Looking for breakthrough ideas for innovation challenges? Try Patsnap Eureka!

Secure isolation system applied to PROFINET industrial Ethernet

A technology of security isolation and Ethernet, which is applied in the security isolation of PROFINET industrial Ethernet, industrial Ethernet and information security, can solve the problems of no technology and products, insufficient investment in security technology research and development, etc., to prevent malicious attacks and prevent leakage Effect

Inactive Publication Date: 2016-11-23
INSTR TECH & ECONOMY INST P R CHINA
View PDF4 Cites 6 Cited by
  • Summary
  • Abstract
  • Description
  • Claims
  • Application Information

AI Technical Summary

Problems solved by technology

However, at present, domestic industrial control equipment and system manufacturers have seriously insufficient investment in the research and development of industrial control system security technology, and there are no related technologies and products in China.

Method used

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
View more

Image

Smart Image Click on the blue labels to locate them in the text.
Viewing Examples
Smart Image
  • Secure isolation system applied to PROFINET industrial Ethernet
  • Secure isolation system applied to PROFINET industrial Ethernet

Examples

Experimental program
Comparison scheme
Effect test

Embodiment Construction

[0015] The invention discloses a PORFINET safety isolation system that can be applied to the field for a long time. Based on the characteristics of PROFINET communication, the system of the invention determines the specific elements considered for identifying dangerous messages, such as: communication quality statistical data, communication messages Logical relationship, timing relationship of communication messages, protocol compliance of communication messages, specific application restrictions, etc., to improve the intelligence and efficiency of the security identification program.

[0016] The system of the present invention has a general firewall function, a deep PROFINET protocol analysis function, a hierarchical risk identification processing and alarm function, and a message forwarding function realized by hardware FPGA to improve real-time performance.

[0017] figure 1 The principle of the safety isolation system of the present invention is shown, and the system incl...

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to View More

PUM

No PUM Login to View More

Abstract

The invention discloses a secure isolation system applied to a PROFINET industrial Ethernet. Taking the PROFINET real-time Ethernet with wide application prospect as a research object, a PROFINET-based dedicated industrial information security device is developed by combining a PROFINET communication protocol depth detection function with a general industrial firewall function. Besides the functions of blocking network attack and defending viruses, preventing unauthorized access of a control network and field equipment and protecting general information security of data encryption, identity authentication and the like, the system also deeply analyzes the communication characteristic of the PROFINET network, and effectively recognizes abnormal communication situations on the network by predicting network communication behaviors according to configuration information and monitoring a communication relation, a real-time throughput and a non-real-time bandwidth at the initial networking stage, as well as deeply detecting data packets of a PROFINET application layer and the like. When a security threat appears, the contact between the PROFINET network and the external network is timely ''isolated'', and a hazard identification processing and alarm log is sent, so that security download can be performed on an out-of-control or fault main station.

Description

Technical field: [0001] The invention relates to the field of industrial Ethernet and information security, in particular to the field of safety isolation of PROFINET industrial Ethernet. Background technique: [0002] With the increasingly widespread application of industrial communication technology, in practice, industrial control systems are facing increasingly prominent security threats. In the past, less consideration was given to the security of industrial control systems, because the communication network of industrial control systems is a dedicated network, and it is generally believed that it is difficult to pose a security threat to industrial control systems. However, the current technological development trend is: the integration and intelligence of industrial enterprise management and control, that is, the management of industrial enterprises is not limited to upper-level information interaction, but frequently obtains data from the underlying production and ma...

Claims

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to View More

Application Information

Patent Timeline
no application Login to View More
Patent Type & Authority Applications(China)
IPC IPC(8): H04L29/06
Inventor 闫晓风赵艳领刘敏刘丹谢素芬
Owner INSTR TECH & ECONOMY INST P R CHINA
Who we serve
  • R&D Engineer
  • R&D Manager
  • IP Professional
Why Patsnap Eureka
  • Industry Leading Data Capabilities
  • Powerful AI technology
  • Patent DNA Extraction
Social media
Patsnap Eureka Blog
Learn More
PatSnap group products