Gateway Signature Verification for Reliable Automation Device Addressing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Automation systems with central hardware executing multiple control processes face challenges in ensuring correct and reliable addressing of automation devices, particularly in hyper-convergent infrastructures, due to limited address space and organizational overhead of existing safety-related communication protocols.
Innovation Solution
The implementation of a device-specific identifier, such as a 64-bit number, is used to sign data telegrams, allowing verification of correct addressing and eliminating address ambiguity, with a processing facility acting as a gateway to adapt and verify data telegrams between device and communication networks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If safety-related communication protocols use codenames for addressing, then addressing reliability is improved, but organizational overhead and device complexity increase
Solution Approach 1:
The patent extracts the security function from the addressing mechanism itself and places it in a separate cryptographic layer. Instead of embedding security logic within the addressing protocol, it uses digital signatures that can be verified independently, thereby reducing the complexity of the addressing system while maintaining reliability.
Solution Approach 2:
The patent introduces digital signatures as an intermediary mechanism between the control apparatus and automation devices. This intermediary provides a standardized, mathematically-based verification method that reduces organizational overhead compared to manual codename management while ensuring addressing reliability through cryptographic verification.
2Adaptability or versatility
If control processes are consolidated on central hardware, then system uniformity and maintenance ease are improved, but addressing verification complexity increases
Solution Approach 1:
The patent segments the verification process into distinct cryptographic operations performed by separate processing facilities. Each control process on the central hardware has its own processing facility that independently verifies digital signatures, distributing the verification complexity across multiple independent units rather than concentrating it in a single complex verification system.
Solution Approach 2:
The patent changes the parameter of verification from manual or protocol-based checking to cryptographic signature verification. This parameter change transforms the verification process into a standardized mathematical operation that can be efficiently performed on central hardware, reducing the effective complexity despite the consolidated architecture.
3Adaptability or versatility
If 32-bit codenames are used for device identification, then addressing capability is provided, but address space is limited
Solution Approach 1:
The patent transitions from using codenames in the traditional addressing dimension to using digital signatures in a cryptographic dimension. This dimensional change allows for effectively unlimited address space, as digital signatures can accommodate arbitrarily large device identifiers without the 32-bit limitation of traditional codenames, while maintaining addressing capability through signature-based identification.
Data Source
AI summary
Automation system, apparatus and method for coupling a device network and a communication network, wherein the system verifies addressing of components in an automation system having a hyper-convergent infrastructure, where a gateway extends data telegrams to include a device-specific signature if such a signature cannot be implemented by the automation device of the automation system itself.


