Industrial Device Reconfiguration via Secured Wireless Side Channel

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Industrial devices in processing plants often lose configuration settings, leading to connectivity issues and requiring labor-intensive physical reconfiguration, which is insecure and time-consuming, exposing them to potential cyber attacks.

Innovation Solution

Implementing a compute device with primary and side channel communication circuitry for secure wireless communication, using protocols like Wi-Fi, Bluetooth, or 5G, to obtain and transmit configuration data via a token-based secured communication session, ensuring secure and remote reconfiguration of industrial devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If physical interface (serial/USB) is used for reconfiguration, then device can be reconfigured, but labor intensive process requiring physical travel to device location

Engineering Contradiction:
Improvereconfiguration processVSAvoidtime for physical travel and reconfiguration
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The patent replaces the mechanical physical interface (serial/USB) with a wireless communication system. The compute device uses wireless communication circuitry to transmit configuration data remotely to the industrial device, eliminating the need for physical travel and manual connection to the device location.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent introduces a wireless communication intermediary (compute device with wireless communication circuitry) that acts as a mediator between the operator and the industrial device. This intermediary enables remote configuration by transmitting configuration data through wireless channels, serving as a bridge that eliminates the need for direct physical access.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If physical interface is used for reconfiguration, then device can be reconfigured, but exposes attack surface for cyber attacks

Engineering Contradiction:
Improvereconfiguration capabilityVSAvoidcyber security risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent replaces the physical interface (serial/USB) with a wireless communication system that incorporates security protocols. The wireless communication circuitry transmits configuration data through encrypted channels, eliminating the physical attack surface while maintaining reconfiguration capability.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent changes the communication parameter from physical connection to wireless transmission with security protocols. By modifying the communication method to use encrypted wireless channels with authentication mechanisms, the system maintains reconfiguration capability while reducing security vulnerabilities.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If main channel (network) is used for communication, then device connectivity is maintained, but configuration data may be lost due to memory corruption

Engineering Contradiction:
Improveconfiguration data integrityVSAvoidcommunication system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a side channel communication intermediary that is separate from the main network channel. This intermediary wireless communication path allows configuration data to be transmitted independently of the main network, providing a backup mechanism that protects against memory corruption on the primary channel.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the communication system into two independent channels: the main network channel for normal operations and a separate wireless side channel for configuration data transmission. This segmentation ensures that corruption or failures on the main channel do not affect the integrity of configuration data transmitted through the isolated side channel.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentEP4135260A1Systems and methods for configuring industrial devices through a secured wireless side channel
Publication Date: 2023.02.15 ABB (SCHWEIZ) AG
  • EP4135260A1 patent drawingFigure 1
  • EP4135260A1 patent drawingFigure 2
  • EP4135260A1 patent drawingFigure 3

AI summary

Systems and methods for configuring industrial devices through a secured wireless side channel may include a compute device. The compute device may have primary communication circuitry configured to communicate through a network and side channel communication circuitry configured to communicate through a wireless side channel that is different from the network. The compute device may additionally include circuitry configured to obtain, via the wireless side channel, configuration data indicative of a configuration for one or more operations of an industrial device of an industrial process plant. Additionally the circuitry may be configured to configure, in response to obtaining the configuration data, the one or more operations of the industrial device.