This application concerns a transmission device for transferring data between a first network and a second network.

[0002] For secure communication between a safety-critical network, such as an industrial control network or a railway safety network, and an open network, such as an IT network, which is preferably designed as an office network or a diagnostic network, one-way communication units, such as data diodes, can be used to enable unidirectional data transmission.

[0003] A data diode with a feedback channel is also known as a bidirectional network guard or security gateway.

[0004] Such a data diode enables secure data transfer between two information systems with different security levels. A corresponding network guard is typically a combination of hardware and software.

[0005] A bidirectional network guard is fundamentally structured such that two separate unidirectional data streams are each implemented using a one-way communication device, with the data streams flowing in opposite directions. This allows data exchange in both directions, ensuring one-way functionality in each case. For example, a bidirectional network guard can transmit data from a network with high security requirements to an open network with low security requirements, or vice versa.

[0006] However, under certain conditions, manipulation of these bidirectional network guards is possible and / or errors can occur during the operation of the bidirectional network guard.

[0007] Furthermore, the Network Guard is designed to ensure that no arbitrary data can be transmitted from the network with low security requirements to the network with high security requirements.

[0008] For this reason, Network Guard implements verification mechanisms to allow only approved or specially marked data to be transferred from the low-security network to the high-security network.

[0009] This implies that the Network Guard must be protected against attacks from networks with low security requirements.

[0010] US Patent 6,404,740 B1 describes a system for testing the internal connectivity of an ATM switch with multiple subsystems. Existing "loopback OAM cells" are augmented with an identifier for each subsystem under test and transmitted by a sender to the ATM switch for further transmission through the individual subsystems. The identifier of the "loopback OAM cell" is checked in successive subsystems. If the entered identifier matches the identifier of the subsystem, that subsystem sends the "loopback OAM cell" back to the sender over the same connection. This allows the sender to verify the boundary between reachable and unreachable subsystems and thus locate a fault.

[0011] US2019007220 A1 describes the coupling of a security device, which is a hardware security module (HSM), with a device. For this purpose, a one-time-use private signing key and device-specific identification information are stored in the security device. The device-specific certificate is generated based on the stored device-specific identification information in the security device and signed with the private signing key. Further access to the private signing key is prevented.

[0012] Against this background, one object of the present invention is to provide means to increase the security of data transmission through the transmission device between a first network and a second network.

[0013] According to a first aspect, a transmission device for transferring data between a first network and a second network is proposed according to independent claim 1.

[0014] The provided transmission device is independently capable of detecting, identifying, and locating any fault that occurs within it, pinpointing in which component and / or between which components the fault originates. Specifically, each communication and one-way communication device within the transmission device can independently test whether at least one fault occurs on the transmission path between the individual communication and / or one-way communication devices, or within any of the communication or one-way communication devices themselves.If a fault occurs, each communication and one-way communication device can independently test in which component, i.e., in which communication or one-way communication device or between which communication or one-way communication devices, the fault originates. Whether a fault occurs and where it is located is determined, in particular, by evaluating the operating state of the transmission device.

[0015] This has the advantage that a self-check of the transmission device, for example at startup, can reliably verify whether the transmission device is functioning correctly. If an error is detected, the administrator or user of the transmission device is advantageously informed, who can then initiate corrective measures. This increases the reliability and safety of the transmission device's operation.

[0016] Another advantage of the transmission device is that its automatic fault localization reduces the time required for troubleshooting by the administrator should a fault occur. This improves the ease of use when operating the transmission device.

[0017] Another advantage of the transmission device is that if the self-check is performed centrally by the selected single communication or one-way communication device, the internal data stream for checking for errors is reduced, particularly the overhead of the data transmitted by the transmission device. This increases the reliability of the transmission device's operation.

[0018] Another advantage of the transmission device is that the evaluation of the operating status, especially the data generated during the evaluation, is logged and stored to make it available to the administrator or user of the transmission device. This allows for the tracking of which errors occurred when and where at any given time. This increases user-friendliness and improves error correction, as measures taken in response to errors are readily available.

[0019] The transmission device is configured in particular as a bidirectional network guard or as a security gateway. The bidirectional network guard is preferably implemented in hardware and / or software.

[0020] The first network typically comprises an industrial control network, such as a production plant, an automation system, or a wind farm network. For example, the first network can be connected to the first communication device via a first interface device. The second network is typically an IT network, configured as an office network or a monitoring network.

[0021] A fault is, in particular, a defective communication or one-way communication device and / or a component within the communication or one-way communication device. Furthermore, a fault exists if, for example, an internal communication link (a connection) between a communication device and a one-way communication device is defective.

[0022] The internal receive port and the internal transmit port are implemented primarily in terms of hardware and / or software.

