Method and communication device for a cryptographically secured data transmission between communication participants

The method ensures secure, flexible encryption in industrial automation systems by authenticating participants to create a session key and configuring encryption parameters, aborting sessions with mismatches, addressing the lack of flexibility and robustness in existing systems.

WO2026068200A1PCT designated stage Publication Date: 2026-04-02SIEMENS AG
View PDF 5 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2025-09-11
Publication Date
2026-04-02

AI Technical Summary

Technical Problem

Existing cryptographic methods in industrial automation systems lack flexibility and robustness against automated attacks, particularly for time-critical data transmission, requiring extensive cryptographic expertise for individualization and configuration.

Method used

A method for cryptographically secured data transmission involving authentication of communication participants to create a session key, with encryption parameters configured before the session, ensuring identical parameters for secure communication, and aborting sessions with mismatched configurations.

Benefits of technology

Enables secure, flexible, and user-friendly encryption adaptation without requiring extensive cryptographic expertise, reducing attack vectors and ensuring data transmission only between intended participants.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure EP2025075833_02042026_PF_FP_ABST
    Figure EP2025075833_02042026_PF_FP_ABST
Patent Text Reader

Abstract

In order to carry out a cryptographically secured data transmission, communication participants (101-106) authenticate themselves before establishing a session and together create a cryptographic session key (230) or use a cryptographic session key provided in advance. The session between the communication participants is established so as to be cryptographically secured on the basis of the session key (230) after a successful authentication of the communication participants (101-106). An encryption parameter (232) is compared between the communication participants for an encryption method to be used within the session, said parameter being used to adapt a cryptographic encryption function (222) of the encryption method. The encryption parameter is preconfigured for each communication participant and cannot be changed within the session. When the encryption parameter (232) is compared, it is checked whether the encryption parameter is identically preconfigured for the communication participants (101-106). If the encryption parameter is identically preconfigured, the encryption parameter (232) is adopted in order to adapt the encryption method, and data transmitted between the communication participants (101-106) within the session is cryptographically secured in accordance with the adapted encryption method.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] 202417071 Foreign version

[0002] 1

[0003] Description

[0004] Method and communication device for cryptographically secured data transmission between communication participants

[0005] The present invention relates to a method for cryptographically secured data transmission, in particular for the transmission of time-critical data within a communication system for an industrial automation system, between communication participants and a communication device, in particular an end device or a pre-device for an end device, for carrying out the method.

[0006] Industrial automation systems typically comprise a multitude of automation devices interconnected via an industrial communication network and serve to control or regulate plants, machines, or equipment within the context of manufacturing or process automation. Due to time-critical conditions in industrial automation systems, real-time communication protocols such as PROFINET, PROFIBUS, Real-Time Ethernet, or Time-Sensitive Networking (TSN) are predominantly used for communication between automation devices. In particular, control services or applications can be automatically and load-dependently distributed across currently available servers or virtual machines within an industrial automation system.

[0007] From EP 3646 559 B1, a method for verifying datagrams transmitted within an industrial automation system with multiple automation cells is known. In this method, datagrams to be verified are transmitted from the automation cells to a firewall system via a respective firewall interface and checked there according to predefined rules. The firewall system is formed by at least one virtual machine provided within a data processing system comprising multiple computing units. A data link tunnel is established between the respective firewall interface and the firewall system for the transmission of the datagrams to be verified. Both datagrams to be verified and at least those that have been successfully verified are transmitted within the respective data link tunnel.

[0008] EP 4 283 925 B1 concerns a secure transmission of time-critical data within a communication system that includes several local networks in which data is transmitted by means of switching, and at least one network superimposed on the local networks in which data is transmitted by means of 202417071 foreign version

[0009] 2

[0010] Routing is transmitted, and a gateway system is included to connect the communication system to at least one unsecured external network. Network layer communication over the higher-level network is only authorized between authenticated system components. Switches authenticate connected end devices and assign them to a physical or logical local network according to their respective end device identity. Data link layer communication within the local networks is implicitly authorized based on the assignment of the respective end devices to the same local network. Communication at OSI layers 3-7 between end devices in different local networks or with end devices in the unsecured external network is authorized using zero trust proxies, each assigned to a specific local network.

