Device with flexible communications structure for real-time capable network applications with high data security, in particular automation device, and method for configuration thereof

EP4689960A1Pending Publication Date: 2026-02-11HILSCHER GES FUR SYSTAUTOMATION +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
EP2024721859
Authority / Receiving Office
EP · EP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-04-06
Filing Date
2024-03-27
Publication Date
2026-02-11

AI Technical Summary

Technical Problem

In automation technology, there is a need for a flexible communication structure that supports real-time capable network applications with high data security, particularly in industrial settings where devices must communicate at rates from 10 Mbps to 1 Gbps, and existing solutions are not adequately multi-protocol capable or efficient in preprocessing, securing, and forwarding high-priority real-time data.

Method used

A device with a flexible communication structure featuring a communication processor that includes a freely programmable communication controller, a freely programmable data controller, and interactive dual-port RAM memory, along with a cryptographic accelerator, allowing for processing, filtering, and distribution of data streams. This setup integrates application-dependent programmable processor cores and an exchangeable physical interface, and the Secure Enclave manages security functions like secure booting and key management.

Benefits of technology

The solution enables efficient preprocessing, securing, and forwarding of high-priority real-time data across various protocols, optimizing performance and ensuring deterministic system response with low latency, while supporting all market-relevant communication protocols and enhancing data security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure EP2024025137_10102024_PF_FP_ABST
    Figure EP2024025137_10102024_PF_FP_ABST
Patent Text Reader

Abstract

1. The invention relates to a device with a flexible communications structure for real-time capable network applications with high data security, in particular an automation device, and a method for configuration thereof. 2.1 To support all the market-relevant communications protocols used in automation engineering, the device (AG) has a communications processor (KP) which has: - at least one freely programmable communications controller (KC), at least one freely programmable data controller (DC) and at least one interactive dual-port RAM memory (DPM), wherein the communications processor (KP) cooperates with a higher-level control system via a host interface (HS), whereby the higher-level control system is exchangeable, - at least one flexible communications structure integrated in the communications controller (KC), consisting of processor cores (gMAC: RPU, TPU; gPECs) programmable as a function of application, - at least one flexible data processing structure integrated in the data controller (DC) and having a cryptography accelerator (KB) and an exchangeable physical interface (PYS) arranged in the device (AG) and connected to the communications controller (KC) arranged in the communications processor (KP) via signal lines for transmitting an identification code (ID), control data (ST), receive data (ED) and transmit data (SD) in such a way that processing, filtering and distribution of data streams is implemented with transmission rates in the range from 10 Mbps to 1 Gbps. 2.2 The invention applies to the field of devices with a flexible communications structure, in particular automation devices.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] Device with flexible communication structure for real-time network applications with high data security, in particular automation device, and method for its configuration

[0002] Description

[0003] The invention relates, according to claim 1, to a device and, according to claim 7, to a method for configuring the device.

[0004] In control and automation technology, it is common practice to use fieldbuses and Ethernet, particularly the extension to Real-Time Ethernet, for data communication between individual units involved in the control of a process. Examples of classic fieldbuses are CANopen, PROFIBUS, Modbus, DeviceNet, or CC-Link. Examples of well-known Real-Time Ethernet systems are PROFINET, EtherNet / IP, EtherCAT, Sercos, POWERLINK, or CC-Link IE. Examples of future gigabit-capable Real-Time Ethernet systems are PROFINET over TSN, EtherCAT-G, or OPC UA over TSN. Communication between the units takes place on the fieldbus / Ethernet using specified protocols. In order to meet the demand for open networking systems, there is a need to provide simple and cost-effective communication mechanisms to make industrial devices network-capable.This requirement is particularly relevant in connection with the coupling of drive components, such as between drive controllers, power units, and encoders in numerically controlled machine tools and robots, where multiple interpolating axes must be operated synchronously. With the increasing networking of various technical systems, the demand for standardized structures in industry is therefore growing.

[0005] In distributed automation systems, for example in the field of drive technology, certain data must arrive at specific times (i.e., real-time-critical data) at the designated nodes and be processed by the recipients. According to IEC 61491, EN61491 SERCOS interface - Technical brief, successful real-time-critical data traffic of the type mentioned can be ensured in distributed automation systems. Furthermore, synchronous, clocked communication systems with equidistance properties are known from automation technology, as described, for example, in DE 101 40 861 A1 for a system

[0006] REPLACEMENT SHEET (RULE 26) and a method for transmitting data between data networks is described.

[0007] In order to design a method and a device for data communication and configuration of bus participants of an open automation system in such a way that the connection of any bus participants with individual, interactive communication and the interchangeability of parts of the device is possible, from EP 1 894 113 B1 the applicant discloses a method for data communication / coupling of bus participants of an open automation system with distributed control, which communicate with each other via a serial data bus and which cooperate with a higher-level control device via at least two communication controllers, in which:

[0008] - each communication controller is composed of at least three freely programmable communication ALUs, which are called the first communication ALU, the second communication ALU and the third communication ALU,

[0009] - for each communication controller, a command code of the first and second communication ALU of the communication ALUs is coded with several commands, the method being characterized in that for each communication controller:

[0010] - in the first and second communication ALU, logic function blocks are arranged in parallel to each other and simultaneously process the instruction code which executes the communication functions,

[0011] - the first communication ALU receives and decode a bit or

[0012] Nibble-oriented serial data stream and its serial / parallel conversion into byte, word or double word representation,

[0013] - the second communication ALU converts byte, word or double word

[0014] Representation in bit or nibble-oriented serial data and the encoding and transmission of this serial data stream and the third communication ALU has a monitoring logic which monitors a large number of events simultaneously and which starts with the associated program code in the event of an event within a system clock cycle, whereby several instructions are executed in one system clock cycle and

[0015] - the third communication ALU controls the transmission and reception process of an associated data packet, whereby the communication functions are not fixed but are implemented by means of the freely programmable communication ALUs, whereby each communication controller is configured by reading in an identification code in the start-up phase and then each associated communication ALU is configured accordingly, and whereby transitions between networks are implemented by means of the higher-level control device and each communication controller.

[0016] For each communication controller, the higher-level control device together with the communication ALU(s) are integrated in a circuit which contains a dual-port memory for coupling to an external control device (host system), or the higher-level control device of the circuit executes the entire application, which then leads out the internal system bus as an extension bus for connecting external memory and peripheral components, and where the same signals are used for both operating modes and these are switched via software.

[0017] Furthermore, from EP 1 894 113 B1 the applicant discloses a device for data communication, for coupling bus participants of an open automation system with distributed control, which communicate with each other via a serial data bus, comprising:

[0018] - at least two communication controllers which cooperate with a higher-level control device and which have at least three freely programmable communication ALUs, namely the first communication ALU, the second communication ALU and the third communication ALU,

[0019] • an instruction code in which several instructions are encoded, the device being characterized by the following features:

[0020] • a parallel arrangement of at least two logic function blocks that simultaneously process the instruction code in the first and second communication ALUs that execute the communication functions,

[0021] • the first communication ALU receives and decode a bit or nibble-oriented serial data stream and converts it into serial / parallel byte, word or double-word representation,

[0022] • the second communication ALU performs the conversion of byte, word or double word representation into bit or nibble-oriented serial data and the encoding and transmission of this serial data stream and

[0023] • the third communication ALU has a monitoring logic which monitors a large number of events simultaneously and which, in the event of an event, starts with the associated program code within a system clock cycle, whereby several commands are executed in one system clock cycle, and the third communication ALU controls the transmission and reception process of an associated data packet,

[0024] - whereby the communication functions are not fixed, but are implemented by means of the freely programmable communication ALUs, whereby each communication controller is configured by reading in an identification code in the start-up phase and then each associated communication ALU is configured accordingly, and whereby transitions between networks are implemented by means of the higher-level control device and two communication controllers.