[0023] Specifically, data transmitted from the first network to the second network is transferred from the first communication device via the first one-way communication device to the second communication device. Specifically, data transmitted from the second network to the first network is transferred from the second communication device via the second one-way communication device to the first communication device.

[0024] The test message is, in particular, a message. In this context, a message is understood to be, in particular, a digital data record, for example, a sequence of zeros and ones, also known as bits, of a specific length.

[0025] If a test message, preferably sent via its internal transmit port of a selected communication or one-way communication device, is received at the internal receive port of the selected communication or one-way communication device, the operating status of the transmission device, in particular the respective communication and / or one-way communication device, can be evaluated.

[0026] The respective device, for example, a communication device, interface device, and / or one-way communication device, can be implemented in hardware and / or software. In a hardware implementation, the respective device can be designed as a device or as part of a device. In a software implementation, the respective device can be designed as a computer program product, as a function, as a routine, as part of program code, or as an executable object.

[0027] According to one embodiment, an internal physical communication link PHY is arranged between each internal transmit port and each internal receive port, which is formed in a transmission layer, layer 1, according to the OSI / ISO layer model.

[0028] According to another embodiment, at least one of the internal communication links is designed as a unidirectional communication link according to an Ethernet standard, an SDI standard, a physical conductor connection, in particular an optical fiber line and / or a conductor track.

[0029] By designing at least one of the internal communication links as a unidirectional link, it is advantageously ensured that data transmission between, for example, the first communication device and the first one-way communication device, is transmitted only from the sender to the receiver, i.e., exclusively from the first communication device to the first one-way communication device, and not vice versa. This increases the tamper resistance and the security of data transmission within the transmission device.

[0030] Preferably, a first internal communication link is arranged between the first communication device and the first one-way communication device. Furthermore, a second internal communication link is arranged between the first one-way communication device and the second communication device. For example, a third internal communication link is arranged between the second communication device and the second one-way communication device. Preferably, a fourth internal communication link is arranged between the second one-way communication device and the first communication device. For example, the first and second internal communication links can be used exclusively to transmit data from the first network to the second network via the first one-way communication device.In particular, the third and fourth communication links may only be used to transmit data from the second network to the first network via the second one-way communication device. Specifically, the first and second internal communication links form a unidirectional connection from the first network to the second network, while the third and fourth internal communication links form an exclusive connection from the second network to the first network. Specifically, the first, second, third, and fourth internal communication links are configured to transmit any test message or data transmitted via them only in a unidirectional direction.

[0031] The Ethernet standard includes, in particular, 10 Mbit / s Ethernet, 100 Mbit / s Ethernet, Gigabit Ethernet, 2.5 and 5 Gbit Ethernet and / or 10 Gbit / s Ethernet.

[0032] The "Serial digital interface" (SDI) standard is, in particular, a serial digital interface for transmitting data over a physical conductor connection.

[0033] A conductor track is understood to be, in particular, a physical conductor connection in which the medium for transmitting data is made of metallic materials, such as preferably copper, aluminum, gold, or silver. An optical fiber line, for example, is understood to be a physical conductor connection in which the medium for transmitting data is light. In this case, optical waveguides and fiber optic cables made of optical fibers are used.

[0034] According to another embodiment, at least one of the communication or one-way communication devices is set up as an embedded processor card, as a system-on-chip, in particular ARM-based, or as a computer.

[0035] Advanced Risk Machine (ARM) is, in particular, a microprocessor design. Specifically, individual functional blocks, such as CPU cores of an ARM-based CPU, can be configured into a system-on-a-chip.

[0036] According to a further embodiment, each communication and one-way communication device is configured to send a test message via its internal transmit port and to evaluate, at its internal receive port, the test message transmitted back from each communication and one-way communication device via the other communication and one-way communication devices and internal communication links to the selected communication or one-way communication device, and in particular supplemented with test data, to determine an operating state of the transmission device.

[0037] Because each communication and one-way communication device sends its own test message, each device can independently perform self-verification. Specifically, if a test message sent by any of the communication devices is received back unchanged, then no error has occurred in the transmission device along the transmission path between the individual communication and one-way communication devices. This has the advantage that errors on the transmission path or manipulation of one of the internal communication links and / or one of the communication or one-way communication devices can be reliably detected. This increases the reliability of data transmission via the transmission device.

[0038] The test data is used in particular to determine and evaluate the operating state of the transmission device. The test data includes at least one piece of information from the sender or generator of the test message and, for example, specific security information. This specific security information can be in the form of a nonce (i.e., a random number). It can also be in the form of a timestamp. The nonce is preferably used as a session identification number. This specific security information can also be referred to as specific test data embedded within the test message.