[0011] EP 4 300 882 B1 discloses a secure transmission of time-critical data within a communication system comprising several local networks, each containing at least one switch and several terminal devices, a control unit that manages the functions of several switches and terminal devices, and a control network assigned to the control unit that is separate from the local networks. Communication within the local networks is implicitly authorized based on the assignment of the respective terminal devices to the same local network. Each terminal device is assigned a Zero Trust adapter that captures the terminal device's status information, forwards this information via the control network to the control unit for evaluation, and authenticates the terminal device to the control unit and / or communication partners.The control unit determines a trust code for each end device based on the status information and applies rules dependent on the trust code for the configuration or for permissible communication relationships of the end devices.

[0012] US Patent 2021 / 050996 A1 describes a method for disclosing at least one cryptographic key used to encrypt at least one communication link between a first communication participant and a second communication participant. At least one of the communication participants is registered with a publish-subscribe server as the publishing entity, while at least one monitoring entity is registered as the subscribing entity. Upon subsequent negotiation of a cryptographic key by the publishing entity, the negotiated cryptographic key is automatically provided by the publishing entity to the publish-subscribe server. The negotiated cryptographic key is also transmitted by the publish-subscribe server to the at least one subscribing entity. (See also the foreign version 202417071.)

[0013] The subscriber unit uses three cryptographic keys to decrypt the encrypted communication link.

[0014] In the Prior Art Journal 2019 #01 (ISBN 978-3-947591-04-6), pages 64-68 describe how to specify a randomization parameter, used for randomized program code execution, through a project design or configuration. This allows, for example, a device-specific randomization parameter to be defined during manufacturing, commissioning, or maintenance. In this way, a device such as an industrial control unit or an IoT (Internet of Things) device exhibits deterministic behavior during operation. This is achieved using a code randomization parameter that can be configured on the device, for example, during manufacturing or by the user.The code randomization parameter can be configured directly, or it can be generated based on multiple source randomization parameters, such as through an XOR operation (exclusive OR) or a cryptographic hash function of the concatenated source randomization parameters. Code randomization parameters can be device randomization parameters configured during manufacturing. They can also be configuration randomization parameters defined as part of the configuration data entered by the user, or firmware randomization parameters contained within the firmware.

[0015] In many use cases, only generally accepted cryptographic algorithms are used, such as those recommended by the BSI (Federal Office for Information Security) or NIST (National Institute of Standards and Technology). However, in some cases, it can be advantageous to use a modified cryptographic algorithm. This can make automated attacks, such as those based on reverse engineering, vulnerability analysis, or side-channel attacks, more difficult, especially when tools designed for widely used cryptographic algorithms are not directly applicable.

[0016] For the authentication of subscribers in mobile networks, cryptographic algorithms can be used where a mobile network operator can specify a particular algorithm variant by defining the OP parameter (Operator Variant Algorithm Configuration). This allows a mobile network operator to define and use a specific cryptographic algorithm for authentication with minimal effort. The mobile network operator only needs to select the OP parameter to specify a 202417071 foreign version

[0017] Four specific variants of the cryptographic algorithm can be created. Additionally, tweakable block ciphers (see https: / / en.wikipedia.org / wiki / Block_cipher, section "Tweakable block ciphers") can be used, where a tweaking parameter is taken as an input parameter in addition to the key and plaintext. These tweaking parameters primarily serve to implement more efficient authenticated encryption operating modes. Some operating modes of a regular block cipher can take into account an IV value (initialization vector), which can include information such as a network address.

[0018] Furthermore, key derivation allows parameters such as a network name to be used to generate a derived key. Numerous approaches exist for creating variants of an encryption algorithm depending on a parameter. However, specifying such a parameter on the communication participant side is not currently possible. Therefore, adapting an encryption algorithm to minimize attack vectors requires extensive expertise that not every user possesses.

[0019] The present invention therefore aims to provide a method for cryptographically secured data transmission between communication participants that is robust against automated attacks, in particular for the exchange of time-critical data within an industrial automation system, which enables simple and flexible individualization of the cryptographic algorithms used, and to provide a suitable device for the technical implementation of the method.

