EP3704847A1 - Vorrichtung und verfahren zum übertragen von daten zwischen einem ersten und einem zweiten netzwerk - Google Patents
Vorrichtung und verfahren zum übertragen von daten zwischen einem ersten und einem zweiten netzwerkInfo
- Publication number
- EP3704847A1 EP3704847A1 EP18810905.2A EP18810905A EP3704847A1 EP 3704847 A1 EP3704847 A1 EP 3704847A1 EP 18810905 A EP18810905 A EP 18810905A EP 3704847 A1 EP3704847 A1 EP 3704847A1
- Authority
- EP
- European Patent Office
- Prior art keywords
- data
- network
- communication path
- way communication
- diode
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Withdrawn
Links
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/02—Network architectures or network communication protocols for network security for separating internal from external traffic, e.g. firewalls
- H04L63/0281—Proxies
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/04—Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks
- H04L63/0428—Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks wherein the data content is protected, e.g. by encrypting or encapsulating the payload
- H04L63/0471—Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks wherein the data content is protected, e.g. by encrypting or encapsulating the payload applying encryption by an intermediary, e.g. receiving clear information at the intermediary and encrypting the received information at the intermediary before forwarding
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/18—Network architectures or network communication protocols for network security using different networks or channels, e.g. using out of band channels
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/06—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols the encryption apparatus using shift registers or memories for block-wise or stream coding, e.g. DES systems or RC4; Hash functions; Pseudorandom sequence generators
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/10—Network architectures or network communication protocols for network security for controlling access to devices or network resources
- H04L63/105—Multiple levels of security
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/08—Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
- H04L9/0816—Key establishment, i.e. cryptographic processes or cryptographic protocols whereby a shared secret becomes available to two or more parties, for subsequent use
- H04L9/0838—Key agreement, i.e. key establishment technique in which a shared key is derived by parties as a function of information contributed by, or associated with, each of these
- H04L9/0841—Key agreement, i.e. key establishment technique in which a shared key is derived by parties as a function of information contributed by, or associated with, each of these involving Diffie-Hellman or related key agreement protocols
- H04L9/0844—Key agreement, i.e. key establishment technique in which a shared key is derived by parties as a function of information contributed by, or associated with, each of these involving Diffie-Hellman or related key agreement protocols with user authentication or key authentication, e.g. ElGamal, MTI, MQV-Menezes-Qu-Vanstone protocol or Diffie-Hellman protocols using implicitly-certified keys
Definitions
- the present invention relates to an apparatus for transferring data between a first and a second network and a method for transferring data between the first and the second network.
- transmission of data between a first and a second network of the system may be desired.
- data encryption may require encryption and / or decryption of the data. There is a need to reliably encrypt and / or decrypt the data to ensure the security of the system.
- an object of the present invention is to provide an improved transfer of data between a first and a second network.
- an apparatus for transmitting data between a first and a second network comprises:
- a first one-way communication path for exclusively transferring data from the first to the second network with a first data diode and an encryption means for cryptographically encrypting the data to be transmitted from the first to the second network; and a second one-way communication path for exclusively transferring data from the second to the first network with a second data diode and a decryption means for cryptographically decrypting the data to be transmitted from the second to the first network.
- the first and the second network are systems which each comprise a plurality of interconnected devices, such as industrial networks, control networks, automation networks, process networks, private networks and / or
- the first network is an industrial network and the second network is a public network, such as the Internet, the two networks may be part of a same environment or system, such as an industrial system.
- a single device eg a network-capable machine tool or a robot, can be located in a network.
- the data can be any data, e.g. Control data, be.
- the data is especially security relevant data.
- the device for transferring the data between the networks hereinafter also referred to as "transmission device”, may be suitable for transmitting data bidirectionally, ie for transmitting data both from the first to the second network and from the second to the first network.
- the transmission device can also be referred to as a communication interface of the first network for communication with the second network It is also possible to designate the transmission device as an encryption device.
- the transmission device For transmission of the data from the first to the second network, the transmission device comprises the first one-way communication path, which can also be referred to as a first one-way communication path.
- the first disposable The communication path serves exclusively to transmit / transmit data from the first network to the second network and thus in particular allows only unidirectional data transmission from the first to the second network. In particular, all data transmitted from the first to the second network is transmitted over the first one-way communication path.
- the first path Einwegkommuni cation includes in particular a cable for REMtra supply, which connects the first data diode and the encryption device together.
- the cable can be an electric cable, eg a twisted-pair cable or a coaxial cable, an optical cable (optical fiber) or a waveguide.
- the first data diode which is part of the first one-way communication path, is in particular a component which passes data only in a predetermined direction. It can also be referred to as a unidirectional interface.
- the first data diode is opaque to data transmitted against the predetermined direction to the data diode.