[0039] The specific security information and the information of the sender or generator of the test message are used to evaluate the operating status of the transmission device. In particular, the evaluation includes a Ab The test message received at the internal receiving port of the communication or one-way communication device is compared with the expected test message to obtain an evaluation result. The expected test message is preferably the test message originally sent by the communication or one-way communication device. If the received test message matches the expected test message, this indicates, for example, that the transmission device is functioning correctly.

[0040] According to another embodiment, the transmission device also includes an intermediate storage device for storing an evaluation result.

[0041] In particular, the received test message, which is received at the first or second communication device and / or the first or second one-way communication device, is evaluated to determine the operating state of the transmission device in order to obtain an evaluation result. The evaluation result is stored, in particular, by means of the transmission device's buffer. The buffer is implemented, in particular, in hardware and / or software.

[0042] According to a further embodiment, the selected communication or one-way communication device is configured to generate a respective test message which includes at least identification information for identifying the selected communication or one-way communication device and / or at least test data specific to the sent test message.

[0043] The identification information for identifying the selected communication or one-way communication device includes, in particular, information about the originator and / or the source of the respective test message.

[0044] According to another embodiment, the selected communication or one-way communication device is configured to provide the test message and / or the test data with a cryptographic checksum.

[0045] According to a further embodiment, at least one of the other communication or one-way communication devices is configured to validate a cryptographically checked checksum-bearing test message and / or cryptographically checked checksum-bearing test data received at its internal receiving port using a public key or a symmetric key of the selected communication or one-way communication device.

[0046] The provided validation of the test message using cryptographic keys advantageously allows for verification that the test message actually originates from the communication or one-way communication device claiming to have sent it, and also advantageously for validating the message's integrity. Specifically, the integrity of the test message is ensured if it has not been unintentionally modified or altered during transmission from at least one internal send port to an internal receive port. This enhances the security of data transmission between the first and second networks.

[0047] A cryptographic key is, in particular, a public, a private, or a symmetric cryptographic key. The private key of the selected communication or one-way communication device is used to assign a cryptographic checksum to the verification message. Alternatively, a symmetric key can also be used.

[0048] In this context, a digital signature is understood to mean, in particular, a digital signature procedure in which a sender, for example, the first selected communication or one-way communication device, signs the verification message and / or the verification data using its private key. The signing process includes the calculation of a cryptographic checksum, which is, in particular, part of the verification message and / or appended to it. Using this checksum, a recipient, for example, one of the other communication or one-way communication devices, can preferably verify the authenticity of the selected communication or one-way communication device and the integrity of the verification message using the public key of the selected communication or one-way communication device. The digital signing or the digital signature procedure can be implemented using Cryptographic Message Syntax (CMS).

[0049] A public key is preferably a cryptographic key. In particular, the public key is not secret. Digital signatures, in particular, can be verified using the public key. A public key can be uniquely assigned to a communication or one-way communication device, such as the selected communication or one-way communication device. The public key is uniquely identified, in particular, by means of a fingerprint (for example, a hash value).

[0050] The private key of a communication or one-way communication device, such as the selected communication or one-way communication device, is preferably used to sign the test message and / or the test data, or to provide the test message and / or the test data with a cryptographic checksum. In particular, only the selected communication or one-way communication device possesses the private key for digitally signing the test message and / or the test data. The private key of a communication or one-way communication device, such as the selected communication or one-way communication device, is specifically secret. Thus, the other communication or one-way communication devices have no information about the secret private key of the selected communication or one-way communication device.

[0051] In particular, as an alternative to private and public cryptographic keys, a symmetric key is used to generate a Message Authentication Code (MAC), such as HMAC-SHA256. The symmetric key is preferably used to sign and validate the test message and / or the test data.

[0052] The verification message, in particular the message's verification data, i.e., the identification information and the specific verification data, is preferably provided with a cryptographic checksum. The cryptographic checksum can be generated using HMAC, a symmetric key, or a public-private key pair.

[0053] According to a further embodiment, each of the other communication or one-way communication devices is configured to add test data to a received test message, in particular to add test data assigned to the respective communication or one-way communication devices receiving the test message.

[0054] According to another embodiment, only the selected communication or one-way communication device is configured as the master device to generate and send a test message, with the other communication or one-way communication devices acting as slave devices to add test data to the respective received test messages and forward them.

[0055] By adding test data to the test message generated by the master device and forwarding the test message only via other communication or one-way communication devices and transmitting it back to the master device, the overhead of the data transmitted by the transmission device is reduced. This places less strain on the transmission device, as less data is generated when determining the operating state of the transmission device using the above approach. This results in more stable and reliable operation during data transmission using the transmission device.

[0056] The associated security information includes, in particular, a nonce (i.e., a random number) or a timestamp. The associated security information can also be referred to as specific check data embedded within the check message.

