Field Device Module Authentication Using Manufacturer Signatures
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The authenticity of electronic modules in field devices used in automation technology is not reliably verified, posing a significant security risk as unauthorized modules may be used, potentially leading to unsafe conditions in environments like explosive areas.
Innovation Solution
A method that ensures only electronic modules from authorized manufacturers can be used by assigning a key pair to each trustworthy manufacturer, with public keys stored in the field device or a communicating unit, and verifying the manufacturer signature of each module using asymmetric public key cryptography, ensuring the module's authenticity.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If visual inspection is performed to verify electronic module authenticity, then installation can be carried out by qualified service technicians, but the verification is not reliable and safety risks remain
Solution Approach 1:
The patent applies preliminary action by pre-assigning cryptographic key pairs to electronic modules during manufacturing before deployment. The manufacturer's public key is embedded in each module along with a digital signature, enabling automatic authenticity verification at installation time without requiring complex manual inspection procedures. This resolves the contradiction by making verification reliable through pre-configured cryptographic credentials while keeping the verification process itself simple.
Solution Approach 2:
The patent replaces the mechanical/visual inspection system with a cryptographic verification system. Instead of relying on service technicians to visually inspect modules, the system uses automated cryptographic verification of digital signatures and public keys. This substitution provides reliable authenticity verification while actually reducing operational complexity, as the automated cryptographic check is simpler than trained visual inspection.
2Reliability
If no verification is performed on electronic modules, then installation is simple and quick, but unauthorized modules may be used leading to safety hazards
Solution Approach 1:
The patent applies preliminary action by pre-configuring electronic modules with cryptographic credentials (public keys and digital signatures) during manufacturing. This allows for rapid automated verification at installation time without requiring complex manual safety checks. The safety assurance is achieved through this pre-prepared cryptographic infrastructure, while installation remains easy because the verification process is automated and requires minimal user intervention.
Solution Approach 2:
The patent implements self-service by enabling the field device to automatically verify module authenticity using the manufacturer's public key and digital signature embedded in each module. The system performs its own verification without requiring external validation or complex manual procedures. This resolves the contradiction by providing robust safety assurance through automated self-verification while keeping installation simple and quick.
3Reliability
If cryptographic verification is implemented for all electronic modules, then only authorized modules can be used, but the verification process becomes more complex
Solution Approach 1:
The patent applies preliminary action by pre-assigning cryptographic key pairs to manufacturers and embedding their public keys in the field device before deployment. Electronic modules are pre-signed with manufacturer private keys during manufacturing. This preliminary cryptographic setup enables simple verification processes later, as the field device only needs to check signatures against pre-stored public keys. This resolves the contradiction by making the verification process itself simple through advance preparation, while maintaining high reliability.
Solution Approach 2:
The patent implements a universal cryptographic verification mechanism that can be applied to all electronic modules regardless of type or manufacturer. The same verification process (checking digital signature against manufacturer's public key) works for all modules, simplifying the verification process through standardization. This universal approach maintains high reliability while reducing complexity by eliminating the need for different verification procedures for different module types.
Applied Scientific Principles
This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.
Function Achieved in This Case
This method effectively prevents the use of unauthorized electronic modules by verifying the manufacturer's trustworthiness and authenticity, ensuring safety and compliance with safety regulations in automation technology.
Implementation Method 1
each trusted manufacturer of an electronic module of the field device is assigned a key pair consisting of a public key and a private key... the manufacturer signature involves encrypting the public key of the electronic module with the private key of the authorized manufacturer
Data Source
Figure 1~2
Figure 3
Figure 4
AI summary
The invention relates to a method for verifying the origin of electronic modules (Mk with k = 1, 2 ... n) of a modularly constructed field device (FG) for automation technology, wherein each manufacturer of an electronic module (Mk) of the field device (FG) classified as trusted is assigned a key pair (Vm, vm with m = 1, ... l) consisting of a public key (Vm) and a private key (vm), and wherein the public keys (Vm) of the manufacturers classified as trusted are stored in a list (PTL) in the field device (FG) or in a unit communicating with the field device (FG), wherein each electronic module (Mk) of the field device (FG) contains, in addition to a suitable key pair (Pk, pk with k = 1, 2 ... n) identifying the electronic module (Mk) as trusted, consisting of a public key (Pk) and a private key (pk), the manufacturer's public key (Vm) and a manufacturer signature (vm(Pk)).wherein the manufacturer signature (vm(Pk)) confirms the public key (Pk) of the electronic module (Mk) as trusted, the procedure comprising the following steps: - when exchanging or adding an electronic module (Mk), the field device (FG) or the unit (U) communicating with the field device (FG) verifies: - whether the exchanged or added electronic module (Mk) has a key pair (Pk, pk) and a manufacturer signature (vm(Pk)), - whether the manufacturer's public key (Vm) of the electronic module (Mk) is listed in the Public Key List (PTL) of trusted manufacturers, - whether the manufacturer signature (vm(Pk)) matches the manufacturer and the electronic module (Mk), i.e., whether the electronic module (Mk) actually originates from the trusted manufacturer, and - whether the electronic module (Mk) possesses the correct private key (pk).Communication or interaction between the replaced or added electronic module (Mk) and the field device (FG) or another electronic module (Mk) relating to the functionality of the field device (FG) is permitted if the verification is completed with a positive result.