Data collection device and method for operating as a one-way communication connection between a private network and a public network

By configuring a one-way communication connection, using time stamps and encryption in the data acquisition device of the industrial control system, and defining loops, the network attacks and data integrity verification problems faced by ICS are solved, and the security and integrity of data transmission are achieved.

CN115552844BActive Publication Date: 2025-05-13SIEMENS MOBILITY GMBH
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202180034632.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2020-05-12
Filing Date
2021-05-10
Publication Date
2025-05-13
Estimated Expiration
2041-05-10

AI Technical Summary

Technical Problem

Industrial control systems (ICS) are threatened by cyber attacks, and existing technologies are difficult to effectively prevent intrusions, especially in terms of information assurance and integrity verification.

Method used

By configuring a one-way communication connection in the data acquisition device, data integrity is ensured using timestamps and encryption, and loops are defined by monitoring devices and interceptors to achieve one-way communication.

Benefits of technology

It enhances the security capabilities of industrial control systems, ensures the integrity and security of data during transmission, and prevents cyber attacks and data tampering.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115552844B_ABST
    Figure CN115552844B_ABST
Patent Text Reader

Abstract

In an industrial system, a data acquisition device (106) can be configured to operate as a one-way communication connection between a private network (104) and a public network (102). The data acquisition device (106) can also be configured to time stamp the data, such as digitally signing the data with the time stamp, thereby ensuring data integrity on the one-way communication connection while maintaining physical isolation between the private network (104) and the public network (102).
Need to check novelty before this filing date? Find Prior Art

Description

Background Art

[0001] Cyber ​​attacks on private computer networks have long been at the forefront of detection and protection efforts using information technology. However, it is recognized herein that the threat of cyber attackers invading industrial systems such as automation and control systems that support critical infrastructure is gaining attention. Due to aspects such as vertical integration of production systems and horizontal integration of value chains, Industrial Control System (ICS) networks are often directly or indirectly connected to IT networks (office networks) and the Internet, providing cyber attackers with opportunities to penetrate this environment and exploit any existing weaknesses. It is further recognized herein that OT (Operational Technology) systems, such as Programmable Logic Controllers (PLCs), Distributed Control Systems (DCSs), Motion Controllers, Supervisory Control and Data Acquisition (SCADA) servers, and Human Machine Interfaces (HMIs), provide many additional challenges when deploying security measures.

[0002] Furthermore, attack methods have evolved from simple methods performed by curious hackers to advanced persistent threats (APTs) carefully designed by highly motivated top experts, sometimes with extended resources sponsored by nation-states. In some cases, detecting such targeted attacks and other general attack activities may require the adoption of security monitoring technologies, including signature-based intrusion detection, behavior-based anomaly detection, endpoint detection and response (EDR), etc. Furthermore, in some cases, network- or host-based security detection mechanisms employed within enterprise information technology (IT) systems do not translate to industrial control systems, for example, because some industrial systems require non-intrusive methods that minimize the risk of system disruption. Additionally, OT systems often include a large number of legacy devices that are susceptible to supporting new embedded systems, for example, systems that perform intrusive and system profiling employed by port scanning and vulnerability enumeration tools.

[0003] It is also recognized herein that current methods of preventing intrusions into industrial systems lack capabilities, such as those related in particular to information assurance and integrity verification. For example, in the case of information systems that can define highly critical or mission-critical information systems, these shortcomings can be particularly detrimental. Summary of the invention

[0004] Embodiments of the present invention address and overcome one or more of the shortcomings described herein by providing methods, systems, and devices that enhance security capabilities in industrial control systems. For example, a data acquisition device can be configured to operate as a one-way communication connection between a private network and a public network. The data acquisition device can also be configured to time stamp and encrypt data from the private network to ensure data integrity on the one-way communication connection. For example, the data acquisition device can apply a digitally signed timestamp to the data.

[0005] In one exemplary aspect, a data collection device includes a sending machine, a receiving machine, and a monitoring device between the sending machine and the receiving machine. The receiving machine can include: a unidirectional network interface coupled to one or more devices of a private network; an input coupled to a wire; and an output coupled to the wire. The sending machine can be configured to collect data from one or more devices of a private or operational network. The data collection device can also include a monitoring device, which includes a wire coupled to the output and input of the sending machine to define a loop. The monitoring device can also include an interceptor inductively coupled to the loop to define a unidirectional communication connection. The receiving machine can be coupled to the interceptor and the private network. The receiving machine can be configured to receive data from the sending machine on a unidirectional communication connection from the sending machine to the receiving machine defined by the monitoring device. The sending machine can also include a timestamp module, which is configured to apply a timestamp (e.g., a digitally signed timestamp) to data sent to the receiving machine. The receiving machine can use the digitally signed timestamp to verify the integrity of the data it receives. In addition, the receiving machine can send the verified data to a system within the public network, for example, for analysis. BRIEF DESCRIPTION OF THE DRAWINGS

[0006] The above and other aspects of the present invention can be best understood from the following detailed description when read in conjunction with the accompanying drawings. For the purpose of illustrating the invention, presently preferred embodiments are shown in the accompanying drawings, however, it should be understood that the invention is not limited to the specific means disclosed. The accompanying drawings include the following drawings:

[0007] Figure 1 A block diagram of a data acquisition unit (DCU) device deployed within an exemplary industrial control system (ICS) is shown.

[0008] Figure 2 Another block diagram of a DCU according to an exemplary embodiment is shown.

[0009] Figure 3 A flow chart that can be performed by a computing system and other nodes within an ICS, and thus by the ICS itself, is shown according to an exemplary embodiment.

[0010] Figure 4 A computing environment is shown in which embodiments of the invention can be implemented. DETAILED DESCRIPTION

[0011] First reference Figure 1, an exemplary distributed control system (DCS) or industrial control system (ICS) 100 includes an office or corporate IT network 102 and an operational technology (OT) or production network 104 communicatively coupled to the IT network 102 via a data control device or data control unit (DCU) 106. The IT network 102 can define an office or public network with lower security requirements than the OT network 104, and the OT network 104 can define a private or critical production network. The DCU 106 can be configured to operate as a unidirectional communication connection between the private network and the public network. The DCU 106 can collect network traffic data shared on the OT network 104 via a communication link 112 from the OT network 104 to the DCU 106. Specifically, for example, the OT network 104 can include various production machines configured to work together to perform one or more manufacturing operations. Exemplary production machines of the production network 104 can include, but are not limited to, robots and other field devices, such as sensors, actuators, or other machines, which can be controlled by corresponding programmable logic controllers (PLCs) 108. The PLC 108 can send instructions to various field devices. In some cases, a given PLC 108 can be coupled, or the OT network 104 can additionally include a human-machine interface (HMI) 110. It should be understood that the ICS 100 is simplified for exemplary purposes. That is, the ICS 100 can include additional or alternative nodes or systems that define alternative configurations, such as other network devices, and all such configurations are considered to be within the scope of the present invention.