[0020] This problem is solved according to the invention by a method with the features specified in claim 1 and by a communication device with the features specified in claim 11. Advantageous embodiments of the present invention are specified in the dependent claims.

[0021] According to the inventive method for cryptographically secured data transmission between communication participants, the communication participants authenticate themselves before establishing a session and jointly create a cryptographic session key or use a pre-provided cryptographic session key. The communication participants can, for example, authenticate themselves directly to at least the other communication participant or to an authentication server. Accordingly, the session key can advantageously be agreed upon between the communication participants or [202417071 Foreign Version].

[0022] 5. The authentication server specifies the session key. If data transmission occurs between more than two communication participants, the session key is preferably a group key, with the authentication server being, in particular, a group key management server that provides the group key. Furthermore, when establishing the session, an encryption method supported by the communication participants, in particular a cipher suite, can be selected. Examples of cipher suites are AES-GCM, AES-CCM, TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384,

[0023] TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256 or

[0024] TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_SHA256.

[0025] According to the invention, after successful authentication of the communication participants, the session between them is established cryptographically using the session key. For an encryption method to be used within the session, an encryption parameter, in particular a crypto-diversification parameter, is compared between the communication participants, based on which a cryptographic encryption function of the encryption method is adapted. The encryption parameter is preconfigured for each communication participant and remains unchanged within the session. Preferably, the encryption parameters can only be configured or changed on the communication devices assigned to each communication participant after successful user authentication and authorization verification.

[0026] Depending on the encryption parameter, and especially the crypto diversification parameter, a specific block cipher variant or stream cipher variant—that is, a cryptographic algorithm variant specific to the respective encryption parameter or crypto diversification parameter—can be defined. This specific cryptographic algorithm variant is used for the encryption method employed within the session between the communication participants, utilizing the cryptographic session key agreed upon or established between them. This has the advantage that the cryptographic algorithm variant used by the encryption method, and thus the encryption method itself, is adapted to the encryption parameter or crypto diversification parameter.An encryption method, in particular a cipher suite, can use several cryptographic algorithms in combination, e.g. a first cryptographic algorithm for encrypting the user data and a second 202417071 foreign version.

[0027] 6. Cryptographic algorithms for the cryptographic protection of user data integrity and user data authenticity. However, it is also possible to use a combined cryptographic algorithm, which can also be referred to as authenticated encryption. The encryption parameter or crypto diversification parameter can specifically refer to the cryptographic algorithm used for user data encryption, the cryptographic algorithm used for the cryptographic protection of user data integrity and user data authenticity, or a cryptographic algorithm used for authenticating encryption. Thus, a specific cryptographic algorithm variant can be defined depending on the encryption parameter or crypto diversification parameter.When using multiple cryptographic algorithms, especially for user data encryption and for the cryptographic protection of user data integrity and user data authenticity, in an encryption procedure, a common encryption parameter or crypto diversification parameter can be used, or several encryption parameters or crypto diversification parameters specific to the respective cryptographic algorithm of the encryption procedure can be used.

[0028] According to the invention, when comparing the encryption parameter, it is checked whether it is identically preconfigured for the communication participants. If the preconfiguration is identical, the encryption parameter is adopted to adapt the encryption method, and data transmitted between the communication participants within the session is cryptographically secured according to the adapted encryption method. If, however, the preconfigured encryption parameters differ, the session is terminated or the session setup is aborted.

[0029] With the present invention, users, such as operators of industrial automation systems or system integrators, can easily and reliably implement a cryptographically diversified encryption method without requiring extensive cryptographic expertise themselves. In particular, the user-side setting of the diversifying encryption parameter can be prepared or implemented by a device manufacturer who possesses the necessary cryptographic expertise. Furthermore, the encryption method can be configured by the user independently of the actual cryptographic keys, so that the effects of using the method according to the invention on other relevant aspects are minimal. 202417071 Foreign version

[0030] 7

[0031] According to a preferred embodiment of the present invention, the encryption parameters or crypto-diversification parameters are configured by an engineering system on the communication devices assigned to each communication participant. In particular, the engineering system can specify, by means of the encryption parameters, between which communication participants encrypted communication is intended or permitted. In this way, it can be ensured with a high degree of reliability that data transmission is only possible between intended communication partners. Furthermore, the potential for attack can be reduced by diversifying the encryption parameters used. Thus, potential damage that could arise, for example, from a faulty configuration or the loss of authentication credentials, can be limited accordingly.

