Gateway Signature Verification for Reliable Automation Device Addressing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Automation systems with central hardware executing multiple control processes face challenges in ensuring correct and reliable addressing of automation devices, particularly in hyper-convergent infrastructures, due to limited address space and organizational overhead of existing safety-related communication protocols.

Innovation Solution

The implementation of a device-specific identifier, such as a 64-bit number, is used to sign data telegrams, allowing verification of correct addressing and eliminating address ambiguity, with a processing facility acting as a gateway to adapt and verify data telegrams between device and communication networks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If safety-related communication protocols use codenames for addressing, then addressing reliability is improved, but organizational overhead and device complexity increase

Engineering Contradiction:
Improveaddressing reliabilityVSAvoidorganizational overhead
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the security function from the addressing mechanism itself and places it in a separate cryptographic layer. Instead of embedding security logic within the addressing protocol, it uses digital signatures that can be verified independently, thereby reducing the complexity of the addressing system while maintaining reliability.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces digital signatures as an intermediary mechanism between the control apparatus and automation devices. This intermediary provides a standardized, mathematically-based verification method that reduces organizational overhead compared to manual codename management while ensuring addressing reliability through cryptographic verification.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If control processes are consolidated on central hardware, then system uniformity and maintenance ease are improved, but addressing verification complexity increases

Engineering Contradiction:
Improvesystem uniformityVSAvoidaddressing verification complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the verification process into distinct cryptographic operations performed by separate processing facilities. Each control process on the central hardware has its own processing facility that independently verifies digital signatures, distributing the verification complexity across multiple independent units rather than concentrating it in a single complex verification system.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent changes the parameter of verification from manual or protocol-based checking to cryptographic signature verification. This parameter change transforms the verification process into a standardized mathematical operation that can be efficiently performed on central hardware, reducing the effective complexity despite the consolidated architecture.

Inventive Principle:
Principle #35Parameter changes

3Adaptability or versatility

If 32-bit codenames are used for device identification, then addressing capability is provided, but address space is limited

Engineering Contradiction:
Improveaddressing capabilityVSAvoidaddress space
Core Design Contradiction:
Adaptability or versatilityVSQuantity of substance

Solution Approach 1:

The patent transitions from using codenames in the traditional addressing dimension to using digital signatures in a cryptographic dimension. This dimensional change allows for effectively unlimited address space, as digital signatures can accommodate arbitrarily large device identifiers without the 32-bit limitation of traditional codenames, while maintaining addressing capability through signature-based identification.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS20240019846A1Apparatus, Automation System and Method for Coupling a Device Network and a Communication Network
Publication Date: 2024.01.18 SIEMENS AG
  • US20240019846A1 patent drawing
  • US20240019846A1 patent drawing
  • US20240019846A1 patent drawing

AI summary

Automation system, apparatus and method for coupling a device network and a communication network, wherein the system verifies addressing of components in an automation system having a hyper-convergent infrastructure, where a gateway extends data telegrams to include a device-specific signature if such a signature cannot be implemented by the automation device of the automation system itself.