DEVICE FOR CRYPTOGRAPHICALLY SECURING A COMMUNICATION DEVICE FOR AN INDUSTRIAL AUTOMATION SYSTEM
Patent Information
- Application Number
- DE502023001469
- Authority / Receiving Office
- DE · DE
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2023-09-19
- Publication Date
- 2025-08-14
- Estimated Expiration
- 2043-09-19
AI Technical Summary
Existing industrial automation systems face challenges in ensuring secure authentication, encryption, and storage of cryptographic keys under economically feasible conditions, particularly for non-PROFINET security-capable devices and devices without inherent cryptographic functions, which are common in older systems.
A device with a cryptography module and security sensor is integrated into existing communication devices, enabling encryption, decryption, and secure key management, with the security sensor blocking cryptographic functions upon disconnection, allowing non-PROFINET devices to participate in secure network communication without replacement.
Enables secure, cost-effective integration of non-PROFINET devices into PROFINET environments by ensuring secure communication and reliable key management, even in the absence of inherent cryptographic capabilities.
Description
[0001] The present invention relates to a device for cryptographically securing a communication device for an industrial automation system, in particular a device without cryptography functions.
[0002] An industrial automation system typically comprises a large number of automation devices interconnected via an industrial communication network and is used to control or regulate systems, machines, or devices within the context of production or process automation. Due to the time-critical conditions in industrial automation systems, real-time communication protocols such as PROFINET, PROFIBUS, Real-Time Ethernet, or Time-Sensitive Networking (TSN) are predominantly used for communication between automation devices.
[0003] Due to their often highly diverse use in Ethernet-based communication networks, problems can arise, for example, when network resources for transmitting data streams or data frames with real-time requirements are used concurrently with transmitting data frames with large payloads without specific quality of service requirements. This can result in data streams or data frames with real-time requirements not being transmitted according to the requested or required quality of service.
[0004] EP 3 270 560 B1 describes a method for establishing secure communication connections to an industrial automation system. Upon a positive authorization verification result, a connection management device provides access control information for establishing an encrypted communication connection between a first communication device of a requesting user and a selected second communication device for these communication devices. The connection management device is formed by a server instance running on a firewall system.Data packets transmitted via an encrypted communication connection between the requesting user's first communication device and the selected second communication device are decrypted by the firewall system for verification based on defined security rules and, if the verification is successful, forwarded in encrypted form to the requesting user's first communication device or to the selected second communication device.
[0005] The older European patent application EP 4 283 925 A1 relates to a secure transmission of time-critical data within a communications system comprising several local networks in which data is transmitted via switching, at least one network overlaid on the local networks in which data is transmitted via routing, and a gateway system for connecting the communications system to at least one unsecured external network. Network-layer communication via the overlaid network is only authorized between authenticated system components. Switches authenticate connected terminal devices and assign them to a physical or logical local network according to a respective terminal device identity. Data link-layer communication within the local networks is implicitly authorized based on the assignment of the respective terminal devices to the same local network.Communication on OSI layers 3-7 between end devices in different local networks or with end devices in the unsecured external network is authorized using zero-trust proxies, each of which is assigned to a local network.
[0006] From the older European patent application EP 4 300 882 A1, a method for the secure transmission of time-critical data within a communications system is known. The communications system comprises several local networks, each comprising at least one switch and several terminal devices, a control unit that controls the functions of several switches and terminal devices, and a control network assigned to the control unit, which is separate from the local networks. Communication within the local networks is implicitly authorized based on the assignment of the respective terminal devices to the same local network. Each terminal device is assigned a zero-trust adapter, which acquires status information from the terminal device, forwards the status information to the control unit via the control network for evaluation, and authenticates the terminal device to the control unit or communication partners.The control unit determines a trust index for each end device based on the status information and applies rules dependent on the trust index for the configuration or for permissible communication relationships of the end devices.
[0007] US 2022 / 067221 A1 describes a method for implementing security operations in an input / output (I / O) device. The I / O device comprises an I / O port, a host bus connected to a host, a data processing pipeline within the I / O device coupled to the I / O port and the host bus, and a hardware security module. The hardware security module is also connected to the host bus and the data processing pipeline and includes a cryptographic engine that can encrypt and decrypt data from the data processing pipeline. Furthermore, the hardware security module includes a secure key store in which encryption keys for encrypting and decrypting packets are stored. Keys encrypted by and accessible from the hardware security module are stored in the secure key store.
[0008] Zero-trust concepts, in particular, require users or devices to authenticate themselves to communication partners or when accessing protected resources, regardless of their location or environment, in order to access desired data or applications after successful authentication. However, meeting cybersecurity requirements faces limitations in application areas where not every user or device is able to ensure secure authentication, encryption / decryption, or storage of cryptographic keys under economically feasible conditions. This is often a problem, especially in industrial automation systems with existing components that have been in use for an extended period of time.