[0025] Compared to the construction of a dedicated communication controller by programming FPGAs (Field Programmable Gate Arrays) or parts thereof according to the prior art, which also correspond to hard-wired logic, the subject matter of EP 1 894 113 B1 of the applicant enables the simple construction of a "quasi-dedicated" communication controller by constructing it as one or more freely programmable communication ALUs (Arithmetic and Logical Units), which have an instruction set and hardware architecture optimized for the communication tasks. This solution thus offers the following advantages:

[0026] - The development, production and distribution of such a circuit can be carried out independently of a specific fieldbus system / Ethernet.

[0027] - Extensions within the fieldbus / Ethernet and real-time Ethernet specifications or implementations of completely new fieldbus systems can be carried out via software updates and do not require a new circuit.

[0028] - Especially with two or more communication interfaces within a circuit, the respective fieldbus / Ethernet systems are defined by loading the software and can therefore be combined completely flexibly.

[0029] Furthermore, in the subject matter of the applicant's EP 1 894 113 B1, unlike conventional ALUs, the instructions are executed in parallel in a single clock cycle. For this purpose, the associated logic function blocks in the ALUs are arranged in parallel and can process the instruction code simultaneously, thus enabling the necessary functions to be implemented even at high baud rates, e.g., 100 / 1000 Mbps Ethernet.For each communication controller, an exchangeable, physical interface without its own intelligence or controller function is provided, which is connected to the communication controller via four signal line groups for transmitting an identification code, control data, receive data and transmit data. This interface registers itself with the freely programmable communication controller using an identification code in the start-up phase, so that the physical interface is exchangeable and extensions within a fieldbus specification or implementations of completely new fieldbus systems can be carried out via software update.Finally, for each communication controller, the physical interface is designed as a printed circuit with a connector of a communication network or with a connector of a communication network as an integrated unit, and the communication processor processes both an application and a transmission protocol.

[0030] Furthermore, from EP 2 110 754 B1, the applicant discloses a method and a device for synchronizing bus participants of an open automation system, which communicate with each other via a serial data bus, in an open automation system with distributed control. The method for synchronizing bus participants of an open automation system with distributed control, which communicate with each other via a serial data bus, is designed in such a way that automatic and highly accurate synchronization is enabled by one of the bus participants having at least one communication controller, one of the at least one communication controller, referred to below as the communication controller, interacting with a downstream control device via three freely programmable communication ALUs, namely the first communication ALU, the second communication ALU, and the third communication ALU, and the method comprises the following steps:

[0031] - the communication controller detects the occurrence of a specific date or event,

[0032] - the communication ALUs carry out synchronous control functions independently, completely deterministically and without the downstream control device, in that the first communication ALU decodes the received bit or nibble serial data stream according to the transmission rate and converts it into a parallel representation, the second communication ALU encodes data from a parallel representation into a bit or nibble serial data stream and sends it to the line at the correct transmission rate, and the third communication ALU controls the transmission and reception process of a related data packet, and

[0033] - Between the synchronization times, the measured and control values ​​are exchanged between the communication controller and the control device, whereby the communication controller, the three communication ALUs and the control device are adapted in such a way that the interrupt latency times of the downstream control device are not included in the synchronization.

[0034] Alternatively, a method is known from EP 2 110754 B1 of the applicants, wherein the method is characterized in that one of the bus participants has at least one communication controller, and that one of the at least one communication controller, which is referred to as the communication controller in the following text, cooperates with a downstream control device via three freely programmable communication ALUs, which are called the first communication ALU, the second communication ALU and the third communication ALU, and that the method comprises the following steps:

[0035] - the programmable communication ALUs independently execute synchronous control functions completely deterministically and without the downstream control device, whereby the first communication ALU decodes the received bit or nibble serial data stream according to the transmission rate and converts it into a parallel representation, the second communication ALU encodes data from a parallel representation into a bit or nibble serial data stream and transmits it to the line at the correct transmission rate, the third communication ALU controls the transmission and reception process of a related data packet,

[0036] - since the control functions are cyclic and have a cycle time, a synchronized local time is stored in a latch at the start time of the cyclic control functions,

[0037] - the cycle time is measured by forming the difference with a time stored as a synchronized local time at the last start time on the basis of a local time of a local clock, and a current cycle time is kept constant with respect to the local time and in a fixed phase relationship by increasing or decreasing the current cycle time by means of the communication controller, and

[0038] - the entire cycle is synchronized to the local time both in its cycle time and in its phase position, whereby the communication controller, the three communication ALUs and the control device are adapted to this, so that the interrupt latency times of the downstream control device are not included in the synchronization.

[0039] In comparison to the first-mentioned method of EP 2 110754 B1 of the applicants, in which a direct synchronization of the control functions takes place without the downstream control device by means of the “quasi-dedicated” communication controller, the synchronization in the method according to the alternative method is carried out in accordance with a stored local time with each start of a control function, which requires a somewhat higher hardware outlay for maintaining a local time.

[0040] Furthermore, from EP 2 110 754 B 1 of the applicant a device for automatic and high-precision synchronization is known, which is characterized in that the bus participant has a communications processor with at least one communications controller, one of the at least one communications controllers being referred to as the communications controller in the following text, and a control device connected downstream of the communications controller, the communications controller having three freely programmable communications ALUs, namely the first communications ALU, the second communications ALU and the third communications ALU, the communications ALUs being adapted to independently carry out synchronous control functions in a completely deterministic manner and without the downstream control device, in that the first communications ALU assigns the received bit or MHz bit rate to the received bit rate in accordance with the transmission rate.Nibble-serial data stream is decoded and converted into a parallel representation, the second communication ALU encodes data from a parallel representation into a bit or nibble-serial data stream and sends it to the line at the correct transmission rate, the third communication ALU controls the transmission and reception process of a related data packet, the communication controller being adapted to detect the occurrence of a specific date or event, the device having a logic function block of the communication processor with means for measuring and storing times in the communication ALUs, and the communication controller, the three communication ALUs and the control device are adapted so that the interrupt latency times of the downstream control device are not included in the synchronization.

[0041] As the above assessment of the prior art demonstrates, the applicant's EP 1 894 113 B1 discloses a device for data communication and for coupling bus devices of an open automation system with distributed control that communicate with each other via a serial data bus. Furthermore, the applicant's EP 2 110 754 B1 discloses a method and device for automatic and highly precise synchronization, in which the interrupt latency times of the control device are not included in the synchronization.