[0012] In some cases, the communication link 112 is configured to receive data from the OT network 104, but not to send data to the production network 104, such that the communication link 112 defines a unidirectional communication link from the OT network 104 to the DCU 106. The network packets collected by the DCU 106 can be used by network security functions executed on the IT network 102. The collected network packets can be sent from the DCU 106 to the IT network 102, and in particular to systems within the IT network 102, such as, but not limited to, an intrusion detection system (IDS) 114, a security information and event management (SIEM) system 116, and a forensic analysis system 118. As an example, the collected data packets can be provided to the IT network 102 for verification, such as verification required by security rules, etc. Such verification can involve data packets at the communication level. For example, the sender or receiver of the data packet can be verified, or the timing associated with various commands or settings sent within the OT network 104 of the ICS 100 can be verified. In some cases, if the integrity of the collected data is not guaranteed, authentication and other security functions performed within the IT network 102 may not be performed correctly. For example, if the data collected from the OT network 104 is corrupted, the collected data may not represent the true state of network traffic within the OT network 104. The corrupted data may not reflect the true state of network traffic. Therefore, it is recognized here that the integrity of the data within the DCU 106 is important for the security functions and other functions provided by the IT network 102.

[0013] Continue to refer Figure 1 , the DCU 106 can include an Ethernet port 120 connected to the OT network 104, for example, via a switch 122. The Ethernet port 120 can define a unidirectional interface configured to receive raw data packets but not to send out data packets. The DCU 106 can also include a multidirectional interface or port 124 that can communicate with the IT network 102, for example, via a switch 128. Specifically, the multidirectional interface 124 can send and receive data to and from the IDS 114, the SIEM system 116, and the forensic analysis system 118. In some cases, for example, the multidirectional port 124 is exposed to the IT network 102 so that the IDS 114, the SIEM system 116, and the forensic analysis system 118 can access the packets collected by the DCU 106 in order to record the packets and / or perform packet analysis on the recorded packets. Therefore, it is recognized herein that the integrity of packets at rest and in motion can be critical to various functions associated with the DCU 106.

[0014] As an example, if the integrity of the collected data is not verified, a hacker can manipulate (e.g., change, delete, create) the collected data on the DCU 106. For example, a hacker can access the DCU 106 via the multi-way port 124 through the IT network 102 in order to manipulate the data on the DCU 106. As another example, a hacker can hijack a communication session between the DCU 106 and other devices (e.g., a log server or IDS 114) by sending false data over the communication link 126 between the DCU 106 and the IT network 102 in order to perform a man-in-the-middle (MITM) network attack.

[0015] In some cases, the industrial control system includes a data acquisition device that is only capable of sending collected data packets to the IT network via a TCP stream by providing an http link for configuration, which, as recognized herein, may be unsafe for network attacks. For example, a hacker can use a computing device connected to the IT network to directly or indirectly access the DCU, manipulate the data collected within the DCU, and / or hijack the communication link between the DCU and other devices such as an IDS or SIEM system. However, according to various embodiments described herein, data used for analysis within the IT network 102 can be verified to ensure that the data has not been tampered with.

[0016] Also refer to Figure 2, the exemplary ICS 200 can include a DCU 106. According to an exemplary embodiment, the DCU 106 can include a first or sending machine 202 and a second or receiving machine 204 configured to receive data from the sending machine 202. The DCU 106 can also include a unidirectional network interface 206 coupled to the sending machine 202 and the private OT network 104, so that the sending machine 202 can receive data from the private OT 104 via the unidirectional network interface 206. In one example, the unidirectional network interface 206 includes an Ethernet port 120. The sending machine 202 can include a unidirectional network interface 206 that can be coupled to one or more devices of the private network (e.g., the OT network 104). The multidirectional port 124 of the DCU 106 can be coupled to the receiving machine 204 and the IT network 102, so that the receiving machine 204 can send data to the IT network 102 or receive data from the IT network 102. In some instances, the unidirectional network interface 206 allows only receiving data from the OT network 104 and not sending data to the OT network 104, thereby allowing only unidirectional communication from the OT network 104 to the public IT network 102. The OT or production network 104 can define a critical or private network, such as a network for industrial automation, a financial network, a network for railway automation and control, a life-critical system, etc. In some cases, the OT network 104 obtains monitoring and assessment services from a service provider located in the IT network 102, which can define an unsecured public network, such as an Internet-based or cloud-based service that can provide intensive data analysis related to safety or diagnostics. The DCU 106 can listen to the unidirectional network interface 206, particularly the Ethernet port 120, in a passive manner, such as by performing a listening operation so that active requests are not sent to devices within the OT network 104.

[0017] The DCU can also include a monitoring device 208 configured to transmit data from the sending machine 202 to the receiving machine 204 without allowing data to be transmitted from the receiving machine 204 to the sending machine 202. In some examples, the monitoring device 208 can define a data replicator or network tap to provide a unidirectional data transmission from the sending machine 202 to the receiving machine 204 without hard-wiring the sending machine 202 and the receiving machine 204 together. In one example, the monitoring device 208 can include a conductor 210 arranged in a loop so that the conductor 210 is connected to an output terminal 212 defined by the sending machine 202, and an input terminal 214 defined by the sending machine 202. Thus, the monitoring device 208 can include the conductor 210 coupled to the input terminal 214 and the output terminal 212 to define a loop. Data can be transmitted along the conductor 210 by the sending machine 202 at the output terminal 212 and returned to the sending machine 202 at the input terminal. The input 214 and output 212 of the sending machine 202 can be isolated from the unidirectional network interface 206. In one example, the monitoring device 208, and in particular the wire 210, can define an inductor to transmit data from the sending machine 202 to the receiving machine 204 without a wire or cable connected between the sending machine 202 and the receiving machine 204. For example, the monitoring device 208 can also include an interceptor 216 connected to the receiving machine 204. The interceptor 216 can be inductively coupled to the loop to define a unidirectional communication connection between the sending machine 202 and the receiving machine 204, thereby defining a unidirectional communication connection between the OT network 104 and the IT network 102. In some examples, the interceptor 216 can define the wire so that the wire and the wire 210 defining the loop can be inductively coupled to each other.

