Safety Control Device Secret Splitting for Industrial Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current IT security mechanisms in industrial environments are complex and require additional trusted parties for secure data transmission and access, which can be computationally expensive and vulnerable to attacks, particularly in scenarios involving multi-party computations.

Innovation Solution

A safety control device comprising a basic control device and a security module that splits a secret into partial secrets, merging them using a calculation rule to achieve a security function without revealing the overall secret, ensuring secure data transmission and access while detecting and responding to potential manipulations or disconnections.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If cryptographic IT security mechanisms are used to protect data transmission and access, then security and integrity are improved, but computational cost and complexity increase

Engineering Contradiction:
Improvedata securityVSAvoidsecurity mechanism complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The secret key is divided into multiple partial secrets distributed across different components (basic control device and security module). Each component holds only a portion, and the complete secret can only be reconstructed when all parts are combined through the calculation rule, preventing any single component from having full access to the cryptographic key.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A trust center acts as an intermediary that facilitates the distribution of partial secrets to multiple devices without revealing the complete secret. The trust center enables secure multi-party computation by coordinating the key distribution process while maintaining the secrecy of the overall cryptographic key.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If multi-party computation is used for secure key distribution, then security is improved, but computational expense increases

Engineering Contradiction:
Improvekey distribution securityVSAvoidcomputational energy
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The computationally intensive key distribution process is segmented into smaller operations performed by different parties. Each device performs local computations on its partial secret rather than participating in full multi-party computation, reducing individual computational burden while maintaining overall security through the distributed nature of the system.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentEP3439228B1Method and devices for achieving a safety function, particularly in the vicinity of a device control and/or system control
Publication Date: 2020.07.29 SIEMENS AG
  • EP3439228B1 patent drawingFigure 1

AI summary

The invention claims a method for achieving a security function for a security control device (E) for controlling a device or system, comprising: a basic control unit (G), wherein the basic control unit is designed and configured such that a device or system connectable to or associated with the basic control unit can be controlled or is controlled by means of the execution of a control program in the basic control unit, and a security module (S), which is designed and configured to provide or execute a cryptographic functionality for the basic control unit, wherein the security module can be connected to or associated with the basic control unit by means of a data connection, comprising the following steps: a) providing at least a first partial secret (KS1), which is stored in the basic control unit,b) Providing at least one second partial secret (KS2) which is stored in the security module, c) Combining the at least one first and second partial secret to achieve the security function, characterized in that the at least one first partial secret is broken down into sub-secrets of a predefinable size and the quantity of sub-secrets is gradually combined with the at least second partial secret by means of a calculation rule which, according to their size and quantity, can be processed within a predefinable time period during the execution of the calculation rule.