Remote Query Interface for Safety Control Signal Isolation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing security systems face challenges in allowing remote querying of data from control devices while preventing manipulation and ensuring the integrity of query commands, particularly in safety-critical applications like railway technology where high safety standards are mandatory.
Innovation Solution
An interface device is connected to the control device, featuring a test device that checks received remote query signals for permissible interrogation commands and only forwards those, blocking other control commands, ensuring the control device is protected from direct access. This interface device can have multiple stages with different transmission protocols and includes a data diode for unidirectional data transmission, and a signature memory for validating software updates.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If remote querying is enabled to allow external access to system data, then data accessibility and monitoring capability are improved, but system security and protection against unauthorized manipulation deteriorate
Solution Approach 1:
An interface device is introduced as an intermediary component between the external remote query device and the control device. This interface device receives query signals from external devices, validates them against stored admissible query commands, and only forwards validated commands to the control device. This mediator architecture enables remote querying while protecting the control device from direct external access and potential manipulation.
2Adaptability or versatility
If direct external access to control device is permitted for remote querying, then operational flexibility and remote monitoring are improved, but protection against unauthorized control signals deteriorates
Solution Approach 1:
The interface device performs preliminary validation of incoming query signals before they reach the control device. By checking whether received query commands match stored admissible query commands in advance, the system prevents unauthorized control signals from ever reaching the control device, thus maintaining operational flexibility while blocking harmful factors beforehand.
3Reliability
If query commands are validated before forwarding to control device, then system security and integrity are improved, but device complexity and processing overhead increase
Solution Approach 1:
The interface device stores copies of admissible query commands in its memory. Instead of implementing complex validation logic, the device simply compares incoming query signals against these pre-stored command copies. This copying approach enables reliable query validation while keeping the interface device structure relatively simple and avoiding excessive processing overhead.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
The invention relates, inter alia, to an arrangement having a technical system (10), in particular a safety-related system (10), and a control device (20) which controls the system (10) and can change the technical state of the system (10) by means of control commands (SB). The invention provides for an interface device (30) to be connected to the control device (20), which interface device forms an external interface for connection to an external remote query device (40), wherein the interface device (30) has a checking device (31) which is configured in such a manner that it checks a received remote query signal (FAS(AB)) for the presence of a query command (AB) stored as permissible in the interface device (30) and, in the event of permissibility, forwards only the query command (AB) to the control device (20) and blocks the forwarding of the remote query signal (FAS(AB)) as such or all other control commands which are not query commands (AB) stored as permissible.