Protective Device for Secure Data Transmission in Automation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing data transmission technologies in automation systems are not adequately protected against manipulation and eavesdropping, especially in closed networks, due to high installation and configuration costs, and the need for external security devices.
Innovation Solution
A protective device comprising two mutually associated cryptographic units with equivalently configured cryptographic functions, which can be connected directly to data transmission devices, providing secure data transmission without the need for external or internal security configurations, using symmetric keys for encryption and decryption, and optionally displaying status signals for secure connection establishment.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If remote security devices such as firewalls or gateways are placed upstream of the device to protect data communication, then data transmission security is improved, but device complexity and installation cost increase
Solution Approach 1:
The patent combines the cryptographic protection function directly into the protective device (connector) itself, merging security functionality with the physical connection interface. This eliminates the need for separate remote security devices like firewalls or gateways, thereby maintaining data transmission security while reducing installation complexity and cost.
Solution Approach 2:
The protective device acts as an intermediary component between the data transmission device and the network cable. It provides cryptographic protection at the connection point without requiring external security infrastructure, thus improving security while avoiding the complexity of remote security devices.
2Reliability
If cryptographic protection is implemented on devices themselves, then data transmission security is improved, but configuration effort and cost increase
Solution Approach 1:
The cryptographic functions are pre-configured in the protective devices during manufacturing. Each protective device contains pre-loaded cryptographic keys and algorithms, so no configuration is needed at the site of installation. This maintains high security while eliminating configuration effort and cost.
Solution Approach 2:
The protective devices automatically perform cryptographic protection without requiring user configuration or intervention. The devices self-configure through automatic key exchange and establishment of secure communication channels, thereby maintaining security while minimizing configuration effort.
3Reliability
If network cabling is protected by lockable system cabinets or factory buildings, then data transmission security is improved, but installation cost and complexity increase
Solution Approach 1:
The patent extracts the security function from the physical infrastructure (lockable cabinets or buildings) and relocates it to the protective devices at the connection points. This maintains network cabling security while eliminating the need for complex physical protection structures, thereby reducing installation cost and complexity.
4Reliability
If VPN boxes are used to set up virtual private network connections, then data transmission security is improved, but configuration complexity increases
Solution Approach 1:
The protective devices automatically establish secure communication channels through pre-configured cryptographic functions and automatic key exchange. This eliminates the need for manual VPN box configuration, thereby maintaining data transmission security while reducing configuration complexity to zero.
Data Source
Figure 1~2
Figure 3~4
AI summary
Network cabling device and protective device (10) for the protected transmission of data, comprising at least two mutually associated protective devices (20, 30), each of which can be connected to one end of a data transmission device (40), wherein each protective device (20, 30) has: - a first interface (22, 32) for connecting to the data transmission device, - a second interface (23, 33) for connecting to a device, and - a crypto unit (21, 31) which has a cryptographic function configured equivalently on each of the associated protective devices (20, 30) and cryptographically protects the data to be transmitted.