Privacy-protected one-way communication device

By using data acquisition devices to generate anonymized or synthetic data between IT networks and OT systems, the problem of data privacy leakage in ICS is solved, enabling effective data analysis and monitoring, and enhancing data privacy protection and anomaly detection capabilities.

CN115867913BActive Publication Date: 2026-03-31SIEMENS MOBILITY GMBH
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-04-15
Publication Date
2026-03-31

AI Technical Summary

Technical Problem

Existing technologies pose privacy and data security risks when collecting data from industrial control systems (ICS), especially during data transmission between IT networks and OT systems, which may lead to the leakage of trade secrets and confidential information. Furthermore, existing privacy protection methods are not applicable to heterogeneous OT networks.

Method used

By using a data acquisition device as a one-way communication connection, anonymous or synthetic data is generated to represent the original data for analysis without disclosing the real data. Anonymous or synthetic data is generated through the data acquisition device, and generative adversarial networks (GANs) are used to learn the distribution of the original data and generate synthetic data, ensuring privacy protection during data transmission.

Benefits of technology

It enables effective data analysis and monitoring without disclosing the original data, enhances data privacy protection, improves anomaly detection capabilities and confidence in data sharing, and reduces the risk of data leakage.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115867913B_ABST
    Figure CN115867913B_ABST
Patent Text Reader

Abstract

In an industrial system, a data collection device can be configured to operate as a one-way communication connection between a private network and a public network. The data collection device can also be configured to collect raw data from the private network. The raw data can define a data distribution. The data collection device can also be configured to generate anonymized data or synthetic data representative of the raw data based on the data distribution of the raw data. The anonymized data can be transmitted to a receiver of the data collection device over the one-way communication connection. In some cases, the receiver can send the anonymized data to an analytics system within the public network such that the analytics system can analyze the raw data based on the anonymized data representative of the raw data without the analytics system obtaining the raw data.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to a data acquisition device and a method performed by the data acquisition device. Background Technology

[0002] For a long time, cyberattacks on private computer networks have been at the forefront of detection and protection efforts using information technology. However, this paper recognizes that the threat of cyber attackers infiltrating industrial systems, such as automation and control systems that support critical infrastructure, is gaining attention. Industrial control system (ICS) networks are often directly or indirectly connected to IT networks (office networks) and the Internet due to factors such as the vertical integration of production systems and the horizontal integration of the value chain, providing cyber attackers with opportunities to penetrate such environments and exploit any existing vulnerabilities. This paper also recognizes that OT (operational technology) systems, such as programmable logic controllers (PLCs), distributed control systems (DCS), motion controllers, supervisory control and data acquisition (SCADA) servers, and human-machine interfaces (HMIs), present many additional challenges when deploying security measures.

[0003] Specifically, IT networks frequently connect to OT systems to collect data from them. However, this paper recognizes that current methods of collecting data from OT systems can compromise data-related privacy, potentially leading to the disclosure of valuable trade secrets, logic, data, and other information to competitors or others. For example, secrets can be derived from network traffic used for network monitoring, such as process recipes or other ICS data. This paper also recognizes that current methods often require security monitoring operations to be hosted in the cloud or off-site, which increases the risk of data breaches. Summary of the Invention

[0004] Embodiments of the present invention address and overcome one or more of the disadvantages described herein by providing methods, systems, and apparatus for protecting data privacy. By protecting the privacy of raw data, for example by generating anonymous or synthetic data representing the raw data, the raw data can be used or analyzed using the anonymous or synthetic data. For example, the data acquisition device can be configured to operate as a one-way communication connection between a private network and a public network. The data acquisition device can also be configured to generate anonymous or synthetic data from real data collected from a private network. The anonymous or synthetic data can represent the real data, thereby enabling the analysis of the real data outside the data acquisition device without the data acquisition device disclosing the actual real data.

[0005] In an example, the data acquisition device is configured to operate as a one-way communication connection between a private network and a public network. The data acquisition device may include a transmitter with a one-way network interface coupled to one or more devices on the private network. The transmitter may be configured to collect raw data from one or more devices on the private network. The raw data may define a first data distribution. The data acquisition device may also include a receiver configured to receive synthesized data from the transmitter via the one-way communication connection. The transmitter may also be configured to generate synthesized data based on the first data distribution of the raw data, such that the synthesized data represents the raw data without disclosing the raw data. Therefore, the transmitter can connect to the source data and forward anonymized or synthesized data based on the source data to the receiver, which may be physically separated from the transmitter and thus unable to access the source data. Attached Figure Description

[0006] The foregoing and other aspects of the invention will be best understood when the following detailed description is read in conjunction with the accompanying drawings. For the purpose of illustrating the invention, presently preferred embodiments are shown in the drawings; however, it should be understood that the invention is not limited to the specific means disclosed. The drawings include the following images:

[0007] Figure 1 A block diagram of a data capture unit (DCU) device deployed within an exemplary industrial control system (ICS) is shown.

