Fieldbus Security Coupler for Legacy Nodes and Tamper Blocking

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing fieldbus network protocols lack security mechanisms to protect communication links against external attacks, making them vulnerable, and devices without security functionality cannot ensure secure information exchange.

Innovation Solution

A security device is integrated with a fieldbus system that connects to non-secure fieldbus participants, implementing a predetermined security protocol for authentication, encryption, and decryption, and includes a control mechanism to block operation if disconnected or damaged, ensuring secure communication and tamper protection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If fieldbus network protocols are used for communication, then device compatibility and ease of operation are improved, but communication security deteriorates because the protocols lack security mechanisms

Engineering Contradiction:
Improvedevice compatibilityVSAvoidcommunication security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

A security device is introduced as an intermediary component between fieldbus participants. This security device includes authentication, encryption, and decryption functions that protect communication without requiring modifications to the fieldbus protocols themselves. The security device acts as a mediator that transparently secures data exchanges while maintaining protocol compatibility.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The security functionality is segmented into a separate security device rather than being integrated into each fieldbus participant. This segmentation allows standard fieldbus devices to maintain their simplicity and compatibility while the dedicated security device provides centralized security management through authentication and cryptographic operations.

Inventive Principle:
Principle #1Segmentation

2Reliability

If security mechanisms are added to fieldbus participants, then communication security is improved, but device complexity increases

Engineering Contradiction:
Improvecommunication securityVSAvoiddevice structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The security device serves as an intermediary that offloads all security-related complexity from fieldbus participants. By placing authentication, encryption, and decryption functions in a separate security device, individual fieldbus participants remain simple and unchanged, avoiding the complexity increase that would result from integrating security mechanisms directly into them.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The security device provides self-service security functions by automatically performing authentication, encryption, and decryption operations without requiring complex configurations or management interventions. The device autonomously manages security protocols and cryptographic keys, reducing the operational complexity that would otherwise be required to maintain secure communication.

Inventive Principle:
Principle #25Self-service

3Adaptability or versatility

If fieldbus participants without security functionality are connected to the fieldbus, then system adaptability and ease of operation are improved, but vulnerability to external attacks increases

Engineering Contradiction:
Improvesystem compatibilityVSAvoidvulnerability to attacks
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The security device acts as a protective intermediary between fieldbus participants without native security functionality and the fieldbus network. It intercepts and secures all communications from these vulnerable devices, providing authentication and encryption services that protect them from external attacks while allowing them to remain simple and compatible with the fieldbus system.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The security device provides beforehand cushioning by pre-establishing security measures before communications occur. Authentication is performed in advance to verify device identities, and encryption is applied proactively to all data transmissions, creating a protective buffer that shields vulnerable fieldbus participants from potential attacks before they can exploit any weaknesses.

Inventive Principle:
Principle #11Beforehand cushioning (Prior cushioning)

Data Source

PatentEP3559854B1Security device and field bus system for supporting secure communication by means of a field bus
Publication Date: 2021.07.21 PHOENIX CONTACT GMBH & CO KG
  • EP3559854B1 patent drawingFigure 1
  • EP3559854B1 patent drawingFigure 2
  • EP3559854B1 patent drawingFigure 3

AI summary

The invention relates, inter alia, to a security device (20; 120) for supporting secure communication by means of a field bus (60). The security device (20; 120) has a connection apparatus (10; 121) for directly coupling the security device (20; 120) to a network interface (31; 81) of a field bus subscriber (30; 80), which field bus subscriber is not designed for secure communication by means of the field bus, said network interface (31; 81) being designed for connecting to a field bus (60). In the coupled state, there is a connection between the security device (20; 120) and the field bus subscriber (30) in such a way that, if the coupling is disconnected or damaged, the proper operation of the security device (20; 120) is reversibly or irreversibly blocked. Furthermore, a transmitting and receiving apparatus (24; 123) is provided, which is designed to transfer, securely by means of the field bus in accordance with a predefined security protocol, data coming from a directly coupled field bus subscriber (30) that is not designed for secure communication and which is also designed to receive data transferred by means of the field bus (60) in accordance with the predefined security protocol and intended for the field bus subscriber (30) and to transfer said data to the field bus subscriber.