VPN Box Authentication Using Field Device Cryptographic Keys
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing VPN solutions for industrial field devices require time-consuming and error-prone configuration of secret cryptographic keys on VPN boxes for secure data transmission, which complicates implementation and maintenance.
Innovation Solution
A VPN box uses the field device's secret cryptographic key for authentication and communication, eliminating the need for key configuration on the VPN box by leveraging the field device's stored key, which can be used for symmetric or asymmetric cryptography methods, and allowing the field device to act as a security token or provide authentication, thus simplifying setup and maintenance.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If secret cryptographic keys are stored on the VPN box for secure data transmission, then security is improved, but configuration time and error probability increase
Solution Approach 1:
The cryptographic key functionality is extracted from the VPN box and relocated to the field device. The field device now stores and manages its own cryptographic keys, while the VPN box only needs to retrieve and use these keys during VPN setup. This extraction eliminates the need for separate key configuration on the VPN box, reducing configuration time while maintaining security through the field device's secure key storage.
2Reliability
If secret cryptographic keys are stored on the VPN box, then secure communication is enabled, but device complexity increases
Solution Approach 1:
The field device is empowered to self-manage its cryptographic keys without requiring external key configuration. The field device automatically provides its stored keys to the VPN box during authentication, eliminating the need for manual key provisioning and management on the VPN box. This self-service approach simplifies the VPN box's key management complexity while maintaining secure communication capabilities.
3Reliability
If separate key material is stored on the VPN box, then authentication is possible, but implementation and maintenance become more difficult
Solution Approach 1:
The key storage and authentication functions are merged into the field device, which already possesses secure storage capabilities for its operational keys. The VPN box no longer requires separate key material storage, as it retrieves keys directly from the field device during authentication. This merging simplifies the VPN box's implementation and maintenance while preserving authentication capability through the field device's integrated key management.
Data Source
AI summary
A VPN box is connected upstream of a field device. The VPN box uses a secret cryptographic key of the field device for authentication when setting up a VPN tunnel and/or when setting up a cryptographically protected communication link.