- the first data diode is aligned in the first one-way communication path in particular such that it can pass only data from the first to the second network.
- the first data diode may prevent data sent from the second to the first network from being transmitted over the first one-way communication path.
- all data transmitted from the first to the second network must be timed by the first one.
- the data diode may e.g. a physical data diode that enables data transmission physically only in one direction (e.g., an optical data transmission device and an optical data reception device) or a network listening device, also referred to as a network tap.
- the encryption device which is also part of the first one-way communication path, can be used to cryptographically encrypt the data from the first to the second Network are transmitted to be used.
- all data transmitted from the first to the second network is encrypted by the encryption device.
- the encryption device can have an encryption key for data encryption, in particular a private, secret encryption key or a public encryption key.
- the encryption device can be used to ensure that all data sent by the first network is properly cryptographically protected, so that it can not be read by unauthorized devices.
- the transmission device For transmission of the data from the second to the first network, the transmission device comprises the second one-way communication path, which can also be referred to as a second path Einwegkommu nikationslayer.
- the second one-way communication path is the exclusive Studentstra
- the second one-way communication path includes, in particular, a cable for data transmission, which interconnects the second data diode and the decision-making device.
- the second data diode which is part of the first one-way communication path, is designed, in particular, analogously to the first data diode, that is to say as a component which transmits data only in a predetermined direction. It can also be referred to as a unidirectional interface.
- the second data diode is for data that are transmitted against the solicitstimm th direction to the data diode, opaque sig.
- the second data diode is particularly aligned in the second one-way communication path so as to pass only data from the second to the first network can.
- the second data diode may prevent data transmitted from the first to the second network from being transmitted via the second one-way communication path. In particular, all data transmitted from the second to the first network must be through the second data diode.
- the first and second data diodes can also be designed as a network tap
- the network tap has, for example, the property that it is only available for data in its own In addition, a control of the data to be transmitted may be possible.
- the decryption device which is also part of the second one-way communication path, can be used to cryptographically decrypt the data transmitted from the second to the first network.
- all data transmitted from the second to the first network is decrypted by the decryption device.
- the decryption device can have a decryption key, in particular a private decryption key, for data decryption.
- the encryption key of the encryption means and the decryption key of the decryption means may be negotiated in a key negotiation procedure.
- the encryption key and the decryption key can form corresponding keys of a key pair.
- the decryption key is a public key of a communication partner, ie a second device, the decryption key is the private key of the first device itself. It is also possible that the encryption key is a first secret symmetric key and the decryption key second secret key are. It is possible that the encryption key and the decryption key are derived from a common master session key.
- the master session key can be formed by an authentication and key agreement protocol, eg IKEv2 or TLS Authentication and Key Agreement, using long-lived keys. It is furthermore possible for the decryption key and the encryption key to be formed and set up independently of one another.
- the transmission device has two separate one-way communication paths ensures that all data transmitted from the first to the second network is encrypted with the encryption device of the first one-way communication path, and that all data transmitted from the second to the second first network are decrypted with the decryption device of the second A wegkommunikationspfads. This ensures that all data entering the first network from the second network is properly decrypted by the decryption device, and that all data issuing from the first network to the second network is properly encrypted by the encryption device.
- the transmission device thus forms a protection for the first network in particular.
- the first one-way communication path with the first data diode as a one-way communication path, for example, it is possible to prevent attack data being generated in an attack on the second network from being transmitted toward the first network and endanger the security of the first network.
- An attack is understood to mean, in particular, a hack attack.
- Characterized in that the second one-way communication path with the second data diode is designed as a one-way communication path can be prevented, for example, attack data that are generated, for example, in an attack on the first network, are transmitted towards the second network and endanger the security of the second network.
- the transmission device contributes particularly to the security of the first network.
- the transmission device is part of the first network.
- the transmission device can therefore in particular increase the safety of the data transmission and can be used in critical systems in which data relating to safety, in particular safety, are transmitted on the basis of the first and / or second network. With the Neillsvor direction a feedback-free data transmission between tween the first and the second network can be created.
- the components which are needed for the composition of the icosvor direction in particular known, ver spread components.
- the icosvorrich device can be produced inexpensively, because no new components have to be developed and manufactured.
- the first and second one-way communication paths are physically and / or logically separate from one another.
- no data can be transmitted / exchanged between the first and second one-way communication paths.
- the first data diode of the encryption device is connected in series along the first one-way communication path or serially connected in series.
- the second data deio of the decryption device along the second A wegkommunikationspfads connected in series or connected in series.
- the first data diode to be switched serially in front of the encryption device is particularly advantageous because it can prevent attack data that is generated in the case of an attack on the encryption device from being transmitted in the direction of the first network and the security of the first network compromise. In other words, data can be prevented from being sent to the first network by the encryption device.
- the first one-way communication path comprises a plurality of first data diodes.
