Protective Device for Secure Data Transmission in Automation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data transmission technologies in automation systems are not adequately protected against manipulation and eavesdropping, especially in closed networks, due to high installation and configuration costs, and the need for external security devices.

Innovation Solution

A protective device comprising two mutually associated cryptographic units with equivalently configured cryptographic functions, which can be connected directly to data transmission devices, providing secure data transmission without the need for external or internal security configurations, using symmetric keys for encryption and decryption, and optionally displaying status signals for secure connection establishment.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If remote security devices such as firewalls or gateways are placed upstream of the device to protect data communication, then data transmission security is improved, but device complexity and installation cost increase

Engineering Contradiction:
Improvedata transmission securityVSAvoidinstallation complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines the cryptographic protection function directly into the protective device (connector) itself, merging security functionality with the physical connection interface. This eliminates the need for separate remote security devices like firewalls or gateways, thereby maintaining data transmission security while reducing installation complexity and cost.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The protective device acts as an intermediary component between the data transmission device and the network cable. It provides cryptographic protection at the connection point without requiring external security infrastructure, thus improving security while avoiding the complexity of remote security devices.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If cryptographic protection is implemented on devices themselves, then data transmission security is improved, but configuration effort and cost increase

Engineering Contradiction:
Improvedata transmission securityVSAvoidconfiguration effort
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The cryptographic functions are pre-configured in the protective devices during manufacturing. Each protective device contains pre-loaded cryptographic keys and algorithms, so no configuration is needed at the site of installation. This maintains high security while eliminating configuration effort and cost.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The protective devices automatically perform cryptographic protection without requiring user configuration or intervention. The devices self-configure through automatic key exchange and establishment of secure communication channels, thereby maintaining security while minimizing configuration effort.

Inventive Principle:
Principle #25Self-service

3Reliability

If network cabling is protected by lockable system cabinets or factory buildings, then data transmission security is improved, but installation cost and complexity increase

Engineering Contradiction:
Improvenetwork cabling securityVSAvoidinstallation structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the security function from the physical infrastructure (lockable cabinets or buildings) and relocates it to the protective devices at the connection points. This maintains network cabling security while eliminating the need for complex physical protection structures, thereby reducing installation cost and complexity.

Inventive Principle:
Principle #2Taking out (Extraction)

4Reliability

If VPN boxes are used to set up virtual private network connections, then data transmission security is improved, but configuration complexity increases

Engineering Contradiction:
Improvedata transmission securityVSAvoidconfiguration complexity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The protective devices automatically establish secure communication channels through pre-configured cryptographic functions and automatic key exchange. This eliminates the need for manual VPN box configuration, thereby maintaining data transmission security while reducing configuration complexity to zero.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP3324596B1Protective device and network cabling device for the protected transmission of data
Publication Date: 2020.03.04 SIEMENS AG
  • EP3324596B1 patent drawingFigure 1~2
  • EP3324596B1 patent drawingFigure 3~4

AI summary

Network cabling device and protective device (10) for the protected transmission of data, comprising at least two mutually associated protective devices (20, 30), each of which can be connected to one end of a data transmission device (40), wherein each protective device (20, 30) has: - a first interface (22, 32) for connecting to the data transmission device, - a second interface (23, 33) for connecting to a device, and - a crypto unit (21, 31) which has a cryptographic function configured equivalently on each of the associated protective devices (20, 30) and cryptographically protects the data to be transmitted.