[0042] The continuous advancement of networking in production is leading to machines being equipped with ever more sensors. However, the increase in the number of sensors and actuators and the resulting increase in cabling is leading to the problem that the maintenance, fault analysis, and installation of wired sensors is becoming increasingly complex. With the introduction of Industry 4.0, the collection of device and sensor data and its transmission to a cloud platform is becoming crucial.In order to transmit cryptographically protected data transmitted in a first network to a less secure second network and evaluate it there, DE 10 2015 200279 A1 discloses a device for implementing cryptographically protected communication and a method for the non-reactive acquisition of data that is transmitted in a cryptographically protected manner between devices in a first network and is intercepted by the one-way transmission device in a second network. The method comprises the following method steps: negotiating at least one cryptographic parameter between the communicating devices in the first network for use in subsequent communication.In the next method step, a transmission structure, which at least partially contains the negotiated cryptographic parameters, is generated in at least one of the devices and transmitted within the first network. In the subsequent method step, the transmission data structure is intercepted by a one-way transmission device and transmitted to the second network. In an advantageous embodiment of the method, the transmission data structure is transmitted protected by a configurable cryptographic transmission key. This ensures, in particular, that the cryptographic parameters can only be read by an authorized person with whom the transmission key was agreed.The device for implementing cryptographically protected communication provided in the subject matter of DE 10 2015 200 279 A1 comprises a negotiation unit configured to negotiate cryptographic parameters for implementing cryptographically protected communication with a communication partner. The device further comprises a generation unit configured to generate a transmission data structure that at least partially contains the negotiated cryptographic parameters and to transmit this to the first network. Furthermore, the device can have a generation device that generates a configurable cryptographic transmission key and is configured to output the transmission data structure, protected by the cryptographic transmission key, to the first network.This ensures that only authorized persons can evaluate the transmission data structure and use it to decrypt the data transmitted in the first network. This also allows configuration of who can evaluate which messages. For example, cryptographic parameters for control messages can be encrypted using a first cryptographic transmission key, and cryptographic parameters for the encryption of diagnostic data can be encrypted using a second transmission key. If the first transmission key is known only to the evaluation unit, the first one-way transmission unit can decrypt the control messages but not the diagnostic data.Furthermore, a monitoring unit can be provided, which is configured to monitor cryptographic parameters between devices in a first network, and a storage unit, which is configured to store the cryptographic parameters and transmit them to a second network. The one-way transmission device can have a decryption unit, which is configured to decrypt cryptographically protected data transmitted from the first network using the cryptographic parameters. Furthermore, the decryption device can be configured such that only successfully cryptographically verified monitored data is forwarded to the second network.

[0043] To enable a better overview of a fieldbus network and its components on the part of a frame application, a frame application for device access software is known from DE 10 2016 120 972 A1. The frame application can be installed on a host, and at least one driver designed to access an associated fieldbus component of a fieldbus network can be integrated into the frame application. The frame application has at least one standard interface for each integrated driver, via which data can be exchanged between the driver and the frame application.In addition to the at least one standard interface, the framework application has one or more proprietary interfaces for at least some of the integrated drivers, via which data can be exchanged between the respective driver and the framework application, wherein information on additional functionalities supported by the driver or an associated fieldbus component can be transmitted from the driver to the framework application via at least one of the proprietary interfaces. In addition to the at least one standard interface, one or more proprietary interfaces are provided between the framework application and at least some of the integrated drivers. For example, merging information on additional functionalities on the framework application side is particularly advantageous if the framework application can be connected to a cloud.Information on supported additional functionalities can, for example, be uploaded to the cloud along with other data, providing a complete overview of the system from the cloud. Additional functionalities can then also be activated from the cloud, for example. This means that the time-consuming activation of additional functionalities on-site, i.e., at the location of the field device, can be replaced by activation from the cloud. In order to correctly address the various components of the fieldbus network, the device access software requires information about the properties and parameters of the field devices, gateways, remote I / Os, etc. of the fieldbus network. This information is usually provided by the manufacturers of the various devices in the form of device description files or device drivers.To describe devices for acyclic data exchange, the fieldbus protocols Profibus-DP, Profibus-PA, Fieldbus Foundation, and HART use device descriptions according to the DTM (Device Type Manager), DD (Device Description), EDD (Enhanced Device Description), and FDI device packages. In particular, the EDD and DTM standards specify not only device parameters, device functionality, and address space allocation, but also graphic features and graphical user interfaces to facilitate the parameterization and configuration of the respective field device. To generate these graphical interfaces, the EDD standard provides special graphic commands that are processed like an interpreter language. In the FDT / DTM standard, the DTMs (Device Type Manager) are provided in the form of dynamically loadable libraries (DLLs) or executable files. A DTM also includes the aforementioned graphic features.The various DTMs for the various components of the fieldbus network are integrated into a common FDT framework application, where FDT stands for “Field Device Tool”. This provides a common framework application into which the DTMs for different devices and from different manufacturers can be integrated. The FDT standard is increasingly being supplemented by the FDI Device Packages standard and may later be replaced. In addition to the fieldbus protocols Profibus, Fieldbus Foundation and HART discussed so far, the so-called Industrial Ethernet protocols are gaining in importance, which include the fieldbus protocols EtherNet / IP, ProfiNet and EtherCAT. The EtherNet / IP fieldbus protocol provides a device description file according to the EDS (Electronic Data Sheet) standard to describe both cyclic and acyclic data exchange.The first possible additional functionality, which can be activated for a fee, is connectivity to the cloud, also known as the "Internet of Things," or IoT for short. This functionality enables data to be uploaded from a DTM to the cloud via the FDT framework application. There, the data can be archived and linked to other data. For example, it is possible to upload flow measurement data to the cloud and use it as a basis for reordering and inventory management. The use of IoT connectivity is activated on the DTM side. Another additional functionality that can be activated is the ability to perform device function tests and self-tests.

[0044] Furthermore, DE 10 2016 215 742 A1 discloses a gateway and a method for connecting a data source system to an IT system, wherein the gateway has a real-time middleware and a non-real-time middleware on a common operating system. An application for communicating via a network protocol, for example TCP / IP, OPC-UA or http(s), is executed on the non-real-time middleware, and the non-real-time middleware comprises a framework. Real-time capability means that individual calculation steps are completed within defined time periods. In real-time environments, it can be guaranteed that a calculation result is available in a timely manner, so that, particularly in industrial machines, the movements of different units also run synchronously. The subject matter of DE 10 2016 215 742 A1 relates to data source systems having at least one data source, such as a computing unit (e.g.It makes a programmable logic controller (PLC), numerical control (NC), or CNC (computerized numerical control) or a sensor, especially existing ones, "internet-capable" in a particularly simple way. It is a scalable approach for retrofitting existing machines without programming using only web-based configuration. The solution offers modular expandability with additional sensors, logic, and providers and automatic provision of the associated web-based interfaces. Existing PLCs of the data source system can be connected to the data source system as additional components via the gateway. This enables easy subsequent connection without modifying an existing data source system.In this case, PLC functionality does not need to be present on the gateway, but can be provided additionally to connect any additional components for the data source system directly to the gateway. For completely new data source systems, the gateway can also be used as a PLC from the start, allowing an initial connection between the data source system and the IT system.

