Industrial AI Module Two-Stage Decryption for Secure Controller Use

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing industrial automation systems face challenges in securely protecting AI data sets from unauthorized access and cyber attacks while ensuring legitimate use and licensing of AI models and algorithms.

Innovation Solution

A two-stage decryption method is implemented using cryptographic key pairs, where the AI data set is encrypted on an independent AI module with a separate processor, and the decryption keys are distributed in encrypted form, ensuring access only through interaction with the industrial controller, coupled with a hardware-specific token verification.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If AI data sets are stored on memory cards for easy access, then ease of operation is improved, but security protection deteriorates due to unauthorized access risk

Engineering Contradiction:
Improveaccess to AI data setVSAvoidunauthorized access
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The decryption key is segmented into two parts: a first decryption key stored in the AI module and a second decryption key stored in the industrial controller. Both keys are required to decrypt the AI data set, preventing unauthorized access while maintaining operational ease through automated key management.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A cryptographic module acts as an intermediary between the AI module and the industrial controller, facilitating secure key exchange and data decryption. The cryptographic module verifies authentication information and enables secure communication without requiring direct trust between components.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If cryptographic protection mechanisms like TPMs or USB dongles are used, then security protection is improved, but device complexity increases

Engineering Contradiction:
Improveunauthorized accessVSAvoidcryptographic mechanism
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The industrial controller's existing cryptographic module is utilized for multiple purposes: storing the second decryption key, verifying authentication information from the AI module, and enabling secure data decryption. This eliminates the need for separate security hardware like TPMs or USB dongles.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system uses built-in cryptographic capabilities already present in the industrial controller and AI module to provide security functions. The cryptographic module serves itself by using the controller's existing hardware resources rather than requiring external security devices.

Inventive Principle:
Principle #25Self-service

3Device complexity

If AI module is integrated into industrial controller, then device complexity is reduced, but security protection deteriorates due to shared processor vulnerability

Engineering Contradiction:
Improveprocessor integrationVSAvoidcyber attacks
Core Design Contradiction:
Device complexityVSObject-affected harmful factors

Solution Approach 1:

The decryption process is segmented into two independent parts stored in different locations: the first decryption key in the AI module and the second decryption key in the industrial controller. This segmentation ensures that even if one component is compromised, the other retains security capability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Security protection is added as a new dimension to the integrated architecture by introducing cryptographic key separation. The AI module and industrial controller maintain functional integration while being protected through distributed cryptographic storage, creating a multi-layered security approach.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS12634131B2AI module and method for securely operating an industrial control device
Publication Date: 2026.05.19 SIEMENS AG
  • US12634131B2 patent drawing
  • US12634131B2 patent drawing
  • US12634131B2 patent drawing

AI summary

A method for securely operating an industrial control device together with an AI module for processing at least one AI data set via a two-stage decryption method.