- the second one-way communication path comprises a plurality of second data diodes.
- Each first data diode has, in particular, the previously described properties of the first data diode. Every second data diode has, in particular, the above described eigenvalue. on the second data diode.
- Providing a plurality of data diodes in a one-way communication path may serve to prevent data in portions of the one-way communication paths from transmitting data in the non-data-direction permeable direction of the data diodes.
- individual elements of the communication paths for example the encryption device and / or the decryption device, and the networks can be protected against attacks.
- At least one first data diode of the plurality of first data diodes is connected in series along the first one-way communication path of the encryption device, and at least one further first data region of the plurality of first data diodes is connected downstream along the first one-way communication path of the encryption device.
- at least a second data diode of the plurality of second Da tendioden along the second one-way communication path of the decryption device is connected in series and at least one further second data diode of the plurality of second Since then diode is connected in series along the second one-way communication path of the decryption device.
- a first data diode can be switched before and a first data diode after the encryption device.
- data transmitted in the direction from the second to the first network e.g. Attack data
- the first one-way communication path neither the encryption device, nor the first network can be transmitted. This protects the shutters and the first network from attacking various locations on the first one-way communication path.
- It can also be a second data diode before and a second Da tendiode switched after the decryption device who the. This can be used to ensure that data stored in tion from the first to the second network who the, for example, attack data, via the second one-way onsunpath path neither to the decryption device nor the two th network can be transmitted. As a result, the decryption device and the second network are protected against attacks on different locations of the second path of the one-way communication path.
- the device comprises at least one further encryption device which is part of the first one-way communication path.
- the device comprises at least one further decryption device which is part of the second one-way communication path.
- the further encryption device is in particular like the encryption device described above removable det and arranged to encrypt data transmitted from the first to the second network, cryptographically ver.
- the further encryption device can have a further encryption key.
- the further encryption device is, for example, upstream or downstream of the encryption device along the first one-way communication path.
- the further encryption device can be implemented differently and / or independently of the previously described encryption device.
- the encryption device and the further encryption device enable, in particular, a double encryption with different implementations. If one of the encryption devices does not properly encrypt the data, the encryption of the data is ensured by the other encryption device. This can increase the security of the data transmission who the, because the data is encrypted, even if one of the encryption devices is attacked.
- the above- transmission device can have any number of such additional encryption devices Ver.
- the further decryption device is in particular like the decryption device described above removablebil det and arranged to cryptographically decrypt data that are transmitted from the second to the first network.
- the further Decrypting device can have a further decryption key.
- the further decryption device is, for example, the decryption device along the second one-way commu nication path serially upstream or downstream.
- the further decoding device can be implemented differently and / or independently of the previously described decoding device.
- the decryption device and the further decision-making device allow, in particular, a double decryption with different implementations. If one of the decryption devices does not properly decrypt the data, decryption of the data is ensured by the other decryption device. Thereby, the security of the data transmission can be increased because the data is decrypted properly even if one of the decryption devices is attacked.
- the transmission device can have any number of such further decoding devices.
- At least one first data diode is arranged serially between the two encryption devices.
- at least one second data diode is arranged in series between the two decoding devices.
- the first network is a private network.
- the second network is a public network.
- the first communication path comprises a first data processing device for processing the data transmitted from the first to the second network.
- the second one-way communication path comprises a second data processing device for processing the data transmitted from the second to the first network.
- the first and second data processing devices include, for example, applications that process and / or process transmitted data, for example, to perform data analysis. and / or the encrypting device and / or the decrypting device are executed as the data processing device.
- the device further comprises a control device for setting up the closure device and / or the decoding device.
- the controller may negotiate the encryption keys and encryption keys for the encryption device and the decryption device.
- the method is performed with the device according to the first aspect or according to an embodiment of the first aspect.
- a computer program product which causes the implementation of the method according to the second aspect or according to an embodiment of the second aspect on a program-controlled device.
- a computer program product such as a computer program means may, for example, be used as a storage medium, e.g.
- Fig. 1 shows an apparatus for transmitting data
- Fig. 2 shows an apparatus for transmitting data
- Fig. 3 shows an apparatus for transmitting data
- Fig. 4 shows an apparatus for transmitting data
- Fig. 5 shows a first example of a transmission system
- Fig. Fig. 6 shows a second example of a transmission system
- FIG. 7 shows a method of transferring data between a first and a second network according to an embodiment.
- the same or functionally identical elements have been given the same reference numerals, unless stated otherwise.
- FIG. 1 shows an apparatus 1 for transmitting data between a first and a second network 2, 3 according to a first embodiment.
- the first network 2 is an industrial control network which serves to control non-constituted production machines.
- the second network 3 is a public network formed as an Internet of Things network.
- the second network 3 has several Internet-of-things interfaces 32 for exchanging data with a plurality of networks.
