Series Terminal Cryptographic Key Storage for Automation Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing automation systems are vulnerable to external attacks due to the storage of cryptographic keys in the head end, allowing unauthorized access and potential sabotage or manipulation.

Innovation Solution

The automation system incorporates a series terminal with a second processing unit that stores cryptographic keys, allowing the head end to access these keys only for read purposes via the local bus, thereby securing communication and preventing unauthorized access by distributing key management across the system.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If cryptographic keys are stored in the head end for secure communication, then communication security is improved, but the system becomes vulnerable to attacks originating at the head end

Engineering Contradiction:
Improvecommunication securityVSAvoidvulnerability to attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent divides the cryptographic key storage function from the head end and relocates it to distributed series terminals. Each series terminal stores its own cryptographic keys locally in a memory area that is not directly accessible from the head end, thereby segmenting the security-critical storage function across multiple independent components in the automation system.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a series terminal as an intermediary component between the head end and the data bus. The series terminal acts as a mediator that provides read access to cryptographic keys for the head end while preventing direct writing or manipulation of these keys, thus protecting the system against attacks originating at the head end.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If cryptographic keys are stored in series terminals for security, then resistance to head end attacks is improved, but the head end loses direct control over key management

Engineering Contradiction:
Improveresistance to attacksVSAvoidkey management control
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The patent implements a feedback mechanism where the series terminal provides read access to the head end for cryptographic keys stored in its memory area. The head end can query and read the keys as needed for secure communication, while the series terminal maintains ultimate control by preventing any write operations or direct manipulation of the stored keys.

Inventive Principle:
Principle #23Feedback

3Reliability

If cryptographic keys are distributed across series terminals, then system security against sabotage is improved, but the system complexity increases

Engineering Contradiction:
Improveprotection against sabotageVSAvoidkey distribution architecture
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent makes the series terminal a multi-functional component that not only performs its traditional automation functions but also serves as a secure cryptographic key storage unit. By combining data processing and secure key storage in a single component, the patent avoids the need for separate dedicated key storage devices, thereby limiting the increase in overall system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10892909B2Automation system, series terminal for automation systems and associated method
Publication Date: 2021.01.12 WAGO VERW GMBH
  • US10892909B2 patent drawing
  • US10892909B2 patent drawing
  • US10892909B2 patent drawing

AI summary

A series terminal for an automation system, having an insulating housing, which has an electrical contact on at least one side of the housing with which the series terminal can be connected with a data bus of an automation system. The series terminal comprises an integrated electronic processing unit which is connected to the at least one contact device and is designed for transmitting and/or receiving data via the data bus. In this case, the integrated electronic processing unit is set up to query a configuration of the automation system and, based on the configuration, to generate an individual cryptographic key for the automation system in conjunction with a secret cryptographic key stored in the series terminal.