Coupling Device Isolates Secure Communication Path

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Industrial systems face security vulnerabilities due to non-secure communication paths, particularly through the second interface device, which can lead to unauthorized access and impairment of the system.

Innovation Solution

A coupling device that can be set into two states, allowing communication through the first interface device while interrupting it in the second state, detected by a control unit to prevent unauthorized access and isolate the system from further devices in case of an attack.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If the second interface device is used for non-secure communication with auxiliary devices, then ease of operation is improved, but system security deteriorates

Engineering Contradiction:
Improveease of connection and disconnectionVSAvoidsystem security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The communication path is segmented into a first secure communication path (wire-bound) and a second non-secure communication path (via second interface device). The coupling device further segments the first communication path by providing a controllable connection state (coupled or uncoupled) between the first interface device and the connecting device, allowing selective isolation of the secure path while maintaining the non-secure path for auxiliary devices.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The coupling device acts as an intermediary element inserted into the first communication path between the first interface device and the connecting device. This intermediary provides controlled access to the secure communication path, allowing it to be coupled when security is not threatened and uncoupled when an attack is detected, thereby mediating between security requirements and operational needs.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If the first communication path is always connected for secure communication, then system security is improved, but ease of operation deteriorates due to inability to isolate during attacks

Engineering Contradiction:
Improvesystem securityVSAvoidability to isolate during attack
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The coupling device introduces dynamic controllability to the first communication path. The connection state between the first interface device and the connecting device can be changed from coupled to uncoupled and vice versa based on security conditions. The control unit dynamically adjusts the coupling state in response to attack detection, making the secure communication path adaptive rather than static.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The coupling device is pre-configured to be capable of uncoupling the first communication path as a protective measure. When an attack is detected via the second interface device, the control unit activates the coupling device to uncouple the secure path, preventing the attack from propagating through the secure communication path to other electrical devices connected via the connecting device.

Inventive Principle:
Principle #9Preliminary anti-action

3Ease of operation

If auxiliary devices are allowed to connect freely to the second interface device, then ease of operation is improved, but object-affected harmful factors increase due to unauthorized access

Engineering Contradiction:
Improveaccess by auxiliary devicesVSAvoidunauthorized communication and system impairment
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system segments communication into two distinct paths: the second communication path for non-secure auxiliary device access and the first secure communication path. The coupling device further segments the first path by providing controllable coupling/uncoupling capability. This segmentation allows auxiliary devices to freely access the second path while the secure first path remains protected and can be isolated when threats are detected.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11062027B2System with an electrical apparatus
Publication Date: 2021.07.13 KROHNE MESSTECHNICK GMBH & CO KG
  • US11062027B2 patent drawing
  • US11062027B2 patent drawing

AI summary

A system includes an electrical apparatus and a connecting device. The electrical apparatus comprises a control unit, a first interface device and a second interface device. A wire-bound first communication path is provided between the control unit and the connecting device via the first interface device and a second communication path is provided between the control unit and the second interface device. The system further includes a coupling device that can be set into a first coupling state and into a second coupling state. The first communication path is led through the coupling device in the first coupling state and is interrupted in the coupling device in the second coupling state. The control unit detects an attack on the system via the second interface device and, in the event of a detected attack, sets the coupling device from the first coupling state into the second coupling state.