- Data are exchanged between the first and the second network 2, 3, which takes place exclusively via the device 1.
- the data transmitted from the first network 2 to the second network 3 are, in particular, production data and / or sensor data describing the production by the production machines of the first network 2.
- the data transmitted from the second network 3 to the first network 2 is e.g. Control data for driving the production machines of the first network 2.
- the device 1 is connected by means of cable 31 between the two networks 2, 3.
- the device 1 has a first one-way communication path 4, which is used exclusively for data transmission from the first network 2 to the second network 3, and a second one-way communication path 5, which serves for exclusive data transmission from the second network 3 to the first network 2 ,
- the first one-way communication path 4 includes a first Da tendiode 6 and an encryption device 8, wherein the first data diode 6 along the first one-way communication path 4 of the encryption device 8 is connected upstream.
- the first data diode 6 can only pass data transmitted from the first to the second network 2, 3.
- For Data transmitted from the second network 3 to the first network 2 is the first data diode 6 inoperative.
- the first data diode 6 and the encryption device 8 are connected to each other via a cable 31.
- the encryption device 8 has an encryption key with which it can cryptographically encrypt the data that is transmitted from the first network 2 to the second network 3. This prevents secret data from being sent unprotected to facilities located outside the first network 2.
- the encryption device 8 If the encryption device 8 is damaged by a hacker attack, no attack data resulting from the attack can be transmitted to the first network 2 via the first one-way communication path 4, whereby the first network 2 is protected.
- the second one-way communication path 5 comprises a second Da tendiode 7 and a decryption device 9, wherein the second data diode 7 along the second one-way communication path 5 of the decryption device 9 is connected upstream.
- the second data diode 7 can only pass data transmitted from the second to the first network 3, 2.
- the second data diode 7 is un transmissive.
- the second data diode 7 and the decryption device 9 are connected to each other via a cable 31.
- the decryption device 9 has a decryption key, with which it can cryptographically decrypt the data that transmits from the second network 3 to the first network 2 the. This ensures that all data received by the second network 3 was properly encrypted and originated from a reliable sender. If the decryption device 9 is damaged by a hackeran attack, can not be transferred through the second path Einwegkommuni cation 5 attack data resulting from the attack to the second network 3, whereby the second network 3 is protected.
- Fig. 1 the direction of the data exchange within the device 1 is schematically represented by arrows.
- FIG. 2 shows a device 10 for transferring data between a first and a second network 2, 3 according to a second embodiment.
- the device 10 according to the second embodiment differs from the device 1 shown in FIG. 1 according to the first embodiment in that the first one-way communication path 4 has an additional first diode 16 and the second one-way communication path 5 has an additional second diode 17 ,
- the encryption device 8 is switched along the first one-way communication path 4 se between the first two data diodes 6, 16.
- the arrangement of the additional first data diode 16 in the first one-way communication path 4 prevents data transmitted from the second network 3 to the first network 2 from ever being able to reach the encryption device 8.
- the decryption device 9 is connected in series along the second one-way communication path 5 between the two two-th data diodes 7, 17.
- the arrangement of the additional second data diode 17 in the second one-way communication path 5 prevents data, which is transmitted from the first network 2 to the second network 3, from ever reaching the decryption device 9
- the device 10 furthermore has a control device 20 for setting up the encryption device 8 and the decrypting device 9.
- the controller 20 serves to generate the encryption key and the decryption key.
- the encryption key and the decryption key can be generated when the encryption device 8 and the decryption device 9 are initialized.
- FIG. 3 shows a device 11 for transferring data between a first and a second network 2, 3 according to a third embodiment.
- the device 11 according to the third embodiment differs from the devices 1, 10 according to the first and second embodiments by the components provided in the first and second disposable communication paths 4, 5.
- the first communication path 4 includes the first data diode
- the second communication path 5 includes the second data diode
- Two encryption devices 8, 18 serve to ensure the encryption of the data transmitted from the first network 2 to the second network 3, even if one of the encryption devices
- Two decryption devices 9, 19 serve to ensure the decoding of the data transmitted from the second network 3 to the first network 2, even if one of the decryption devices 9, 19 fails or attacked. This ensures that the data is always properly encrypted / decrypted by the device 11.
- FIG. 4 shows a device 12 for transferring data between a first and a second network 2, 3 according to a fourth embodiment.
- the device 12 according to the fourth embodiment differs from the devices 1 according to the first embodiment in that the first one-way communication path 4 has a first data processing device 21 and the second one-way communication path 5 has a second data transmission device 22.
- the first data processing device 21 is the first Da tendiode 6 in the first one-way communication channel 4 nachge switched. It comprises two applications 24, 25 which evaluate the data transmitted from the first network 2 to the second network 3. For this purpose, the applications 24, 25 carry out calculations on the data.