[0032] Advantageously, the encryption parameters or crypto-diversification parameters on the communication devices assigned to the communication participants are configured or changed only via a local interface on the respective communication device. This reliably prevents an encryption parameter or crypto-diversification parameter from being modified during an attack on a device, for example, via a remote device management protocol such as SSH, NETCONF / YANG, RESTCONF / YANG, SNMP, or OMA Device Management (Open Mobile Alliance). The local interface can be implemented, for example, as a serial interface, e.g., RS232, USB, or SPI. It is also possible to use a network interface, e.g., Ethernet, in which case the device itself is responsible for configuring or changing the encryption parameter.Crypto diversification parameters should be configured via a direct, non-routed, i.e., link-local, network connection. For example, the device can check whether a link-local IP address is being used, or it can check the hop count of an IP packet. This has the advantage that while a Remote Device Management Protocol is used to configure or change the encryption or crypto diversification parameter, this is only possible locally, i.e., in close proximity to the device.

[0033] According to a further advantageous embodiment of the present invention, the encryption parameters or crypto-diversification parameters are configured or changed on the communication devices assigned to the communication participants via a first interface on the respective communication device. 202417071 Foreign version

[0034] 8

[0035] In contrast, authentication credentials assigned to communication participants, particularly user certificates, are set up on the respective communication device via a second interface, separate from the first. This ensures that encryption parameters or crypto-diversification parameters, on the one hand, and authentication credentials, on the other, can only be configured independently of each other, further reducing attack vectors.

[0036] Preferably, during the authentication of a communication participant or the agreement of the session key, at least one other communication participant is notified that data transmitted between them within the session will be cryptographically secured using an encryption method with an encryption function adapted based on the encryption parameter or crypto-diversification parameter. This has the advantage that it can be detected during authentication and key agreement if a different encryption parameter or crypto-diversification parameter is configured for another communication participant. It is also possible, in principle, to define a specific cipher suite for diversifiable encryption. Advantageously, the encryption parameter or crypto-diversification parameter is...A checksum calculated using the encryption parameter is transmitted to or displayed to the other communication participant. This ensures transparency regarding the configured encryption parameter.

[0037] The communication device according to the invention, in particular an end device or a pre-device for an end device, is designed to carry out a method according to the preceding descriptions and is configured to authenticate a communication participant to whom the communication device is assigned before a session is established and to create a cryptographic session key together with at least one other communication participant or to use a previously provided cryptographic session key. Furthermore, the communication device is configured to establish the session between the communication participants in a cryptographically secure manner using the session key after successful authentication of the communication participants and to compare an encryption parameter between the communication participants for an encryption method to be used within the session. Based on this 202417071 foreign version

[0038] 9

[0039] The encryption parameter involves adjusting a cryptographic encryption function of the encryption method, whereby the encryption parameter is preconfigured and immutable within the session.

[0040] Furthermore, the communication device according to the invention is configured to check, upon comparison of the encryption parameter, whether it is identically preconfigured for the communication participants, and, if the preconfiguration is identical, to adopt the encryption parameter to adapt the encryption method and to cryptographically secure data transmitted between the communication participants within the session according to the adapted encryption method. The communication device is also configured to terminate the session or abort the session setup if different preconfigured encryption parameters are detected.

[0041] The present invention disclosure is explained in more detail below using an exemplary embodiment with reference to the drawing. It shows

[0042] Figure 1 shows a representation of an industrial automation system that interacts with a real, physical environment via sensors and actuators.

[0043] Figure 2 shows a communication component that can be integrated into an end device for user-diversified encrypted data transmission.

