Safety Control Device Secret Splitting for Industrial Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current IT security mechanisms in industrial environments are complex and require additional trusted parties for secure data transmission and access, which can be computationally expensive and vulnerable to attacks, particularly in scenarios involving multi-party computations.
Innovation Solution
A safety control device comprising a basic control device and a security module that splits a secret into partial secrets, merging them using a calculation rule to achieve a security function without revealing the overall secret, ensuring secure data transmission and access while detecting and responding to potential manipulations or disconnections.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If cryptographic IT security mechanisms are used to protect data transmission and access, then security and integrity are improved, but computational cost and complexity increase
Solution Approach 1:
The secret key is divided into multiple partial secrets distributed across different components (basic control device and security module). Each component holds only a portion, and the complete secret can only be reconstructed when all parts are combined through the calculation rule, preventing any single component from having full access to the cryptographic key.
Solution Approach 2:
A trust center acts as an intermediary that facilitates the distribution of partial secrets to multiple devices without revealing the complete secret. The trust center enables secure multi-party computation by coordinating the key distribution process while maintaining the secrecy of the overall cryptographic key.
2Reliability
If multi-party computation is used for secure key distribution, then security is improved, but computational expense increases
Solution Approach 1:
The computationally intensive key distribution process is segmented into smaller operations performed by different parties. Each device performs local computations on its partial secret rather than participating in full multi-party computation, reducing individual computational burden while maintaining overall security through the distributed nature of the system.
Data Source
Figure 1
AI summary
The invention claims a method for achieving a security function for a security control device (E) for controlling a device or system, comprising: a basic control unit (G), wherein the basic control unit is designed and configured such that a device or system connectable to or associated with the basic control unit can be controlled or is controlled by means of the execution of a control program in the basic control unit, and a security module (S), which is designed and configured to provide or execute a cryptographic functionality for the basic control unit, wherein the security module can be connected to or associated with the basic control unit by means of a data connection, comprising the following steps: a) providing at least a first partial secret (KS1), which is stored in the basic control unit,b) Providing at least one second partial secret (KS2) which is stored in the security module, c) Combining the at least one first and second partial secret to achieve the security function, characterized in that the at least one first partial secret is broken down into sub-secrets of a predefinable size and the quantity of sub-secrets is gradually combined with the at least second partial secret by means of a calculation rule which, according to their size and quantity, can be processed within a predefinable time period during the execution of the calculation rule.