Field Security Device Authentication for Traffic Control Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traffic management systems are vulnerable to security breaches and unauthorized access, posing risks to public safety and system integrity due to the use of Ethernet and Internet protocols for communication between traffic management centers and controllers.

Innovation Solution

A field security device and authentication server system that establishes a secure private network between traffic controllers and management centers using device identifiers based on user-configurable and non-user-configurable parameters, ensuring only authorized devices can access the network, thereby preventing unauthorized access and cyber threats.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of manufacture

If Ethernet and Internet protocols are used for communication between traffic management centers and controllers, then communication cost is reduced and interoperability is improved, but system security is compromised and vulnerability to attacks increases

Engineering Contradiction:
Improvecommunication costVSAvoidsystem security
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

A security gateway device is introduced as an intermediary component between the traffic controllers and the traffic management center. This gateway terminates the Ethernet connection from controllers and provides authentication, encryption, and security filtering before allowing access to the IP-based management network, thus maintaining low-cost Ethernet communication while adding necessary security layers

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The network architecture is segmented into distinct security zones: a controller access network using Ethernet/IP protocols, a security gateway layer for authentication and protocol translation, and a protected management network for TMC operations. This segmentation allows cost-effective Ethernet communication in the access layer while isolating the management network from direct exposure to internet protocols and attacks

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If wireless communication protocols are used for communicating with TMCs and traffic controllers, then deployment flexibility and cost-effectiveness are improved, but security vulnerabilities and susceptibility to unauthorized access increase

Engineering Contradiction:
Improvedeployment flexibilityVSAvoidsecurity vulnerabilities
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

Authentication and security credentials are pre-configured in the security gateway and controller devices before deployment. The system performs preliminary authentication checks and establishes secure communication channels before allowing any data transmission, preventing unauthorized wireless access from the outset

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system dynamically changes communication parameters including encryption keys, authentication tokens, and session identifiers for each wireless connection. This parameter variation ensures that even if one wireless session is compromised, other sessions remain secure, addressing the inherent vulnerabilities of wireless communication while maintaining deployment flexibility

Inventive Principle:
Principle #35Parameter changes

3Reliability

If centralized authentication and secure private network establishment are implemented, then system security and protection from attacks are improved, but device complexity and implementation requirements increase

Engineering Contradiction:
Improvesystem securityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The security gateway automatically performs authentication, generates session keys, establishes secure private networks, and manages cryptographic operations without requiring manual configuration or intervention. This self-service capability handles the complexity internally while presenting a simple interface to operators, reducing the perceived device complexity despite enhanced security functions

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS8812701B2Device and method for secured communication
Publication Date: 2014.08.19 UNILOC 2017 LLC
  • US8812701B2 patent drawing
  • US8812701B2 patent drawing
  • US8812701B2 patent drawing

AI summary

Devices and methods are provided for securing communication between a traffic management center (TMC) and a traffic controller via utilization of a field security device. In one embodiment, the field security device transmits a device identifier to the TMC upon being powered up or connected to the traffic controller. The device identifier is generally based on a combination of user-configurable and non-user-configurable parameters of the field security device. In response to the TMC authenticating the device identifier, the field security device establishes a secure private network (SPN) between the field security device and the TMC.