[0018] In various examples, the receiving machine 204 can be coupled to the interceptor 216 and the private OT network 104 so as to be configured to receive data from the sending machine 202 over a unidirectional communication connection defined by the monitoring device from the sending machine to the receiving machine. Thus, in one example, a data stream can pass from the output 212 through the wire 210 through the loop to the input 214. Such a data stream can be inductively replicated by the interceptor 216 and delivered to the receiving machine 204 via a connection between the interceptor 216 (e.g., wire) and the receiving machine 204. The original data stream through the loop can remain unchanged from the output 212 to the input 214. Thus, the monitoring device 208 can define an inductive configuration that connects the sending machine 202 to the receiving machine 204, thereby connecting the OT network 104 to the IT network 102. In particular, the monitoring device 208 can define a physically separate connection between the OT network 104 and the IT network 102. In some cases, due to the inductive configuration of the monitoring device 208, only the replicated data from the wires 210 defining the loop can be transmitted unidirectionally to the receiving machine 204. That is, in various instances, data cannot flow from the interceptor 216 to the wires 210 defining the loop, thereby providing interference-free operation for the OT network 104 relative to the IT network 102. In one instance, the interceptor 216 functions as a network test access point (TAP) that intercepts transmissions between the output 212 and input 214 defined by the sending machine 202 and replicates the data to the monitor port of the receiving machine 204. In another instance, the interceptor 216 can be implemented as a switched port analyzer (SPAN) that performs port mirroring on the intercepted transmissions on the wires 210 defining the loop.

[0019] Still reference Figure 2 , the sending machine 202 can also include a boot loader 218 and firmware 220, which can include operating instructions for the sending machine 202 and, therefore, for the DCU 106. Similarly, the receiving machine 204 can also include a boot loader 222 and firmware 224, which can include operating instructions for the receiving machine 204, and, therefore, for the DCU 106. The DCU 106 can also include one or more databases. For example, the sending machine 202 can include a sender database 226, and the receiving machine 204 can include a receiver database 228. In one example, data copied from the sending machine 202 can be cached in the receiver database 228. Similarly, data received by the sending machine 202 from the OT network 104 can be cached in, for example, the sender database 226, so that the data can be sent via the wires 210 of the monitoring device 208 at regular intervals, predetermined times, etc.

[0020] In various examples, the DCU 106 can include one or more processors, which can include one or more central processing units (CPUs), graphics processing units (GPUs), or any other processors known in the art. More generally, the processor described herein is a device for executing machine-readable instructions stored on a computer-readable medium for performing tasks, and can include any one or a combination of hardware and firmware. In terms of examples, any software and firmware deployed in the receiving machine 204 can be executed by the processor of the receiving machine 204. In one aspect, any software and firmware deployed in the sending machine 202 can be executed by the processor of the sending machine 202 to maintain physical isolation between the public IT network 102 and the private OT network 104, and to ensure one-way communication. The processor of the DCU 106 can also include a memory storing executable machine-readable instructions for performing tasks. The processor of the DCU 106 can use or include the capabilities of, for example, a computer, a controller, or a microprocessor, and use executable instructions to adjust to perform special functions that are not performed by a general-purpose computer. The DCU 106 can include one or more processors, which include any type of suitable processing unit, including but not limited to a central processing unit, a microprocessor, a reduced instruction set computer (RISC) microprocessor, a complex instruction set computer (CISC) microprocessor, a microcontroller, an application-specific integrated circuit (ASIC), a field programmable gate array (FPGA), a system on a chip (SoC), a digital signal processor (DSP), etc. In addition, the processor of the DCU 106 can have any suitable micro-architecture design, which includes any number of constituent components, such as registers, multiplexers, arithmetic logic units, a cache controller for controlling read / write operations to a cache memory, a branch predictor, etc. The micro-architecture design of the processor can support any of a variety of instruction sets.

[0021] Continue to refer Figure 2, the receiving machine 204 can include various applications or modules, such as embedded network security applications for supporting security monitoring and diagnostics associated with the OT network 104. For example, the sending machine 202 can include a transceiver module 232, which is configured to send and receive data to devices in various networks such as GPRS, LTE, or 5G networks. Additionally or alternatively, the receiving machine 204 can include a data management application 230, which can be configured with a given data processing policy and can process data according to the data processing policy. In one example, the data management application 230 can read and / or delete data from the receiver database 228. In some cases, the data management application 230 can calculate a hash and verify that it calculates the same hash as the sending machine 202. In addition, the data management application 230 can filter and / or compress the data according to the policy. In addition, the data management application 230 can send the copied data from the sending machine 202 to the IT network 102, specifically, for example, to the IDS 114, the SIEM system 116, or the forensic analysis system 118. The replicated data can be sent via the transceiver module 232 or the multi-directional port 124. In some cases, the data received in the receiving machine 204 can be sent to the system within the IT network 102 via a push mechanism, such as by delivering the data in a publish-subscribe approach. Additionally or alternatively, the data can be cached in the receiver database 228 and can be delivered by the system within the IT network 102 via a pull mechanism. For example, the system can actively request data from the receiver database 228 or the receiving machine 204, such as via the multi-directional port 124.

[0022] The sending machine 202 can also include various applications or modules according to various embodiments. In some instances, the sending machine 202 can include a data processing application 234, which is configured to receive data from a data acquisition port (e.g., Ethernet port 120) of the unidirectional network interface 206. In some cases, the data processing application 234 can be configured to filter data according to a policy. In some instances, such a policy or configuration can be obtained by the data processing application 234 from the sender database 226. The sending machine 202 can also include a timestamp module 236, which is configured to use timestamps to provide data processing application data integrity services for the DCU 106, as further described herein. In the example configuration, 234 is separated from the timestamp module 236 so that the data processing application 234 can be updated or scaled without interrupting the timestamp module 236 application program. In one example, the time stamp module 236 can include a hash 238, a clock source 240, and a hardware security module 242, and thus the sending machine 202 can include the hash application 238, the clock source 240, and the hardware security module 242. The clock source 240 can define a low-level clock source, a high-precision clock, etc. Thus, in some cases, applications and modules within the sending machine 202 can perform operations on the trusted side of the ICS 100 (and the DCU 106), while applications and modules within the receiving machine 204 can perform operations on the untrusted side of the ICS 100 (and the DCU 106). In addition, the sending machine 202 can ensure data integrity and can be protected so that it cannot be configured or manipulated by a user, and the receiving machine 204 can be managed by a user for data management.

[0023] In some instances, the sending machine 202 and the receiving machine 204 each define an application layer on which corresponding modular applications can be deployed. Such a configuration can allow for the instant addition and removal of applications. Modular applications can be distributed and deployed from an application market, where device operators can select applications as appropriate and automatically install or remove them via management tools provided as part of the DCU 106. Modular applications can allow the performance overhead of running applications to be controlled by dividing functions between applications. In some cases, the DCU 106 can be easily reconfigured without having to reconstruct or modify the architecture of the secure OT network 104. In addition, the deployment of modular applications is flexible by allowing the deployment of applications or libraries that are not dedicated to any one vendor or manufacturer (including original equipment manufacturers (OEMs)). This flexibility allows the protection of the OT network 104 to be maintained using newly deployed new software-based technologies, including analytical capabilities, when they become available, or in the case where a particular application is revealed to have newly discovered vulnerabilities, the newly discovered vulnerabilities require patches or replacements of applications from different vendors. One or more security and processing applications at the application layer can provide cost-effective, decentralized analysis and early warning capabilities of collected data by alerting operators of the OT network 104 when abnormal data packets are found.

