EP3140971A1 - Verfahren zur verschlüsselten datenübertragung in der prozessautomatisierungstechnik - Google Patents
Verfahren zur verschlüsselten datenübertragung in der prozessautomatisierungstechnikInfo
- Publication number
- EP3140971A1 EP3140971A1 EP14724056.8A EP14724056A EP3140971A1 EP 3140971 A1 EP3140971 A1 EP 3140971A1 EP 14724056 A EP14724056 A EP 14724056A EP 3140971 A1 EP3140971 A1 EP 3140971A1
- Authority
- EP
- European Patent Office
- Prior art keywords
- key
- field device
- specific
- server
- encrypted
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Withdrawn
Links
- 238000000034 method Methods 0.000 title claims abstract description 38
- 238000005516 engineering process Methods 0.000 title claims abstract description 15
- 238000004801 process automation Methods 0.000 title claims abstract description 15
- 230000005540 biological transmission Effects 0.000 claims description 20
- 238000003860 storage Methods 0.000 claims description 6
- 238000004891 communication Methods 0.000 description 15
- 238000004519 manufacturing process Methods 0.000 description 13
- 238000010586 diagram Methods 0.000 description 2
- 238000007726 management method Methods 0.000 description 2
- 238000004886 process control Methods 0.000 description 2
- 238000009420 retrofitting Methods 0.000 description 2
- 241000251468 Actinopterygii Species 0.000 description 1
- OPFJDXRVMFKJJO-ZHHKINOHSA-N N-{[3-(2-benzamido-4-methyl-1,3-thiazol-5-yl)-pyrazol-5-yl]carbonyl}-G-dR-G-dD-dD-dD-NH2 Chemical compound S1C(C=2NN=C(C=2)C(=O)NCC(=O)N[C@H](CCCN=C(N)N)C(=O)NCC(=O)N[C@H](CC(O)=O)C(=O)N[C@H](CC(O)=O)C(=O)N[C@H](CC(O)=O)C(N)=O)=C(C)N=C1NC(=O)C1=CC=CC=C1 OPFJDXRVMFKJJO-ZHHKINOHSA-N 0.000 description 1
- 238000004458 analytical method Methods 0.000 description 1
- 230000015572 biosynthetic process Effects 0.000 description 1
- 229940126086 compound 21 Drugs 0.000 description 1
- 150000001875 compounds Chemical class 0.000 description 1
- 230000001276 controlling effect Effects 0.000 description 1
- 230000001419 dependent effect Effects 0.000 description 1
- 238000005755 formation reaction Methods 0.000 description 1
- 108090000623 proteins and genes Proteins 0.000 description 1
- 230000001105 regulatory effect Effects 0.000 description 1
- 230000007704 transition Effects 0.000 description 1
- 238000012795 verification Methods 0.000 description 1
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/06—Network architectures or network communication protocols for network security for supporting key management in a packet data network
- H04L63/062—Network architectures or network communication protocols for network security for supporting key management in a packet data network for key distribution, e.g. centrally by trusted party
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/04—Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks
- H04L63/0428—Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks wherein the data content is protected, e.g. by encrypting or encapsulating the payload
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L67/00—Network arrangements or protocols for supporting network services or applications
- H04L67/01—Protocols
- H04L67/12—Protocols specially adapted for proprietary or special-purpose networking environments, e.g. medical networks, sensor networks, networks in vehicles or remote metering networks
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/08—Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
- H04L9/0816—Key establishment, i.e. cryptographic processes or cryptographic protocols whereby a shared secret becomes available to two or more parties, for subsequent use
- H04L9/0819—Key transport or distribution, i.e. key establishment techniques where one party creates or otherwise obtains a secret value, and securely transfers it to the other(s)
- H04L9/0822—Key transport or distribution, i.e. key establishment techniques where one party creates or otherwise obtains a secret value, and securely transfers it to the other(s) using key encryption key
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/08—Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
- H04L9/0816—Key establishment, i.e. cryptographic processes or cryptographic protocols whereby a shared secret becomes available to two or more parties, for subsequent use
- H04L9/0819—Key transport or distribution, i.e. key establishment techniques where one party creates or otherwise obtains a secret value, and securely transfers it to the other(s)
- H04L9/083—Key transport or distribution, i.e. key establishment techniques where one party creates or otherwise obtains a secret value, and securely transfers it to the other(s) involving central third party, e.g. key distribution center [KDC] or trusted third party [TTP]
- H04L9/0833—Key transport or distribution, i.e. key establishment techniques where one party creates or otherwise obtains a secret value, and securely transfers it to the other(s) involving central third party, e.g. key distribution center [KDC] or trusted third party [TTP] involving conference or group key
Definitions
- Modern process automation techniques often involve communication over the Internet between an occasionally referred to as a "host" Internet service server, such as a web server, an email server, a file server or the like, and one or more field devices that are used for process control or Process control can be achieved by determining, controlling or regulating (at least) one process variable Examples of such field devices include sensors or actuators.
