Measurement Data Integrity Verification with Transmitter-Side Cryptography

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for integrity-secured transmission of measurement data are inflexible, require specialized components, and do not protect against intentional data manipulation, especially when using point-to-point connections.

Innovation Solution

Shift the integrity verification process from the receiver to the transmitter, using cryptographic methods to generate and maintain a secured representation of the data on the control device, allowing the receiver to form a confirmation message with less computational intensity, and verify integrity based on this representation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If cryptographic verification is performed on the receiver side using point-to-point connections, then transmission integrity is secured, but device complexity increases and requires specialized components

Engineering Contradiction:
Improvetransmission integrityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent inverts the traditional verification approach by moving the cryptographic verification responsibility from the receiver (auxiliary device) to the transmitter (control device). The control device generates cryptographic hash values and signatures for measurement data, while the auxiliary device simply forwards data and receives verification results. This inversion reduces complexity at the receiver side while maintaining integrity verification.

Inventive Principle:
Principle #13The other way round (Inversion)

Solution Approach 2:

The patent extracts the complex cryptographic verification functions from the auxiliary device and consolidates them in the control device. By separating verification tasks from forwarding tasks, the system reduces device complexity at the receiver while maintaining reliability through centralized cryptographic processing at the source.

Inventive Principle:
Principle #2Taking out (Extraction)

2Reliability

If traditional checksum methods are used for error detection, then transmission errors can be detected, but protection against intentional manipulation is insufficient

Engineering Contradiction:
Improveerror detection capabilityVSAvoidintentional data manipulation
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent changes the cryptographic parameter from simple checksums to cryptographic hash functions and digital signatures. Instead of using basic error-detection codes, the system employs cryptographically secure hash algorithms that provide both error detection and protection against intentional manipulation, significantly enhancing security while maintaining detection capability.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If point-to-point connections with separation of validation and measurement tasks are used, then transmission integrity is verified, but system flexibility and adaptability are reduced

Engineering Contradiction:
Improvetransmission validationVSAvoidsystem flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent makes the control device universal by combining measurement, cryptographic verification, and validation functions in a single system. The control device can serve multiple auxiliary devices simultaneously, performing both measurement tasks and cryptographic verification, eliminating the need for separate validation infrastructure and enhancing system flexibility and adaptability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Applied Scientific Principles

This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.

Function Achieved in This Case

Ensures secure data transmission without the need for specialized components, maintains system flexibility, and protects against intentional data alteration, while reducing computational load on the receiver.

Implementation Method 1

generating and maintaining a cryptographically secured first representation of the measurement data set in the control device (CTR)... the cryptographically secured representation is generated with a cryptographic hash function

Methodology Applied
Scientific EffectCryptographic hash function:

Implementation Method 2

the received cryptographically secured second representation is decrypted by means of a public signature key assignable to the auxiliary device (DSP) before the assignability is checked

Methodology Applied
Scientific EffectPublic key cryptography:

Implementation Method 3

after verification of the integrity of the transmitted measurement data set, the received cryptographically secured second representation is signed with a private signature key assignable to the control device (CTR)

Methodology Applied
Scientific EffectDigital signature:

Data Source

PatentUS20250358131A1Method And Systems For Integrity-Secured Transmission Of At Least One Measurement Data Point
Publication Date: 2025.11.20 SIEMENS AG
  • US20250358131A1 patent drawing
  • US20250358131A1 patent drawing
  • US20250358131A1 patent drawing

AI summary

Some embodiments include methods for integrity-securing transmission of a measurement data point from a control device to an auxiliary device. This transmission is cryptographically unsecured. On the receiver side, the measurement data point is converted into a cryptographically secured representation. The measurement data set is transmitted cryptographically unsecured and then gradually converted into other representations, until finally a cryptographically secured representation is generated, which is checked for assignability to or agreement with a representation stored or retained in the control device CTR. Substantial parts of the processing on the side of the control device CTR can be delayed to a time period in which more computer resources are available than at the time of reception of the confirmation message.