Field Device Registration Using Two-Stage Encryption Keys

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for registering field devices with computing facilities in energy supply networks are time-consuming, require technical expertise, and are prone to errors, hindering fast deployment and secure communication.

Innovation Solution

A method involving a first encryption method for initial communication, followed by a user-specific and device-specific second encryption method, using key pairs and certificates, facilitates secure and efficient registration of devices with computing facilities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual configuration and parameterization tools are used for device registration, then secure communication can be established, but the process becomes time-consuming and requires technical expertise

Engineering Contradiction:
Improvesecure communicationVSAvoidregistration time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The device performs self-registration with the computing facility by automatically establishing encrypted communication channels and exchanging cryptographic keys without requiring manual configuration. The device autonomously generates or receives encryption keys and configures its communication parameters, eliminating the need for technicians to manually set up secure connections while maintaining security standards.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The device is pre-configured with cryptographic keys and certification authorities during manufacturing or prior deployment. This preliminary preparation enables the device to immediately establish secure communication upon activation, bypassing the time-consuming manual key exchange and configuration steps that would otherwise be required during registration.

Inventive Principle:
Principle #10Preliminary action

2Ease of manufacture

If manual configuration is performed by technicians, then device registration can be completed, but operating errors occur and deployment speed decreases

Engineering Contradiction:
Improvedevice registrationVSAvoiderror-free operation
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The registration process is automated through self-service mechanisms where the device autonomously completes configuration tasks by exchanging cryptographic parameters with the computing facility. This eliminates human intervention in the configuration process, thereby removing the source of operating errors while maintaining ease of deployment.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The manual mechanical process of technician configuration is replaced with an automated electronic/key-based configuration system. Cryptographic key exchange and automatic parameter configuration replace the manual steps of typing, copying, and verifying configuration parameters, eliminating errors associated with manual operations.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Adaptability or versatility

If conventional login processes are used for field devices, then cloud service integration is achieved, but the process requires multiple work steps and technical understanding

Engineering Contradiction:
Improvecloud service integrationVSAvoidlogin process simplicity
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The login process is segmented into distinct automated phases: initial device activation, automatic key exchange with the computing facility, and seamless integration with cloud services. Each segment is handled autonomously by the device without requiring user intervention, simplifying the overall process while maintaining comprehensive cloud service integration capabilities.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A cryptographic key management system acts as an intermediary between the field device and cloud services. The device communicates with the computing facility through standardized encrypted channels, which automatically handle authentication and authorization, eliminating the need for users to understand complex login procedures while ensuring proper cloud service integration.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Ease of operation

If device communication is enabled without pre-configuration, then deployment is simplified, but secure communication cannot be established

Engineering Contradiction:
Improvedeployment simplicityVSAvoidsecure communication
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

Cryptographic keys and security parameters are pre-configured in the device during manufacturing or prior deployment. This preliminary action enables the device to immediately establish secure communication upon activation without requiring post-deployment configuration, thus maintaining both deployment simplicity and communication security.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The device autonomously manages its security configuration by automatically exchanging cryptographic parameters with the computing facility upon first connection. This self-service approach eliminates the need for manual pre-configuration while ensuring secure communication is established from the outset, combining deployment simplicity with security reliability.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12362932B2Method for registering a device with a computing facility, communication system and energy supply network
Publication Date: 2025.07.15 SIEMENS AG
  • US12362932B2 patent drawing
  • US12362932B2 patent drawing

AI summary

A method for registering a device with a connected computing facility includes registering the device with the computing facility by using a first encryption method, defining, in the computing facility, a user-specific and device-specific second encryption method based on device identification data and user identification data, and communicating the second encryption method from the computing facility to the device for future communication. A communication system and an energy supply network are also provided.