- a host Internet service server such as a web server, an email server, a file server or the like
- field devices that are used for process control or Process control can be achieved by determining, controlling or regulating (at least) one process variable
- Examples of such field devices include sensors or actuators.
- Such communication via the Internet always involves the risk that unauthorized persons gain access to the process data or, worse, gain the opportunity to give control commands to the field devices.
- a known means of at least reducing this risk consists in the encryption of the transmitted data. Suitable encryption algorithms, eg DES, 3DES, IDEA, AES or RSA, and possibilities for their implementation are known from the prior art.
- the object underlying the invention is to provide a method for encrypted data transmission in process automation technology, in which a field device for encrypted communication can be enabled even after production.
- the method according to the invention for encrypted data transmission in process automation technology wherein the keyed data transmission between at least one field device and at least one Internet service server, has at least the following steps:
- a key identical to all or at least a large number of field devices is stored in the field device and in a key server, for example in the manufacture of the field device Field device specific key (which is also referred to as “device-specific key”) in the production, but still need to be managed except a device-specific key only the device-specific keys that are actually used and therefore deposited.
- a key server is possible in which a different, different (not just the type of field device identifying, but different field devices of the same type differ)
- the "device-specific key” is at least stored on the key server, the device-specific key is thus generated only on demand and on the
- the communication between the field device and the Internet service server which is e.g. a web server, an email server, a file server or the like can be encrypted.
- the Internet service server can preferably be a server or at least virtually separate from the key server server; but he has access rights to the data stored in the key server. If a message encrypted with a device-specific key is received by the Internet service server, the latter can look up the key on the key server and decrypt the message with the help of the information obtained.
- the data for storing a key specific to the field device on the key server comprise a specific key generated on the field device or transferred from a storage medium to the field device.
- This approach has the advantage that the specific for the field device key on the field device itself deposited directly ⁇ who can and must not be transmitted and stored by a return transmission from the key server to the field device. If the field device generates the key itself, this can be done, for example, using the serial number and / or production date and time as input data for the key generation algorithm.
- Crucial for the Generating a key on the field device is the generation of a random number that enters the key. Such a random number can be generated via a corresponding algorithm by a software module or by a dedicated hardware in the field device.
- the data for storing a field device specific key on the key server for the field device may include specific data and instructions for generating the field device specific key by the key server.
- the field device would thus with the device-nonspecific key encrypts ge ⁇ device specific information, such as its serial number and / or production date and -Time as input data for a
- Key generation algorithm which is executed on the key server, submit to the key server and ask him to generate a key.
- This procedure can be advantageous in two ways: On the one hand, this prevents the device-specific key itself from being sent via the only device-unspecifically encrypted connection. However, in this case, a device-specific key, which is generated using the same key generation algorithm and which is based on the same device-specific data, must be generated and / or stored on the field device.
- the particular device-specific Keyring ⁇ sel from specific data of the field device such as serial number or manufacturing date and time, can be determined unambiguously. In this way, a double allocation of keys, which can lead to ambiguities in the data communication, safely avoided.
- the validity of the key that is specific to the field device can be verified by the Internet service server with the aid of the key server. This is particularly realized when the for the field device specific key ⁇ ⁇ fish is kierbar on the key server as invalid mar.