- the bearbei processing device 21 also serves to encrypt the data and is thus out forms as an encryption device 6, which is also suitable for data processing.
- the second data processing device 22 is connected downstream of the second data diode 7 in the second one-way communication channel 5. It also comprises two applications 28, 29 which evaluate the data transmitted from the second network 3 to the first network 2. For this purpose, the applications 28, 29 carry out calculations on the data and check whether the data originate from a reliable transmitter.
- the data processing device 22 also serves to decipher the data and is thus used as a decryption device. direction 7 formed, which is also suitable for data processing geeig net.
- the device 12 according to the fourth embodiment also comprises a bidirectional interface 23 which can both transmit data to the second network 3 and receive data from the second network 3.
- the transmission system 40 is used to transfer data between the first network 2 and another network 30 via the second network network 3.
- the transmission system 40 includes for this purpose in particular the device 10 according to the second embodiment, which has been described with reference to FIG. 2 BE, as well as a further device 13 which is formed analogous log to the device 10.
- first data is transmitted from the first network 2 via the device 10 to the second network 3, and then transmitted from the second network 3 via a device 13 to the further network 30.
- a data transmission from the further network 30 to the first network 2 is exactly the other way round.
- the further network 30 of the transmission system 40 may be formed as an industrial network.
- the devices 10, 13 as VPN interfaces (Virtual Private Network) for the networks 2, 30 are formed.
- the transmission system 40 enables with the devices 10, 13 a particularly secure data transmission between the networks 2 and 30.
- Fig. 6 shows a second example of a transmission system 41.
- the transmission system 41 is used for the transmission of data between the first network 2 and the other Network 30 via the second network 3.
- the transmission system 41 according to the second example differs from the transmission system 40 according to the first example of FIG.
- the devices 14, 15 are analogous to each other. They include a combination of the components described with respect to the devices 1, 10-13 of FIGS. 1-5.
- the first one-way communication path 4 of the devices 14, 15 comprises the first data diode 6, the first data processing device 21, the first data diode 16, the shutters treatment device 8 and the first data diode 26, which are arranged in this order serially along the first communication path 4.
- the second communication path 5 to summarizes the second data diode 27, the Entcryptionseinrich device 9, the second data diode 17, the second bearbei processing device 22 and the second data diode 7, which are arranged in this order serially along the second communication onspfads 5. Furthermore, the devices 14, 15 each have a control device 20.
- the transmission system 40 with the devices 10, 13 enables particularly secure data transmission between the networks 2 and 30.
- Fig. 7 shows a method for transmitting data between a first and a second network 2, 3 according to egg ner first embodiment. The method can be carried out with one of the previously described devices 1, 10-15.
- a preparation step SO one of the previously described devices 1, 10-15 is provided.
- a step S1 an exclusive transfer of data takes place from the first to the second network 2, 3 via the first one-way communication path 4 with the first data diode 6 and the encryption device 8.
- a step S2 it follows an exclusive transfer of data from the second network 3 to the first network 2 via the second A wegkommunikationspfad 5 with the second data diode 7 and the decryption device.
- the steps S1 and S2 may be parallel to each other or to each other. In this case, the step S2 can also be performed before the step S1.
- the components arranged in the first one-way communication path 4 and in the second one-way communication path 5 may be selected from the components described with reference to FIGS. 1 to 6 and combined differently than described.
- the described devices 1, 10 - 15 can be modi mo.
