Access Protection for Secure Telegram Transmission Compliance

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing secure message transmission methods in rail automation and signaling lack sufficient security, particularly over insecure transmission media, and may violate legal constraints against encrypted message transmission.

Innovation Solution

A method involving a transmitter-side and receiver-side access protection device that encrypts check data using a secret key, leaving the message unencrypted, ensuring secure transmission over insecure channels while maintaining compliance with legal constraints.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If check data is encrypted using a secret key to prevent unauthorized access and tampering, then transmission security is improved, but device complexity increases due to the need for additional access protection devices

Engineering Contradiction:
Improvetransmission securityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces access protection devices as intermediary components between the transmitter and receiver. These devices encrypt check data using a secret key known only to them, creating a security layer without requiring modifications to the existing transmitter and receiver systems. The intermediary handles the complexity of encryption while the main systems remain unchanged.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the telegram into two distinct parts: unencrypted message data and encrypted check data. This segmentation allows the message to remain accessible and unmodified while only the security-critical check data is protected through encryption, reducing the overall complexity compared to encrypting the entire transmission.

Inventive Principle:
Principle #1Segmentation

2Reliability

If the message is encrypted to ensure security, then transmission security is improved, but legal compliance deteriorates due to strict legal constraints against encrypted message transmission in some countries

Engineering Contradiction:
Improvetransmission securityVSAvoidlegal compliance
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent applies encryption selectively only to the check data portion of the telegram, while leaving the message portion unencrypted. This local application of encryption provides security for integrity verification without violating legal constraints that prohibit encrypting message content, thus achieving both security and legal compliance.

Inventive Principle:
Principle #3Local quality

3Measurement precision

If additional check data is added and encrypted to detect transmission errors or manipulations, then measurement precision is improved, but device complexity increases

Engineering Contradiction:
Improveerror detection capabilityVSAvoiddevice complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The access protection devices perform preliminary encryption of check data before transmission occurs. This preliminary action ensures that integrity verification data is protected in advance, enabling reliable error and manipulation detection without adding complex real-time processing requirements during transmission or reception.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12506593B2Method and arrangement for the secure transmission of a message from a transmitter to a receiver
Publication Date: 2025.12.23 SIEMENS MOBILITY GMBH
  • US12506593B2 patent drawing
  • US12506593B2 patent drawing
  • US12506593B2 patent drawing

AI summary

A method transmits a message from a transmitter to a receiver. A telegram generated by the transmitter and contains the message and check data, is transferred to a transmitter-side access protection device. The transmitter-side access protection device modifies the telegram and then transmits it to a receiver-side access protection device. The transmitter-side access protection device modifies the telegram by encrypting the check data, which contains a security code formed with the message by the transmitter, using a secret key forming coded data. The message remains unencrypted in the telegram. The receiver-side access protection device processes the modified telegram and passes the processed telegram to the receiver. The receiver-side access protection device forms the processed telegram by decrypting the coded data, and the receiver verifies the processed telegram using the message contained therein and the check data contained therein and rejects the message if the check data does not correlate.