- the advantage associated with such a verification option is that it can be ensured via the key server that only field devices that are actually still used in a given production facility also participate in the encrypted communication of this production facility.
- the device-nonspecific Keyring ⁇ sel is stored in the field device in the firmware. This measure ⁇ takeover has the advantage that a simple "retrofitting" of an originally nonadedleg ⁇ th for encrypted communication field device by an appropriate firmware update possible borrowed is.
- the field device is set by the firmware in the location, the encrypted communication to It is possible that the key server has a permanently stored in the field device, a selectable or a freely configurable address, which makes it possible to limit the complexity of key management hold, because not mandatory All keys must be managed by the same key server and optionally have centralized or decentralized key management.
- the invention will be described in more detail below with reference to figures, which show spe ⁇ cial embodiments of the invention, tert erläu ⁇ tert. Show it:
- FIG. 1 shows the schematic structure of a system with Internet server, key server and three field devices and their communication paths
- FIG. 2 shows a flowchart of a first variant of a method for encrypted data transmission in process automation technology
- Figure 3 is a flow diagram of a second variant of a procedural ⁇ proceedings for encrypted data transmission in process automation technology
- Figure 4 is a flow diagram of a third variant of a method for encrypted data transmission in process automation technology.
- FIGS 2 to 4 indicate the preferred order of the method sequence, but there are deviations ⁇ gen possible.
- FIG. 1 shows the schematic structure of a system for use in process automation technology, with an Inter- net server 10, a key server 20 and three field devices 30,40,50, optionally via an unillustrated interface ⁇ point for a non-illustrated storage medium , eg a USB stick or an SD card.
- a non-illustrated storage medium eg a USB stick or an SD card.
- the field devices 30,40,50 can each have a identical with a ieriunspezifi- rule, that is for all field devices 30,40,50, Keyring ⁇ sel encrypted and therefore shipping ⁇ hene with the same reference numerals, and displayed in the same line type connection 21 with the key server will communicate 20 and deposit on that a device-specific key or generate said to-retransmitted in this case the device-specific key generated in the key server 20 via the device-nonspecific Locks ⁇ doubted compound 21 to the respective field device 30,40,50 and stored got to. This is omitted in the first case, because then already the device-specific Keys ⁇ sel is stored and stored on the field device 30,40,50.
- the field devices 30,40,50 can further th for the transmission of DA and / or control commands to communicate with the Internet server 10, wherein the field device 30 to an encrypted with its device-specific key ⁇ connection 31, the field device 40 is a ⁇ with his device-specific key encrypted connection 41 and the field device 50 uses a encrypted with his device-specific key connection 51. Since the compounds are 31,41,51 each encrypted with different keys ⁇ union, they are shown in Figure 1 with different line types.
- a commands to encrypt entspre ⁇ accordingly to the field devices 30,40,50 is provided in particular that of the web server 10 via a connection 11 which may also be encrypted communicates with the key server 20 on which the corresponding device-specific keys are stored.
- the key server 20 can thereby manage the gerä ⁇ tespezifischen keys and key example as un- Mark valid so that field devices are excluded from communicating with the Internet server. Both symmetric and asymmetric keys can be used. For asymmetric keys, only the public part of the key is stored on the key server 20. The private part of the asymmetric key is stored exclusively in the field devices 30, 40, 50.
- FIG. 2 shows a flow chart of a first variant of a method for encrypted data transmission in process automation technology, which can be executed in particular on a system according to FIG.
- a device-unspecific key which may be identical in particular for all field devices 30, 40, 50, is stored in the field device 30, 40, 50. This can be especially true in the production of the
- an encrypted connection 21 is constructed for key server 20 using this gerä ⁇ teunspezifischen key on the below in step 130 device-specific data, for example, o- the serial number of the time of manufacture of the field device 30,40,50 to the key Server 20, where from them - optionally after transmission of a control command via the connection 21- a device-specific key is generated in step 140, which is deposited on the key server 20 and in step 150 for storage to the associated field device 30,40 , 50 is transmitted via the connection 21 encrypted with the device-unspecified key.