- the device 1 may have a bidirectional interface 23 arranged on the side of the second network 3.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Computer Hardware Design (AREA)
- Computing Systems (AREA)
- General Engineering & Computer Science (AREA)
- Data Exchanges In Wide-Area Networks (AREA)
- Small-Scale Networks (AREA)
Abstract
Description
Claims
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| DE102017223099.1A DE102017223099A1 (de) | 2017-12-18 | 2017-12-18 | Vorrichtung und Verfahren zum Übertragen von Daten zwischen einem ersten und einem zweiten Netzwerk |
| PCT/EP2018/081294 WO2019120778A1 (de) | 2017-12-18 | 2018-11-15 | Vorrichtung und verfahren zum übertragen von daten zwischen einem ersten und einem zweiten netzwerk |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| EP3704847A1 true EP3704847A1 (de) | 2020-09-09 |
Family
ID=64500331
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| EP18810905.2A Withdrawn EP3704847A1 (de) | 2017-12-18 | 2018-11-15 | Vorrichtung und verfahren zum übertragen von daten zwischen einem ersten und einem zweiten netzwerk |
Country Status (6)
| Country | Link |
|---|---|
| US (1) | US20210176223A1 (de) |
| EP (1) | EP3704847A1 (de) |
| CN (1) | CN111543036A (de) |
| AU (1) | AU2018389883B2 (de) |
| DE (1) | DE102017223099A1 (de) |
| WO (1) | WO2019120778A1 (de) |
Families Citing this family (24)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US11030618B1 (en) | 2016-09-30 | 2021-06-08 | Winkk, Inc. | Authentication and personal data sharing for partner services using out-of-band optical mark recognition |
| US11637694B2 (en) | 2018-07-16 | 2023-04-25 | Winkk, Inc. | Secret material exchange and authentication cryptography operations |
| KR102228686B1 (ko) * | 2019-04-18 | 2021-03-16 | (주) 시스메이트 | 단방향 보안 게이트웨이 시스템에서 물리적으로 격리된 단방향 데이터 송신장치와 수신장치 간의 안전한 관리용 통신 채널을 제공하는 방법 및 이를 위한 2개의 단방향 통신채널을 제공하는 단방향 데이터 송수신 장치 |
| US11928193B2 (en) | 2019-12-10 | 2024-03-12 | Winkk, Inc. | Multi-factor authentication using behavior and machine learning |
| US11328042B2 (en) | 2019-12-10 | 2022-05-10 | Winkk, Inc. | Automated transparent login without saved credentials or passwords |
| US12153678B2 (en) | 2019-12-10 | 2024-11-26 | Winkk, Inc. | Analytics with shared traits |
| US11936787B2 (en) | 2019-12-10 | 2024-03-19 | Winkk, Inc. | User identification proofing using a combination of user responses to system turing tests using biometric methods |
| US12132763B2 (en) | 2019-12-10 | 2024-10-29 | Winkk, Inc. | Bus for aggregated trust framework |
| US12143419B2 (en) | 2019-12-10 | 2024-11-12 | Winkk, Inc. | Aggregated trust framework |
| US12335399B2 (en) | 2019-12-10 | 2025-06-17 | Winkk, Inc. | User as a password |
| US11652815B2 (en) | 2019-12-10 | 2023-05-16 | Winkk, Inc. | Security platform architecture |
| US12073378B2 (en) | 2019-12-10 | 2024-08-27 | Winkk, Inc. | Method and apparatus for electronic transactions using personal computing devices and proxy services |
| US11588794B2 (en) | 2019-12-10 | 2023-02-21 | Winkk, Inc. | Method and apparatus for secure application framework and platform |
| US12341790B2 (en) | 2019-12-10 | 2025-06-24 | Winkk, Inc. | Device behavior analytics |
| US11657140B2 (en) | 2019-12-10 | 2023-05-23 | Winkk, Inc. | Device handoff identification proofing using behavioral analytics |
| US11574045B2 (en) | 2019-12-10 | 2023-02-07 | Winkk, Inc. | Automated ID proofing using a random multitude of real-time behavioral biometric samplings |
| US11553337B2 (en) | 2019-12-10 | 2023-01-10 | Winkk, Inc. | Method and apparatus for encryption key exchange with enhanced security through opti-encryption channel |
| DE102020109896A1 (de) * | 2020-04-08 | 2021-10-14 | Endress + Hauser Process Solutions Ag | Verfahren zum Verschlüsseln von Daten eines Feldgeräts |
| US11843943B2 (en) | 2021-06-04 | 2023-12-12 | Winkk, Inc. | Dynamic key exchange for moving target |
| US12095751B2 (en) * | 2021-06-04 | 2024-09-17 | Winkk, Inc. | Encryption for one-way data stream |
| JP2024536788A (ja) | 2021-09-17 | 2024-10-08 | チェン リム、ハン | 通信リンク |
| US12425230B2 (en) | 2022-09-21 | 2025-09-23 | Winkk, Inc. | System for authentication, digital signatures and exposed and unregistered public certificate use |
| US12513135B2 (en) * | 2022-11-21 | 2025-12-30 | Gm Cruise Holdings Llc | One-way segregation of AV subsystems and user devices |
