Dual Cryptographic Security for Industrial Network Elements
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current industrial communication networks lack effective security measures to protect logical communication paths and prevent denial-of-service attacks, especially in real-time environments like industrial automation systems, where zone-based security models are inadequate for flexible and dynamic communication scenarios.
Innovation Solution
Implementing a dual cryptographic security function within the network elements to verify the authenticity and integrity of messages, using separate keys for confidentiality and integrity protection, allowing secure communication beyond traditional zone boundaries and preventing unauthorized access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If zone-based security models are used to protect industrial communication networks, then security boundaries are established, but flexibility and adaptability for dynamic communication scenarios are reduced
Solution Approach 1:
The patent divides security protection into two independent layers: endpoint security (protecting communication partners) and network element security (protecting routing infrastructure). This segmentation allows each layer to operate independently with its own security functions, enabling flexible communication patterns while maintaining comprehensive security coverage.
Solution Approach 2:
The patent introduces network elements as intermediaries that perform independent security verification of messages. These intermediaries validate message integrity and authenticity using cryptographic checksums, enabling secure routing decisions without requiring endpoint devices to manage complex zone-based security policies.
2Reliability
If cryptographic security functions are implemented to protect data transmission, then data confidentiality and integrity are improved, but computational overhead and processing time increase
Solution Approach 1:
The patent performs cryptographic checksum verification at network elements before routing decisions are made. This preliminary security validation prevents malformed or malicious messages from consuming additional processing resources downstream, reducing overall computational overhead in real-time communication scenarios.
Solution Approach 2:
The patent implements selective security verification where network elements perform lightweight cryptographic checksum validation on all messages, while endpoint devices perform more comprehensive security checks only on critical control messages. This partial application of security functions optimizes the balance between security and processing time.
3Reliability
If multiple security functions are deployed to prevent denial-of-service attacks, then security reliability is improved, but system complexity increases
Solution Approach 1:
The patent segments security functions into distinct modules: endpoint security functions implemented at communication devices and network element security functions implemented at routing infrastructure. Each segment handles specific security tasks independently, reducing the complexity burden on any single device while providing comprehensive security coverage.
Solution Approach 2:
The patent designs network elements with multi-functional capabilities that combine routing operations with security verification. By integrating these functions into a single component, the system avoids the complexity of separate security appliances while maintaining security reliability through unified message validation and routing control.
Data Source
AI summary
The invention relates to a communication network having at least one network element (NE), via which data associated with the communication are conducted. The method comprises the following steps: securing, by means of a first cryptographic security function, the data (D) that are transferred from at least one first communication device (PLC1) to at least one second communication device (PLC2), providing a second cryptographic security function, which secures, between a communication device and a network element, messages that are conducted from the first communication device to the at least second communication device via the at least one network element and that contain the data, providing a checking function by means of the at least one network element, which checking function checks the authenticity and/or integrity of the messages on the basis of the second security function, continuing (6) or stopping (5) the communication in accordance with the result of the check (4) by the checking function, wherein, if the communication is continued, the data remain secured by means of the first security function until the data are received by the at least second communication device.