[0024] Continue to refer Figure 2 According to an exemplary embodiment, in order to ensure that no tampering is performed on the data used or analyzed on the IT network 102 or the untrusted side, the date or time of data creation is maintained. For example, data sent to the receiving machine 204 can be time stamped in a trusted manner by the timestamp module 236. Such a trusted timestamp can make it possible to verify the existence of certain information at a given point in time. In addition, such verification can prevent modification of the data, thereby ensuring the integrity of the data. In one example, the sending machine 202 generates a tamper-proof timestamp for its digital content, and then the receiving machine 204 can trust the content by verifying the timestamp of the data it receives from the sending machine 202. Specifically, as an example, the sending machine 202, such as the timestamp module 236, can execute the IETF PKI timestamp protocol (TSP) to generate a link number of a digital signature associated with the data sent by the sending machine 202 to the receiving machine 204.

[0025] In addition, as described herein, the architecture and structure of the DCU 106 can prevent data from the OT network 104 from being exposed to other sources when the data is collected and processed. Operations performed on the collected data (e.g., sending, deleting, etc.) can be recorded within the DCU 106. The configuration of the DCU 106 can also be recorded. As an example, the DCU 106 can reside in a cabinet or roadside, and operations can be recorded by recording commands or settings received from an HMI associated with the DCU 106. Such traffic (e.g., commands, settings) can be digitally signed with a timestamp (e.g., according to an IETF PKI TSP) while preventing network and traffic exposure to unauthorized networks or devices.

[0026] In various examples, the DCU 106 can collect data by passively listening to a data acquisition port (e.g., Ethernet port 120) of its unidirectional network interface 206. The collected data can be sent to a data processing application 234. For example, the data processing application 234 can be configured by obtaining configuration data from the transmitter database 226. In one example, the data processing application 234 can filter the collected data based on the configuration. For example, the configuration data can indicate which packets should be recorded, when the packets should be recorded, etc. As another example, the configuration data obtained from the transmitter database 226 can inform the data processing application 234 of the protocol to be implemented. For example, the protocol can indicate which data is time-stamped, among other requirements. Therefore, the DCU 106 can perform time stamping based on the configuration or protocol. The data processing application 234 can also compress the data of the time stamp module 236. In some cases, the data processing application 234 can filter and compress the collected data before storing the data in the transmitter database 226. Such filtering and compression can also save bandwidth usage when sending data to systems within the IT network 102 via the multi-directional port 124. In some instances, systems of the IT network 102 (e.g., the IDS 114, the SIEM system 116, or the forensic analysis system 118) can recover the compressed data. Additionally or alternatively, the data processing application can include a deep packet inspection engine configured to read the collected data packets at the application layer. The deep packet inspection engine can also be configured to determine which packets should be protected in terms of integrity in order to save computing power of the DCU 106.

[0027] For example, in some cases, the DCU 106 can be configured with a specific protocol parser associated with packets to be encrypted and to be time-stamped. During such configuration, the user interface of the DCU 106 can indicate a decomposed packet structure for browsing sample packets. In one example, a filter, such as a Wireshark filter, can be applied to a portion of the packet to be protected, such as a timestamp by a digital signature. Therefore, when the DCU 106 determines or a portion of the collected data packets is determined by the DCU 106 to be confidential, the data processing application 234 can encrypt these data packets or portions of these data packets. In some cases, the data packets collected by the sending machine 202 are encrypted before being stored in the sender database 206. Therefore, if unencrypted sensitive traffic is received, the DCU 106 can store such sensitive or confidential data as encrypted data rather than plain text. In various instances, the data processing application 234 selects which data to send to the timestamp module 236. Therefore, in some cases, the data processing application 234 can select which data to time-stamp and / or hash.

[0028] The timestamp module 236 can perform TSP and other techniques to apply a timestamp (e.g., a digitally encrypted timestamp) to data. The timestamp module 236 can be configured to receive at least a portion of the data collected from the unidirectional network interface 206. The hash application 238 and the timestamp module 236 can be configured to calculate a message digest or hash, such as a first hash value, which represents the portion of the data collected from the unidirectional network interface 206. In some cases, hashes are generated only for the most meaningful data, which can be determined by a filter (e.g., a Wireshark filter) that can be applied to the collected data to select the portion of the data that is hashed. Examples of hash values ​​or data that hashes can be generated by the hash application 238 include, but are not limited to, MAC source / destination addresses, IP source / destination addresses, timestamps, protocols, packet sizes, or packet data units (PDUs). In another example, the timestamp module 236 generates a message digest, such as a hash value, for the payload of the data packet rather than the entire original data packet. In yet another example, the timestamp module 236 can generate a message digest, such as a hash, for all data sent to the receiving machine 204 via the conductor 210. It is understood that replacement data for the hash can be selected as desired, such as by the data processing application 234. The hashing of the data can ensure the integrity of the data associated with the hash.

[0029] The timestamp module 236 can use the clock source 240 to apply a timestamp to the hashed data or hash value, such as the first hash value. Thus, in some cases, the timestamp module 236 generates a timestamp for all data transmitted to the receiving machine 204 via the conductor 210. In other instances, specific data is selected for timestamping, such as payload data, but it will be appreciated that data can be selected for timestamping as desired, such as by the data processing application 234. Alternatively or additionally, the receiving machine 204 can include a timestamp module configured to timestamp data received from the sending machine 202. Thus, the receiving machine 204 can also include a clock, such as a low-level clock source or a high-precision clock, such as the clock source 240.

[0030] The hash application 238 and the timestamp module 236 can be configured to calculate or operate a hash representing the hash data (e.g., the first hash value) and the timestamp, such as the second hash value, to generate hashed timestamp data. In some instances, the hashed timestamp data can be sent to the hardware security module 242, wherein the hardware security module 242 can sign the data, for example, using the digital certificate of the DCU 106, to generate signed hashed timestamp data or signed hashed timestamp data. In some instances, the hardware security module 242 can calculate a cryptographic hash function of the data. The signature data, which can include the timestamp and the hash of the collected data, can be written to the receiver database 228 by transmitting the data on the wire 210. In addition, data can be sent to the receiving machine 204 at any time or at a specific time, and the data can include the signature hash of the timestamp and all or part of the data collected by the sending machine 202. For example, the signed hash can be sent at specific times of the day, and the receiving machine 204 can be configured to listen to the sending machine 202 at these specific times. As a result of the isolation and unidirectional nature of the sending machine 202 and the receiving machine 204, as described herein, in various configurations, the receiving machine 204 cannot request data from the sending machine 202. Therefore, in various examples, the receiving machine 204 is configured to listen to the sending machine 202 at predetermined or specific times. As another example, the sending machine 202 can broadcast its data during specific time slots, and the receiving machine 204 can be configured to listen during these time slots.

