Secure Interface Partitioning in Industrial Electrical Units

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Industrial electrical devices face vulnerabilities in secure communication systems, allowing manipulation of information transmitted via insecure interfaces, which can compromise the integrity of the devices and other facilities in industrial plants.

Innovation Solution

The electrical device is divided into secure and insecure functional blocks with dedicated transmission paths, where the first interface handles secure communication from the secure block to the insecure block, and the second interface handles insecure communication from the insecure block to the secure block, with the ability to activate and deactivate the second transmission device to prevent manipulation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If both secure and insecure interfaces are implemented in the same functional unit, then communication versatility is improved, but information security deteriorates due to vulnerability to manipulation

Engineering Contradiction:
Improvecommunication versatilityVSAvoidinformation security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The functional unit is divided into a secure functional block and an insecure functional block, with each block having its own dedicated transmission device. The first transmission device handles secure communication exclusively, while the second transmission device handles insecure communication exclusively. This segmentation prevents manipulation from the insecure block from affecting the secure communication paths.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A functional device acts as an intermediary between the secure and insecure functional blocks. This intermediary controls and monitors the interaction between the two blocks, enabling secure communication while preventing unauthorized manipulation. The intermediary ensures that the secure functional block's operations are not compromised by the insecure block.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If the second transmission device is always active for insecure communication, then communication capability is improved, but susceptibility to manipulation increases

Engineering Contradiction:
Improvecommunication capabilityVSAvoidsusceptibility to manipulation
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The second transmission device is designed to be dynamically controllable, allowing it to be activated or deactivated based on security requirements. When secure communication is prioritized, the second transmission device can be deactivated to eliminate the manipulation vulnerability. When insecure communication is needed, it can be activated temporarily, providing flexible security management.

Inventive Principle:
Principle #15Dynamics

3Reliability

If the functional unit is divided into separate secure and insecure blocks with dedicated transmission paths, then information integrity is improved, but device complexity increases

Engineering Contradiction:
Improveinformation integrityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The functional unit is segmented into distinct secure and insecure functional blocks, each with dedicated transmission devices and paths. This clear segmentation simplifies the security architecture by creating well-defined boundaries and isolation mechanisms, making it easier to manage security requirements while maintaining information integrity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The functional device serving as an intermediary between secure and insecure blocks can perform multiple functions: it manages communication between blocks, controls activation of the second transmission device, and enforces security policies. This multi-functionality reduces the need for additional separate components, thereby managing complexity while maintaining security.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP3244274B1Electric device with a functional unit
Publication Date: 2021.01.27 KROHNE MESSTECHNICK GMBH & CO KG
  • EP3244274B1 patent drawingFigure 1
  • EP3244274B1 patent drawingFigure 2

AI summary

An electrical device (1) with a functional unit (2) is shown and described, wherein the functional unit (2) has a first interface unit (4) for secure communication and a second interface unit (5) for insecure communication. The invention is based on the objective of providing an electrical device (1) in which the manipulation of information transmitted via the first interface unit (4) is at least made more difficult.The problem is solved by dividing the functional unit (2) into a safe functional block (8) and an unsafe functional block (9) and having only one first transmission unit (10), by arranging the first interface unit (4) in the safe functional block (8) and the second interface unit (5) in the unsafe functional block (9), and by designing the first transmission unit (10) to transmit first signals exclusively from the safe functional block (8) via a first signal path (11) to the unsafe functional block (9).