Trustworthy Data Packet Creation for Zero Trust Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data transmission systems lack a comprehensive method to assess the trustworthiness of data sources beyond network segmentation, especially in a Zero Trust security context, leading to potential security vulnerabilities during data exchange across organizational boundaries.

Innovation Solution

A method for creating and storing trustworthy data packets by associating trustworthiness information, determined through integrity checks and cryptographic verification, with the data units, allowing for explicit assessment of the data source's trustworthiness, rather than relying on network zones.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If network segmentation (zones) is used to determine security levels, then data transmission between trusted connectors is simplified, but the security assessment becomes insufficient in Zero Trust contexts where device integrity must be verified

Engineering Contradiction:
Improvedata transmission simplicityVSAvoidsecurity assessment reliability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the trust assessment into multiple independent components: device integrity information, connector trustworthiness, and data origin verification. Each component is evaluated separately through integrity checks and cryptographic verification, allowing comprehensive security assessment without relying on coarse network zone classifications.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent performs preliminary integrity checks and trustworthiness assessments before data transmission occurs. Device integrity information is verified in advance, and trust packets are prepared with cryptographic signatures beforehand, enabling rapid Zero Trust verification during data exchange without compromising security reliability.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If integrity checks and cryptographic verification are performed for every data source, then trustworthiness assessment reliability improves, but system complexity increases

Engineering Contradiction:
Improvetrustworthiness assessment reliabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent creates a universal trust packet structure that can be applied to any data source regardless of network location or device type. The same integrity check and cryptographic verification mechanisms work across diverse sources (files, streams, data units), reducing the need for source-specific complexity while maintaining reliable trustworthiness assessment.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent uses cryptographic signatures and hash values to create verified copies of integrity information. Instead of performing complex real-time verification of entire data sources, the system uses compact cryptographic representations (signatures, hashes) that efficiently prove trustworthiness without requiring proportional system complexity.

Inventive Principle:
Principle #26Copying

3Reliability

If trustworthiness information is stored with every data unit, then data security and traceability improve, but storage requirements and processing overhead increase

Engineering Contradiction:
Improvedata securityVSAvoiddata storage volume
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent stores compact cryptographic representations of trustworthiness information rather than extensive verification data. Hash values and digital signatures serve as concise proofs of integrity and origin, providing high security assurance with minimal storage overhead compared to storing complete device states or verification logs.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent prepares and attaches trust packets with cryptographic signatures in advance of data storage. By computing integrity hashes and generating signatures beforehand, the system minimizes processing overhead during data operations while ensuring security information is readily available for verification when needed.

Inventive Principle:
Principle #10Preliminary action

4Measurement precision

If explicit trustworthiness assessment is implemented instead of network zone classification, then security precision improves, but the complexity of determining trust levels increases

Engineering Contradiction:
Improvetrustworthiness measurement precisionVSAvoidtrust determination complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent replaces manual or policy-based trust determination with automated cryptographic verification. Instead of complex human judgment or intricate policy evaluation, the system uses mathematical proofs (digital signatures, hash verification) to objectively determine trustworthiness, achieving high precision through computational rather than procedural complexity.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent enables data sources to self-verify their trustworthiness through built-in integrity checks and automatic signature generation. Devices perform their own integrity verification and attach cryptographic proofs to their data, eliminating the need for complex centralized trust determination mechanisms while achieving precise trust assessment.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP4557150A1Creating a trusted data packet
Publication Date: 2025.05.21 SIEMENS AG
  • EP4557150A1 patent drawingFigure 1
  • EP4557150A1 patent drawingFigure 2
  • EP4557150A1 patent drawing

AI summary

The invention relates to a method for storing a trustworthy data packet (32, 32B), comprising the steps of: - receiving (S1) from a data source (1) of: ∘ at least one data unit (32), ∘ at least one piece of integrity information (32A) of the data source (1) which is assigned to the at least one data unit (32), - determining (S2) trustworthiness information (32B) as a function of the at least one piece of integrity information (32A), - creating (S3) the trustworthy data packet (32, 32B) by assigning the trustworthiness information (32B) to the at least one data unit (32), and - storing (S4) the trustworthy data packet (32, 32B). The invention also relates to a computer program product, a computer-readable medium, and a higher-level system.