Secure Connection Identification for Dynamic Industrial Data Exchange

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for functionally secure communication in industrial settings, such as PROFIsafe, require permanent configuration of address relationships between communication subscribers, which is inefficient and impractical for dynamic communication scenarios like reconfigurable machines and driverless transport systems, as they necessitate constant monitoring and reconfiguration of unique authentication codes for each potential connection.

Innovation Solution

A method for functionally secure connection identification where the second communication subscriber sends an order number and address identifier in a request message, and the first subscriber responds with safety-related data, address identifiers, and a checksum, allowing unilateral checking by the second subscriber to ensure data integrity, authenticity, and timeliness, eliminating the need for continuous monitoring and reconfiguration.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If permanent configuration of address relationships with unique authentication codes is used for each potential connection, then functional security and connection identification are ensured, but device complexity and configuration effort increase significantly

Engineering Contradiction:
Improvefunctional securityVSAvoidconfiguration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies universality by using a single authentication code that serves multiple connections dynamically. Instead of having unique authentication codes for each potential connection (n·(n−1) codes), one authentication code is shared across multiple connections, and the actual connection identification is achieved through dynamic address identifiers in messages. This reduces the number of authentication codes from O(n²) to O(1), significantly simplifying configuration while maintaining security.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent applies dynamics by making address identifiers changeable rather than fixed. The data requester and data provider dynamically assign and use address identifiers for each communication session. This allows the system to adapt to changing communication relationships without reconfiguring authentication codes, enabling flexible connection management while maintaining security through dynamic identification.

Inventive Principle:
Principle #15Dynamics

2Reliability

If unique authentication codes are assigned for each potential connection between n subscribers, then secure identification of addressing errors is achieved, but the number of authentication codes and monitoring requirements increase to n·(n−1)

Engineering Contradiction:
Improveconnection identification accuracyVSAvoidnumber of authentication codes
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent reduces the quantity of authentication codes by making one authentication code universal across multiple connections. The authentication code no longer needs to be unique per connection but instead works universally with dynamic address identifiers. This reduces the number of authentication codes from n·(n−1) to 1, while connection identification accuracy is maintained through the dynamic address fields in messages.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent extracts the connection identification function from the authentication code. Instead of encoding connection identity within the authentication code itself (requiring unique codes per connection), the authentication code is separated from the identification function. Connection identification is achieved through dedicated address identifier fields in messages, allowing one authentication code to secure multiple connections.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If address relationships are permanently configured, then functional security is maintained, but adaptability to dynamic communication scenarios decreases

Engineering Contradiction:
Improvesecurity assuranceVSAvoidcommunication flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent applies dynamics by making address identifiers changeable rather than fixed. The data requester and data provider can dynamically assign address identifiers for different communication sessions and scenarios. This enables the system to adapt to reconfigurable machines, driverless transport systems, and other dynamic environments while maintaining security through the authentication code and dynamic identification mechanism.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent applies preliminary action by pre-configuring only one authentication code and the basic communication framework, rather than pre-configuring all possible address relationships. The dynamic address identifiers are assigned as needed during operation, allowing the system to be prepared for security requirements while remaining flexible for various communication scenarios without extensive preconfiguration.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11290881B2Method for functionally secure connection identification
Publication Date: 2022.03.29 SIEMENS AG
  • US11290881B2 patent drawing
  • US11290881B2 patent drawing
  • US11290881B2 patent drawing

AI summary

A method for functionally secure connection identification during data exchange between two communication subscribers in a communication system, wherein a first subscriber operates as a data provider with a first address identifier and a second subscriber operates as a data requester with a second address identifier, wherein in a request of safety-related data of the first subscriber in a request message, the second subscriber transmits an order number of the data request and its second address identifier and the first subscriber responds with a response message, the second subscriber subsequently checking to determine whether this message contains (i) a second address identifier of the requesting second subscriber, (ii) an order number of the request message of the second subscriber and (iii) the first address identifier of the requested first subscriber, in the event all checking steps are positive, the safety-related data being accepted and otherwise discarded.