[0045] Furthermore, trust zone support with a security enclave processor (SEP) is known for a system on a chip (SOC) from US Pat. No. 8,775,757 B2. The system on a chip (SOC) implements a security enclave processor (SEP). The SEP can contain a processor and one or more security peripherals. The SEP can be isolated from the rest of the system on a chip (SOC) (e.g., one or more central processing units (CPUs) in the SOC or application processors (APs) in the SOC). Access to the security enclave processor (SEP) can be strictly controlled by hardware. For example, a mechanism is described in which the central processing units (CPUs) or the application processors (APs) can only access a mailbox in the security enclave processor (SEP). The CPU / AP can write a message to the mailbox, which the security enclave processor (SEP) can read and respond to.The SEP may, in some embodiments, include one or more of the following components: secure key management using wrapping keys, SEP control of boot and / or power management, and separate trust zones in memory.

[0046] In further development of this, US 9,747,435 B2 contains a variety of different

[0047] Embodiments for authenticating and controlling encryption keys are known. Generally speaking, a device may include a security circuit, a processor, and an interface controller. The security circuit may be configured to generate a keyword. The processor may be configured to determine one or more policies to apply to the use of the keyword and to generate a policy value. The policy value may include one or more data bits indicating the determined one or more policies. The interface controller may be configured to generate a message containing the keyword and the policy value. The interface controller may also be configured to: Send the message.In another embodiment, the one or more policies may include an indication of one or more of a plurality of functional units that are permitted to use the keyword. In another embodiment, the one or more policies may include a permitted size for the keyword. In another embodiment, the one or more policies may include an indication that the keyword may be used to encrypt data and an indication that the keyword may be used to decrypt data. In another embodiment, the one or more policies include an indication of a length of time for which the keyword may be used. In one embodiment, the security circuit may be further configured to encrypt the keyword.In another embodiment, the one or more policies may include an indication of one or more additional operations required to be performed on the message to decrypt the keyword.

[0048] Modern processor architectures now feature a secure enclave that performs security-relevant tasks depending on the product lifecycle. Examples of product lifecycles include: During chip manufacturing, it must be possible to test the chip extensively. When the chip leaves the factory, the lifecycle is "continued," and the interfaces for testing the chip's internals are disabled. When the finished device is installed on-site in a facility, the interfaces required for developing the device software are disabled. The software running on the automation device enables additional security functions for the end application, such as secure booting, key management, certificate handling, etc.

[0049] Real-time Ethernet, as applied in automation, differs from conventional Ethernet in other industries. Therefore, new concepts must be developed that are not found in traditional processor architectures.

[0050] Real-time Ethernet in automation technology refers to cyclic data communication between devices. In the future, for devices with transmission rates of 1 Gbps, cycle times will be in the microsecond range. Data will no longer be transmitted in plain text, but encrypted.

[0051] In this context, cryptography acceleration is important. An edge network can be implemented as any type of network that provides edge computing and / or storage resources located near radio access network (RAN)-enabled endpoint devices (e.g., mobile computing devices, Internet of Things (IoT) devices, smart devices, etc.). DE 102019 130 686 A1 discloses a method and apparatus for providing dynamic selection of edge and local accelerator resources, wherein the apparatus comprises circuitry for identifying a function of an application to be accelerated, determining one or more properties of the accelerator resource available at the edge of a network at which the device is located, and determining one or more properties of an accelerator resource available in the device.So-called edge devices, somewhat comparable to industrial PCs, extend functionality to include local accelerators for various tasks such as artificial intelligence, cryptography, (FPGA), etc. Expansion via I / O cards is achieved, for example, via PCIe (Peripheral Component Interconnect Express, usually abbreviated to PCIe, is a bus standard for connecting peripheral devices to a processor's chipset). The accelerator device is thus a type of device expansion, similar to how desktop PCs were expanded via slots in the motherboard, for example, by plugging in a graphics card or network card. Windows, as the operating system, was able to recognize the card, install the driver, and make it available for the application.

[0052] Furthermore, DE 603 ​​14 060 T2 discloses a method and a key management system for secure data transmission. The secure data transmission system comprises:

[0053] - a secure channel established via at least one data channel,

[0054] - a host processor connected to a network to communicate with user applications running on other processors connected to the network,

[0055] - a main security module connected to the host processor for sending encrypted private keys of an asymmetric private and public key encryption scheme, wherein the private keys have been encrypted using at least one key encryption key, wherein the main security module is further configured to send the encrypted private keys over the data channel and to send the key encryption key over the secure channel, and wherein the main security module comprises a security module configured to control key generation operations and an associated data store.

[0056] In particular, the secure data transmission system according to DE 603 ​​14 060 T2 is characterized by:

[0057] - at least one satellite module connected to the host processor for receiving the at least one key encryption key after transmission over the secure channel, for receiving the encrypted private keys after transmission over the data channel, for decrypting the private keys using the received key encryption key and for encrypting or decrypting data using the decrypted private keys, wherein the satellite security module comprises a cryptography accelerator having a key manager, initial parsing units (IPUs), cipher engines and a non-volatile data memory, EEPROM.

[0058] Furthermore, the secure data transmission system according to DE 603 ​​14060 T2 is characterized in that the secure channel is established by the host processor and is designed to be used to initialize and control the at least one satellite security module and to facilitate the secure transmission of the key encryption key and management information. The cryptography accelerator of the secure data transmission system according to DE 603 ​​14060 T2 comprises one or more initial parsing units (IPUs), encryption engines, and a key manager. The IPUs parse (analyze) security association data from the encrypted / unencrypted packets to decrypt the encrypted security associations. The encryption engines are processors that decrypt the encrypted packets and / or encrypt the unencrypted packets.In this embodiment, the cipher engines are dedicated processors that use the decrypted security associations from the Initial Parsing Unit (IPUs) to encrypt or decrypt packets. The key manager manages the key encryption keys (KEKs) used to decrypt the security associations. The cryptography accelerator may provide on-chip memory for the cache, one for each MCR type (e.g., 96 bytes for MCR1 and 648 bytes for MCR2, enough for the AES 256-bit key IPsec context or the RSA 2048-bit private key context). The cryptography accelerator may include additional instruction code for loading and decrypting an instruction context. The cache and KEK to be used would be determined by the MCR over which the instruction was issued.A cached instruction context would be invoked using a packet descriptor with a null instruction context pointer. Furthermore, an apparatus and method for handling key encryption are known from US Pat. No. 11,070,375 B2. The apparatus comprises an encryption key generator for generating a media encryption key for encrypting data in a number of storage components, the encryption key generator being configured to wrap the media encryption key to generate an encrypted media encryption key. The encrypted media encryption key is stored in non-volatile memory. The apparatus comprises firmware with instructions for transitioning the apparatus into and out of a secure state using the encrypted media encryption key.The solution known from US Pat. No. 11,070,375 B2 describes, in the broadest sense, a type of inline encryption for memory. It involves storing data or program code in encrypted form on the storage medium, meaning that data is encrypted when written to the memory and decrypted when read from it. It primarily involves the use of memory chips. The memory chips are connected, for example, to a communications processor. This is intended to prevent third parties from reading the memory contents and thus preventing the disclosure of secrets.

