Zero Trust Adapters for Secure Deterministic Industrial Data

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing industrial automation systems face challenges in integrating zero trust concepts due to economic constraints on cryptographic functionality and hardware limitations, which hinder data security and deterministic data transmission.

Innovation Solution

A communication system with a control network separate from local networks, utilizing zero trust adapters to capture and preprocess status information, determine trust scores, and apply rules for secure communication, ensuring compatibility with existing infrastructure.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If zero trust concepts are integrated into industrial automation systems, then data security is improved, but device complexity and cost increase due to additional cryptographic functionality and hardware requirements

Engineering Contradiction:
Improvedata securityVSAvoidcryptographic functionality and hardware requirements
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a firewall system as an intermediary component that mediates between the existing industrial communication network and the zero trust security requirements. The firewall system performs authentication and authorization functions without requiring cryptographic functionality in every terminal device, thus achieving data security while avoiding the complexity of distributed cryptographic implementations.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates a virtualized firewall system using virtual machines that replicate security functions. Instead of embedding complex cryptographic hardware in each terminal, the system uses virtual machine instances that can be deployed on existing servers, providing the necessary security functionality through software-based copies rather than hardware-intensive implementations.

Inventive Principle:
Principle #26Copying

2Reliability

If mutual authentication of communication partners is implemented, then data security is improved, but deterministic data transmission and processing become more difficult

Engineering Contradiction:
Improvedata securityVSAvoiddeterministic data transmission
Core Design Contradiction:
ReliabilityVSStability of the object's composition

Solution Approach 1:

The patent performs authentication actions preliminarily before data transmission begins. The firewall system authenticates communication partners in advance and establishes secure connections, allowing subsequent data transmission to proceed deterministically without repeated authentication interruptions. This preliminary authentication approach separates the security function from the data transmission function, preserving determinism.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent segments the communication system into distinct functional layers: authentication layer handled by the firewall system, and data transmission layer handled by the industrial communication network. This segmentation allows authentication to occur independently and deterministically, while data transmission follows predictable paths once authentication is complete, maintaining deterministic behavior.

Inventive Principle:
Principle #1Segmentation

3Reliability

If existing security protocols are adapted to implement zero trust concepts, then data security is improved, but integration difficulty increases due to incompatibility with existing infrastructure

Engineering Contradiction:
Improvedata securityVSAvoidintegration with existing infrastructure
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent designs the firewall system to perform multiple functions: authentication, authorization, and data transmission filtering. This multi-functional approach allows the system to work with existing industrial communication protocols while implementing zero trust security, avoiding the need to replace or adapt complex existing infrastructure.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The firewall system acts as an intermediary that translates between existing industrial communication protocols and zero trust security requirements. It intercepts communications, performs authentication according to zero trust principles, and allows or blocks transmissions based on authentication results, thereby integrating security without requiring changes to existing terminal devices or communication protocols.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12381865B2Communication system, adapter for a terminal and method for securely transmitting time-critical data within the communication system
Publication Date: 2025.08.05 SIEMENS AG
  • US12381865B2 patent drawing
  • US12381865B2 patent drawing
  • US12381865B2 patent drawing

AI summary

A method for securely transmitting time-critical data within a communication system that includes local networks each having a switch and a plurality of terminals, a controller that controls functions of switches and terminals, and having a control network assigned to the controller and separate from the local networks, where communication within the local networks is implicitly authorized based on an assignment of respective terminals to the same local network, each terminal is assigned a zero trust adapter that captures status information, transfers the status information via the control network to the controller for evaluation and authenticates the terminal to the controller to communication partners, and where the controller determines a trust index for each of the terminals based on the status information and applies rules dependent on the trust index for configuration or permissible communication relationships of the terminals.