Secure Data Transmission in Open Automation Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current automation systems face challenges in ensuring secure communication within open networks, particularly in environments independent of master/slave, client/server, and producer/consumer architectures, where secure communication protocols are not standardized, leading to inefficiencies and increased configuration and performance efforts.
Innovation Solution
A method and network system that enables secure data transmission between secure producers and consumers using identifiable secure data, where data is written to and read from a data memory, allowing for secure communication even in non-secure data memories, such as those from non-secure servers, with the secure producer generating and the consumer verifying data integrity through identification and timestamps.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If secure communication protocols are used in open networks independent of master/slave, client/server, and producer/consumer architectures, then communication flexibility and adaptability are improved, but configuration effort and system complexity increase due to lack of standardization
Solution Approach 1:
The patent segments the communication system into independent publish-subscribe components that operate without fixed architectural relationships. Each component can independently publish or subscribe to security messages, eliminating the need for complex centralized configuration and enabling flexible adaptation to different network topologies and security requirements.
Solution Approach 2:
The patent creates a universal publish-subscribe mechanism that functions across diverse network architectures (master/slave, client/server, producer/consumer) without requiring architecture-specific configuration. The same subscription mechanism handles security messages regardless of the underlying network structure, reducing configuration complexity while maintaining broad adaptability.
2Adaptability or versatility
If decentralized system components communicate without fixed producer-consumer assignments, then system adaptability and flexibility are improved, but data integrity verification becomes more difficult
Solution Approach 1:
The patent implements feedback mechanisms where subscribers verify data integrity through cryptographic validation of security messages. Each received message is verified against subscription criteria and authentication data, providing continuous integrity checking that maintains reliability despite the absence of fixed producer-consumer relationships.
Solution Approach 2:
The patent introduces an intermediary subscription mechanism that mediates between decentralized publishers and subscribers. This intermediary layer handles authentication, authorization, and integrity verification, allowing flexible decentralized communication while maintaining reliable data validation through standardized subscription processes.
3Ease of operation
If standard network protocols are used for secure data transmission, then ease of operation is improved, but security against transmission errors and unauthorized access may be compromised
Solution Approach 1:
The patent creates a composite communication system that combines standard network protocols for ease of operation with additional security layers (authentication, authorization, cryptographic validation) for reliability. The publish-subscribe mechanism integrates both standard and security-specific functions, allowing the system to operate using familiar protocols while maintaining robust security through composite architectural elements.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
The invention relates to data transmission between at least one safe producer and at least one safe consumer, wherein this safe producer is a network subscriber that is connected to a first network infrastructure, and the safe receiver is a network subscriber that may be connected to the first network infrastructure or to a second network infrastructure. The invention provides for the following: generation of secure data for at least one of these safe consumers by the safe producer, write access to a data memory and writing of these generated data, specifically so as to be identifiable as such, to the data memory, and/or consumption of secure data from at least one safe producer by at least one of these safe consumers, wherein a data memory is accessed, specifically at least read accessed, to which data that are intended for this at least one of these safe consumers are written so as to be identifiable as such, and wherein the data that are written thereto so as to be identifiable as data intended for this at least one safe consumer are read.