Field Bus Security Coupling for Trusted Subscriber Communication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing field bus network protocols lack security mechanisms to protect communication links against external attacks, rendering them insecure despite the use of firewalls or application gateways.

Innovation Solution

A security device is integrated into the field bus system to provide secure communication by directly coupling with field bus subscribers lacking security functionality, using a predetermined security protocol for authentication, encryption, and decryption, and featuring a control apparatus to ensure operation integrity through reversible or irreversible blocking mechanisms.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If firewalls or application gateways are arranged in the periphery to protect field bus networks, then trustworthy zones are created, but the communication within these zones remains insecure

Engineering Contradiction:
Improvetrustworthy zone creationVSAvoidcommunication security
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

A security device is introduced as an intermediary component between field bus subscribers. This device includes authentication, encryption, and decryption functions that actively protect communications. The security device acts as a mediator that processes data between subscribers, applying security protocols to protect against external attacks while enabling secure communication within the previously insecure zone.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If security devices are connected as separate and independent BITW units, then security functions are provided, but device complexity increases

Engineering Contradiction:
Improvesecurity functionVSAvoidindependent unit management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the security device with the field bus subscriber into a single integrated unit. The security device is no longer a separate BITW component but is combined with the subscriber device, reducing the number of independent units. This integration maintains security functions while simplifying the overall system architecture and reducing management complexity.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The integrated field bus subscriber incorporates multiple functions including both the original subscriber capabilities and security functions (authentication, encryption, decryption). This multi-functional design eliminates the need for separate security devices, as each subscriber device itself provides security capabilities, thereby reducing system complexity while maintaining comprehensive security coverage.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Ease of operation

If field bus subscribers lack security functionality, then ease of operation is maintained, but communication protection against external attacks is lost

Engineering Contradiction:
Improvesimple field bus subscriberVSAvoidexternal attacks
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The field bus subscriber is enhanced to provide security functions autonomously without requiring external security devices or complex configuration. The integrated security capabilities (authentication, encryption, decryption) are built into the subscriber itself, enabling it to protect its own communications independently. This self-service approach maintains ease of operation while providing robust protection against external attacks.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11423187B2Security device and field bus system for supporting secure communication by means of a field bus
Publication Date: 2022.08.23 ABB (SCHWEIZ) AG
  • US11423187B2 patent drawing
  • US11423187B2 patent drawing
  • US11423187B2 patent drawing

AI summary

A security device to support secure communication via a field bus, has a connecting apparatus for the direct coupling of the security device to a network interface of a field bus subscriber, which is formed for connecting to a field bus and which is not formed for secure communication via the field bus. In the coupled state, there is a link between the security device and the field bus subscriber such that, if the link is disconnected or damaged, proper operation of the security device is reversibly or irreversibly blocked. Further, a transmitting and receiving apparatus is provided which is formed to securely transfer data coming from a directly coupled field bus participant, which is not formed for secure communication, via the field bus according to a predetermined security protocol, and which is further formed to receive data transferred via the field bus and intended for the field bus participant according to the predetermined security protocol and to deliver them to the field bus participant.