- can 30,40,50 encrypted connections are established 31,41,51 to the Internet server 10 to the respective ge ⁇ device-specific keys of the field devices in step 160, via the communication then the above as step 170 tion between the field device 30,40,50 and Internet server 10 suc ⁇ gene can.
- 210,220, 260 and 270 may therefore be based on the description of
- Steps 110, 120, 160 and 170 are referenced to FIG.
- step 230 the device-specific one becomes
- Key on the field device 30,40,50 instead of generated on the key server 20 from device-specific data (and stored on the field device 30,40,50) and transferred in step 240 on the device-unscrutely encrypted connection 21 to the key server 20, to deposit them there.
- the device-specific data, which are transmitted to the key server 20 via the device-unspecifically encrypted connection 21, are therefore the device-specific key itself.
- Steps 110, 120, 160 and 170 are referenced to FIG.
- step 330 is read in the field ⁇ device 30,40,50, for example, from a locally attached to the field device USB-Stick , stored in step 340 on the field device 30,40,50 and transmitted in step 350 via the device unspecifically encrypted connection 21 to the key server 20 to deposit them there.
- the hardware outlay that is necessary for generating a device-specific key from device-specific data can be avoided.
- the device-specific data which are transmitted to the key server 20 via the device-unspecifically encrypted connection 21, are in the third variant according to FIG. 4 also the device-specific key itself.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Computing Systems (AREA)
- Computer Hardware Design (AREA)
- General Engineering & Computer Science (AREA)
- Health & Medical Sciences (AREA)
- General Health & Medical Sciences (AREA)
- Medical Informatics (AREA)
- Storage Device Security (AREA)
Abstract
Description
Claims
Applications Claiming Priority (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| PCT/EP2014/059275 WO2015169347A1 (de) | 2014-05-06 | 2014-05-06 | Verfahren zur verschlüsselten datenübertragung in der prozessautomatisierungstechnik |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| EP3140971A1 true EP3140971A1 (de) | 2017-03-15 |
Family
ID=50729482
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| EP14724056.8A Withdrawn EP3140971A1 (de) | 2014-05-06 | 2014-05-06 | Verfahren zur verschlüsselten datenübertragung in der prozessautomatisierungstechnik |
Country Status (2)
| Country | Link |
|---|---|
| EP (1) | EP3140971A1 (de) |
| WO (1) | WO2015169347A1 (de) |
Family Cites Families (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| DE10314721A1 (de) * | 2003-03-31 | 2004-11-11 | Endress + Hauser Gmbh + Co. Kg | Verfahren zur sicheren Datenübertragung über einen Feldbus |
| DE102010010760B4 (de) * | 2010-03-09 | 2012-02-02 | Siemens Aktiengesellschaft | Verfahren zur Vergabe eines Schlüssels an ein einem drahtlosen Sensor-Aktor-Netz neu hinzuzufügendes Teilnehmergerät |
| DE102010011656B4 (de) * | 2010-03-17 | 2012-12-20 | Siemens Aktiengesellschaft | Verfahren und Vorrichtung zum kryptographischen Sichern einer Datenübertragung zwischen Netzwerkknoten |
| DE102011085568A1 (de) * | 2011-11-02 | 2013-05-02 | Endress + Hauser Process Solutions Ag | Verfahren zur verschlüsselten Datenübertragung zwischen einer Anlage der Prozessautomatisierungstechnik und einem Webserver |
-
2014
- 2014-05-06 WO PCT/EP2014/059275 patent/WO2015169347A1/de not_active Ceased
- 2014-05-06 EP EP14724056.8A patent/EP3140971A1/de not_active Withdrawn
Non-Patent Citations (2)
| Title |
|---|
| None * |
| See also references of WO2015169347A1 * |
Also Published As
| Publication number | Publication date |
|---|---|
| WO2015169347A1 (de) | 2015-11-12 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| EP2870565B1 (de) | Überprüfung einer integrität von eigenschaftsdaten eines gerätes durch ein prüfgerät | |