[0031] The data management application 230 can read data, delete data, and process data from the receiver database 228 according to the data processing policy. For example, the data management application 230 can filter, adjust the size of the data, or compress the data in order to process the data from the receiver database 228. Specifically, in some instances, the data management application 230 can verify the signature or certificate from the sending machine 202, for example, using a public key infrastructure (PKI). The data management application 230 and the receiving machine 204 can calculate a hash and verify that it calculates the same hash as the sending machine 202. In one example, the receiving machine 204 can receive an encrypted hash from the sending machine 202 and decrypt the encrypted hash using the public key of the corresponding key pair. After decrypting the hash, the hash of the received message or data (which can be saved and retrieved at any time) can be calculated and compared with the corresponding decrypted hash. If the hash does not match, the receiving machine 204 and the DCU 106 can determine that the data may have been tampered with or otherwise changed. If the hashes match, then the DCU 106, and in particular the receiving machine 204, can verify the integrity of the data.

[0032] In addition, the data management application 230 can send the data it reads and / or processes to the transceiver module 232 or the multi-directional port 124 for transmission to the desired destination. In some examples, the data management application 230 records the operations it performs and the operations performed by the DCU 106 in the transmitter database 226. In addition, in some examples, the security professional can configure the DCU 106 via the data management application 230 and / or the transmitter database 226. For example, the security professional can perform operations (e.g., read, delete, etc.) on the data recorded by the data management application 230, and can manage security parameters such as public key infrastructure (PKI), digital certificates, and encryption keys.

[0033] Reference now Figure 3, the exemplary operation 300 can be performed by the DCU 106, which includes a sending machine 202 and a receiving machine 204 physically isolated from the sending machine 202. The monitoring device 208 can be set between the sending machine 202 and the receiving machine 204, and the DCU 106 can be set between the private network and the public network. Therefore, the monitoring device 208 can be set between the private network and the public network. At 302, the sending machine 202 can collect data from one or more devices of the private network. In some cases, the data processing application 234 monitors the unidirectional network interface 206 to collect data from the private network. At 304, the sending machine 202 can select a portion of the collected data to transmit to the receiving machine 204. In one example, the selected portion of the collected data includes all data collected from the private network. In another example, the selected portion of the collected data is based on parameters associated with the data collected from the unidirectional network interface 206. The parameters may indicate various properties of the data, such as whether a particular portion of the data is part of the payload, a protocol associated with the data, a data source, a destination of the data, or a type or classification associated with the data.

[0034] Still reference Figure 3 At 306, the sending machine 202 can generate a timestamp associated with the selected portion of the collected data. In some cases, the timestamp can be applied to a hash value of the selected data, such as a first hash value. In some instances, a hash value, such as a second hash value, is generated from the first hash value and the timestamp. At 308, the sending machine 202 can generate one or more hashes. At 310, the sending machine 202 can send the timestamp and the portion of the collected data along the wire 210 defined by the monitoring device 208, such as as a hash, so as to transmit the portion of the collected data and the timestamp to the receiving machine 204 via a unidirectional communication connection between the sending machine 202 and the receiving machine 204. The receiving machine 204 can also calculate one or more hashes to verify the integrity of the data from the sending machine 202. In some cases, the sending machine 202 sends the data from the output terminal 212 to the input terminal 214 along the wire 210 at one or more specific times so as to send the data to the receiving machine 204 at one or more specific times. The receiving machine 204 can listen to the monitoring device 208 at one or more specific times to receive data from the sending machine 202. The receiving machine 204 can decrypt the hash received from the sending machine 202 and can calculate a corresponding hash based on the data it received from the sending machine 202 to verify the integrity of the data. In addition, at 312, the receiving machine 204 can send portions of the collected data to one or more systems within the public network.

[0035] In each instance, refer again to Figure 1 and Figure 2 , the DCU 106 is configured with protection features so that the receiving machine 204, the sending machine 202 and the monitoring device 208 can operate in physically harsh environments, such as manufacturing, power generation, mobility or other industrial environments. For example, the DCU 106 may include a protective housing that can prevent electromagnetic interference from industrial processes. The DCU 106 can also define or be supported by elastic mountings that can prevent abnormal operation due to vibration. In addition, the DCU 106 can define various thermal management features, such as but not limited to heat sinks, fans, adhesives, etc., which can prevent overheating in thermally harsh environments. Therefore, the DCU 106 can provide a self-contained, industrial-grade, single-device solution for data integrity verification or intrusion detection in an undisturbed protected network, and can avoid direct-connected data collection through non-secure intrusion detection systems. In addition, unlike solutions that involve installing application groups on monitoring devices, the DCU 106 can implement reconfigurable modular application functions.

[0036] By way of example and not limitation, it is understood that the DCU 106 can be deployed in a variety of alternative industrial control systems, and the DCU 106 can be used in a traffic enforcement system. In particular, the DCU 106, including embedded timestamping and digital signature / certificate capabilities, can be connected to one or more cameras configured to monitor pedestrian or automobile traffic. One or more cameras can be coupled to the unidirectional network interface 206. Thus, data (e.g., images) collected by one or more cameras can be digitally timestamped and signed by the sending machine 202 and sent to the receiving machine 204. In one example, the receiving machine 204 can store the data it receives from the sending machine 202 in, for example, a receiver database 228. Additionally or alternatively, the receiving machine 204 can send the data to an evaluation system, such as a traffic enforcement and control office or system, via a transceiver module 232, for example, using LTE or similar technology.

[0037] As described above, and without being bound by theory, the DCU 106 can be configured according to the description herein to prevent hackers from manipulating OT data or sending fake data to replace collected OT data, or to prevent hackers from hijacking communication sessions in other ways. Therefore, the DCU 106 can define a bridge between an IT environment (e.g., an IT network 102) and an OT environment (e.g., a production network 104), in particular a secure link. In addition, as described herein, the DCU 106 can define self-contained data storage capabilities, and can process and compress the collected data, saving bandwidth for sending data through the IT network. Using timestamps and security measures, such as PKI digital certificates, the DCU 106 can ensure the integrity of the data. For example, the DCU 106 can be configured to automatically digitally sign the collected data traffic for forensic analysis and other analysis. The DCU 106 can be configured to verify digital certificates and signatures from inside and outside the DCU 106. For example, the receiving machine 204 can verify the digital certificates and signatures received from the sending machine 202. Relatedly, the DCU 106 can generate and manage certificates within the DCU 106. Thus, as further described herein, the DCU 106 can define a device that implements one-way communication and traffic collection while providing timestamp-based PKI capabilities. In addition, the DCU 106 can log its configuration and operation on the collected data within the DCU 106.