[0059] Finally, a cost-effective cryptography accelerator is known from DE 102017 215 331 A1. The system features:

[0060] - a central processing unit CPU;

[0061] - a memory storing instructions which, when executed by the CPU, cause the CPU to perform operations comprising: obtaining cryptographic data, the cryptographic data identifying a specific cryptographic process to be performed on the cryptographic data;

[0062] - performing a first cryptographic operation on the cryptographic data according to the cryptographic process;

[0063] - Sending the cryptographic data to a hardware accelerator; and receiving, from the hardware accelerator, cryptographic data transformed by the hardware accelerator using a second cryptographic operation according to the cryptographic process that is different from the first cryptographic operation.

[0064] The cryptography accelerator features:

[0065] - an interface configured to receive cryptographic data, wherein the cryptographic data identifies a specific cryptographic process to be performed on the cryptographic data;

[0066] - a transformation logic configured to perform a cryptographic operation on the cryptographic data according to the cryptographic process, wherein the transformation logic comprises logic for performing cryptographic operations for a plurality of different cryptographic processes; and

[0067] - a state register configured to store a result of the cryptographic operation.

[0068] Secure communication between end devices in automation technology will become increasingly isolated from other industries in the future. The Secure Enclave lays the foundation for establishing secure communication. To implement an intelligent device with a flexible communication structure for real-time network applications with high data security, especially automation devices with transmission rates in the range of 10 Mbps to 1 Gbps, further development of the state-of-the-art solution concepts is required.

[0069] In order to design an automation device with a module for network analysis and a module for cloud connection in such a way that a dedicated gateway can be dispensed with, the applicant's DE 102018 008 674 A1 describes the automation device being designed in such a way that an analysis and cloud unit is integrated as an independent module in an AS IC of the automation device and / or that an Ethernet network controller with an interface for lossless reading of all received data of the network on the device-internal side of Ethernet transmitters of all existing Ethernet ports is connected to the analysis and cloud unit.Alternatively, an analysis and cloud unit is integrated as a standalone module in the automation device and / or an Ethernet network controller is designed with an interface in the form of a UART, SPI, SDIO, MAC, PCIe, dual-port memory, FIFO or similar for exchanging an Ethernet frame with the automation device and / or the internal Ethernet switch of the network controller.

[0070] In order to design a device with a flexible communication and control structure and a method for this in such a way that parts of the device can be exchanged, the applicant's DE 10 2006 019 451 A1 discloses a device with a flexible communication and control structure which, for coupling to other devices or a higher-level control device of an automation system via a serial data bus, has: at least two or more communication interfaces and at least one programmable logic controller, so that the programmable logic controller is designed as an exchangeable unit and the data is transmitted between the communication interfaces in a completely transparent manner and / or further processed via the internal programmable logic controller.In the method described in DE 10 2006 019 451 A1 by the applicant for configuring a device with two or more communication interfaces and a programmable logic controller, the interchangeable communication interface is expanded by a PLC function in order to couple devices of an automation system that communicate with each other via a serial data bus, and this PLC function is integrated into the communication path and works completely transparently, both for the device and for a higher-level control device.

[0071] Furthermore, EP 0 982 641 B1 discloses a bus interface comprising a memory area combined in a single module, a communications module, and a functional unit with its own program memory space. Both of these access the same memory area, wherein blocks of variable size can be formed in the memory area. As the size of the first block increases, the size of the second block decreases, and vice versa, wherein communication buffers can be set up in the variable-size second block. Specifically, the first block can be integrated into the program memory space of the functional unit by switching. A physics unit with an asynchronous interface and a synchronous interface is provided for coupling to the bus physics.

[0072] In order to specify a communication module for a modular automation system that relieves the central control unit of the automation system and is particularly suitable for transferring and programming a user program directly from the central unit connected to the communication module into the communication module, the communication module known from DE 10 2009 008 957 A1 comprises a processing unit, preferably designed as a microprocessor, a cooperating zero-voltage-proof memory unit for storing a user program, and at least two mutually independent, configurable, galvanically isolated serial interfaces. The serial interfaces are configurable by the user programs stored in the memory unit and are intended to take over functions of the interfaces of a central control unit connected to the communication module if these are insufficient.

[0073] Finally, DE 10 2004 035 843 discloses a network processor with a plurality of programmable processor elements, in which

[0074] - each processor element of the plurality of processor elements is configured to provide basic communication network protocol functions;

[0075] - a first part of the plurality of processor elements is configured as a communication network - processor elements; and

[0076] - a second part of the plurality of processor elements is configured as interface processor elements configured to provide an output communication interface and / or an input communication interface for the network processor according to a communication protocol.

[0077] The invention is based on the object of further developing a device and a method based on the solutions known from EP 1 894 113 B1 and EP 2 HO 754 B1 of the applicant, which supports all market-relevant communication protocols in automation technology and enables preprocessing, securing and forwarding of high-priority real-time data in the range up to 1 Gbps.

[0078] This object is achieved, according to claim 1, by a device with a flexible communication structure for real-time network applications with high data security, with a communication processor which has:

[0079] - at least one freely programmable communication controller, at least one freely programmable data controller and at least one interactive dual-port RAM memory, wherein the communication processor cooperates with a higher-level control device via a host interface, whereby the higher-level control device is interchangeable,

[0080] - at least one flexible communication structure integrated in the communication controller, consisting of application-dependent programmable processor cores,

[0081] - at least one flexible data processing structure integrated in the data controller with a cryptography accelerator and with an interchangeable physical interface arranged in the device and connected to the communication controller arranged in the communication processor via signal lines for transmitting an identification code, control data, received data and transmitted data, such that processing, filtering and distribution of data streams with transmission rates in the range of 10 Mbps to 1 Gbps is realized.

[0082] Furthermore, this object is achieved, according to claim 7, by a method for configuring a device with a flexible communication structure for real-time network applications with high data security, which has a communication controller, data controller, dual-port RAM memory, secure enclave and host interface arranged in a communication processor, in which:

[0083] - the communication controller and the data controller are freely programmable,

[0084] - Communication controller and data controller cooperate with a higher-level control device via the host interface, making the higher-level control device interchangeable,

[0085] - for processing, filtering and distributing data streams with transmission rates in the range of 10 Mbps to 1 Gbps, at least one flexible communication structure integrated in the communication controller, consisting of application-dependent programmable processor cores, is provided,

[0086] - for the pre-processing, securing and forwarding of high-priority real-time data, at least one flexible data processing structure with a cryptography accelerator, consisting of application-dependent programmable processor cores, is provided, integrated in the data controller,

[0087] - a replaceable physical interface connected to the communication controller is provided in the device and

[0088] - the Secure Enclave takes on security-relevant tasks depending on the respective product life cycle and makes additional security functions available for the end application, including secure booting, key management, and certificate handling.

[0089] The device according to the invention, in particular an automation device, supports all market-relevant communication protocols of the

[0090] Auto mat is ier ung ste chnik .

[0091] In a further development of the invention, according to claim 2, the data controller comprises:

[0092] - an application-specific processor core for dedicated processing of high-priority real-time data,

[0093] - a tightly coupled memory with low latency divided into program memory and data memory,

[0094] - the cryptography accelerator for hash functions, authentication and encryption and decryption of data and

[0095] - a direct memory access controller for interactive data transfer to relieve the processor core. This development of the invention has the advantage of optimizing performance based on size and speed, optimized for the respective application. By enabling single-cycle access at best, latency is kept low, the system response becomes deterministic, and the real-time capability of the overall system is improved.