[0044] Figure 3 shows a pre-device that can be connected to an end device and has two network interfaces for user-diversified encrypted data transmission.

[0045] The industrial automation system shown in Figure 1 comprises a host 101 configured as an edge computing node, an operator and monitoring station or HMI panel 102, a programmable logic controller (PLC) 103, several input / output (I / O) modules 104-105, and an automated guided vehicle (AGV) 106. The host 101, the operator and monitoring station 102, the PLC 103, the I / O modules 104-105, and the AGV 106 are interconnected via a communication network 100. The PLC 103, the I / O modules 104-105, and the AGV 106 are wirelessly connected to the communication network 100, for example, via industrial WLAN or 5G communication. Wired communication is also possible, for example via (real-time) Ethernet, especially PROFINET or TSN (Time-Sensitive Networking).

[0046] 10

[0047] Networking). In this example, control data, monitoring data, configuration data, and management data are transmitted via encrypted communication links. TLS, QUIC, or OPC UA Secure Channel can be used for this purpose. Furthermore, MACsec, IPsec, or radio channel encryption, e.g., in WLAN or 5G, can be used.

[0048] The PLC 103 and the I / O modules 104-105 each comprise several sensors S and actuators A connected to a technical system 110 to be controlled or regulated. The technical system 110 can be, for example, a production plant or a process plant. The operator control and monitoring station 102 serves to visualize process data or measurement and control variables that are processed or acquired by programmable logic controllers (PLCs), input / output units, sensors, or actuators. In particular, the operator control and monitoring station 102 can be used to display values ​​of a control loop and to change control parameters.

[0049] In the present embodiment, the host 101 comprises a container runtime environment by means of which a variety of virtualized control applications 111-114 can be provided, for example, for virtual programmable logic controllers 111, for a virtual SCADA system 112 (Supervisory Control and Data Acquisition), for a virtual controller 113 for driverless vehicles, or for a virtual manufacturing execution system 114. The virtual programmable logic controllers 111 can be used, in particular, to control or monitor the I / O modules 104-105.

[0050] The virtualized control applications 111-114 are deployed using containers, such as Docker or Linux containers, which can be loaded into and executed within the container runtime environment. The containers run in isolation from each other within the container runtime environment and share an operating system kernel of host 100 as well as physical or virtual network resources of host 100, in particular a network adapter. As an alternative to containers, the virtualized control applications 111-114 can also be deployed using virtual machines or WebAssembly or Java bytecode. Accordingly, a hypervisor, a WebAssembly runtime environment, or a Java Virtual Machine can be provided on host 101 as an alternative to the container runtime environment. 202417071 Foreign version

[0051] 11

[0052] For encrypted data transmission, the PLC 103, the I / O modules 104-105, and the driverless vehicle 106 can each include the integrated communication component 200 shown in Figure 2 for user-diversified encrypted data transmission. As an alternative to an integrated solution, the host 101 and the operator and monitoring station 102, for example, can each be connected to the essentially functionally identical control unit 200' shown in Figure 3. While the integrated communication component 200 has only one network interface 201, the control unit 200' includes a first device-side network interface 201a and a second network-side network interface 201b. Only the integrated communication component 200 includes an I / O interface 251 for receiving sensor or actuator data to be transmitted and an associated controller unit 252, which forwards the sensor or actuator data.Actuator data is connected to a functional unit 202 for secure communication. In the case of the ballast 200', the functional unit 202 for secure communication is instead connected to the first device-side network interface 201a. Furthermore, the functional unit 202 for secure communication is also connected to the second network-side network interface 201b of the ballast 200' or to the network interface 201 of the integrated communication component 200. Otherwise, there are no further differences between the integrated communication component 200 and the ballast 200'. The following explanations therefore apply to both variants.