[0038] Figure 4 An example of a computing environment in which embodiments of the present invention can be implemented is shown. The computing environment 400 includes a computer system 510, which may include a communication mechanism such as a system bus 521 or other communication mechanism for transmitting information within the computer system 510. The computer system 510 also includes one or more processors 520 coupled to the system bus 521 for processing information. The robotic device 104 can include or be coupled to the one or more processors 520.

[0039] Processor 520 can include one or more central processing units (CPUs), graphics processing units (GPUs), or any other processors known in the art. More generally, the processor described herein is a device for executing machine-readable instructions stored on a computer-readable medium for performing tasks, and can include any one or a combination of hardware and firmware. The processor can also include a memory storing machine-readable instructions executable for performing tasks. The processor acts on information by manipulating, analyzing, modifying, converting, or transmitting information used by an executable program or information device and / or by routing the information to an output device. The processor can use or include the capabilities of, for example, a computer, a controller, or a microprocessor, and uses executable instructions to adjust to perform special functions not performed by a general-purpose computer. The processor can include any type of appropriate processing unit, including but not limited to a central processing unit, a microprocessor, a reduced instruction set computer (RISC) microprocessor, a complex instruction set computer (CISC) microprocessor, a microcontroller, an application-specific integrated circuit (ASIC), a field programmable gate array (FPGA), a system on a chip (SoC), a digital signal processor (DSP), etc. In addition, processor 520 can have any suitable micro-architecture design, and it comprises any number of components, for example register, multiplexer, arithmetic logic unit, cache controller, branch predictor etc. for controlling the read / write operation to cache memory.The micro-architecture design of processor can support any instruction set in multiple instruction sets.Processor can be coupled (electrically coupled and / or comprise executable components) with any other processor that can interact and / or communicate therebetween.User interface processor or generator are known elements, comprise electronic circuit or software or both combinations for producing display image or its part.User interface comprises one or more display images that enable user to interact with processor or other equipment.

[0040] The system bus 521 can include at least one of a system bus, a memory bus, an address bus, or a message bus, and can allow information (e.g., data (including computer executable code), signaling, etc.) to be exchanged between various components of the computer system 510. The system bus 521 can include, but is not limited to, a memory bus or a memory controller, a peripheral bus, an accelerated graphics port, etc. The system bus 521 can be associated with any suitable bus architecture, including, but not limited to, an Industry Standard Architecture (ISA), a Micro Channel Architecture (MCA), an Enhanced ISA (EISA), a Video Electronics Standards Association (VESA) architecture, an Accelerated Graphics Port (AGP) architecture, a Peripheral Component Interconnect (PCI) architecture, a PCI-Express architecture, a Personal Computer Memory Card International Association (PCMCIA) architecture, a Universal Serial Bus (USB) architecture, etc.

[0041] Continue to refer Figure 4 , the computer system 510 can also include a system memory 530 coupled to the system bus 521 for storing information and instructions to be executed by the processor 520. The system memory 530 can include computer-readable storage media in the form of volatile and / or non-volatile memory, such as read-only memory (ROM) 531 and / or random access memory (RAM) 532. RAM 532 can include other dynamic storage devices (e.g., dynamic RAM, static RAM, and synchronous DRAM). ROM 531 can include other static storage devices (e.g., programmable ROM, erasable PROM, and electrically erasable PROM). In addition, the system memory 530 can be used to store temporary variables or other intermediate information during the execution of instructions by the processor 520. A basic input / output system 533 (BIOS) can be stored in ROM 531, which contains basic routines that help transfer information between elements within the computer system 510, such as during startup. RAM 532 can contain data and / or program modules that can be immediately accessed by the processor 520 and / or are currently being operated by the processor 520. System memory 530 can also include, for example, operating system 534, application programs 535, and other program modules 536. Application programs 535 can also include a user portal for developing applications, allowing parameters to be entered and modified if necessary.

[0042] The operating system 534 can be loaded into the memory 530 and can provide an interface between other application software executing on the computer system 510 and the hardware resources of the computer system 510. More specifically, the operating system 534 may include a set of computer executable instructions for managing the hardware resources of the computer system 510 and providing common services to other applications (e.g., managing memory allocations between various applications). In certain exemplary embodiments, the operating system 534 can control the execution of one or more program modules depicted as being stored in the data repository 540. The operating system 534 may include any operating system now known or that may be developed in the future, including but not limited to any server operating system, any host operating system, or any other proprietary or non-proprietary operating system.

[0043] The computer system 510 can also include a disk / media controller 543 coupled to the system bus 521 to control one or more storage devices for storing information and instructions, such as a magnetic hard disk 541 and / or a removable media drive 542 (e.g., a floppy disk drive, an optical drive, a tape drive, a flash drive, and / or a solid-state drive). The storage device 540 can be added to the computer system 510 using an appropriate device interface (e.g., a small computer system interface (SCSI), an integrated device electronics (IDE), a universal serial bus (USB), or FireWire). The storage devices 541, 542 can be external to the computer system 510.

[0044] The computer system 510 can also include a field device interface 565 coupled to the system bus 521 to control field devices 566, such as devices used in a production line. The computer system 510 can include a user input interface or GUI 561, which can include one or more input devices, such as a keyboard, touch screen, input pad, and / or pointing device, for interacting with a computer user and providing information to the processor 520.

[0045] The computer system 510 can perform part or all of the processing steps of an embodiment of the present invention in response to the processor 520 executing one or more sequences of one or more instructions contained in a memory such as a system memory 530. Such instructions can be read into the system memory 530 from another computer-readable medium (magnetic hard disk 541 or removable media drive 542) of the storage library 540. The magnetic hard disk 541 and / or the removable media drive 542 can contain one or more data stores and data files used by embodiments of the present invention. The data storage library 540 can include, but is not limited to, a database (e.g., relational, object-oriented, etc.), a file system, a flat file, wherein data is stored in a distributed data store on more than one node of a computer network, a peer-to-peer network data store, etc. The data storage can store various types of data, such as skill data, sensor data, or any other data generated according to embodiments of the present invention. The data storage content and data files can be encrypted to improve security. The processor 520 can also be used in a multi-processing arrangement to execute one or more instruction sequences contained in the system memory 530. In an alternative embodiment, hard-wired circuits can replace software instructions or be used in combination with software instructions. Therefore, the embodiment is not limited to any specific combination of hardware circuits and software.

