IP Library Patent Application 14585746
Patent Application
App. No. 14/585,746

SECURE MESSAGE TRANSMISSION

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
14/585,746
Abstract

A method and system are provided for securing messages within a communication network of an industrial process control system, such as a substation automation system. A multi-block message to be transmitted via a communication network is secured by a block-based authentication, encryption and/or integrity information. Only residue of the previous block in the form of block-based information is needed to generate the block based information of the next block. Therefore, the previous block can already be transmitted while block-based information of the next block is generated. The method and system of the present disclosure enable on-the-fly authentication of the multi-block message and authentication at an increased rate.

Claims (54)

1 . A method for securing a multi-block message in a communication network of an industrial process control system, the method comprising:

generating block authentication information for a block of the message based on characters of the block and based on block authentication information of a previous block while transmitting or forwarding the previous block of the message;

generating a message authentication signature as a summary of the authentication information of each block of the message; and

appending the authentication signature to a final block of the message, or verifying a received authentication signature of the message.

2 . The method according to claim 1 , comprising:

encrypting a block of the message while transmitting an encrypted previous block of the message.

3 . The method according to claim 2 , comprising:

encrypting a block of the message, while generating the block authentication information of an encrypted previous block of the message.

4 . The method according to the claim 1 , comprising:

verifying the received authentication signature by comparing the received authentication signature with the generated authentication signature.

5 . The method according to claim 1 , comprising one of:

transmitting the message to a second communication network device via a communication network; and

forwarding the message to an upper layer of a communication stack of the communication network device.

6 . The method according to claim 1 , comprising performing an integrity check operation, the integrity check operation including:

generating an integrity check value for a block of the message based on the characters of the block and based on the integrity check value of the previous block while transmitting the previous block of the message;

generating an integrity checksum based on the integrity check value of the blocks of the message; and

appending the integrity checksum to the message when transmitting the message, or verifying a received integrity checksum of the message when receiving the message.

7 . The method according to claim 6 , wherein the integrity check operation is performed after appending the authentication signature to the message for outgoing messages, or before removing the authentication signature from the message for incoming messages.

8 . The method according to claim 1 , comprising:

appending a tag to the message indicative of a failed authentication for forwarding the message to an upper layer processing unit of a communication network device.

9 . The method according to claim 1 , wherein the industrial process control system is a substation automation system.

10 . The method according to claim 1 , wherein the authentication signature is appended to the final block of the message when transmitting the message, or the received authentication signature of the message is verified when receiving the message.

11 . The method according to claim 2 , comprising performing an integrity check operation, the integrity check operation including:

generating an integrity check value for a block of the message based on the characters of the block and based on the integrity check value of the previous block while transmitting the previous block of the message;

generating an integrity checksum based on the integrity check value of the blocks of the message; and

appending the integrity checksum to the message when transmitting the message, or verifying a received integrity checksum of the message when receiving the message.

12 . The method according to claim 11 , wherein the integrity check operation is performed after appending the authentication signature to the message for outgoing messages, or before removing the authentication signature from the message for incoming messages.

13 . The method according to claim 3 , comprising performing an integrity check operation, the integrity check operation including:

generating an integrity check value for a block of the message based on the characters of the block and based on the integrity check value of the previous block while transmitting the previous block of the message;

generating an integrity checksum based on the integrity check value of the blocks of the message; and

appending the integrity checksum to the message when transmitting the message, or verifying a received integrity checksum of the message when receiving the message.

14 . The method according to claim 13 , wherein the integrity check operation is performed after appending the authentication signature to the message for outgoing messages, or before removing the authentication signature from the message for incoming messages.

15 . The method according to claim 4 , comprising performing an integrity check operation, the integrity check operation including:

generating an integrity check value for a block of the message based on the characters of the block and based on the integrity check value of the previous block while transmitting the previous block of the message;

generating an integrity checksum based on the integrity check value of the blocks of the message; and

appending the integrity checksum to the message when transmitting the message, or verifying a received integrity checksum of the message when receiving the message.

16 . The method according to claim 15 , wherein the integrity check operation is performed after appending the authentication signature to the message for outgoing messages, or before removing the authentication signature from the message for incoming messages.

17 . The method according to claim 5 , comprising performing an integrity check operation, the integrity check operation including:

generating an integrity check value for a block of the message based on the characters of the block and based on the integrity check value of the previous block while transmitting the previous block of the message;

generating an integrity checksum based on the integrity check value of the blocks of the message; and

appending the integrity checksum to the message when transmitting the message, or verifying a received integrity checksum of the message when receiving the message.

18 . The method according to claim 17 , wherein the integrity check operation is performed after appending the authentication signature to the message for outgoing messages, or before removing the authentication signature from the message for incoming messages.

19 . A communication network system of an industrial process control system, the communication network system comprising a communication network device configured to secure a multi-block message in the communication network, the communication network device including a processor configured to:

generate block authentication information for a block of the message based on the characters of the block and based on block authentication information of a previous block while transmitting the previous block of the message;

encrypt a block of the message while transmitting an encrypted previous block of the message;

generate a message authentication signature based on a summary of the authentication information of each block of the message; and

append the authentication signature to a final block of the message, or verify a received authentication signature appended to the message.

20 . The communication network system according to claim 19 , wherein the communication network device is located before one of a physical network interface, in-between two network interfaces, and before several output queues of a multiport bridging device.

21 . The communication network system according to claim 19 , wherein the industrial process control system is a substation automation system.

22 . The communication network system according to claim 19 , wherein the processor is configured to append the authentication signature to the final block of the message when transmitting the message, or verify the received authentication signature of the message when receiving the message.

23 . A non-transitory computer-readable recording medium having a computer program recorded thereon that, when executed by a processor of a communication network device, causes the communication network device to carry out a method of securing a multi-block message in a communication network of an industrial process control system, the method comprising:

generating block authentication information for a block of the message based on characters of the block and based on block authentication information of a previous block while transmitting or forwarding the previous block of the message;

generating a message authentication signature as a summary of the authentication information of each block of the message; and

appending the authentication signature to a final block of the message, or verifying a received authentication signature of the message.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 6, 2020
From: ABB SCHWEIZ AG
To: ABB POWER GRIDS SWITZERLAND AG
Reel/Frame 052916/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 16, 2015
From: KIRRMANN, HUBERT; ONAL, CAGRI
To: ABB RESEARCH LTD
Reel/Frame 035172/0110 →