Communication module

US12301552B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-12301552-B2
Application numberUS-201917312387-A
CountryUS
Kind codeB2
Filing dateDec 12, 2019
Priority dateDec 13, 2018
Publication dateMay 13, 2025
Grant dateMay 13, 2025

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

The invention relates to a communication module for transmitting data between at least one hardware component which is integrated into an internal network of a technical system and a back-end computer system which is connected to a packet-switched data network. The communication module has a device-proximal gateway and a network-proximal gateway, which are connected to one another via a point-to-point connection without intermediate stations. The network-proximal gateway provides a data transmission interface between the packet-switched data network and the point-to-point connection and the device-proximal gateway provides a data transmission interface between the point-to-point connection and the internal network.

First claim

Opening claim text (preview).

The invention claimed is: 1. A communication module for data transmission between at least one hardware component which is integrated into an internal network of a technical system and a back-end computer system which is connected to a packet-switched data network, characterized in that the communication module comprises: a point-to-point connection, wherein communication is carried out via the point-to-point connection according to a non-routable protocol that prevents rerouting of communication and precludes unauthorized access to the internal network, a device-proximal gateway is configured and arranged to provide a data transmission interface between the point-to-point connection and the internal network, and a network-proximal gateway connected to the device-proximal gateway via the point-to-point connection without intermediate stations, the network-proximal gateway configured and arranged to provide a data transmission interface between the packet-switched data network and the point-to-point connection, wherein the point-to-point connection is the only connection between the network-proximal gateway and the device-proximal gateway, and wherein the network-proximal gateway is directly connected to the packet-switched data network without intermediate stations. 2. The communication module according to claim 1 , characterized in that the device-proximal gateway and/or the network-proximal gateway has a gateway security module. 3. The communication module according to claim 2 , characterized in that the at least one gateway security module has a card interface configured and arranged to receive a processor chip card. 4. The communication module according to claim 1 , wherein the point-to-point connection is a direct connection via a serial bus system. 5. A technical system comprising: a communication module according to claim 1 , at least one hardware component, and at least one internal network. 6. The technical system according to claim 5 , characterized in that the at least one hardware component has a security controller with an integrated cryptoprocessor, a non-volatile memory and a volatile memory. 7. The technical system according to claim 5 , characterized in that the technical system is a vehicle with one of autonomy levels 1 to 5. 8. The technical system according to claim 5 , characterized in that the technical system is a machine arrangement configured and arranged to be controlled by an automation system, in particular a test bench. 9. A method for the transmission of device data of a hardware component, which is integrated in an internal network of a technical system, to a back-end computer system which is connected to a packet-switched data network, the method including the following steps: transmitting the device data from the hardware component via the internal network to a device-proximal gateway, transmitting the device data from the device-proximal gateway via a point-to-point connection to a network-proximal gateway, wherein communication is carried out via the point-to-point connection according to a non-routable protocol that prevents rerouting of communication and precludes unauthorized access to the internal network, and wherein the point-to-point connection is the only connection between the network-proximal gateway and the device-proximal gateway, converting the device data into an encrypted instance of the device data by the device-proximal gateway or the network-proximal gateway, and transmitting the encrypted instance of the device data from the network-proximal gateway via the packet-switched data network to the back-end computer system, wherein the network-proximal gateway encrypts the encrypted instance of the device data before it is transmitted over the packet-switched data network in accordance with a network encryption protocol, and wherein the encrypted instance of the device data contains check data which allows the back-end computing system and/or another authorized data receiver to check the integrity and/or authenticity of the device data. 10. The method according to claim 9 , characterized in that the method further includes the following steps: creating an encrypted instance of the device data using a public key of the back-end computer system by the device-proximal gateway using the gateway security module of the device-proximal gateway, or by the network-proximal gateway using the gateway security module of the network-proximal gateway. 11. The method according to claim 9 , characterized in that the step of transmitting the encrypted instance of the device data via the packet-switched data network includes transmitting the encrypted instance to a broker in accordance with a protocol that functions purely via push mechanisms. 12. A method for storing update data in a device memory of a hardware component integrated in an internal network, wherein the update data for the hardware component are provided by a back-end computer system and wherein the method including the following steps: receiving an encrypted instance of the update data by a network-proximal gateway via a packet-switched data network from a back-end computer system, transmitting the update data from the network-proximal gateway via a point-to-point connection to the device-proximal gateway, wherein communication is carried out via the point-to-point connection according to a non-routable protocol that prevents rerouting of communication and precludes unauthorized access to the internal network and the point-to-point connection is the only connection between the network-proximal gateway and the device-proximal gateway, transmitting the update data to the hardware component via the internal network, decrypting the encrypted instance of the update data by the device-proximal gateway or the network-proximal gateway, and storing the decrypted update data in the device memory of the hardware component, wherein the encrypted instance of the update data contains check data which allows the gateway security module of the device-proximal gateway, and/or the gateway security module of the network-proximal gateway and/or the security controller of the hardware component, to check the integrity and/or authenticity of the update data. 13. The method according to claim 12 , characterized in that the encrypted instance of the update data is created by the back-end computer system and/or an authorized data transmitter using a public key of the hardware component and/or the device-proximal gateway and/or the network-proximal gateway. 14. The method according to claim 12 , characterized in that the method further includes the following steps: decrypting the encrypted instance of the update data by the network-proximal gateway using the gateway security module of the network-proximal gateway, or the device-proximal gateway using the gateway security module of the device-proximal gateway. 15. The method according to claim 12 , characterized in that the update data includes firmware, application software and/or parameter data of the hardware component. 16. The method according to claim 12 , characterized in that the step of receiving an encrypted instance of the update data includes retrieving the encrypted instance of the update data from a broker and takes place in accordance with a protocol which functions purely via push mechanisms.

Assignees

Inventors

Classifications

  • the transportation system being a vehicle · CPC title

  • Bus for use in automation systems · CPC title

  • involving the movement of software or configuration parameters  (network booting or remote initial program loading [RIPL] G06F9/4416) · CPC title

  • H04L67/104Primary

    Peer-to-peer [P2P] networks · CPC title

  • using an additional device, e.g. smartcard, SIM or a different communication terminal (cryptographic mechanisms or cryptographic arrangements for entity authentication involving additional secure or trusted devices H04L9/3234) · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US12301552B2 cover?
The invention relates to a communication module for transmitting data between at least one hardware component which is integrated into an internal network of a technical system and a back-end computer system which is connected to a packet-switched data network. The communication module has a device-proximal gateway and a network-proximal gateway, which are connected to one another via a point-t…
Who is the assignee on this patent?
Avl List Gmbh
What technology area does this patent fall under?
Primary CPC classification H04L67/104. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue May 13 2025 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 11 related publications on this page (citations in our corpus or others sharing the same primary CPC).