Auditable Cryptographic Communication System for Industrial Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security systems fail to provide secure, auditable, and continuous communication between enterprise servers and industrial devices across multiple networks without shutting off devices or servers, especially during configuration, reconfiguration, and monitoring, and they are not designed to handle simultaneous communication over uncontrolled networks.

Innovation Solution

A cryptographic communication system that employs in-band and out-of-band messaging, using physical and virtual cryptographic modules, allowing for secure key generation and management, enabling continuous online configuration and monitoring without disrupting industrial devices or enterprise servers, and supporting simultaneous communication over various networks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a security system is implemented to provide secure communication between enterprise server and industrial devices, then security is improved, but the system complexity increases and requires shutting off devices during configuration

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system divides security management into separate modular components: physical cryptographic modules embedded in industrial devices, virtual cryptographic modules in the enterprise server, and a cryptographic manager tool. This segmentation allows independent configuration and management of security functions without shutting down the entire system.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The cryptographic manager tool acts as an intermediary that mediates between the enterprise server and physical cryptographic modules. It enables out-of-band communication for configuration and management, allowing security parameters to be updated without disrupting in-band industrial communication.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If continuous configuration and reconfiguration online is implemented, then operational continuity is improved, but the risk of security vulnerabilities increases

Engineering Contradiction:
Improveoperational continuityVSAvoidsecurity vulnerability risk
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

Security parameters, cryptographic keys, and configuration data are generated and prepared in advance through secure out-of-band communication channels before being deployed to industrial devices. This preliminary action ensures that online configuration operations can proceed without exposing the system to vulnerabilities during key generation or security parameter setup.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system maintains continuous secure communication channels for both in-band industrial data and out-of-band security management. This allows configuration updates to occur continuously without interrupting operational security functions, ensuring both productivity and security are maintained simultaneously.

Inventive Principle:
Principle #20Continuity of useful action

3Reliability

If frequent key generation is implemented to enhance security, then security is improved, but the processing overhead and time consumption increase

Engineering Contradiction:
ImprovesecurityVSAvoidtime consumption
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The cryptographic manager tool implements periodic key generation and rotation schedules based on configurable timeouts. Keys are generated at predetermined intervals through out-of-band communication, providing frequent security updates without requiring continuous processing that would consume excessive time and resources.

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

The system uses virtual cryptographic modules that can replicate and manage multiple cryptographic key sets. This copying capability allows frequent key generation to be handled efficiently by the virtual module, which can manage key lifecycles without proportionally increasing processing overhead on the physical industrial devices.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS8364950B1Auditable cryptographic protected communication system
Publication Date: 2013.01.29 DJ OSBURN MANAGEMENT LLC
  • US8364950B1 patent drawing
  • US8364950B1 patent drawing
  • US8364950B1 patent drawing

AI summary

An auditable cryptographic protected communication system for connecting an enterprise server to a plurality of industrial devices using messaging protocols for each industrial device enabling the industrial devices to receive commands and transmit status and measurement data using the individual device messaging protocols over a network.