Modular Security Module for Upgradable Field Device Cryptography

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Resource-constrained industrial field devices require specialized security hardware for cryptographic operations and key storage, but existing security modules become outdated and costly to replace due to evolving cybersecurity needs.

Innovation Solution

A modular security solution that provides software and hardware coupling for field devices, enabling secure cryptographic operations, key storage, and identity encapsulation, with the ability to be unlinked and migrated to new devices, allowing for cost-effective upgrades and replacements.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If specialized security hardware is tightly coupled into the field device, then security functions are provided, but the device cannot be upgraded when security requirements evolve

Engineering Contradiction:
Improvesecurity function provisionVSAvoidupgradeability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The security module is separated from the field device into an independent, removable component. This segmentation allows the security module to be replaced or upgraded independently from the main field device, resolving the contradiction between providing reliable security functions and enabling future upgrades when security requirements evolve.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The coupling between the security module and field device is made dynamic rather than static. The software interface allows the security module to be selectively coupled and uncoupled, enabling the system to adapt its security capabilities over time while maintaining operational flexibility.

Inventive Principle:
Principle #15Dynamics

2Adaptability or versatility

If security module is detachable and migratable, then upgradeability is improved, but security risk increases due to potential unauthorized removal

Engineering Contradiction:
ImproveupgradeabilityVSAvoidunauthorized removal risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system implements preliminary protective measures against unauthorized removal through the alert function. Before allowing any removal or migration of the security module, the system detects potential unauthorized actions and triggers alerts to prevent security breaches, thus enabling upgradeability while mitigating security risks.

Inventive Principle:
Principle #9Preliminary anti-action

Solution Approach 2:

The alert function provides feedback when the security module is removed or migrated. This feedback mechanism allows the system to monitor the status of the security module and respond appropriately to unauthorized actions, maintaining security while enabling legitimate upgrades.

Inventive Principle:
Principle #23Feedback

3Adaptability or versatility

If software interface is used for coupling, then flexibility and migration capability are improved, but complexity of interface management increases

Engineering Contradiction:
Improvemigration capabilityVSAvoidinterface management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The software interface is designed with universal coupling capabilities that can work across different field devices and security module versions. This universal design simplifies interface management by providing standardized interaction protocols, reducing the complexity that would otherwise arise from managing multiple specialized interfaces.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP4167115A1Security module for a field device
Publication Date: 2023.04.19 ABB (SCHWEIZ) AG
  • EP4167115A1 patent drawingFigure 1~4
  • EP4167115A1 patent drawing
  • EP4167115A1 patent drawing

AI summary

A security module (10, 21, 30, 40) for a field device (22) for providing security functions, comprising: a software interface (12) configured to provide a software coupling for data communication with the field device (22); a processing unit (11) configured to provide at least one security function via the software interface (12) for the field device (22).