[0096] In a preferred embodiment of the invention, according to claim 3, the communication processor has a secure enclave, also called a secure enclave, with a secure enclave process and a secure non-volatile memory connected to it via a bus, wherein the secure enclave takes over security-relevant tasks depending on a respective product life cycle and makes further security functions usable for the end application, including secure booting, key management, certificate handling.

[0097] This embodiment of the invention has the advantage that only the Secure Enclave can access the secure non-volatile memory via the bus. All keys used to encrypt user data originate from an entropy stored in the Secure Enclave's non-volatile memory. The Secure Enclave lays the foundation for secure communication by managing secret keys. Using these keys and special certificates, a session key is negotiated between devices, on the basis of which the cyclic data is encrypted and decrypted. Conventionally, the session key is valid as long as the connection is active. In automation, in a cyclic context, the connection is maintained as long as the system is running. Therefore, the invention makes it possible to renew the negotiated session keys during an active connection.

[0098] Further advantages and details can be found in the following description of preferred embodiments of the invention with reference to the drawings. The drawing shows:

[0099] Fig. 1 shows the block diagram of a communication processor with a freely programmable communication controller based on EP 1 894 113 B 1 and EP 2 110 754 B I of the applicant,

[0100] Fig. 2 shows the block diagram of the data controller according to the invention and Fig. 3 shows the data flow in the device according to the invention with flexible communication structure according to Fig. 1 in detail.

[0101] The inventive solution of the device with a flexible communication structure, in particular an automation device, shown in Fig. 1, is a further development of the methods and devices for data communication described in the applicants' EP 1 894 113 B1 and EP 2 HO 754 B1, for coupling bus participants of an open automation system with distributed control that communicate with each other via a serial data bus. The same reference numerals are used here, so that—by reference thereto—the detailed description of the components and their interconnection can be declared part of the description of the inventive further development in this patent application.

[0102] An intelligent system is a machine with an embedded, internet-connected computer that is capable of collecting and analyzing data and communicating with other systems. The next evolutionary stage is the connection of automation devices to a so-called higher-level cloud. Diagnostic data that the device records about itself or its environment can be used for topics such as predictive maintenance, etc. A representation of the device as a digital twin in the cloud enables, for example, the optimization of processes in production plants, etc. The cloud can be on-premise or remote. Plant operators can also access a cloud on-site in the plant without an internet connection. The automation device AG of the present invention is a device that is currently referred to in technical terms as an intelligent device or smart device.

[0103] The terminology "freely programmable" used in the applicants' EP 1 894 113 B1 and EP 2 110 754 B1 is intended to distinguish devices from those with a fixed scope of programming via a function or script. Using a programming language, application-specific tasks and functions can be freely implemented.

[0104] For example, there are Ethernet MACs (the abbreviation MAC stands for Media Access Controller and describes the unique identification and access control of electronic media within a network (Ethernet, Token Ring, Bluetooth or WLAN)). The MAC address designates the specific physical address for the network adapter with a fixed range of functions, which are colloquially programmed via registers. Ultimately, it is primarily a configuration. This does not allow multi-protocol support to be implemented. In the solution according to the invention, MACs (Media Access Controllers) are programmable in the communication controller KC, for example to support variants of different real-time Ethernet methods by installing different software.

[0105] The block diagram shown in Fig. 1 shows a device, referred to below as the automation device (AG), with a flexible communication structure for real-time network applications with high data security. The automation device (AG) contains a communications processor (KP), which has:

[0106] - at least one freely programmable communication controller KC, at least one freely programmable data controller DC and at least one interactive dual-port RAM memory DPM, wherein the communication processor (KP) cooperates with a higher-level control device via a host interface HS, whereby the higher-level control device is interchangeable,

[0107] - at least one flexible communication structure integrated in the communication controller KC, consisting of application-dependent programmable processor cores PK (RPA, TPA, PEA, see EP 1 894 113 B1 and EP 2 110754 B1 of the applicant and hereinafter referred to as gMAC: RPU, TPU, and

[0108] - at least one flexible data processing structure with cryptography accelerator KB integrated in the data controller DC.

[0109] Furthermore, the automation device AG contains an exchangeable physical interface PYS connected to the communication controller KC arranged in the communication processor KP via signal lines or signal line groups for transmitting an identification code ID, control data ST, received data ED and transmitted data SD, so that processing, filtering and distribution of data streams with transmission rates in the range of 10 Mbps to 1 Gbps is realized.

[0110] The block diagram shown in Fig. 2 shows a data controller DC, which has:

[0111] - at least one application-dependent programmable processor core PK for the dedicated processing of high-priority real-time data,

[0112] - a tightly coupled memory with low latency divided into program memory PS and data memory DS,

[0113] - the cryptography accelerator KB for hash functions, authentication and encryption and decryption of data and

[0114] - a direct memory access DMA controller for interactive data transfer to relieve the processor core PK.

[0115] Many modern processor architectures are now so-called heterogeneous multi-core processor systems. The CPU (Central Processing Unit) is the main processor and interacts with distributed systems (also called subsystems). To distinguish it from the CPU, the processor cores (PKs) of the subsystems are referred to below as application-specific processor cores (PKs).

[0116] In microcomputer technology, the processor core primarily consists of the control unit, the arithmetic and logic unit, and the registers. The arithmetic and logic unit (ALU) is also known as the arithmetic and logic unit.

[0117] The application-specific processor cores (PK) are equipped with tightly coupled memory (TCM) for real-time execution of program code. The technical term for "tightly coupled" memory is TCM (Tightly Coupled Memory), which is defined by the architecture of the PK processor core used. Ultimately, the goal is to optimize performance due to physical limitations resulting from the semiconductor process and the system architecture of the chip. The PK processor core has, among other things, a system interface and a dedicated TCM interface, divided into a data bus and a program bus. Physically speaking, in the chip layout, the TCMs are placed close to the PK processor core and connected directly. High-speed memory cells are used for this purpose, which typically have higher power dissipation.The balance between size and speed, optimized for the specific application, defines performance. The design goal is to keep latency as low as possible, ideally enabling single-cycle access. This makes the system response deterministic and improves the real-time capability of the overall system. In hard real-time, exceeding a fixed response time is considered a failure by the application-dependent programmable processor cores (PK).

[0118] In comparison to traditional memory accesses in the system, this is why we speak of tightly coupled memory with low latency. If one of the data controllers DC accesses the system memory (outside the DC) via the system bus, higher latencies can be expected. These depend on several factors, e.g. the number of bus devices working on the system memory, the respective data traffic on the system bus, internal synchronization levels, etc. In other words, latencies, measured in terms of the number of processor clock cycles, can be in the double-digit range. During this time, the application-dependent programmable PK does nothing other than wait for data access. The DMA controller DMA (Direct Memory Access) serves to relieve the load on the application-dependent programmable processor core PK. The DMA controller DMA executes the memory accesses into the system.The application-dependent programmable processor core PK does not waste clock cycles waiting, but instead executes program instructions.

