Valve Actuator with Standalone Cryptography Module

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing automation solutions for valves in critical infrastructure networks, such as water, gas, and oil supply lines, lack secure and energy-efficient remote control capabilities, particularly due to the absence of a standby mode in existing drive systems, making them vulnerable to unauthorized access and inefficient for decentralized operation.

Innovation Solution

A drive system with an internal or external cryptographic module separate from the operating system, designed to operate in standby mode, provides secure bidirectional wireless communication meeting VS-NfD security levels, incorporating a self-sufficient energy source and modular architecture for enhanced security and energy efficiency.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If drive systems operate continuously to maintain communication readiness, then security response time is improved, but energy consumption increases

Engineering Contradiction:
Improvesecurity response timeVSAvoidenergy consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The system dynamically adjusts its operational state between active and standby modes based on security threats and communication requirements. The cryptography module can be activated on-demand rather than running continuously, reducing energy consumption while maintaining security readiness when needed.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system implements periodic security checks and encrypted communication cycles rather than continuous operation. The cryptography module performs security functions at specific intervals or triggered events, balancing security reliability with energy efficiency by avoiding constant active operation.

Inventive Principle:
Principle #19Periodic action

2Device complexity

If cryptographic module is integrated into the operating system, then device complexity is reduced, but security against unauthorized access deteriorates

Engineering Contradiction:
Improvesystem integrationVSAvoidsecurity protection
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The cryptography module is segmented as a separate, independent component from the operating system. This separation ensures that even if the OS is compromised, the cryptographic functions remain protected and can verify the authenticity of commands, maintaining security while allowing modular integration.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The cryptography module acts as an intermediary layer between the control station and the drive system. It mediates all communication by encrypting and decrypting messages, providing security without being part of the core operating system while still enabling secure operation.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If wireless communication is implemented for remote control, then ease of operation is improved, but vulnerability to unauthorized access increases

Engineering Contradiction:
Improveremote control capabilityVSAvoidunauthorized access vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The cryptography module serves as a security intermediary that all wireless communications must pass through. It encrypts outgoing messages and decrypts incoming messages, ensuring that even though wireless communication is open and accessible, unauthorized access is prevented through cryptographic verification.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system applies preliminary cryptographic protection to all wireless communications before they are transmitted. By pre-encrypting messages and pre-verifying authentication credentials, the system prevents unauthorized access attempts rather than reacting to them after occurrence.

Inventive Principle:
Principle #9Preliminary anti-action

Data Source

PatentEP3026511B1Remote wireless encrypted controled actuator for valves in pipelines
Publication Date: 2019.05.29 SACHAROWITZ FABIAN
  • EP3026511B1 patent drawingFigure 1
  • EP3026511B1 patent drawingFigure 2
  • EP3026511B1 patent drawingFigure 3

AI summary

The invention described here relates to a drive system for an electrically or pneumatically operated drive (1) for fittings in supply lines belonging to the so-called "critical infrastructure" (including district heating and district cooling), to which an internal or external cryptography module (5) separate from the operating system (3) of the drive (1), which is approved for the VSA security level VS-NfD or higher, is assigned and which can be connected bidirectionally and wirelessly to the central information technology of the utility company via a communication module (6).