Dual Cryptographic Security for Industrial Network Elements

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current industrial communication networks lack effective security measures to protect logical communication paths and prevent denial-of-service attacks, especially in real-time environments like industrial automation systems, where zone-based security models are inadequate for flexible and dynamic communication scenarios.

Innovation Solution

Implementing a dual cryptographic security function within the network elements to verify the authenticity and integrity of messages, using separate keys for confidentiality and integrity protection, allowing secure communication beyond traditional zone boundaries and preventing unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If zone-based security models are used to protect industrial communication networks, then security boundaries are established, but flexibility and adaptability for dynamic communication scenarios are reduced

Engineering Contradiction:
ImprovesecurityVSAvoidflexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent divides security protection into two independent layers: endpoint security (protecting communication partners) and network element security (protecting routing infrastructure). This segmentation allows each layer to operate independently with its own security functions, enabling flexible communication patterns while maintaining comprehensive security coverage.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces network elements as intermediaries that perform independent security verification of messages. These intermediaries validate message integrity and authenticity using cryptographic checksums, enabling secure routing decisions without requiring endpoint devices to manage complex zone-based security policies.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If cryptographic security functions are implemented to protect data transmission, then data confidentiality and integrity are improved, but computational overhead and processing time increase

Engineering Contradiction:
Improvedata integrityVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs cryptographic checksum verification at network elements before routing decisions are made. This preliminary security validation prevents malformed or malicious messages from consuming additional processing resources downstream, reducing overall computational overhead in real-time communication scenarios.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements selective security verification where network elements perform lightweight cryptographic checksum validation on all messages, while endpoint devices perform more comprehensive security checks only on critical control messages. This partial application of security functions optimizes the balance between security and processing time.

Inventive Principle:
Principle #16Partial or excessive action

3Reliability

If multiple security functions are deployed to prevent denial-of-service attacks, then security reliability is improved, but system complexity increases

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments security functions into distinct modules: endpoint security functions implemented at communication devices and network element security functions implemented at routing infrastructure. Each segment handles specific security tasks independently, reducing the complexity burden on any single device while providing comprehensive security coverage.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent designs network elements with multi-functional capabilities that combine routing operations with security verification. By integrating these functions into a single component, the system avoids the complexity of separate security appliances while maintaining security reliability through unified message validation and routing control.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11336657B2Securing communication within a communication network using multiple security functions
Publication Date: 2022.05.17 SIEMENS AG
  • US11336657B2 patent drawing
  • US11336657B2 patent drawing

AI summary

The invention relates to a communication network having at least one network element (NE), via which data associated with the communication are conducted. The method comprises the following steps: securing, by means of a first cryptographic security function, the data (D) that are transferred from at least one first communication device (PLC1) to at least one second communication device (PLC2), providing a second cryptographic security function, which secures, between a communication device and a network element, messages that are conducted from the first communication device to the at least second communication device via the at least one network element and that contain the data, providing a checking function by means of the at least one network element, which checking function checks the authenticity and/or integrity of the messages on the basis of the second security function, continuing (6) or stopping (5) the communication in accordance with the result of the check (4) by the checking function, wherein, if the communication is continued, the data remain secured by means of the first security function until the data are received by the at least second communication device.