[0119] As part of the further development of the solution according to the applicants' EP 1 894 113 B 1, the communication controller KC was extended to meet future communication protocol requirements and network transmission requirements, as follows and as shown in detail in Fig. 3:

[0120] • Each communication controller KC consists of several, in particular ten or more application-dependent programmable PKs with communication ALUs

[0121] • The parallel processor cores PK, referred to as RPU (Receive Processing Unit) and TPU (Transmit Processing Unit), form the gMAC (gigabit MAC)

[0122] • the control of the transmission and reception process of associated data packets is carried out by several, in particular two times four gPECs (gigabit Protocol Execution Controllers), whereby the integrated flexible communication structure is formed by means of the application-dependent programmable PK with communication ALUs and is not fixed.

[0123] The number of freely programmable communication controllers KC depends on the expansion level of the device AG for the respective application:

[0124] 1) Process automation end devices occasionally have only one communication port (i.e., a KC communication controller is used). This is usually due to a star-shaped network topology.

[0125] 2) Factory automation end devices have at least two communication ports (i.e., two KC communication controllers are used). This is usually due to a ring-shaped network topology.

[0126] 4) Control devices can have up to four communication ports (i.e., four KC communication controllers are used). This is usually independent of the respective network topology.

[0127] The inventive data controller DC with integrated cryptography accelerator KB meets the requirements of devices with transmission rates of 1 Gbps, where cycle times are in the microsecond range and the data is transmitted encrypted. A distinction is made between cyclic receive data, cyclic transmit data, and acyclic data.

[0128] The Interconnect IC is a key component that connects the various functional blocks. The Interconnect IC manages the data flow between these components and ensures that they work together efficiently and effectively. The IC thus provides an internal communication link for data and control signals. A distinction is made between initiator INT and target TRG (see Fig. 1). This means that an initiator INT is capable of writing to and reading from a target TRG. Fig. 3 shows the access path through the IC from top to bottom. A special feature is the Secure Enclave SE, which is both an initiator INT and a target TRG. During the boot phase, the Secure Enclave SE accesses the memory SP and the external memories via the external memory interface ES, e.g., for secure boot, etc.During runtime, the Secure Enclave SE provides special services to the parent system, e.g. for key management, etc.

[0129] The dual-port RAM DPM for the host interface HS is a volatile memory with arbitration, triple buffering, and handshake mechanisms for synchronization. This allows two pages to access memory contents in the dual-port RAM DPM separately and exchange cyclic and acyclic data. It thus represents a physical separation between the real-time protocol communication and the higher-level control device of the end application, which is connected to an external host interface EHS and is therefore interchangeable.

[0130] The higher-level control device with the corresponding host application can be any device class of factory or process automation, such as an industrial PC, a machine, a drive, an actuator, an I / O system, a sensor, etc.

[0131] In the case of an external host interface (EHS), the end application is implemented on commercially available microprocessors or microcontrollers, or on application-specific FPGA or ASIC solutions (FPGA stands for Field Programmable Gate Array and ASIC stands for Application Specific Integrated Circuit). Using the host interface (HS), the control device of the end application (also called the host system) connects to the communications processor (KP).

[0132] In the case of an internal host interface IHS, the communication processor KP is extended by a complete application system with main processor and thus becomes a system-on-chip (SOC) that can be used as a single-chip solution for end applications.

[0133] Today’s cryptography includes four major goals for protecting information: confidentiality / access protection, integrity / change protection, authenticity /

[0134] Forgery protection, binding nature / non-repudiation. In modern cryptography, three main encryption methods are distinguished:

[0135] • Symmetric cryptography. In symmetric cryptography, a single key is used to encrypt and decrypt a message.

[0136] • Asymmetric cryptography.

[0137] • Hybrid cryptography.

[0138] Within the scope of the invention, the following cryptographic algorithms can be used,

[0139] - Hash / HMAC or MD5

[0140] OSHA1

[0141] OSHA2

[0142] ■ SHA-224

[0143] ■ SHA-256

[0144] ■ SHA-384

[0145] ■ SHA-512

[0146] - AES o key lengths

[0147] ■ AES-128

[0148] ■ AES-192

[0149] ■ AES-256 o Operating modes ■ ECB

[0150] ■ CBC

[0151] ■ CTR

[0152] ■ GCM

[0153] - ChaCha20 o Without authentication o Combined with Poly 1305 O Polyl 305 without ChaCha20

[0154] When it comes to data encryption, AES (Advanced Encryption Standard) encryption remains undeniably one of the most secure and widely used systems in the world.

[0155] Other ciphers include: Salsa20 (also Snuffle 2005) is a stream cipher developed by Daniel J. Bernstein in 2005 and is a family of 256-bit stream ciphers. Salsa20 / 20 with 20 rounds is intended as the standard. XSalsa20 is a variant with an extended nonce (192 bits instead of 64 bits). ChaCha or Snuffle 2008 are variants of Salsa20. ChaCha20-Polyl305 is an Authenticated Encryption Algorithm with Additional Data (AEAD) that combines the ChaCha20 stream cipher with the Polyl305 message authentication code. Its use in lETF protocols is standardized in RFC 8439. It has fast software performance and is typically faster than AES-GCM without hardware acceleration. The ChaCha20-Polyl305 algorithm described in RFC 8439 takes as input a 256-bit key and a 96-bit nonce to encrypt a plaintext with a ciphertext extension of 128 bits (the tag size).In the ChaCha20-Polyl305 construct, ChaCha20 is used in counter mode to derive a keystream, which is XORed with the plaintext. The ciphertext and associated data are then authenticated with a variant of Polyl305, which first encodes the two strings into one. The XChaCha20-Polyl305 construct is an extended 192-bit nonce variant of the ChaCha20-Polyl305 construct that uses XChaCha20 instead of ChaCha20. By randomly selecting nonces, the XChaCha20-Polyl305 construct enables better security than the original construct.

[0156] The data processing structure of the data controller DC depends on the respective software executed by the processor core PK. The respective software is determined by the data model of the higher-level communication protocol, which can vary depending on the communication standard. This also applies, among other things, to the use of the respective encryption algorithm. Communication standard A, for example, prescribes ASE as the algorithm, and communication standard B prescribes ChaCha as the algorithm. Furthermore, task-specific data models that differ from one another run on the data controllers DC. A distinction is made between cyclic receive data, cyclic transmit data, and acyclic data. Therefore, in the solution according to the invention, several (at least three) data controllers DC are implemented in the system. A purely hardware-based cryptography accelerator KB would be disadvantageous.This would make multi-protocol capability of the system and workload sharing impossible. Algorithm acceleration is achieved using a combination of software and hardware. The software in the tightly coupled memory (TCM), which is executed by the processor core (PK), ensures that the data in the tightly coupled memory is processed according to the data model using the hardware accelerator.