[0009] The present invention is therefore based on the object of creating a solution for cryptographically securing a communication device, in particular within an industrial automation system, which can be integrated into existing environments with little effort.
[0010] This object is achieved according to the invention by a device having the features specified in claim 1. Advantageous developments of the present invention are specified in the dependent claims.
[0011] The device according to the invention for cryptographically securing a communication device for an industrial automation system comprises a first Ethernet connector element for connecting to a communication network within which messages are transmitted in a cryptographically secured, in particular encrypted, manner, a second Ethernet connector element for connecting to the communication device, and a cryptography module. For example, the first Ethernet connector element can be an RJ45 or M12 socket, while the second Ethernet connector element is an RJ45 or M12 plug.
[0012] According to the invention, the cryptography module is configured to store cryptographic keys or certificates assigned to the communication device or users of the communication device, to encrypt messages sent by the communication device, and to decrypt messages sent to the communication device. Preferably, the cryptography module is further configured to verify certificates of communication partners of the communication device or users of the communication device.
[0013] According to the invention, a security sensor for monitoring a disconnection of the connection to the communication device is provided on the second Ethernet connector element. This security sensor is configured to trigger a blocking of the cryptographic keys or certificates or the cryptography module upon disconnection of the connection to the communication device. Thus, the present invention enables, in particular, non-PROFINET security-capable devices to be connected to a PROFINET security network and thus participate in cryptographically secured network communication. Therefore, a device replacement is not necessary.
[0014] According to the invention, the cryptography module comprises a processor, e.g., an FPGA or ASIC, configured to encrypt and decrypt messages. Furthermore, functions of the cryptography module can be controlled by an engineering tool via an encrypted connection or via a dedicated configuration interface of the device. Furthermore, the security sensor for monitoring the disconnection of the connection between the device and the communication device can be activated or deactivated by the engineering tool via the encrypted connection or via the dedicated configuration interface.
[0015] The encrypted connection for controlling the functions of the cryptography module can be established, for example, via the first Ethernet connector. Furthermore, the dedicated configuration interface can advantageously be implemented via a USB interface, a serial interface, an NFC interface, a Bluetooth interface, or WLAN.
[0016] According to a particularly preferred embodiment of the present invention, the security sensor is implemented on a connector collar or on a connector contact surface of the device by means of a mechanical button, a capacitive or resistive sensor element, a reed contact, an ultrasonic sensor element, or a photo-optical sensor unit. Thus, with a mechanical separation between the device according to the invention and the communication device to be secured, reliable blocking of the cryptographic keys or certificates or the cryptography module is always ensured. Advantageously, the security sensor is further configured to be activated when the connection to the communication device is established at the second Ethernet connector element.
[0017] When implementing the safety sensor based on a photo-optical sensor unit, this advantageously comprises a light-emitting diode and a phototransistor. The light quantity or intensity emitted by the light-emitting diode into the phototransistor can be used to reliably detect the disconnection between the device and the communication device. In addition, the light-emitting diode can emit coded pulse-shaped signals, the pulse patterns of which, received by the phototransistor, are compared with a reference pattern for consistency.
[0018] The present invention will be explained in more detail using an exemplary embodiment with reference to the drawing. Figure 1a schematic representation of a device for cryptographically securing a communication device for an industrial automation system Figure 2a perspective representation of the device according to Figure 1with a communication device to be protected in a connected state, Figure 3 the device and the communication device to be protected according to Figure 2 in a separated state.
[0019] The Figure 1 The device 1 shown serves for cryptographically securing a communication device for an industrial automation system. Such a communication device can, for example, be a PROFINET device that is not inherently PROFINET security-capable, but is intended to be operated in a PROFINET security environment. In another application scenario, the communication device can be a device without cryptographic functions that is intended to be operated in a zero-trust environment.
[0020] The device comprises a first Ethernet connector element 11 for connection to a communications network, within which messages are transmitted in a cryptographically secure manner. Furthermore, a second Ethernet connector element 12 is provided for connection to the communications device. In the present exemplary embodiment, the first Ethernet connector element 11 is an RJ45 socket, while the second Ethernet connector element 12 is an RJ45 plug. According to an alternative embodiment, the first Ethernet connector element 11 can be an M12 socket, while the second Ethernet connector element 12 can be an M12 plug. Furthermore, the first Ethernet connector element 11 can also be a plug, while the second Ethernet connector element 12 can be a socket. Plug-plug or socket-socket combinations are also possible.
[0021] Furthermore, the device 1 comprises a cryptography module 13 configured to store cryptographic keys or certificates assigned to the communication device or users of the communication device. Additionally, the cryptography module 13 is configured to decrypt encrypted messages 101 sent to the communication device and to encrypt unencrypted messages 102 sent by the communication device. In particular, the cryptography module 13 is configured to verify certificates of communication partners of the communication device or users of the communication device.
