Centralized Security Device for Field Device Tamper Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional tamper protection systems for industrial field devices require a continuous power supply and involve high technical overhead due to local monitoring, which can be compromised if the power source depletes, and necessitate individual installation of tamper monitoring equipment.

Innovation Solution

A security device connected to tamper sensors via a network, providing cryptographic keys only if no manipulation is detected, eliminating the need for local power and reducing technical overhead by enabling remote tamper monitoring and using passive sensors that generate energy from physical manipulations or an electromagnetic field.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If local tamper monitoring is implemented in field devices, then tamper protection capability is improved, but device complexity and technical overhead increase

Engineering Contradiction:
Improvetamper protection capabilityVSAvoidtechnical overhead
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The tamper monitoring function is extracted from the field device and relocated to a centralized server. The server now handles tamper detection and cryptographic key management, while field devices only need to communicate authentication requests and receive keys, significantly reducing local complexity

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The server performs multiple functions including tamper monitoring, cryptographic key generation, and authentication management for multiple field devices simultaneously. This centralized multi-functional approach replaces individual local tamper monitoring systems in each field device

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If continuous power supply is provided for tamper monitoring, then monitoring reliability is improved, but energy consumption increases

Engineering Contradiction:
Improvemonitoring reliabilityVSAvoidenergy consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

Instead of continuous monitoring, the system uses periodic authentication exchanges between field devices and the server. Tamper monitoring occurs at these periodic intervals during authentication, eliminating the need for continuous power supply while maintaining reliable detection capability

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

The authentication protocol itself serves dual purposes: both establishing cryptographic credentials and performing tamper monitoring. The periodic authentication exchanges automatically check for tamper conditions without requiring separate dedicated monitoring power

Inventive Principle:
Principle #25Self-service

3Reliability

If individual tamper monitoring equipment is installed in each field device, then local protection is improved, but installation complexity and costs increase

Engineering Contradiction:
Improvelocal protectionVSAvoidinstallation complexity
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

Multiple individual tamper monitoring functions are merged into a single centralized server that serves all field devices. This consolidation reduces the total number of monitoring components needed and simplifies installation and maintenance

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The server provides universal tamper monitoring and key management services to multiple field devices through the network, eliminating the need for device-specific local monitoring equipment and reducing overall system complexity

Inventive Principle:
Principle #6Universality (Multi-functionality)

Applied Scientific Principles

This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.

Function Achieved in This Case

This solution provides effective tamper protection without the need for continuous power and reduces implementation complexity, ensuring secure operation of field devices by only releasing cryptographic keys if no manipulation is detected, thus enhancing security and reducing costs.

Implementation Method 1

the security device is connected to at least one tamper sensor that is assigned to the field device and will emit a manipulation message upon detecting a physical manipulation carried out on the field device

Methodology Applied
Scientific EffectPhysical manipulation detection:

Implementation Method 2

The security device is not attached to the field device requiring to be monitored but is connected to the field device via a network

Methodology Applied
Scientific EffectElectromagnetic transmission:

Data Source

PatentUS9026806B2Method and device for providing a cryptographic key for a field device
Publication Date: 2015.05.05 SIEMENS AG
  • US9026806B2 patent drawing
  • US9026806B2 patent drawing
  • US9026806B2 patent drawing

AI summary

A security device and a method provide a cryptographic key for a field device. The security device is connected to at least one tamper sensor which is associated with the field device and which, when a physical manipulation carried out on the field device is detected, a manipulation message is emitted. The cryptographic key is only provided to the field device by the security device if the security device does not receive a manipulation message from the tamper sensors associated with the field device.