[0053] The secure communication functional unit 202 comprises an encryption unit 220 with an encryption function 222 that can be adapted using a crypto diversification parameter, and an interface 221 (record layer) for receiving unencrypted data and forwarding it to the encryption function 222. The encryption function 222 reads the crypto diversification parameter from a dedicated storage unit 232 for crypto diversification parameters. This storage unit 232 can only be written to via a dedicated management interface 231 for crypto diversification parameters. Furthermore, both the integrated communication component 200 and the upstream device 200' include a functional unit 223 (authentication and key agreement) for providing cryptographic session keys 230.Functional unit 223 can access certificates or cryptographic keys stored in a dedicated credential storage unit 242 for authentication and for generating the session key 230 jointly with other communication participants. A separate credential management interface (202417071, international version) is required for write access to the credential storage unit 242.

[0054] 12

[0055] 241 is provided. In this way, write access to the storage unit 232 for crypto diversification parameters and to the credential storage unit 242 via the same management interface is prevented.

[0056] Overall, both the integrated communication component 200 and the upstream device 200' are each configured to authenticate an assigned communication participant before a session is established and to generate a session key 230 together with at least one other communication participant, for example, according to TLS, DTLS, QUIC, OPC UA Secure Channel; IPsec / IKEv2, or to use a pre-provided session key 230. Provision of the session key 230 can be carried out, in particular, by means of an authentication server, e.g., an AAA server or RADIUS / DIAMETER server, which authenticates a first communication participant, determines the session key, and provides it to the other communication participant, for example, according to EAP-TLS or EAP-PEAP in WLAN or according to MACsec, 5G SNPN; 5G AKA or EAP-AKA in 5G mobile networks.Data transmission between more than two communication participants is generally possible. In this case, the session key 230 is a group key, and the authentication server is a group key management server that provides the group key, for example using GDOI (see also https: / / datatracker.ietf.org / doc / html / rfc6407).

[0057] After successful authentication of the communication participants, the session is established cryptographically using the session key 230. The crypto diversification parameter, which determines the encryption function 222, is compared between the communication participants to determine the encryption method to be used within the session. The crypto diversification parameter is preconfigured for each communication participant and remains unchanged within the session. Preferably, the crypto diversification parameter can only be configured or changed after successful user authentication and authorization verification. During session setup, the communication participants can also agree on a cipher suite in addition to the crypto diversification parameter.

[0058] A comparison of the crypto diversification parameter checks whether it is identically pre-configured for the communication participants. Both the integrated communication component 200 and the upstream device 200' are each designed for this purpose (202417071 foreign version).

[0059] 13. The system is configured to adopt the crypto diversification parameter when the preconfiguration is identical for adapting the encryption method and to cryptographically secure data transmitted between communication participants within the session according to the encryption method adapted via the crypto diversification parameter. If different preconfigured encryption parameters are used, the session is terminated or the session setup is aborted.

[0060] As explained above, the encryption of user data between communication participants is adjusted based on a user-configurable crypto-diversification parameter. The encryption is therefore not solely dependent on the keys used for authentication and key agreement, and the resulting session key. Specifically, encrypted data transmission between communication participants is only possible if they have configured matching crypto-diversification parameters. This ensures with a high degree of reliability that data transmission is only possible between intended communication participants.Furthermore, diversification can reduce the attack surface, thereby limiting potential damage that can occur due to a misconfiguration or the loss of authentication credentials used for authentication and key agreement. It can also make side-channel attacks more difficult.

[0061] For example, if, in flexibly reconfigurable production environments (Industry 4.0) or due to the implementation of a zero-trust security approach, data communication is filtered less frequently or not at all at network boundaries, the concept described above can still ensure that only automation devices or communication participants within a designated shared virtual zone can communicate with each other using encryption. Depending on the specific technical implementation of crypto diversification for encrypted data transmission, as described below, the attack surface can often be reduced because different, user-specific cryptographic variants are employed, thus preventing or at least hindering a successful attack using pre-prepared, fixed exploits.

[0062] The crypto diversification parameter can be selected and configured based on the following criteria in particular:

[0063] - Operator of an automation system (identifier or name),

[0064] - Location where the automation system is located, 202417071 Foreign version

[0065] 14

[0066] - Security zone of an automation device or communication participant according to IEC62443,

[0067] - Security level of the automation device or communication participant according to IEC62443,

[0068] - Safety Integrity Level

[0069] - Real-time or non-real-time communication,

[0070] - Type of communication, such as diagnostic communication or control communication.

