Communication Module Gateway Segmentation for Secure Data Transmission

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing communication systems between hardware components in technical systems and back-end computer systems are vulnerable to unauthorized access and data manipulation, particularly during firmware updates and data transmission over packet-switched data networks.

Innovation Solution

A communication module with a device-proximal gateway and a network-proximal gateway connected via a point-to-point connection, which prevents rerouting and ensures secure data transmission by implementing complex encryption and signature processes through gateway security modules.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If data is transmitted over a packet-switched data network (e.g., Internet), then communication reach and connectivity are improved, but vulnerability to unauthorized access and data manipulation increases

Engineering Contradiction:
Improvecommunication reachVSAvoidvulnerability to unauthorized access
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The communication module is segmented into two separate gateways: a device-proximal gateway located near the hardware component and a network-proximal gateway located near the packet-switched data network. These gateways are connected via a dedicated point-to-point connection, creating distinct security zones that isolate the internal network from external threats while maintaining communication capability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A point-to-point connection acts as an intermediary between the device-proximal and network-proximal gateways. This dedicated connection serves as a controlled bridge that enables secure data transmission while preventing direct access to the internal network, effectively mediating between the secure internal environment and the external packet-switched network.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If firmware is updated remotely via packet-switched data network, then system maintenance capability is improved, but risk of firmware corruption and unauthorized access increases

Engineering Contradiction:
Improveremote maintenance capabilityVSAvoidfirmware integrity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The device-proximal gateway performs preliminary verification of firmware authenticity and integrity before allowing firmware updates to proceed. This includes validating digital signatures and checking cryptographic hashes of the received firmware, ensuring that only authenticated and uncorrupted firmware can be installed, thereby preventing unauthorized or corrupted firmware from compromising the system.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback mechanisms where the device-proximal gateway continuously monitors and verifies the authenticity of firmware received from the network-proximal gateway. Verification results are fed back into the update process, allowing the system to reject suspicious or corrupted firmware and maintain a log of update operations for security auditing.

Inventive Principle:
Principle #23Feedback

3Reliability

If encryption is implemented for data transmission, then data security is improved, but computational overhead and transmission complexity increase

Engineering Contradiction:
Improvedata securityVSAvoidencryption implementation complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Different security measures are applied locally at different positions in the communication path. The device-proximal gateway implements strong cryptographic verification for incoming firmware and data, while the point-to-point connection uses dedicated secure protocols. This localized application of security measures optimizes protection where most needed without uniformly complicating the entire system.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS12301552B2Communication module
Publication Date: 2025.05.13 AVL LIST GMBH
  • US12301552B2 patent drawing
  • US12301552B2 patent drawing
  • US12301552B2 patent drawing

AI summary

The invention relates to a communication module for transmitting data between at least one hardware component which is integrated into an internal network of a technical system and a back-end computer system which is connected to a packet-switched data network. The communication module has a device-proximal gateway and a network-proximal gateway, which are connected to one another via a point-to-point connection without intermediate stations. The network-proximal gateway provides a data transmission interface between the packet-switched data network and the point-to-point connection and the device-proximal gateway provides a data transmission interface between the point-to-point connection and the internal network.