[0057] In this approach, a selected communication or one-way communication device is configured as a master device, which generates and sends a test message. The other communication or one-way communication devices of the transmission device are each configured as a slave device. Each slave device appends its own associated test data to the test message initiated by the master device. If the master device does not receive its own test message, which includes the information appended during the generation of the test message as well as any additional information added by the slave devices, this indicates that one of the other communication or one-way communication devices, or one of the physical internal communication links, has been tampered with and / or is faulty and no longer functioning correctly.

[0058] According to another embodiment, each of the other communication or one-way communication devices is configured to forward a received test message exclusively.

[0059] In this process, a single test message is received and forwarded via each of the other communication or one-way communication devices until it is received again at the internal receiving port of the sender and / or the generator of the test message, such as the selected communication or one-way communication devices.

[0060] For example, if the generator of the test message uses the selected communication or one-way communication device, which is configured as the first communication device, the message is first forwarded unidirectionally via the first one-way communication device to the second communication device. From there, the test message is forwarded via the second one-way communication device and transmitted back to the first communication device. Preferably, after exactly three forwardings—namely via the first one-way communication device, the second communication device, and the second one-way communication device—the first communication device receives the generated and transmitted test message again.

[0061] According to the invention, as per the first aspect, the communication and one-way communication devices are coupled to each other by means of the internal communication links in such a way that a respective test message is received by all other communication or one-way communication devices.

[0062] This advantageously allows each individual communication or one-way communication device to send, forward, and / or receive a test message. This increases the reliability of data transmission within the transmission device.

[0063] According to another embodiment, the selected communication or one-way communication device is configured to generate the test message at predetermined times and send it via its internal transmission port, in particular when the transmission device is started up.

[0064] This has the advantage that the administrator or user can specify when the transmission device's self-check should be performed. This increases the security of data transmission within the transmission device and the likelihood of detecting tampering or errors.

[0065] Furthermore, other predetermined times are possible, such as regularly at predetermined time intervals, e.g. every hour or every day, and / or irregularly upon user input from the administrator.

[0066] According to another embodiment, the first one-way communication device and the second one-way communication device are integrated as a single communication device.

[0067] It is particularly possible to implement the one-way communication devices in a core board. This means that instead of two separate one-way communication devices, such as the first and second one-way communication devices, only a single one-way communication device is used. This offers the advantage of increased fault tolerance and thus the reliability of the transmission device.

[0068] The aforementioned one-way communication devices can be configured to form the transmission device as a physical unit with fixed internal connections.

[0069] Further advantageous embodiments and aspects of the invention are the subject of the dependent claims and the exemplary embodiments of the invention described below. The invention will be explained in more detail below with reference to preferred embodiments and the accompanying figures. Fig. 1 shows a schematic block diagram of an embodiment of a transmission device; Fig. 2 shows a schematic flowchart of an embodiment for determining an operating state of the transmission device according to Fig. 1 Fig. 3 shows a schematic flowchart of a further embodiment for determining an operating state of the transmission device according to Fig. 1 ; and Fig. 4 shows schematic block diagrams of several test messages, each containing different test data and provided with a cryptographic checksum.

[0070] In the figures, identical or functionally equivalent elements have been given the same reference symbols, unless otherwise indicated.

[0071] The Fig. 1 Figure 1 shows a schematic block diagram of an embodiment of a transmission device 1 for transmitting data between a first network NW1 and a second network NW2. The transmission device 1 of the Fig. 1 comprises a first communication device 2, a second communication device 3, a first one-way communication device 4 and a second one-way communication device 5.

[0072] In the Fig. 1 In one embodiment, one of the communication or one-way communication devices 2, 3, 4, 5 is configured as a system-on-chip, in particular ARM-based. In another embodiment, one of the communication or one-way communication devices 2, 3, 4, 5 is configured as an embedded processor card.

[0073] The first communication device 2 has a first interface device 6 for coupling to the first network NW1, an internal receive port 12 for receiving messages, and an internal send port 8 for sending messages. In the Fig. 1 The first communication device 2 is coupled to the first network NW1 for data exchange via the first communication link 16. Sending and receiving messages in Fig. 1 This includes in particular the sending and receiving of the test message PN supplemented with test data II, SI (see Fig. 2 und 3 ).

[0074] Furthermore, the second communication device 3 has a second interface device 7 for coupling to the second network NW2, an internal receive port 13 for receiving messages, and an internal send port 9 for sending messages. In the Fig. 1 The second communication link 17 connects the second communication device 3 to the second network NW2 for data exchange. Fig. 1 A first communication link 20 is arranged between the internal transmit port 8 of the first communication device 2 and an internal receive port 14 of the first one-way communication device 4 in order to transmit messages, in particular at least the check message PN, unidirectionally from the first communication device 2 to the first one-way communication device 4.

