Secure Maintenance Device for CPS Firmware Updates and Cross-Domain Transfer

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cyber-physical systems lack robust security measures for software updates and data transfer, making them vulnerable to cyber threats and requiring expensive perimeter protection solutions.

Innovation Solution

A secure maintenance device (SMD) is introduced to authenticate and establish secure communication channels with CPS devices, ensuring secure software updates, diagnostics, and data transfer through multiple security domains using a cross-domain solution, domain isolation, and encryption.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If rudimentary firmware update processes are used in CPS devices, then ease of operation is improved, but security is worsened

Engineering Contradiction:
Improvefirmware update processVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system performs preliminary authentication and validation actions before allowing firmware updates. The SMD authenticates the CPS device, establishes secure communication channels, and validates firmware integrity before the update process begins, preventing unauthorized or malicious firmware from being installed

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The Secure Maintenance Device (SMD) acts as an intermediary between the authentication service and the CPS device. It manages secure communication channels, handles authentication credentials, and mediates the firmware update process, adding security layers without complicating the user interface

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If open access ports are provided for firmware updates, then ease of operation is improved, but vulnerability to cyber threats is worsened

Engineering Contradiction:
Improveaccessibility for updatesVSAvoidcyber threats
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system applies preliminary anti-action by implementing authentication and encryption measures before the access port is utilized. The SMD establishes secure communication channels and validates credentials before allowing any firmware or data transfer, preventing cyber threats from exploiting open access points

Inventive Principle:
Principle #9Preliminary anti-action

Solution Approach 2:

The SMD serves as a security intermediary that sits between the open access port and the CPS device internals. It controls and monitors all communications through the access port, allowing legitimate operations while blocking malicious activities

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If perimeter protection solutions are implemented, then security is improved, but cost is worsened

Engineering Contradiction:
ImprovesecurityVSAvoidcost
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The solution extracts security functionality from expensive external perimeter protection systems and embeds it directly into the CPS device through the SMD. The authentication service and secure channel management are integrated into the device itself, eliminating the need for costly external security infrastructure

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The CPS device becomes self-service capable in terms of security management. The device can authenticate itself, establish secure channels, and validate firmware updates without requiring expensive external perimeter protection systems, reducing overall security costs

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP3901763B1Systems and methods for secure maintenance device for cyber-physical systems
Publication Date: 2025.08.27 HONEYWELL INTERNATIONAL INC
  • EP3901763B1 patent drawingFigure 1
  • EP3901763B1 patent drawingFigure 2
  • EP3901763B1 patent drawingFigure 3

AI summary

Systems and methods are disclosed for providing a secure and assured method for updating software of a cyber-physical system (CPS) device, maintaining a CPS device, diagnosing a CPS device, and transferring of CPS data. The method may include authenticating a moment a secure maintenance device (SMD) is connected to a first device before a software-based communication is established, establishing a secure communication channel between the SMD and the first device, authenticating a user of the first device and determining access rights of the user using an identity of the first device; transmitting digitally signed updates from the SMD to the first device; receiving, at the SMD, digitally signed first data from the first device, performing diagnostic and maintenance functions at the first device, and exporting data from the first device to the SMD for mobile transfer to another platform.