Real-Time Integrity Checking for Industrial Fieldbus Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current industrial fieldbus protocols lack effective real-time security measures below the OSI layer 3, which are essential for preventing active manipulation and ensuring the integrity of communication in industrial production and automation systems, especially as they are not compatible with the existing zone models that delay data flow and affect real-time behavior.
Innovation Solution
Implementing a method that provides integrity checking for messages between communication partners using definable filter criteria, forming and correlating integrity reference values at each partner, and issuing warnings or alarms if deviations occur, without altering the communication protocol or affecting real-time performance, through passive security interfaces that monitor and verify message integrity without interfering with the message flow.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If cryptographic security measures are implemented in conventional IT networks using TLS or IPSec, then security and data integrity are improved, but real-time performance deteriorates due to processing overhead
Solution Approach 1:
The patent segments the security functionality into distributed security modules at each network node, rather than using centralized cryptographic processing. Each node independently performs security checks on its incoming and outgoing messages using local security descriptors, eliminating the need for heavy cryptographic operations while maintaining security.
Solution Approach 2:
The patent changes the security verification parameters from cryptographic hash comparisons to simple attribute matching against security descriptors. Instead of computationally intensive cryptographic verification, the system uses lightweight parameter comparison that maintains security while enabling real-time performance.
2Reliability
If zone models are used to protect industrial components, then security is improved through isolation, but real-time behavior deteriorates due to communication delays at zone boundaries
Solution Approach 1:
The patent introduces security descriptors as intermediary elements that mediate security verification without requiring physical or logical zone boundaries. These descriptors contain security attributes that enable automated verification at each node, eliminating the need for zone boundary crossings and associated delays.
Solution Approach 2:
The patent performs security verification in advance by attaching security descriptors to messages before transmission. This preliminary action allows receiving nodes to verify security attributes immediately upon message arrival without requiring additional processing steps or zone boundary crossings.
3Reliability
If cryptographic integrity checks are performed on all messages, then data integrity is improved, but network load increases due to processing overhead
Solution Approach 1:
The patent applies partial action by performing security verification only on messages that require it, based on their security descriptors. Not all messages undergo the same level of verification, allowing the system to maintain data integrity for critical messages while minimizing processing overhead for less critical traffic.
Solution Approach 2:
The patent uses security descriptors as simplified copies or representations of full security credentials. Instead of performing complete cryptographic verification, the system uses these descriptor copies to quickly assess message integrity and security requirements, significantly reducing processing load.
Data Source
Figure 1
AI summary
The invention relates to a device (IA) for integrity checking, which is used to provide secure communication between at least two communication partners (IOC, IOD) inside a communications network capable of operating in real time, particularly in the environment of industrial production and/or automation, said device comprising: a unit for receiving a formed first integrity reference value (I1) for at least one isolated message (m) and/or for receiving at least one formed second integrity reference value (I2) for at least one isolated message; a unit for correlating the first integrity reference value (I1) with the at least second integrity reference value (I2) and for comparing same; and a unit for emitting a warning and/or alarm signal, which is provided for a position initiating corresponding counter-measures when the correlated integrity reference values deviate from each other.