VPN Box Authentication Using Field Device Cryptographic Keys

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing VPN solutions for industrial field devices require time-consuming and error-prone configuration of secret cryptographic keys on VPN boxes for secure data transmission, which complicates implementation and maintenance.

Innovation Solution

A VPN box uses the field device's secret cryptographic key for authentication and communication, eliminating the need for key configuration on the VPN box by leveraging the field device's stored key, which can be used for symmetric or asymmetric cryptography methods, and allowing the field device to act as a security token or provide authentication, thus simplifying setup and maintenance.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If secret cryptographic keys are stored on the VPN box for secure data transmission, then security is improved, but configuration time and error probability increase

Engineering Contradiction:
ImprovesecurityVSAvoidconfiguration time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The cryptographic key functionality is extracted from the VPN box and relocated to the field device. The field device now stores and manages its own cryptographic keys, while the VPN box only needs to retrieve and use these keys during VPN setup. This extraction eliminates the need for separate key configuration on the VPN box, reducing configuration time while maintaining security through the field device's secure key storage.

Inventive Principle:
Principle #2Taking out (Extraction)

2Reliability

If secret cryptographic keys are stored on the VPN box, then secure communication is enabled, but device complexity increases

Engineering Contradiction:
Improvesecure communicationVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The field device is empowered to self-manage its cryptographic keys without requiring external key configuration. The field device automatically provides its stored keys to the VPN box during authentication, eliminating the need for manual key provisioning and management on the VPN box. This self-service approach simplifies the VPN box's key management complexity while maintaining secure communication capabilities.

Inventive Principle:
Principle #25Self-service

3Reliability

If separate key material is stored on the VPN box, then authentication is possible, but implementation and maintenance become more difficult

Engineering Contradiction:
Improveauthentication capabilityVSAvoidimplementation ease
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The key storage and authentication functions are merged into the field device, which already possesses secure storage capabilities for its operational keys. The VPN box no longer requires separate key material storage, as it retrieves keys directly from the field device during authentication. This merging simplifies the VPN box's implementation and maintenance while preserving authentication capability through the field device's integrated key management.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS11171922B2Method and system for secure data transmission with a VPN box
Publication Date: 2021.11.09 SIEMENS MOBILITY GMBH
  • US11171922B2 patent drawing
  • US11171922B2 patent drawing
  • US11171922B2 patent drawing

AI summary

A VPN box is connected upstream of a field device. The VPN box uses a secret cryptographic key of the field device for authentication when setting up a VPN tunnel and/or when setting up a cryptographically protected communication link.