Secure Data Transmission in Open Automation Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current automation systems face challenges in ensuring secure communication within open networks, particularly in environments independent of master/slave, client/server, and producer/consumer architectures, where secure communication protocols are not standardized, leading to inefficiencies and increased configuration and performance efforts.

Innovation Solution

A method and network system that enables secure data transmission between secure producers and consumers using identifiable secure data, where data is written to and read from a data memory, allowing for secure communication even in non-secure data memories, such as those from non-secure servers, with the secure producer generating and the consumer verifying data integrity through identification and timestamps.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If secure communication protocols are used in open networks independent of master/slave, client/server, and producer/consumer architectures, then communication flexibility and adaptability are improved, but configuration effort and system complexity increase due to lack of standardization

Engineering Contradiction:
Improvecommunication flexibilityVSAvoidconfiguration effort
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the communication system into independent publish-subscribe components that operate without fixed architectural relationships. Each component can independently publish or subscribe to security messages, eliminating the need for complex centralized configuration and enabling flexible adaptation to different network topologies and security requirements.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent creates a universal publish-subscribe mechanism that functions across diverse network architectures (master/slave, client/server, producer/consumer) without requiring architecture-specific configuration. The same subscription mechanism handles security messages regardless of the underlying network structure, reducing configuration complexity while maintaining broad adaptability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If decentralized system components communicate without fixed producer-consumer assignments, then system adaptability and flexibility are improved, but data integrity verification becomes more difficult

Engineering Contradiction:
Improvesystem flexibilityVSAvoiddata integrity verification
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent implements feedback mechanisms where subscribers verify data integrity through cryptographic validation of security messages. Each received message is verified against subscription criteria and authentication data, providing continuous integrity checking that maintains reliability despite the absence of fixed producer-consumer relationships.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent introduces an intermediary subscription mechanism that mediates between decentralized publishers and subscribers. This intermediary layer handles authentication, authorization, and integrity verification, allowing flexible decentralized communication while maintaining reliable data validation through standardized subscription processes.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If standard network protocols are used for secure data transmission, then ease of operation is improved, but security against transmission errors and unauthorized access may be compromised

Engineering Contradiction:
Improveease of useVSAvoidsecurity against errors and unauthorized access
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent creates a composite communication system that combines standard network protocols for ease of operation with additional security layers (authentication, authorization, cryptographic validation) for reliability. The publish-subscribe mechanism integrates both standard and security-specific functions, allowing the system to operate using familiar protocols while maintaining robust security through composite architectural elements.

Inventive Principle:
Principle #40Composite materials

Data Source

PatentEP3189645B1Data transmission between at least one safe producer and at least one safe consumer
Publication Date: 2020.05.06 PHOENIX CONTACT GMBH & CO KG
  • EP3189645B1 patent drawingFigure 1
  • EP3189645B1 patent drawingFigure 2
  • EP3189645B1 patent drawingFigure 3

AI summary

The invention relates to data transmission between at least one safe producer and at least one safe consumer, wherein this safe producer is a network subscriber that is connected to a first network infrastructure, and the safe receiver is a network subscriber that may be connected to the first network infrastructure or to a second network infrastructure. The invention provides for the following: generation of secure data for at least one of these safe consumers by the safe producer, write access to a data memory and writing of these generated data, specifically so as to be identifiable as such, to the data memory, and/or consumption of secure data from at least one safe producer by at least one of these safe consumers, wherein a data memory is accessed, specifically at least read accessed, to which data that are intended for this at least one of these safe consumers are written so as to be identifiable as such, and wherein the data that are written thereto so as to be identifiable as data intended for this at least one safe consumer are read.