[0075] Furthermore, in the Fig. 1 The first one-way communication device 4 is shown, which includes the internal receive port 14 for receiving messages from the first communication device 2 and an internal transmit port 10 for sending messages to the second communication device 3. Furthermore, in Fig. 1 A second communication link 21 is arranged between the internal transmit port 10 of the first one-way communication device 4 and the internal receive port 13 of the second communication device 3 in order to transmit messages, in particular at least the test message PN, unidirectionally from the first one-way communication device 4 to the second communication device 3.

[0076] Also in Fig. 1 The second one-way communication device 5 is shown, which has an internal receive port 15 for receiving messages from the second communication device 3 and an internal transmit port 11 for sending messages to the first communication device 2. In an embodiment not shown, the first one-way communication device 4 and the second one-way communication device 5 are integrated as a single one-way communication device.

[0077] Furthermore, in Fig. 1 A third communication link 22 is arranged between the internal transmit port 9 of the second communication device 3 and the internal receive port 15 of the second one-way communication device 5 in order to transmit messages, in particular at least the test message PN, unidirectionally from the second communication device 3 to the second one-way communication device 5, while a fourth communication link 23 is arranged between the internal transmit port 11 of the second one-way communication device 5 and the internal receive port 12 of the first communication device 2 in order to transmit messages, in particular at least the test message PN, unidirectionally from the second one-way communication device 5 to the first communication device 2.Each of the communication links 20, 21, 22, 23 is arranged as an internal physical communication link 20, 21, 22, 23, which is formed in a transmission layer, layer 1, according to the OSI / ISO layer model.

[0078] In addition, at least one of the internal communication links 20, 21, 22, 23 is configured in this embodiment as a unidirectional physical conductor connection, in particular as a conductor track. In a further embodiment, at least one of the internal communication links 20, 21, 22, 23 is configured as a unidirectional communication link according to an Ethernet standard, an SDI standard, or according to a physical conductor connection, in particular an optical fiber cable.

[0079] A selected communication or one-way communication device 2, 3, 4, 5 of the Fig. 1 The first communication device 2, as in this embodiment, is configured to send a test message PN via its internal transmit port 8 and to evaluate the test message PN, which is transmitted back internally to the selected communication device 2 via the other communication devices 3 and one-way communication devices 4, 5 and supplemented with test data II, SI, at its internal receive port 12 in order to determine an operating state of the transmission device 1. This test message PN comprises in the Fig. 1 bis Fig. 4 at least one identification piece of information II for identifying the selected communication or one-way communication device 2, 3, 4, 5 and at least one security information SI specific to the transmitted test message PN. The specific security information SI can also be referred to as specific test data.

[0080] Fig. 2 shows a schematic flowchart of an exemplary embodiment for determining an operating state of the transmission device 1 according to Fig. 1 For example, the determination of the operating state of the transmission device 1 begins in Fig. 2 during the startup of the transmission device 1.

[0081] The first communication device 2 is configured as the selected communication device. In a first step, the first communication device 2 sends the test message PN, supplemented and generated with test data SI and II, to the first one-way communication device 4 via the first communication link 20. This transmitted test message PN includes the identification information II of the sender, i.e., the first communication device 2, as well as the specific security information SI. This is illustrated in Fig. 2 with the reference symbols PN (2, II, SI).

[0082] In the next step, the test message PN (2, II, SI), supplemented with test data, is transmitted from the first one-way communication device 4 to the second communication device 3 via the second communication link 21. Then, in a further step, the test message PN (2, II, SI), supplemented with test data, is transmitted via the third communication link 22 to the second one-way communication device 5. Finally, in a last step, the test message PN (2, II, SI), supplemented with test data, is transmitted from the second one-way communication device 5 back to the first communication device 2 via the fourth communication link 23. Thus, within one cycle for determining the operating state of the transmission device 1, each communication and one-way communication device 2, 3, 4, 5 sends and receives the test message PN (2, II, SI), supplemented with test data.Within the transmission device 1, the test message PN (2, II, SI), supplemented with test data, is transmitted exactly four times until it is received again at its original (selected) communication device 2. Each of the other communication or one-way communication devices 3, 4, 5 is configured to forward the received test message PN (2, II, SI) exclusively.

[0083] After the test message PN (2, II, SI), supplemented with test data and originally generated by the first communication device 2, has been received again at the same device, a comparison takes place to determine the operating status of the transmission device 1.

[0084] The comparison process involves comparing the test message PN received at the first communication device 2 with the expected test message PN to obtain an evaluation result. The expected test message is preferably the test message PN originally sent by the first communication device 2. If the received test message PN (2, II, SI) matches the expected test message PN (2, II, SI), specifically if the test data of the test message—namely, the identification information II and the specific security information SI—match, this indicates, for example, that the transmission device 1 is functioning correctly. The resulting evaluation is then stored in an intermediate storage device.