[0046] As described above, the computer system 510 can include at least one computer-readable medium or memory for storing instructions programmed according to embodiments of the present invention, and for containing data structures, tables, records, or other data described herein. The term "computer-readable medium" used herein refers to any medium that participates in providing instructions to the processor 520 for execution. Computer-readable media can take many forms, including but not limited to non-transient, non-volatile media, volatile media, and transmission media. Non-limiting examples of non-volatile media include optical disks, solid-state drives, magnetic disks, and magneto-optical disks, such as magnetic hard disks 541 or removable media drives 542. Non-limiting examples of volatile media include dynamic memory, such as system memory 530. Non-limiting examples of transmission media include coaxial cables, copper wires, and optical fibers, including wires that constitute the system bus 521. Transmission media can also take the form of sound waves or light waves, such as sound waves or light waves generated during radio wave and infrared data communications.

[0047] The computer-readable medium instructions for performing the operation of the present invention can be assembly instructions, instruction set architecture (ISA) instructions, machine instructions, machine-related instructions, microcode, firmware instructions, state setting data, or source code or object code written in any combination of one or more programming languages, including object-oriented programming languages ​​such as Smalltalk, C++, and conventional process programming languages ​​such as "C" programming language or similar programming languages. Computer-readable program instructions can be executed completely on the user's computer, partially on the user's computer, as an independent software package, partially on the user's computer, partially on a remote computer, or completely on a remote computer or server. In the latter case, the remote computer can be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or connected to an external computer (for example, by using the Internet of an Internet service provider). In some embodiments, the electronic circuit including, for example, a programmable logic circuit, a field programmable gate array (FPGA) or a programmable logic array (PLA) can perform computer-readable program instructions by utilizing the state information of the computer-readable program instructions to personalize the electronic circuit so as to perform various aspects of the present invention.

[0048] Various aspects of the present invention are described herein with reference to flowchart illustrations and / or block diagrams of methods, devices (systems) and computer program products according to embodiments of the present invention. It should be understood that each block of the flowchart illustration and / or block diagram and the combination of blocks in the flowchart illustration and / or block diagram can be implemented by computer-readable medium instructions.

[0049] The computing environment 400 can also include a computer system 510 operating in a networked environment using logical connections to one or more remote computers, such as remote computing devices 580. The network interface 570 can enable communication with other remote devices 580 or systems and / or storage devices 541, 542, for example, via a network 571. The remote computing device 580 can be a personal computer (laptop or desktop), a mobile device, a server, a router, a network PC, a peer device, or other public network node, and typically includes many or all of the elements described above with respect to the computer system 510. When used in a networked environment, the computer system 510 can include a modem 572 for establishing communications over a network 571, such as the Internet. The modem 572 can be connected to the system bus 521 via the user network interface 570 or via another appropriate mechanism.

[0050] The network 571 can be any network or system generally known in the art, including the Internet, an intranet, a local area network (LAN), a wide area network (WAN), a metropolitan area network (MAN), a direct connection or a series of connections, a cellular telephone network, or any other network or medium that can facilitate communication between the computer system 510 and other computers (e.g., remote computing devices 580). The network 571 can be wired, wireless, or a combination thereof. Wired connections can be implemented using Ethernet, a universal serial bus (USB), RJ-6, or any other wired connection known in the art. Wireless connections can be implemented using Wi-Fi, WiMAX, and Bluetooth, infrared, cellular networks, satellites, or any other wireless connection methods known in the art. In addition, several networks can work alone or communicate with each other to facilitate communication in the network 571.

[0051] It should be understood that Figure 4 The program modules, applications, computer executable instructions, codes, etc. described as being stored in system memory 530 are merely illustrative and not exhaustive, and the processing described as being supported by any particular module can alternatively be distributed across multiple modules or performed by different modules. In addition, various program modules, scripts, plug-ins, application programming interfaces (APIs), or any other suitable computer executable code hosted locally on the computer system 510, remote devices 580, and / or hosted on other computing devices accessible via one or more networks 571 can be provided to support the processing supported by Figure 4 The functions and / or additional or alternative functions provided by the program modules, applications or computer executable codes depicted in the embodiment of the present invention can be modularized in different ways, so that the functions described as being composed of Figure 4The processing collectively supported by the set of program modules depicted in the description can be performed by a fewer or greater number of modules, or the functionality described as supported by any particular module can be supported at least in part by another module. In addition, the program modules supporting the functionality described herein can form part of one or more applications that can be executed on any number of systems or devices according to any suitable computing model, such as a client-server model, a peer-to-peer model, etc. In addition, the processing collectively supported by the set of program modules depicted in the description can be performed by a fewer or greater number of modules, or the functionality described as supported by any particular module can be supported at least in part by another module. In addition, the program modules supporting the functionality described herein can form part of one or more applications that can be executed on any number of systems or devices according to any suitable computing model, such as a client-server model, a peer-to-peer model, etc. Figure 4 Any functionality supported by any program module depicted in the can be implemented, at least in part, in hardware and / or firmware on any number of devices.

[0052] It should also be understood that the computer system 510 can include alternative and / or additional hardware, software or firmware components other than those described or depicted without departing from the scope of the present invention. More specifically, it should be understood that the software, firmware or hardware components depicted as forming part of the computer system 510 are merely illustrative, and that certain components may not be present or additional components may be provided in various embodiments. Although various illustrative program modules have been depicted and described as software modules stored in the system memory 530, it should be understood that the functionality described as supported by the program modules may be enabled by any combination of hardware, software and / or firmware. It should be further understood that in various embodiments, each of the above modules may represent a logical partition of the supported functions. The logical partition is depicted for ease of explanation of the functions and may not represent the structure of the software, hardware and / or firmware used to implement the functions. Therefore, it should be understood that in various embodiments, the functionality described as provided by a specific module may be provided at least in part by one or more other modules. In addition, in some embodiments, one or more of the depicted modules may not be present, while in other embodiments, additional modules that are not depicted may be present and may support at least a portion of the functionality and / or additional functionality. Furthermore, while certain modules may be depicted and described as sub-modules of another module, in certain embodiments such modules may be provided as stand-alone modules or sub-modules of other modules.

[0053] Although specific embodiments of the present invention have been described, it will be appreciated by those skilled in the art that many other modifications and alternative embodiments exist within the scope of the present invention. For example, any function and / or processing capability described about a particular device or component can be performed by any other device or component. In addition, although various illustrative implementations and architectures have been described according to embodiments of the present invention, it will be appreciated by those skilled in the art that many other modifications to the illustrative implementations and architectures described herein are also within the scope of the present invention. In addition, it should be understood that any operation described herein as being based on another operation, element, component, data, etc., elements, components, data, etc., can be based on one or more other operations, elements, components, data, etc. in addition. Therefore, phrase "based on" or its variants should be interpreted as "based at least in part on".

