Secure Gateway Memory for Internet Access to Industrial Data

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Industrial devices with hardware-related communication protocols, lacking full OSI layer support and security features, pose security risks when integrated into service-oriented architectures, especially when accessed by third parties, and existing solutions fail to securely integrate these devices into Internet-enabled systems.

Innovation Solution

A device with a security controller and secure memory that manages communication via both web-enabled and hardware-related interfaces, using certificates for authentication and encryption, ensuring secure data access and preventing direct connections to data-generating units, with access authorization defined by certificates stored in the secure memory.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If devices with hardware-level communication protocols are integrated into service-oriented architectures with web-enabled interfaces, then adaptability and Internet connectivity are improved, but security vulnerabilities and exposure to hacking attacks increase

Engineering Contradiction:
ImproveInternet connectivityVSAvoidsecurity vulnerabilities
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a gateway device as an intermediary between data-generating units with hardware-level protocols and the web-enabled network. The gateway terminates web connections and establishes separate connections to data-generating units, preventing direct exposure of industrial devices to Internet risks while enabling Internet connectivity through the intermediary gateway.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system is segmented into distinct functional components: data-generating units with hardware-level protocols, a gateway with web-enabled interfaces and secure memory, and remote communication units. This segmentation isolates vulnerable industrial devices from direct Internet exposure while maintaining connectivity through the segmented gateway architecture.

Inventive Principle:
Principle #1Segmentation

2Ease of operation

If open ports are configured for incoming communication to enable remote data retrieval, then ease of operation and remote access are improved, but security risks and vulnerability to attacks increase

Engineering Contradiction:
Improveremote data retrievalVSAvoidsecurity risks
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The gateway acts as an intermediary that receives web-enabled connections on open ports and forwards authenticated requests to data-generating units through hardware-level interfaces. This allows remote data retrieval with open ports configured while the gateway mediates security, preventing direct access to industrial devices.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The gateway performs preliminary authentication and connection establishment before forwarding requests to data-generating units. Certificates are verified and connections are secured in advance, so that when remote data retrieval is initiated, the security framework is already in place, enabling ease of operation without exposing security risks.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If certificates are stored on end devices for secure communication, then reliability of encrypted connections is improved, but device complexity and security management burden increase

Engineering Contradiction:
Improveencrypted connectionVSAvoidcertificate management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Multiple certificates for different data-generating units are merged and stored centrally in the gateway's secure memory. This consolidation maintains reliable encrypted connections for multiple devices while reducing overall system complexity, as certificates are managed from a central location rather than distributed across numerous individual devices.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The gateway's secure memory provides universal certificate storage and management functionality for multiple data-generating units. This multi-functional certificate management system serves all connected devices through a single centralized repository, improving reliability of encrypted connections while avoiding the complexity of individual certificate management at each device.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Speed

If direct connections are established between remote communication units and data-generating units, then speed of data access is improved, but security exposure and vulnerability to attacks increase

Engineering Contradiction:
Improvedata accessVSAvoidsecurity exposure
Core Design Contradiction:
SpeedVSObject-affected harmful factors

Solution Approach 1:

The gateway serves as a necessary intermediary that all communication must pass through. While this adds a routing step compared to direct connections, the gateway optimizes data access speed while simultaneously providing security protection, achieving a balance where speed is maintained through efficient gateway processing but security exposure is eliminated by preventing direct device-to-device connections.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP3129888B2Transmission of data out of a secured storage
Publication Date: 2023.02.22 AVL LIST GMBH
  • EP3129888B2 patent drawingFigure 1
  • EP3129888B2 patent drawingFigure 2
  • EP3129888B2 patent drawingFigure 3

AI summary

The invention relates to an apparatus (1) for transmitting data between at least one data-generating unit (2a-f) and a remote communication unit (5a-5c). The apparatus (1) has at least one interface (6a-6d) for a web-compatible communication protocol for secure communication with the remote communication unit (5a-c) via a nonproprietary and preferably publicly accessible network (7) and at least one interface (8a-i) for a hardware-level communication protocol for communication with the data-generating unit (2a-f). In addition, the apparatus has a security controller (9) that is capable of controlling the communication via the web-compatible interface(s) (6a-6d) and via the hardware-level interface(s) (8a-8i), wherein the security controller (9) has an associated secure memory (10) that has defined memory areas (A, B, C, D). At least one memory area (A, B, C, D) has at least one associated certificate (a, b, c).