[0085] In Fig. 2 This illustrates the case in which the transmission device 1 is functioning correctly and the test message PN (2, II, SI), supplemented with test data, is received and evaluated unchanged at the first communication device 2. Therefore, there is neither a fault in any of the communication or one-way communication devices 2, 3, 4, 5, nor is any of the internal communication links 20, 21, 22, 23 defective.

[0086] In an example not shown, the transmission device 1 is not functioning correctly. During startup, the evaluation of the operating state reveals that, for instance, the second communication link 21 is interrupted. Consequently, the test message PN (2, II, SI), which includes test data, cannot reach the first communication device 2. The evaluation of the operating state thus indicates that the test message PN (2, II, SI), which includes test data, does not reach the second communication device 3. This suggests that the second communication link 21 is defective and interrupted, or at least that transmission via the first one-way communication device 4 failed and a fault exists in the first one-way communication device 4.This procedure can be adapted to each of the communication and one-way communication devices 3, 4, 5 as well as communication links 20, 22, 23 in order to detect and locate the exact cause of the error occurring.

[0087] In another embodiment of the Fig. 2 For example, the first one-way communication device 4 is configured to generate and send a test message PN (2, II, SI) supplemented with test data. If this test message PN (2, II, SI) supplemented with test data is received unchanged by the first one-way communication device 4 via the four communication links 21, 22, 23, 20, this indicates that the transmission device 1 is working correctly.

[0088] Fig. 3 shows a schematic flowchart of a further embodiment for determining an operating state of the transmission device 1 according to Fig. 1 For example, the determination of the operating state of the transmission device 1 begins in Fig. 3 , as in Fig. 2 also, when the transmission device 1 is started up.

[0089] In this process, only the selected communication or one-way communication device 2, 3, 4, 5, acting as a master device, generates and sends a test message PN (3, II, SI) supplemented with test data. Fig. 3 The second communication facility, number 3, is the master facility.

[0090] Each of the other communication or one-way communication devices 2, 4, 5 are in the Fig. 3 It is set up to add to each received test message PN test data II, SI, in particular to one of the respective communication or one-way communication devices 2, 4, 5 receiving the test message PN, the safety information SI assigned to it. The assigned safety information SI can also be referred to as assigned test data. In the Fig. 3 The other communication or one-way communication devices 2, 4, 5 act as slave devices, which add test data II, SI to the respective received test messages PN and forward them.

[0091] This will be explained in detail below using the following examples: Fig. 3 described.

[0092] In a first step, only the second communication device 3, acting as the master device, generates and sends the test message PN (3, II, SI), supplemented with test data, unidirectionally to the second one-way communication device 5 via the third communication link 22. The reference numeral 3 is the identification information that identifies that the second communication device 3 sent or generated the message, and the reference numeral SI indicates the associated security information SI of the second communication device 3.

[0093] The second one-way communication device 5 appends its own identification information 5, II, to the received test message PN (3, II, SI) supplemented with test data and forwards this test message PN (3, 5, II, SI) supplemented with test data to the first communication device 2 via the fourth communication link 23.

[0094] Subsequently, the first communication device 2 appends its own identification information 2, II, to the received test message PN (3, 5, II, SI) supplemented with test data and forwards this test message PN (3, 5, 2, II, SI) supplemented with test data to the first one-way communication device 4 via the first communication link 20.

[0095] In a final step, the first one-way communication device 4 adds its own identification information 4, II, to the received test message PN (3, 5, 2, II, SI) supplemented with test data and forwards this test message PN (3, 5, 2, 4, II, SI) supplemented with test data to the second communication device 3 via the second communication link 20.

[0096] The second communication device 3 then checks whether the received test message PN (3, 5, 2, 4, II, SI), supplemented with test data, contains all the identification information of the other communication and one-way communication devices 2, 4, 5. If this is the case, it indicates that the transmission device 1 is working correctly. This is also in Fig. 3 The following is shown. No communication link 20, 21, 22, 23 is interrupted or defective, and every other communication and one-way communication device 2, 4, 5 is working correctly, since the second communication device 3 receives a test message PN which contains all test data (3, 5, 2, 4, II, SI) of the other communication and one-way communication devices 2, 4, 5.

[0097] The steps described above also apply if another communication or one-way communication device 2, 4, 5 is the master device. Only the starting point for generating and sending the test message PN (II, SI) containing test data changes.

