Cryptographic Manager Tool for Industrial Device Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

There is a need for a cryptographic manager tool system that provides secure, encrypted communication between an enterprise server and industrial devices, allowing for both in-band and out-of-band communication, while enabling continuous online configuration and monitoring without shutting off the devices or the server, and ensuring security across multiple uncontrolled networks.

Innovation Solution

The cryptographic manager tool employs a system of in-band and out-of-band messaging protocols, using physical and virtual cryptographic modules to facilitate secure communication, key generation, and continuous monitoring, with the ability to handle multiple networks and devices simultaneously, and includes features like auditable communication trails and customizable cryptographic time outs based on security standards.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If encryption is applied to all communication between enterprise server and industrial devices, then security is improved, but communication complexity and processing overhead increase

Engineering Contradiction:
ImprovesecurityVSAvoidcommunication complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The communication channel is segmented into two distinct paths: in-band communication for operational data and out-of-band communication for cryptographic key exchange. This segmentation allows encryption to be applied selectively rather than to all communication, reducing overall complexity while maintaining security where most needed

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A cryptographic manager tool is introduced as an intermediary component that handles cryptographic operations separately from the main communication flow. This mediator manages key generation, distribution, and decryption processes, isolating cryptographic complexity from the primary communication path

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If cryptographic key management is performed manually, then security control is improved, but time consumption and operational efficiency deteriorate

Engineering Contradiction:
Improvesecurity controlVSAvoidtime consumption
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The cryptographic manager tool automatically performs key generation, distribution, and management operations without requiring manual human intervention. The system self-manages cryptographic credentials while maintaining security controls, eliminating the time consumption associated with manual key management

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

Cryptographic keys and security credentials are generated and distributed in advance through automated processes before communication is needed. This preliminary automated setup eliminates the need for time-consuming manual key management during operational phases

Inventive Principle:
Principle #10Preliminary action

3Productivity

If configuration changes are made while devices are running, then operational continuity is improved, but risk of communication errors and security vulnerabilities increases

Engineering Contradiction:
Improveoperational continuityVSAvoidcommunication reliability
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system maintains continuous operational functionality by allowing configuration changes to be applied without shutting down industrial devices. The cryptographic manager tool ensures that security protocols remain active and communication channels stay secure throughout the reconfiguration process

Inventive Principle:
Principle #20Continuity of useful action

Solution Approach 2:

The system prepares and validates configuration changes through the cryptographic manager tool before applying them to running devices. This preliminary validation ensures that security protocols are properly maintained during transitions, cushioning against potential communication errors or security vulnerabilities

Inventive Principle:
Principle #11Beforehand cushioning (Prior cushioning)

Data Source

PatentUS8316232B1Cryptographic manager tool system
Publication Date: 2012.11.20 DJ OSBURN MANAGEMENT LLC
  • US8316232B1 patent drawing
  • US8316232B1 patent drawing
  • US8316232B1 patent drawing

AI summary

A cryptographic manager tool for providing encrypted communication between an enterprise server and a plurality of industrial devices using messaging protocols for each industrial device, enabling the industrial devices to receive commands and transmit status and measurement data to the enterprise server in out of band encrypted and decrypted messaging, simultaneously, using the individual device messaging protocols over a network.