[0071] The crypto diversification parameter can preferably be configured as a string, but alternatively as a bit sequence, a decimal value, or a hexadecimal value. The encrypted data transmission can also be authenticated encryption, meaning that the integrity of the transmitted data is cryptographically protected. Furthermore, it can be implemented that the crypto diversification parameter is set only once (sealing of the crypto diversification parameter) and can then either not be reset at all or only via a factory reset. According to another implementation variant, the crypto diversification parameter can only be set or changed via a device-local interface, but not via a remote device management protocol such as SSH, NETCONF / YANG, RESTCONF / YANG, SNMP, or OMA Device Management (Open Mobile Alliance).This ensures with a high degree of reliability that the crypto diversification parameter cannot be modified during an attack on a device. Preferably, the crypto diversification parameter is set up (configured and stored) only locally on a device assigned to the respective communication participant, e.g., communication device, IoT device, control unit, communication processor. This further reduces the possibilities for manipulation.

[0072] Furthermore, in a 5G mobile communication system, the crypto diversification parameter for a mobile subscriber can be stored in the UDM (Unified Data Management). This crypto diversification parameter can preferably be set or changed via a Network Exposure Function (NEF) interface of the mobile communication system for an individual mobile subscriber or a group of mobile subscribers. This crypto diversification parameter can, for example, be set by an operator of an automation system and serves as an additional security parameter when a session key for mobile encryption is determined or when mobile encryption is performed. If a general or public 5G mobile network of a 5G mobile provider serves as the basis for a communications network (202417071 foreign version).

[0073] If a 5G cellular network operator uses a crypto diversification parameter (e.g., via Closed Access Group or Network Slicing), the operator can influence the encryption within the 5G cellular network via this parameter. The crypto diversification parameter can also be referred to as the OT-Operator-Configurable Crypto Algorithm Variant Parameter, as it allows an OT (Operational Technology) operator, or an operator of an automation system, to configure a specific encryption variant.

[0074] The crypto diversification parameter can modify the encryption in different ways:

[0075] - Use of an encryption algorithm that already incorporates diversification in its design.

[0076] - In a round-based block cipher, an additional round is performed depending on the crypto diversification parameter, preferably at the beginning or end of the round-based block cipher. For example, in AES, an additional round can be calculated that incorporates the crypto diversification parameter.

[0077] - Determining an initialization vector value depending on the configured crypto diversification parameter in an operating mode of a block cipher that uses an initialization vector, for example, in CTR mode or GCM mode. In particular, a subrange or a portion of the bits of the initialization vector can be specified depending on the configured crypto diversification parameter.

[0078] - Use of the crypto diversification parameter as a tweaking parameter of a tweakable block cipher.

[0079] - An additional key derivation parameter when a key is derived using a Key Derivation Function (KDF) during authentication and key agreement. The crypto diversification parameter is included as a key derivation parameter in the key derivation of the session key used for encrypted data transmission via a KDF. For example, in TLS Key Schedule, the crypto diversification parameter would be included as an additional key derivation parameter, along with a pre-shared key and an (elliptic curve) Diffie-Hellman shared secret.

[0080] - Additional parameter in a key schedule of a block cipher, where round-specific round keys are determined.

[0081] - Constant parameters of a cryptographic algorithm, e.g., S-box or 3GPP cryptographic parameters. 202417071 Foreign version

[0082] 16

[0083] Preferably, during authentication and key agreement, the other communication participant is notified that cryptographic diversification is taking place. This can be additional information, allowing defined cipher suites to be reused. For example, a base cipher suite and diversification can be signaled. It is possible not only to signal that diversification is taking place, but also to transmit the cryptographic diversification parameter, an identifier, or a checksum of the cryptographic diversification parameter. This has the advantage that it can be detected during authentication and key agreement if the communication partners have configured different cryptographic diversification parameters. However, it is also possible to define a special cipher suite for diversifiable encryption.