| US12047460B2 (en) * | 2022-12-01 | 2024-07-23 | Saudi Arabian Oil Company | Cross-communication links for a unidirectional, bilateral data network |
Family Cites Families (22)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| WO2005119462A1 (en) * | 2004-06-01 | 2005-12-15 | The Commonwealth Of Australia | Multilevel secure information transfer device |
| DE102007038763A1 (de) | 2007-08-16 | 2009-02-19 | Siemens Ag | Verfahren und Vorrichtung zur Sicherung eines Programms gegen eine Kontrollflussmanipulation und gegen einen fehlerhaften Programmablauf |
| DE102007040343B4 (de) | 2007-08-27 | 2010-12-30 | Siemens Ag | Vorrichtung und Verfahren zum Erzeugen einer Zufallsbitfolge |
| DE102008018678B4 (de) | 2008-04-14 | 2011-02-03 | Siemens Aktiengesellschaft | Vorrichtung und Verfahren zum Erzeugen einer Zufallsbitfolge |
| DE102008061483A1 (de) | 2008-12-10 | 2010-06-24 | Siemens Aktiengesellschaft | Verfahren und Vorrichtung zum Verarbeiten von Daten |
| DE102011007572A1 (de) | 2011-04-18 | 2012-10-18 | Siemens Aktiengesellschaft | Verfahren zur Überwachung eines Tamperschutzes sowie Überwachungssystem für ein Feldgerät mit Tamperschutz |
| US8838955B2 (en) * | 2011-08-24 | 2014-09-16 | General Electric Company | Two-way, secure, data communication within critical infrastructures |
| DE102011087804A1 (de) | 2011-12-06 | 2013-06-06 | Siemens Aktiengesellschaft | Vorrichtung und Verfahren zum Entschlüsseln von Daten |
| DE102011088502B3 (de) | 2011-12-14 | 2013-05-08 | Siemens Aktiengesellschaft | Verfahren und Vorrichtung zur Absicherung von Blockchiffren gegen Template-Attacken |
| US8588416B2 (en) * | 2012-01-12 | 2013-11-19 | The Boeing Company | System and method for secure communication |
| US10171540B2 (en) * | 2012-09-07 | 2019-01-01 | High Sec Labs Ltd | Method and apparatus for streaming video security |
| DE102012217743B4 (de) | 2012-09-28 | 2018-10-31 | Siemens Ag | Überprüfung einer Integrität von Eigenschaftsdaten eines Gerätes durch ein Prüfgerät |
| DE102013200017A1 (de) | 2013-01-02 | 2014-07-03 | Siemens Aktiengesellschaft | RFID-Tag und Verfahren zum Betreiben eines RFID-Tags |
| DE102013208152A1 (de) | 2013-05-03 | 2014-11-20 | Siemens Aktiengesellschaft | Vorrichtung und Verfahren zum Erzeugen von Zufallsbits |
| US20150009874A1 (en) * | 2013-07-08 | 2015-01-08 | Amazon Technologies, Inc. | Techniques for optimizing propagation of multiple types of data |
| DE102013218373A1 (de) * | 2013-09-13 | 2015-03-19 | Siemens Aktiengesellschaft | Verfahren und System zur kryptographischen Absicherung eines vorgegebenen Nachrichtenbearbeitungsflusses |
| DE102013222218A1 (de) | 2013-10-31 | 2014-05-22 | Siemens Aktiengesellschaft | Konstruieren einer Schaltung geeignet zur Erzeugung von Zufallsbits und Schaltung zur Erzeugung von Zufallsbits |
| US9674698B2 (en) * | 2014-07-22 | 2017-06-06 | Nokia Technologies Oy | Method and apparatus for providing an anonymous communication session |
| US10320761B2 (en) * | 2015-11-02 | 2019-06-11 | Servicenow, Inc. | Selective encryption configuration |
| GB201520380D0 (en) * | 2015-11-19 | 2016-01-06 | Qinetiq Ltd | A data hub for a cross-domain communication system |
| KR101862348B1 (ko) | 2016-02-09 | 2018-05-29 | 지멘스 악티엔게젤샤프트 | 프로그램 명령들의 안전한 실행을 위한 방법 및 실행 환경 |
| CN106385404B (zh) * | 2016-08-31 | 2019-08-02 | 华北电力大学(保定) | 基于移动终端的电力信息系统构建方法 |
-
2017
- 2017-12-18 DE DE102017223099.1A patent/DE102017223099A1/de not_active Withdrawn
-
2018
- 2018-11-15 AU AU2018389883A patent/AU2018389883B2/en not_active Ceased
- 2018-11-15 EP EP18810905.2A patent/EP3704847A1/de not_active Withdrawn
- 2018-11-15 WO PCT/EP2018/081294 patent/WO2019120778A1/de not_active Ceased
- 2018-11-15 CN CN201880081924.5A patent/CN111543036A/zh active Pending
- 2018-11-15 US US16/769,619 patent/US20210176223A1/en not_active Abandoned
Non-Patent Citations (1)
| Title |
|---|
| HAMED OKHRAVI ET AL: "Data diodes in support of trustworthy cyber infrastructure", CYBER SECURITY AND INFORMATION INTELLIGENCE RESEARCH, ACM, 2 PENN PLAZA, SUITE 701 NEW YORK NY 10121-0701 USA, 21 April 2010 (2010-04-21), pages 1 - 4, XP058199308, ISBN: 978-1-4503-0017-9, DOI: 10.1145/1852666.1852692 * |
Also Published As
| Publication number | Publication date |
|---|---|
| US20210176223A1 (en) | 2021-06-10 |
| DE102017223099A1 (de) | 2019-06-19 |
| AU2018389883B2 (en) | 2021-02-11 |
| AU2018389883A1 (en) | 2020-06-25 |
| WO2019120778A1 (de) | 2019-06-27 |
