Data Transmission Intermediary for Safety-Critical Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In industrial automation systems, securely transmitting data from a general communication network to a safety-critical network is challenging due to the impracticality of continuously updating virus patterns, especially in environments where hourly or daily updates are not feasible, and the limitations of white list scanners in handling variable data with external systems.

Innovation Solution

A method and device that temporarily store data with a control value in a dwell memory, allowing it to be checked with current test patterns after a dwell time has elapsed, ensuring up-to-date malware detection and reducing storage capacity needs, by determining dwell time based on data properties, sender trust, and recipient security levels.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If virus patterns are updated hourly or daily to detect malware, then malware detection capability is improved, but deployment becomes impractical in industrial environments

Engineering Contradiction:
Improvemalware detection capabilityVSAvoiddeployment feasibility
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The system performs preliminary actions by pre-registering incoming data in a quarantine queue before final approval. Data is temporarily stored and subjected to multiple rounds of virus pattern checking before being released to the safety-critical network. This preliminary quarantine and repeated checking approach enables reliable malware detection without requiring frequent pattern updates, as the extended inspection period compensates for less frequent pattern refreshes.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If data is stored temporarily in a security device for quarantine and checking, then security is improved, but storage capacity requirements increase

Engineering Contradiction:
ImprovesecurityVSAvoidstorage capacity
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The system extracts only the essential elements needed for security verification while discarding unnecessary data. Specifically, after the quarantine period and security checks are complete, only approved data is released to the safety-critical network, while rejected data is discarded. This extraction approach maintains high security through thorough checking while minimizing storage requirements by not retaining all quarantined data indefinitely.

Inventive Principle:
Principle #2Taking out (Extraction)

3Quantity of substance

If whitelist scanners are used to permit specific patterns, then storage requirements are reduced, but adaptability to variable external data is lost

Engineering Contradiction:
Improvestorage requirementsVSAvoidhandling variable data
Core Design Contradiction:
Quantity of substanceVSAdaptability or versatility

Solution Approach 1:

The system implements dynamic adaptability by continuously updating virus patterns and re-checking quarantined data with updated patterns. Unlike static whitelist approaches, this dynamic system can adapt to new malware threats and variable external data by refreshing its detection patterns and re-evaluating stored data. This maintains low storage requirements while achieving versatility in handling variable data through repeated checking with updated patterns.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentEP3025478B1Apparatus and method for transmitting data
Publication Date: 2019.02.27 SIEMENS AG
  • EP3025478B1 patent drawingFigure 1
  • EP3025478B1 patent drawingFigure 2~3

AI summary

A method and an apparatus for transmitting data from a transmitter in a first communication network (21) to a receiver in a second, safety-critical application network (22) comprises an input buffer unit (31), an output buffer unit (32), a waiting unit (33) and a testing unit (34). The input buffer unit (31) provides the data that are to be transmitted. The waiting unit (33) detects an input time for the data that are to be transmitted, ascertains a dwell time for the data and stores the data that are to be transmitted and/or a check value for the data that are to be transmitted. The testing unit (34) is designed to test the data that are to be transmitted, following expiry of the dwell time, using a test pattern (41) that is up-to-date following expiry of the dwell time. The output buffer unit (32) is designed to provide the data for the receiver if the data have been deemed uncritical during the check. The test pattern preferably relates to a virus pattern.