Claims

202417071 Foreign version 17 Patent claims 1. Method for cryptographically secured data transmission between communication participants, in which - the communication participants (101-106) authenticate themselves before setting up a session and jointly create a cryptographic session key (230) or use a pre-provided cryptographic session key, - based on the session key (230) after successful authentication of the communication participants (101-106), the session between the communication participants is cryptographically secured, characterized by the fact that - for an encryption method to be used within the session between the communication participants, an encryption parameter (232) is compared, on the basis of which a cryptographic encryption function (222) of the encryption method is adapted, wherein the encryption parameter is preconfigured for each communication participant and is unchangeable within the session, - when comparing the encryption parameter (232), it is checked whether it is identically pre-configured for the communication participants (101-106), - the encryption parameter (232) is adopted for the adaptation of the encryption method with identical pre-configuration and data transmitted between the communication participants (101-106) within the session are cryptographically secured according to the adapted encryption method, - the session ends due to different pre-configured encryption parameters, or the session setup is aborted.

2. Method according to claim 1, wherein the communication participants (101-106) authenticate themselves directly to each other communication participant or to an authentication server and wherein the session key (230) is agreed between the communication participants or specified by the authentication server.

3. The method of claim 2, wherein the data transmission takes place between more than two communication participants (101-106), wherein the session key (230) is a group key and wherein the 202417071 Foreign version 18 The authentication server is a group key management server that provides the group key.

4. Method according to any one of claims 1 to 3, wherein the encryption parameters (232) are configured by an engineering system on the communication devices assigned to the communication participants (101-106).

5. Method according to claim 4, wherein the engineering system specifies, by means of the encryption parameters (232), between which communication participants (101-106) encrypted communication is provided and / or permitted.

6. Method according to one of claims 1 to 5, wherein the encryption parameters (232) are configurable and / or changeable only after successful user authentication and authorization verification on the communication devices assigned to the communication participants (101-106).

7. Method according to any one of claims 1 to 6, wherein the encryption parameters (232) on the communication devices assigned to the communication participants (101-106) are configured and / or changed only via a local interface on the respective communication device.

8. Method according to one of claims 1 to 7, wherein the encryption parameters (232) on the communication devices assigned to the communication participants (101-106) are configured and / or changed via a first interface (231) on the respective communication device, and wherein authentication credentials (242), in particular user certificates, assigned to the communication participants are set up via a second interface (242) on the respective communication device, different from the first interface.

9. A method according to any one of claims 1 to 8, wherein, upon authentication of a communication participant and / or upon agreement of the session key, at least one other communication participant is signaled that data transmitted within the session between the communication participants is encrypted according to an encryption method based on the 202417071 Foreign version 19 The encryption function, adapted to the encryption parameters, can be cryptographically secured.

10. Method according to claim 9, wherein the encryption parameter and / or a checksum calculated via the encryption parameter is transmitted to and / or displayed to the respective other communication participant.

11. Communication device for carrying out a method according to one of claims 1 to 10. 10, where the communication device is set up for this purpose, - to authenticate a communication participant to whom the communication device is assigned before establishing a session and to create a cryptographic session key together with at least one other communication participant or to use a pre-provided cryptographic session key, - to establish a cryptographically secure session between the communication participants using the session key after successful authentication of the communication participants, - to compare an encryption parameter between the communication participants for an encryption method to be used within the session, based on which an adjustment of a cryptographic encryption function of the encryption method is made, whereby the encryption parameter is preconfigured and unchangeable within the session, - to check, when comparing the encryption parameter, whether it is identically pre-configured for the communication participants, - to adopt the encryption parameter with identical pre-configuration to adapt the encryption method and to cryptographically secure data transmitted between communication participants within the session according to the adapted encryption method, - to end the session or to abort the session setup if different pre-configured encryption parameters are used.

Citation Information

Patent Citations

  • Method for inspecting datagrams transmitted within an industrial automation system and automation and / or communication device

    EP3646559B1

  • Method for secure transmission of time-critical data within a communication system and communication system

    EP4283925B1

  • Method for secure transmission of time-critical data within a communication system, communication system and adapter for end device

    EP4300882B1

  • Method and system for providing time-critical services by means of a process control environment

    EP4135298A1

  • Method and system for disclosing at least one cryptographic key

    US20210050996A1