| CN111543036A (zh) | 2020-08-14 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| EP3704847A1 (de) | Vorrichtung und verfahren zum übertragen von daten zwischen einem ersten und einem zweiten netzwerk | |
| DE60308384T2 (de) | Vorrichtung zum gesicherten datenaustausch zwischen zwei vorrichtungen | |
| DE102009024604B4 (de) | Erzeugung eines Session-Schlüssels zur Authentisierung und sicheren Datenübertragung | |
| EP3562115A1 (de) | Geschützte übertragung von daten mit hilfe post-quanten kryptographie | |
| EP2572494B1 (de) | Verfahren und system zur sicheren datenübertragung mit einer vpn- box | |
| WO2018010949A1 (de) | Verfahren zum aufbau gesicherter kommunikationsverbindungen zu einem industriellen automatisierungssystem und firewall-system | |
| EP3518489A1 (de) | Verfahren und system zur offenlegung mindestens eines kryptographischen schlüssels | |
| EP3559854B1 (de) | Sicherheitsgerät und feldbussystem zur unterstützung einer sicheren kommunikation über einen feldbus | |
| EP3422657A1 (de) | Verfahren und sicherheits-steuerungseinrichtungen zum senden und empfangen kryptographisch geschützter netzwerkpakete | |
| DE102017118164A1 (de) | Kryptographische schaltung und datenverarbeitung | |
| DE102005025169B4 (de) | Kommunikationsvorrichtung und Verfahren zur Übermittlung von Daten | |
| EP3759958B1 (de) | Verfahren, vorrichtung und computerprogrammprodukt zur überwachung einer verschlüsselten verbindung in einem netzwerk | |
| EP3767909B1 (de) | Verfahren und kommunikationseinheit zur kryptographisch geschützten unidirektionalen datenübertragung von nutzdaten zwischen zwei netzwerken | |
| EP2499594A1 (de) | Verfahren und system zum vertraulichen bereitstellen von softwarekomponenten | |
| AT520170B1 (de) | Verfahren zum sicheren Administrieren eines Schlosses, insbesondere für einen Safe, mittels eines Computers | |
| EP2186285B1 (de) | Verfahren und einrichtung zur authentisierung übertragener nutzdaten | |
| EP2184695A1 (de) | Verfahren zum Kombinieren von Daten mit einer zur Verarbeitung der Daten vorgesehenen Vorrichtung, korrespondierende Funktionalität zur Ausführung einzelner Schritte des Verfahrens und Computerprogram zur Implementierung des Verfahrens | |
| EP2898635B1 (de) | System und verfahren zur wartung einer werkzeugmaschine | |
| EP3489775A1 (de) | Kryptographischer schutz von parametern zur steuerung eines aktors | |
| DE102007023206B4 (de) | Verfahren und Einrichtung zur sicheren Erzeugung und Verwaltung von Schlüsseln und deren Nutzung in Netzwerken zur sicheren Übertragung von Daten | |
| DE202016103460U1 (de) | Kommunikationsteilnehmer eines Feldbussystems und Feldbussystem | |
| WO2018091703A1 (de) | Verfahren und vorrichtung zum sichern einer elektronischen datenübertragung | |
| EP3515033A1 (de) | Verfahren und vorrichtung zum übertragen eines datensatzes von einer ersten an eine zweite einrichtung | |
| EP2351319A2 (de) | Datenkommunikation mit portablem endgerät | |
| DE4420967C2 (de) | Entschlüsselungseinrichtung von digitalen Informationen und Verfahren zur Durchführung der Ver- und Entschlüsselung dieser mit Hilfe der Entschlüsselungseinrichtung |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: UNKNOWN |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: THE INTERNATIONAL PUBLICATION HAS BEEN MADE |
|
| PUAI | Public reference made under article 153(3) epc to a published international application that has entered the european phase |
Free format text: ORIGINAL CODE: 0009012 |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: REQUEST FOR EXAMINATION WAS MADE |
|
| 17P | Request for examination filed |
Effective date: 20200602 |
|
| AK | Designated contracting states |
Kind code of ref document: A1 Designated state(s): AL AT BE BG CH CY CZ DE DK EE ES FI FR GB GR HR HU IE IS IT LI LT LU LV MC MK MT NL NO PL PT RO RS SE SI SK SM TR |
|
| AX | Request for extension of the european patent |
Extension state: BA ME |
|
| DAV | Request for validation of the european patent (deleted) | ||
| DAX | Request for extension of the european patent (deleted) | ||
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: EXAMINATION IS IN PROGRESS |
|
| 17Q | First examination report despatched |
Effective date: 20220128 |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: THE APPLICATION IS DEEMED TO BE WITHDRAWN |
|
| 18D | Application deemed to be withdrawn |
Effective date: 20220608 |