Wireless Side-Channel Configuration for Secure Industrial Reconnection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Industrial devices in processing plants often lose configuration settings, leading to connectivity issues and requiring labor-intensive physical reconfiguration, which is insecure and time-consuming, exposing them to potential cyber attacks.

Innovation Solution

Implementing a compute device with primary and side channel communication circuitry to securely retrieve and transmit configuration data via a wireless side channel using protocols like Wi-Fi, Bluetooth, or 5G, utilizing token-based secured communication sessions to restore and maintain industrial device configurations without physical access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If physical interface (e.g., USB) is used for reconfiguration, then device can be reconfigured, but labor intensive process requiring physical travel to device location

Engineering Contradiction:
Improvereconfiguration processVSAvoidtime for physical travel and reconfiguration
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The patent replaces the mechanical physical interface (USB connection requiring physical access) with a wireless communication system. The compute device uses wireless communication circuitry to transmit configuration data remotely to the industrial device, eliminating the need for physical travel and manual connection establishment.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent introduces a compute device as an intermediary between the configuration source and the industrial device. This intermediary handles the configuration data transmission wirelessly, acting as a mediator that enables remote reconfiguration without requiring direct physical access to the target device.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of repair

If physical interface is used for reconfiguration, then device can be reconfigured, but exposes attack surface for cyber attacks

Engineering Contradiction:
Improvedevice reconfiguration capabilityVSAvoidcyber security risk
Core Design Contradiction:
Ease of repairVSObject-affected harmful factors

Solution Approach 1:

The patent replaces the physical interface (USB port) that exposes attack surfaces with a wireless communication system. The wireless interface eliminates physical access requirements and reduces the attack surface by removing physical connection points that could be exploited by attackers.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent extracts the configuration capability from the physical device interface and relocates it to a separate compute device. This separation removes the configuration function from the potentially vulnerable physical interface of the industrial device, isolating the attack surface.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If main channel (network) is used for communication, then device connectivity is maintained, but configuration data may be lost due to memory corruption

Engineering Contradiction:
Improveconfiguration data integrityVSAvoidcommunication system structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the communication system into two distinct channels: the main network channel for operational communication and a separate wireless side channel for configuration data transmission. This segmentation isolates configuration operations from the potentially corrupting main network environment, protecting configuration data integrity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The compute device acts as an intermediary that receives configuration data through the wireless side channel and transmits it to the industrial device. This intermediary layer protects the main network channel from direct exposure to configuration operations, maintaining data integrity while enabling secure configuration updates.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12262202B2Systems and methods for configuring industrial devices through a secured wireless side channel
Publication Date: 2025.03.25 ABB (SCHWEIZ) AG
  • US12262202B2 patent drawing
  • US12262202B2 patent drawing
  • US12262202B2 patent drawing

AI summary

Systems and methods for configuring industrial devices through a secured wireless side channel may include a compute device. The compute device may have primary communication circuitry configured to communicate through a network and side channel communication circuitry configured to communicate through a wireless side channel that is different from the network. The compute device may additionally include circuitry configured to obtain, via the wireless side channel, configuration data indicative of a configuration for one or more operations of an industrial device of an industrial process plant. Additionally the circuitry may be configured to configure, in response to obtaining the configuration data, the one or more operations of the industrial device.