Redundant Encryption Links for Secure Supervisory Control Data

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Supervisory Control Systems (SCS) such as CAN Bus, SCADA, and IoT lack effective security measures to prevent hacking, ensure real-time data integrity, and maintain low-cost, low-complexity operations, particularly in critical applications where timely and secure data delivery is essential.

Innovation Solution

Implementing redundant message delivery using symmetrical encryption methods like SPECK or SIMON, which encrypt messages and transmit them in duplicate over multiple physical or logical links, ensuring precise and tamper-free data delivery without requiring significant processing power or redesign of existing systems.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional encryption methods are used in SCS, then security is improved, but processing power requirements and system complexity increase

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the encryption process into two distinct phases: a first encryption operation performed by the sensor node with limited processing power, and a second encryption operation performed by the gateway device with greater processing power. This segmentation allows the sensor node to use simpler encryption while the gateway handles more complex encryption, resolving the contradiction between security requirements and the processing constraints of resource-limited devices.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The gateway device acts as an intermediary between the sensor node and the central server. It receives encrypted data from the sensor node, performs additional encryption operations, and then forwards the doubly-encrypted data to the server. This intermediary approach enables enhanced security through multiple encryption layers without requiring the sensor node itself to handle complex encryption operations.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If redundant message delivery is implemented, then data integrity is improved, but network bandwidth and transmission time increase

Engineering Contradiction:
Improvedata integrityVSAvoidtransmission time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements preliminary action by having the gateway device perform the second encryption operation and validation checks before data is transmitted to the central server. This advance processing ensures data integrity is verified and enhanced encryption is applied prior to transmission, reducing the need for retransmissions and validation checks at the server端, thereby minimizing overall transmission time despite the additional encryption step.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11741243B1Method for using redundant encryption to secure data in supervisory control systems
Publication Date: 2023.08.29 MATSUMOTO SUMITAKA
  • US11741243B1 patent drawing
  • US11741243B1 patent drawing
  • US11741243B1 patent drawing

AI summary

The invention described herein addresses the security shortcomings in existing Supervisory Control Systems (SCS), inclusive of but not limited to CAN Bus, SCADA, DCS, HEMS and IoT. The invention references U.S. Pat. No. 10,367,794 B2 Sayers et al., which is improved by the addition of a Validated Transmission data system, a Receiver Validation data system, and redundant links, which may be comprised of but not limited to technologies such as fiberoptics, time division multiplexing, frequency division multiplexing, various radio frequency links inclusive of TDM, OFDM, and CDMA modulation schemes, and a novel scheme for validating transmissions through self-generated tables by network elements.