Network Security Interface Component for IoT Data Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Industrial control systems and IoT devices often lack authentication data, making it difficult to verify the authenticity of sensor data, and are vulnerable to cyber attacks that can compromise data integrity, leading to security and safety risks.

Innovation Solution

A network security interface component with a unidirectional connection and an authentication module that adds authentication data to incoming data from sensors, ensuring data integrity and preventing reverse data transmission, using cryptographic functions like MAC algorithms or digital signatures.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If sensors and data sources are equipped with authentication capabilities, then data authenticity can be verified, but device complexity and cost increase

Engineering Contradiction:
Improvedata authenticityVSAvoidsensor complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary device (gateway or edge computing device) that adds authentication data to sensor readings. This intermediary acts as a mediator between sensors lacking authentication capabilities and the control system requiring authenticated data, thereby resolving the contradiction by providing authentication without modifying the sensors themselves.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The authentication function is segmented from the sensor and placed in a separate intermediary device. This allows the sensor to remain simple while the authentication capability resides in the intermediary, resolving the contradiction between data authenticity and device complexity.

Inventive Principle:
Principle #1Segmentation

2Reliability

If authentication data is added to all data transmissions, then data security is improved, but processing time and computational resources increase

Engineering Contradiction:
Improvedata securityVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

Authentication data is added in advance by the intermediary device before data transmission to the control system. This preliminary action allows the control system to receive pre-authenticated data, reducing processing time at the control system end and improving overall efficiency.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If unidirectional communication is implemented, then protection against cyber attacks is improved, but communication flexibility is reduced

Engineering Contradiction:
Improvecyber attack protectionVSAvoidcommunication flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The intermediary device serves as a trusted mediator that implements unidirectional authentication while maintaining communication flexibility. It can add authentication data to transmissions from sensors to the control system while preventing unauthorized reverse transmissions, thus providing security without completely restricting communication flexibility.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP3732848B1Network security interface component and data transmission method
Publication Date: 2025.07.23 NAGRAVISION SA
  • EP3732848B1 patent drawingFigure 1
  • EP3732848B1 patent drawingFigure 2
  • EP3732848B1 patent drawingFigure 3

AI summary

In overview, disclosed components and methods relate to a network security interface component with a first network interface and a second network interface, separate from the first network interface, connected by a unidirectional connection. The unidirectional connection allows data transfer from the first network interface to the second network interface and prevents data transfer from the second network interface to the first network interface via the unidirectional connection. The network security interface component also includes an authentication module. The authentication module adds authentication data to data received at the first network interface. In this way, a network component is provided in which the first network interface is shielded from the second network interface and in which authentication data can be provided for data received at the first interface, by which the data can subsequently be authenticated as having passed through the network security interface component.