[0098] In an example not shown, the transmission device 1 is not functioning correctly. During startup, the evaluation of the operating state reveals that, for instance, the first communication link 20 is interrupted. Consequently, the test message PN (3, 5, II, SI), supplemented with test data, cannot reach the first one-way communication device 4. The evaluation of the operating state thus indicates that the test message PN (3, 5, II, SI), supplemented with test data, is not reaching the first one-way communication device 4. This suggests that the first communication link 20 is defective and interrupted, or at least that forwarding by the first communication device 2 is not functioning and a fault exists in the first communication device 2.This procedure can be adapted to each of the communication and one-way communication devices 2, 4, 5 as well as communication links 21, 22, 23 in order to detect and locate the exact cause of the error occurring.

[0099] Fig. 4 The diagram shows schematic block diagrams of several test messages 40, 41, 42, 43, 44, each of which is provided with a cryptographic checksum and comprises different test data II, SI. The cryptographic checksum is generated using a signature procedure. Therefore, the following also refer to signed test messages or data.

[0100] The communication and one-way communication devices 2, 3, 4, 5 of the transmission device 1 are also configured to sign the test data II, SI or the test message PN comprising the test data II, SI in order to transmit them securely to the respective other communication or one-way communication device 2, 3, 4, 5. This is demonstrated by the Fig. 4 A more detailed explanation.

[0101] In Fig. 4 Reference numeral 40 shows a check message 40 (2, II, SI) signed by means of a cryptographic key using a digital signature, which according to the Fig. 2 was generated and signed by the first communication device 2. The signing is performed in particular with a private cryptographic key of the first communication device. 2. This signed verification message 40 is issued according to Fig. 2 The first one-way communication device 4 is transmitted via the first communication link 20. The first one-way communication device 4 can then validate the signed test message 40 (2, II, SI) using a public key of the first communication device 2. This advantageously ensures that the transmitted signed test message 40 (2, II, SI) has not been manipulated and also that it was generated and sent by the first communication device 2.

[0102] In a subsequent step (not shown), the first one-way communication device 4 digitally signs the check message (2, II, SI) received from the first communication device 2 for further transmission to the second communication device 3 using its own private key. The first one-way communication device 4 can then transmit the signed check message PN (4, II, SI), not shown, to the second communication device 5. The second communication device 5 is then configured to verify the integrity of the signed check message PN (4, II, SI) and its sender using the public key of the first one-way communication device 4, and thereby validate the signed check message PN (4, II, SI).The second communication device 3 and the second one-way communication device 5 are also configured to sign the test message and to validate a received signed test message 40, thereby advantageously increasing the security of the transmission of test messages PN in the transmission device 1.

[0103] Using the embodiment of the Fig. 3 , is in Fig. 4 The diagram shows how the selected communication device 3 (master device) is set up to sign and further process the test message PN and the test data (3, II, SI) using a cryptographic key with a digital signature.

[0104] In Fig. 4 Reference 41 shows a verification message 41 (3, II, SI) signed by means of a cryptographic key using a digital signature, which according to the Fig. 3 was generated and signed by the second communication device 3. The signing is performed in particular with a private cryptographic key of the second communication device 3. This signed verification message 41 is then processed according to... Fig. 3 The second one-way communication device 5 is transmitted via the third communication link 22. The second one-way communication device 5 can then validate the signed test message 41 (3, II, SI) using a public key of the second communication device 3. This advantageously ensures that the transmitted test message 41 (3, II, SI) has not been manipulated and was also generated and sent by the second communication device 3.

[0105] The second communication device then adds test data specific to the second communication device 5 to the test message 41 and signs this specific test data (5, II, SI) with the private key using a digital signature of the second communication device 5. This creates the test message 42 (3, 5, II, SI), which is then forwarded to the first communication device 2.

[0106] The first communication device now adds test data specific to the first communication device 2 to the test message 42 and signs this specific test data (2, II, SI) with the private key using a digital signature of the first communication device 2. This creates the test message 43 (3, 5, 2, II, SI), which is then forwarded to the first one-way communication device 4.

[0107] The first one-way communication device then adds test data specific to the first one-way communication device 4 to the test message 43 and signs this specific test data (4, II, SI) with the private key using a digital signature of the first one-way communication device 4. This creates the test message 44 (3, 5, 2, 4, II, SI), which is then forwarded back to the second communication device 3.

[0108] Then the master device 3 can validate the signed test message 44 and subsequently determine the operating status of the transmission device 1.

[0109] The proposed diagnostic procedures implemented in the transmission devices, using test messages within the bidirectional network guards, enable reliable operation of data traffic between different networks. Determining the current operating status allows intervention in the event of errors or tampering with the transmission devices, such as those implemented as a system-on-a-chip (SoC). This results in improved network and data security.