[0157] In summary, the method according to the invention for configuring the device AG with a flexible communication structure for real-time capable network applications with high data security, which comprises the communication controller KC, data controller DC, dual-port RAM memory DPM, secure enclave SE and host interface HS arranged in the communication processor KP, is characterized by:

[0158] • the communication controller KC and the data controller DC are freely programmable,

[0159] • Communication controller KC and data controller DC work together with a higher-level control device via the host interface HS, whereby the higher-level control device is interchangeable, • For processing, filtering and distribution of data streams with transmission rates in the range of 10 Mbps to 1 Gbps, at least one flexible communication structure is provided integrated in the communication controller KC, consisting of application-dependent programmable processor cores PK,

[0160] • For the processing, securing and forwarding of high-priority real-time data, at least one flexible data processing structure with cryptography accelerator KB, consisting of application-dependent programmable processor cores PK, is provided, integrated in the data controller DC,

[0161] • an exchangeable physical interface PYS is provided in the device AG connected to the communication controller KC and

[0162] • The Secure Enclave SE takes on security-relevant tasks depending on the respective product life cycle and makes additional security functions available for the end application, including secure booting, key management and certificate handling.

[0163] Preferably, the Secure Enclave SE manages secret keys, which are used to negotiate a session key between the devices using these keys and special certificates. This session key is used to encrypt and decrypt the cyclic data. The session key is valid as long as the connection is active; in particular, the negotiated session key is renewable during an active connection.

[0164] Furthermore, according to the invention, with respect to the cryptographic algorithms determined by the data model of a higher-level communication protocol, the software structure of the cryptography accelerator KB is modified to realize the multi-protocol capability of the device AG and to distribute the workload.

[0165] The invention is not limited to the illustrated and described embodiments, but also encompasses all equivalent embodiments within the meaning of the invention and is, in particular, limited only by the patent claims. List of reference symbols:

[0166] AG: Automation device

[0167] CPU: Central Processing Unit

[0168] DC: Data Controller

[0169] DPM: Dual-Port RAM

[0170] DS: Data storage

[0171] DMA: Direct Memory Access Controller

[0172] ED: Reception data

[0173] EHS: External host system

[0174] ES: external storage interface

[0175] FIFO: First In First Out data buffer gMAC: gigabit Media Access Controller HS: Host interface

[0176] ID: Identification code

[0177] IC: Interconnect

[0178] IHS: Internal host system

[0179] INT: Initiator

[0180] KB : Cryptography Accelerator

[0181] KC: Communication Controller

[0182] KP: Communication processor

[0183] PE: Peripherals

[0184] PK: Processor core

[0185] PS: physical interface

[0186] PSP: Program memory

[0187] RPU: Receive Processing Unit

[0188] SD: Broadcast data

[0189] SE: Secure Enclave

[0190] SP: Memory

[0191] SR: Shared Register

[0192] ST: Tax data

[0193] TPU: Transmit Processing Unit

[0194] TRG: Target

Claims

Patent claims 1. Device (AG) with a flexible communication structure for real-time network applications with high data security, with a communication processor (KP) which has: - at least one freely programmable communication controller (KC), at least one freely programmable data controller (DC) and at least one interactive dual-port RAM memory (DPM), wherein the communication processor (KP) cooperates with a higher-level control device via a host interface (HS), whereby the higher-level control device is interchangeable, - at least one flexible communication structure integrated in the communication controller (KC), consisting of application-dependent programmable processor cores (gMAC: RPU, TPU; gPECs), - at least one flexible data processing structure integrated in the data controller (DC) with a cryptography accelerator (KB) and with a device (AG) arranged in the device (AG) and connected via signal lines for the transmission of an identification code (ID), control data (ST), received data (ED) and transmitted data (SD) with the An exchangeable physical interface (PYS) connected to the communication processor (KP) and the communication controller (KC) is provided, such that processing, filtering and distribution of data streams with transmission rates in the range of 10 Mbps to 1 Gbps is realized.

2. Device (AG) according to claim 1, wherein the data controller (DC) comprises: - at least one application-dependent programmable processor core (PK) for the dedicated processing of high-priority real-time data, - a tightly coupled, low-latency memory divided into program memory (PS) and data memory (DS), - the cryptography accelerator (KB) for hash functions, authentication and encryption and decryption of data and - a Direct Memory Access (DMA) controller for interactive data transfer to relieve the processor core (PK).

3. Device (AG) according to claim 1 or 2, wherein the communication processor (KP) has a Secure Enclave (SE), also called a secure enclave, with a Secure Enclave processor and a secure non-volatile memory connected to it via an internal bus, wherein the Secure Enclave (SE) takes over security-relevant tasks depending on a respective product life cycle and makes further security functions usable for the end application, including secure booting, key management, certificate handling.

4. Device (AG) according to claim 1, wherein in a ring-shaped embodiment of the network topology the device for factory automation has at least two communication controllers (KC) and that independently of the network topology the devices have up to four communication controllers (KC).

5. Device (AG) according to claim 2, wherein the communication processor (KP) has at least three data controllers (DC) for distinguishing between cyclic receive data, cyclic transmit data and acyclic data.

6. Device (AG) according to claim 1 or 2, wherein each communication controller (KC) consists of several application-dependent programmable processor cores (PK) with communication ALUs (Arithmetic and Logical Units), • the parallel processor cores (PK) referred to as RPU (Receive Processing Unit) and TPU (Transmit Processing Unit) form a gMAC (gigabit Media Access Controller), • the control of the transmission and reception process of associated data packets is carried out by several gPECs (gigabit Protocol Execution Controllers), whereby an integrated flexible communication structure is formed by means of the application-dependent programmable processor cores (PK) with communication ALUs.

7. Method for configuring a device (AG) with a flexible communication structure for real-time capable network applications with high data security, which device has a communication controller (KC), data controller (DC), dual-port RAM memory (DPM), secure enclave (SE) and host interface (HS) arranged in a communication processor (KP), in which: • the communication controller (KC) and the data controller (DC) are freely programmable, • Communication controller (KC) and data controller (DC) cooperate with a higher-level control device via the host interface (HS), whereby the higher-level control device is interchangeable, • for processing, filtering and distributing data streams with Transmission rates in the range of 10 Mbps to 1 Gbps, at least one flexible communication structure integrated in the communication controller (KC), consisting of application-dependent programmable processor cores (PK), is provided, • for pre-processing, securing and forwarding high-priority • Real-time data at least one flexible data processing structure integrated in the data controller (DC) with cryptography accelerator (KB), consisting of application-dependent programmable processor cores is provided • an exchangeable physical interface (PYS) connected to the communication controller (KC) is provided in the device (AG) and • the Secure Enclave (SE) takes on security-relevant tasks depending on the respective product life cycle and makes additional security functions available for the end application, including comprehensive secure booting, key management and certificate handling.

8. The method according to claim 7, wherein for cyclic data communication the data controller (DC) distinguishes between cyclic receive data, cyclic transmit data and acyclic data.

9. Method according to claim 7 and / or 8, in which the Secure Enclave (SE) manages secret keys, using these keys and special certificates a session key is negotiated between devices, on the basis of which the cyclic data is encrypted and decrypted, the session key is valid as long as the connection is active and the negotiated session key is renewable during an active connection.

10. Method according to one or more of claims 7 to 9, wherein, with respect to the cryptographic algorithms determined by the data model of a higher-level communication protocol, the software structure for the application of the cryptography accelerator (KB) is changed to realize the multi-protocol capability of the device (AG) and to divide the workload.