[0022] The cryptography module 13 preferably comprises a processor, an FPGA, or an ASIC configured to encrypt and decrypt messages. Advantageously, functions of the cryptography module 13 can be controlled by an engineering tool via an encrypted connection or via a dedicated configuration interface 131 of the device. The dedicated configuration interface can be implemented, for example, via a USB interface, a serial interface, an NFC interface, a Bluetooth interface, or via WLAN. If no dedicated configuration interface 131 is provided, the encrypted connection for controlling the functions of the cryptography module 13 can be established via the first Ethernet connector element 11.
[0023] In addition, the Figure 1The device 1 shown has an optional power supply connection 132. Alternatively, the device 1 can be supplied with power, for example, via Power over Ethernet.
[0024] A safety sensor 121 is provided on the second Ethernet connector element 12 to monitor a disconnection of the connection shown in Figure 2 with the communication device 2. The safety sensor 121 is configured to Figure 3 The illustrated disconnection of the connection to the communication device 2 triggers a blocking of the cryptographic keys or certificates or of the cryptography module 13. Advantageously, the security sensor 121 is arranged on a connector collar or on a connector contact surface of the second Ethernet connector element 12 or a housing 14 of the device 1 enclosing the cryptography module 13.
[0025] The safety sensor 121 can be implemented, for example, by means of a mechanical button, by means of a capacitive or resistive sensor element, by means of a reed contact, by means of an ultrasonic sensor element, or by means of a photo-optical sensor unit. In the case of implementation using a photo-optical sensor unit, this comprises a light-emitting diode and a phototransistor. Based on the quantity or intensity of light emitted by the light-emitting diode into the phototransistor, the severance of the connection between the device 1 and the communication device 2 can be reliably detected. In addition, the light-emitting diode can be controlled such that it emits a predetermined or random pulse sequence. Signals received at the phototransistor can then be compared to determine whether they match this pulse sequence.
[0026] According to a preferred embodiment, the safety sensor 121 for monitoring the disconnection of the connection between the device 1 and the communication device 2 can be activated or deactivated by the engineering tool via the encrypted connection or via the dedicated configuration interface 131. Alternatively or additionally, the safety sensor 121 can be activated when the connection to the communication device 2 is established at the second Ethernet connector element 12.
Claims
1. Apparatus for cryptographically securing a communication device for an industrial automation system, wherein the apparatus comprises - a first Ethernet plug-in connection element (11) for connecting to a communication network, within which it is possible for messages to be transmitted in a cryptographically secured manner, - a second Ethernet plug-in connection element (12) for connecting to the communication device (2) and - a cryptography module (13), which is configured for storing cryptographic keys and / or certificates assigned to the communication device and / or users of the communication device, for encrypting messages (102) sent by the communication device and for decrypting messages (101) sent to the communication device, - wherein the cryptography module (13) comprises a processor, which is configured for encrypting and decrypting messages, and functions of the cryptography module can be controlled by an engineering tool via an encrypted connection and / or via a dedicated configuration interface (131) of the apparatus (1), - wherein there is provision on the second Ethernet plug-in connection element for a safety sensor (121) for monitoring a disconnection of the connection to the communication device, which safety sensor is configured to trigger a blocking of the cryptographic keys and / or certificates and / or of the cryptography module when the connection to the communication device is disconnected, - wherein the safety sensor (121) for monitoring the disconnection of the connection between the apparatus (1) and the communication device (2) can be activated and / or deactivated by the engineering tool via the encrypted connection and / or via the dedicated configuration interface (131).
2. Apparatus according to claim 1, in which the cryptography module (13) is configured to review certificates of communication partners of the communication device (2) and / or the users of the communication device.
3. Apparatus according to one of claims 1 or 2, in which the encrypted connection for control of the functions of the cryptography module (13) is set up via the first Ethernet plug-in connection element (11).
4. Apparatus according to claim 3, in which the dedicated configuration interface (131) is realised by means of a USB interface, a serial interface, an NFC interface, a Bluetooth interface or by means of WLAN.
5. Apparatus according to one of claims 1 to 4, in which the safety sensor (121) is realised on a plug collar and / or on a plug-in connection contact area of the apparatus by means of a mechanical probe, by means of a capacitive or resistive sensor element, by means of a reed contact, by means of an ultrasonic sensor element or by means of a photo-optical sensor unit.
6. Apparatus according to claim 5, in which the photo-optical sensor unit comprises a light-emitting diode and a phototransistor and in which it is possible to detect the disconnection of the connection between the apparatus (1) and the communication device (2) on the basis of an amount and / or intensity of light emitted by the light-emitting diode into the phototransistor.
7. Apparatus according to one of claims 5 or 6, in which the safety sensor (121) is configured to be activated when the connection to the communication device (2) is established at the second Ethernet plug-in connection element (12).
8. Apparatus according to one of claims 1 to 7, in which the first Ethernet plug-in connection element (11) is an RJ45 or M12 socket and in which the second Ethernet plug-in connection element (12) is an RJ45 or M12 plug.