| WO2008124854A2 (de) | Kommunikationsverfahren und apparat zur effizienten und sicheren übertragung von tt-ethernet nachrichten | |
| AT506735B1 (de) | Verteilte datenspeicherungseinrichtung | |
| EP3023896B1 (de) | Verfahren zum Übertragen von medizinischen Datensätzen | |
| EP4154070A1 (de) | Digital-twin basierte prozesssteuerung in einem iot-netzwerk | |
| WO2025113933A1 (de) | Verfahren und system zur anmeldung eines benutzers an einem oder mehreren feldgeräten der automatisierungstechnik | |
| WO2020207717A1 (de) | Verfahren und steuersystem zum steuern einer ausführung von transaktionen | |
| EP3743844A1 (de) | Blockchain-basiertes identitätssystem | |
| EP3881486B1 (de) | Verfahren zur bereitstellung eines herkunftsortnachweises für ein digitales schlüsselpaar | |
| WO2015173147A1 (de) | Feldgerät, verfahren zum betreiben eines feldgerätes und cloud-dienst | |
| EP2618226B1 (de) | Industrielles Automatisierungssystem und Verfahren zu dessen Absicherung | |
| WO2022022997A1 (de) | Kanalbasierte kommunikation in einem iot-netzwerk | |
| EP3140971A1 (de) | Verfahren zur verschlüsselten datenübertragung in der prozessautomatisierungstechnik | |
| EP2333624A1 (de) | Verfahren und Einrichtung zur Konfigurierung einer Komponente in einer industriellen Automatisierungsanordnung | |
| EP1403749A1 (de) | Automatisierungssystem sowie Verfahren zu dessen Betrieb | |
| WO2014206451A1 (de) | Verfahren und vorrichtung zum sicheren übertragen von signaldaten in einer anlage | |
| DE102022130426A1 (de) | Verfahren und System zum Dokumentieren von Logbuchdaten von einem oder mehreren ersten Feldgeräten | |
| EP4275330B1 (de) | Verfahren zur anonymen übermittlung von daten | |
| WO2022167073A1 (de) | Verfahren zum betreiben eines feldgeräts und system zum betreiben von feldgeräten | |
| DE102020213487A1 (de) | Steuervorrichtung | |
| DE102023129934A1 (de) | Verfahren und System zur Bedienung eines Feldgeräts der Automatisierungstechnik über eine Maschine-zu-Maschine- Kommunikation zwischen einer Bedieneinheit und dem Feldgerät | |
| DE102024120252A1 (de) | Verfahren zur Verwaltung eines Bestandsfeldgeräts und entsprechendes System | |
| LU101163B1 (de) | Verfahren und Vorrichtungen für eine Lastzuweisung und Überwachung für eine zuzuweisende versorgungssicherheitskritische Ressource in einem Netzwerk | |
| DE102024120251A1 (de) | Verfahren und System zur Anmeldung eines Benutzers an einem oder mehreren Feldgeräten der Automatisierungstechnik | |
| WO2018114101A1 (de) | Verfahren zum überprüfen einer mandantenzuordnung, computerprogrammprodukt und automatisierungssystem mit feldgeräten |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| PUAI | Public reference made under article 153(3) epc to a published international application that has entered the european phase |
Free format text: ORIGINAL CODE: 0009012 |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: REQUEST FOR EXAMINATION WAS MADE |
|
| 17P | Request for examination filed |
Effective date: 20160919 |
|
| AK | Designated contracting states |
Kind code of ref document: A1 Designated state(s): AL AT BE BG CH CY CZ DE DK EE ES FI FR GB GR HR HU IE IS IT LI LT LU LV MC MK MT NL NO PL PT RO RS SE SI SK SM TR |
|
| AX | Request for extension of the european patent |
Extension state: BA ME |
|
| DAX | Request for extension of the european patent (deleted) | ||
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: EXAMINATION IS IN PROGRESS |
|
| 17Q | First examination report despatched |
Effective date: 20190402 |
|
| GRAP | Despatch of communication of intention to grant a patent |
Free format text: ORIGINAL CODE: EPIDOSNIGR1 |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: GRANT OF PATENT IS INTENDED |
|
| INTG | Intention to grant announced |
Effective date: 20201223 |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: THE APPLICATION IS DEEMED TO BE WITHDRAWN |
|
| 18D | Application deemed to be withdrawn |
Effective date: 20210504 |