Auxiliary Control Unit for Read-Only Access to Safety-Critical Controllers

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Safety-critical control devices are vulnerable to unauthorized access through data connections, which can lead to detrimental interventions in technical systems, necessitating a solution to prevent commanding or writing access while allowing diagnostic and maintenance data reading.

Innovation Solution

A device with an additional control unit that connects to the safety-critical control device, featuring a first communication interface for reading operating and process data and a software module to prevent command and write requests, ensuring only authorized data access for diagnostic and maintenance purposes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If data connection interfaces are provided for reading operating and process parameters from a safety-critical control unit, then diagnostic and maintenance purposes are enabled, but unauthorized access and manipulation risks are introduced

Engineering Contradiction:
Improvedata reading capabilityVSAvoidsafety integrity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

An auxiliary control unit is introduced as an intermediary between the diagnostic device and the safety-critical control unit. This mediator enables data reading functionality while blocking unauthorized command and write access to the safety-critical control unit, thus resolving the contradiction between enabling diagnostics and maintaining safety integrity

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If unrestricted access is allowed to control units for diagnostic purposes, then data reading is simplified, but unauthorized manipulation and safety compromises become possible

Engineering Contradiction:
Improveaccess flexibilityVSAvoidunauthorized manipulation risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The auxiliary control unit implements selective access control where different types of access requests are treated differently: read requests from authorized diagnostic devices are permitted, while command and write requests are blocked. This local differentiation of access permissions enables versatile data reading while preventing harmful manipulations

Inventive Principle:
Principle #3Local quality

Data Source

PatentEP3246778B1Device for reading out data from a safety-critical control device
Publication Date: 2023.12.20 KNORR BREMSE SYST FUR SCHIENENFAHRZEUGE GMBH
  • EP3246778B1 patent drawingFigure 1

AI summary

A device for reading data from a safety-critical control unit (108) is described, which prevents unauthorized access to the safety-critical control unit (108). For this purpose, an auxiliary control unit (110) is provided, which can be connected to the safety-critical control unit (108) via a first communication interface (112) in order to transfer data between the safety-critical control unit (108) and the auxiliary control unit (110). The auxiliary control unit (110) has a second communication interface (114) with which data can be transferred between the auxiliary control unit (110) and peripheral devices (116). The auxiliary control unit (110) is designed to prevent the transmission of commands and write requests to the safety-critical control unit (108).Furthermore, a diagnostic and maintenance system (102) is described which includes a device according to the invention for reading data from a safety-critical control unit (108).