Claims

1. Transmission apparatus (1) for transmitting data between a first network (NW1) and a second network (NW2), wherein the transmission apparatus (1) comprises: a first communication device (2) having a first interface device (6) for coupling to the first network (NW1), an internal receiving port (12) for receiving messages and an internal sending port (8) for sending messages, a second communication device (3) having a second interface device (7) for coupling to the second network (NW2), an internal receiving port (13) for receiving messages and an internal sending port (9) for sending messages, a first one-way communication device (4) having an internal receiving port (14) for receiving messages from the first communication device (2) and an internal sending port (10) for sending messages to the second communication device (3); and a second one-way communication device (5) having an internal receiving port (15) for receiving messages from the second communication device (3) and an internal sending port (11) for sending messages to the first communication device (2); wherein at least one selected communication or one-way communication device (2, 3, 4, 5) is configured to send a test message (PN) via its internal sending port (8 - 11) and to evaluate, at its internal receiving port (12 - 15), the test message (PN) internally transmitted back to the selected communication or one-way communication device (2 - 5) via the other communication devices (2, 3) and one-way communication devices (4, 5) and supplemented with test data (II, SI) in order to determine an operating state of the transmission apparatus (1), wherein the communication and one-way communication devices (2 - 5) are coupled to each other by means of internal communication links (20 - 23) in such a way that a respective test message (PN) is received by all other communication or one-way communication devices (2 - 5).

2. Transmission apparatus according to Claim 1, characterized in that one of the internal communication links (20, 21, 22, 23) is arranged as an internal physical communication link between a respective internal sending port (8, 9, 10, 11) and a respective internal receiving port (12, 13, 14, 15), which link is formed in particular in a physical layer, layer 1, according to the OSI / ISO layer model.

3. Transmission apparatus according to Claim 2, characterized in that at least one of the internal communication links (20 - 23) is in the form of a unidirectional communication link, in particular according to an Ethernet standard, an SDI standard, a physical conductor connection, in particular an optical fibre line and / or a conductor track.

4. Transmission apparatus according to one of Claims 1 to 3, characterized in that at least one of the communication or one-way communication devices is configured as an embedded processor card, in particular as a system-on-chip, in particular ARM-based, or as a computer.

5. Transmission apparatus according to one of Claims 1 to 4, characterized in that each communication and one-way communication device (2 - 5) is configured to send a test message (PN) via its internal sending port (8 - 11) and to evaluate, at its internal receiving port (12 - 15), the test message (PN) transmitted back to the selected communication or one-way communication device (2 - 5) from each communication and one-way communication device (2 - 5) via the other communication and one-way communication devices (2 - 5) and internal communication links (20 - 23) and supplemented in particular with test data (II, SI) in order to determine an operating state of the transmission apparatus (1).

6. Transmission apparatus according to Claim 5, further comprising a buffer device for storing an evaluation result.

7. Transmission apparatus according to one of Claims 1 to 6, characterized in that the selected communication or one-way communication device (2, 3, 4, 5) is configured to generate a respective test message (PN) which includes at least identification information (II) for identifying the selected communication or one-way communication device (2, 3, 4, 5) and / or at least test data (SI) specific to the test message (PN) sent.

8. Transmission apparatus according to one of Claims 1 to 7, characterized in that the selected communication or one-way communication device (2 - 5) is configured to provide the test message (PN) and / or the test data (II, SI) with a cryptographic checksum.

9. Transmission apparatus according to one of Claims 1 to 8, characterized in that at least one of the other communication or one-way communication devices (2 - 5) is configured to validate a test message (PN) and / or test data (II, SI) provided with a cryptographic checksum and received at its internal receiving port (12 - 15) by means of a public key or a symmetric key of the selected communication or one-way communication device (2 - 5).

10. Transmission apparatus according to one of Claims 1 to 9, characterized in that each of the other communication or one-way communication devices (2 - 5) is configured to add test data (II, SI) to a received test message (PN), in particular to add test data (SI) associated with the respective communication or one-way communication devices (2 - 5) receiving the test message (PN).

11. Transmission apparatus according to Claim 10, characterized in that only the selected communication or one-way communication device (2, 3, 4, 5) as the master device generates and sends a test message (PN), wherein the other communication or one-way communication devices (2 - 5) as slave devices add test data (II, SI) to the respective received test messages (PN) and forward them.

12. Transmission apparatus according to one of Claims 1 to 9, characterized in that each of the other communication or one-way communication devices (2 - 5) is configured to exclusively forward a received test message (PN).

13. Transmission apparatus according to one of Claims 1 to 12, characterized in that the selected communication or one-way communication device (2, 3, 4, 5) is configured to generate the test message (PN) at predefined times and to send it via its internal sending port (8-11), in particular when the transmission apparatus is started up.

14. Transmission apparatus according to one of Claims 1 to 13, characterized in that the first one-way communication device (4) and the second one-way communication device (5) are integrated as a single communication device.