[0054] Although the embodiments have been described with the language dedicated to structural features and / or method actions, it should be understood that the present invention is not necessarily limited to the specific features or actions described. On the contrary, these specific features and actions are disclosed as illustrative forms for realizing these embodiments. Conditional language, such as "can", "can", "may" or "may", etc., unless otherwise specifically stated or understood in the context used, is generally intended to convey that certain embodiments may include certain features, elements and / or steps that other embodiments do not include. Therefore, such conditional language is generally not intended to imply that one or more embodiments require features, elements and / or steps in any way, or one or more embodiments must include logic for determining whether these features, elements and / or steps are included in any particular embodiment or to be performed in any particular embodiment with or without user input or prompts.

[0055] Flowchart and block diagram in the figure show the possible architecture, function and operation of the system, method and computer program product according to various embodiments of the present invention.In this regard, each frame in the flow chart or block diagram can represent the module, segment or part of instruction, which includes one or more executable instructions for realizing the specified logical function.In some replaceable embodiments, the function pointed out in the square frame can not occur in the order pointed out in the accompanying drawings.For example, according to the function involved, the two frames shown in succession can actually be performed substantially at the same time, or these frames can sometimes be performed in reverse order.It will also be noted that each frame in the block diagram and / or flow chart illustration and the combination of the frames in the block diagram and / or flow chart illustration can be realized by a system based on special hardware that performs a specified function or action or performs a combination of special hardware and computer instructions.

Claims

1. A data collection device configured to operate as a one-way communication connection between a private network and a public network, the data collection device comprising: A sending machine, the sending machine comprising: 1) a unidirectional network interface, the unidirectional network interface coupled to one or more devices of the private network; 2) an input end, the input end coupled to a wire; and 3) an output end, the output end coupled to the wire, the sending machine being configured to collect data from the one or more devices of the private network; a monitoring device, the monitoring device comprising the wire coupled to the output and the input of the sending machine to define a loop, the monitoring device further comprising an interceptor inductively coupled to the loop to define the unidirectional communication connection; and a receiving machine coupled to the interceptor and the public network, the receiving machine being configured to receive data from the sending machine via the unidirectional communication connection defined by the monitoring device from the sending machine to the receiving machine, wherein the sending machine further comprises a time stamp module, the time stamp module being configured to apply a time stamp to the data sent to the receiving machine, In which, the data flow can reach the input end from the output end through the wire through the loop, the data flow can be inductively copied by the interceptor and transmitted to the receiving machine via the connection between the interceptor and the receiving machine, and the original data flow through the loop can remain unchanged from the output end to the input end.

2. The data acquisition device according to claim 1, wherein: The timestamp module is further configured to: receiving at least a portion of the data collected from the unidirectional network interface; calculating a first hash value representing the portion of the data collected from the unidirectional network interface; as well as The timestamp is applied to the first hash value.

3. The data acquisition device according to claim 2, wherein: The timestamp module is further configured to: A second hash value representing the timestamp and the first hash value is calculated, thereby generating hashed timestamp data.

4. The data acquisition device according to claim 3, wherein: The sending machine further includes a hardware security module configured to sign the hashed timestamp data, thereby generating signed hashed timestamp data.

5. The data acquisition device according to claim 4, wherein: The sending machine is further configured to send the signed hashed timestamp data from the output to the input along the wire, thereby transmitting the signed hashed timestamp data to the receiving machine.

6. The data acquisition device according to claim 5, wherein: The receiving machine is further configured to calculate the second hash value to verify the integrity of the portion of the data collected from the unidirectional network interface.

7. The data acquisition device according to claim 1, wherein: The timestamp module of the sending machine includes a clock source configured to generate a timestamp.

8. The data collection device according to claim 1, further comprising a data processing application, wherein the data processing application is configured to: monitoring the unidirectional network interface to collect data from the one or more devices of the private network; selecting a portion of the data collected from the unidirectional network interface; as well as The selected portion of the data is sent to the time stamp module.

9. The data acquisition device according to claim 1, wherein: The data processing application is further configured to select a portion of data to send to the time stamp module based on parameters associated with the data collected from the unidirectional network interface.

10. The data acquisition device according to claim 1, wherein: The transmitting machine is further configured to transmit data along the wire from the output end to the input end at one or more specific times, thereby transmitting the data to the receiving machine at the one or more specific times.

11. The data acquisition device according to claim 1, wherein: The receiving machine is configured to listen to the interceptor at the one or more specific times to receive the data from the sending machine.

12. The data acquisition device according to claim 1, wherein: The receiving machine further includes a transceiver module configured to transmit data from the sending machine to one or more systems within the public network.

13. A method performed by the data collection device according to claim 1, the data collection device comprising a sending machine, a receiving machine physically isolated from the sending machine, and a monitoring device between the sending machine and the receiving machine, the data collection device being arranged between a private network and a public network, the method comprising: The sending machine collects data from one or more devices of the private network; The sending machine selects a portion of the collected data for transmission to the receiving machine; generating a timestamp associated with said portion of said collected data; as well as The sending machine sends the timestamp and the portion of the collected data along the wire defined by the monitoring device, thereby transmitting the portion of the collected data and the timestamp to the receiving machine over the unidirectional communication connection between the sending machine and the receiving machine.

14. The method according to claim 13, further comprising: The sending machine calculates a first hash value representing the portion of the collected data; as well as The timestamp is applied to the first hash value.

15. The method according to claim 14, further comprising: A second hash value representing the timestamp and the first hash value is calculated, thereby generating hashed timestamp data.

16. The method according to claim 15, further comprising: The sending machine signs the hash time stamp data, thereby generating signed hash time stamp data.

17. The method according to claim 16, wherein: The sending machine defines an input and an output, the method further comprising: The signed hashed time stamp data is sent along the wire from the output end to the input end, thereby transmitting the signed hashed time stamp data to the receiving machine.

18. The method according to claim 13, further comprising: The transmitting machine transmits data from the output end to the input end along the wire at one or more specific times, thereby transmitting the data to the receiving machine at the one or more specific times.

19. The method according to claim 18, further comprising: The receiving machine listens to the monitoring device at the one or more specific times, thereby receiving the data from the sending machine; The receiving machine stores the data; as well as The receiving machine calculates a hash value of the data to verify the integrity of the data.

20. The method according to claim 13, wherein: The method of the sending machine selecting the portion of the collected data to transmit to the receiving machine further comprises: A filter is applied to the collected data such that the portion of the collected data defines a portion of the packet that is parsed and protected.

Citation Information

Patent Citations

  • Security certification system based on broadcast television one-way transmission network

    CN104506503A

  • Authenticated sensor interface device

    US20130117556A1