[0008] Figure 2 Another block diagram of a DCU according to an exemplary embodiment is shown.

[0009] Figure 3 An exemplary system according to an exemplary embodiment is shown, the exemplary system including a plurality of DCU devices coupled to a central server for analysis.

[0010] Figure 4 A flowchart illustrating an actionable function of a DCU device according to an exemplary embodiment is shown.

[0011] Figure 5 A computing environment in which embodiments of the present invention can be implemented is shown. Detailed Implementation

[0012] First refer to Figure 1An exemplary distributed control system (DCS) or industrial control system (ICS) 100 includes an untrusted or insecure IT network 102, such as an office network or corporate network, and a secure or trusted operating technology (OT) network 104, such as a production network, communicatively coupled to the IT network 102 via a data control device or data control unit (DCU) 106. The IT network 102 can define an office network or public network with lower security requirements than the OT network 104, while the OT network can define a private network or a critical production network. The DCU 106 can be configured to operate as a unidirectional communication connection between a private network and a public network. The DCU 106 can collect network traffic data shared on the OT network 104 via a communication link 112 from the OT network 104 to the DCU 106. Specifically, for example, the OT network 104 can include various production machines configured to work together to perform one or more manufacturing operations. Exemplary production machines of the production network 104 can include, but are not limited to, robots and other field devices, such as sensors, actuators, or other machines, which can be controlled by a corresponding programmable logic controller (PLC) 108. PLC 108 is capable of sending instructions to various field devices. In some cases, a given PLC 108 can be coupled, or the OT network 104 can additionally include a Human-Machine Interface (HMI) 110. It should be understood that ICS 100 has been simplified for illustrative purposes. That is to say, ICS 100 can include additional or alternative nodes or systems, such as other network devices defining alternative configurations, and all such configurations are considered to be within the scope of this invention. For example, ICS 100 can be configured for building automation, energy automation, traffic management systems, train automation, embedded medical devices, etc.

[0013] In some cases, communication link 112 is configured to receive data from OT network 104 but not to send data to production network 104, such that communication link 112 defines a unidirectional communication link from OT network 104 to DCU 106. Therefore, DCU 106 can define a unidirectional communication connection between IT network 102 and OT network 104, for example, from OT network 104 to IT network 102, or in other cases, from IT network 102 to OT network 104. Network packets collected by DCU 106 can be used by network security functions performed on IT network 102. The collected network packets can be sent from DCU 106 to IT network 102, particularly to systems within IT network 102, such as, but not limited to, Intrusion Detection System (IDS) 114, Security Information and Event Management (SIEM) System 116, and Forensic Analysis System 118. IT network 104 can also define or include the cloud. For example, a Managed Security Service Provider (MSSP) can host monitoring data (such as IDS 114, SIEM system 116, or forensic analysis system 118) off-site or in the cloud. This document recognizes that such fine-grained data extracted from critical production systems (such as those within OT network 104) raises privacy concerns. For instance, OT network 104 may include different asset owners, each controlling their own data, and breaches of data privacy could lead to the disclosure of confidential information to these different asset owners. Such data or privacy breaches can also cause different asset owners to avoid sharing their data with a central entity (such as IDS 114, SIEM system 116, or forensic analysis system 118), which reduces overall security capabilities in anomaly detection and has other negative consequences. Therefore, the embodiments described herein address the privacy concerns associated with data collected from OT network 104 while maintaining the utility of the collected data.

[0014] Continue to refer to Figure 1The DCU 106 may include, for example, an Ethernet port 120 connected to the OT network 104 via a switch 122. The Ethernet port 120 may define a unidirectional interface configured to receive real or raw data packets, but not to send packets out. The DCU 106 may also include a multidirectional interface or port 124 capable of communicating with the IT network 102, for example, via a switch 128. Specifically, the multidirectional interface 124 may send and receive data to and from the IDS 114, SIEM system 116, and forensic analysis system 118. In some cases, for example, the multidirectional port 124 may be exposed to the IT network 102, allowing the IDS 114, SIEM system 116, and forensic analysis system 118 to access packets collected by the DCU 106 for recording packets and / or performing packet analysis on the recorded packets. Therefore, this document recognizes that both stationary and moving data packets may be critical to the various functions associated with the DCU 106. Furthermore, it should be understood that providing security monitoring is an exemplary use case for data provided by the DCU 106, and this data is not limited to security purposes. For example, data provided by the DCU 106 can be used for state-based monitoring. In such an example, process variable content (e.g., time-series data from sensors) can be anonymized and transmitted to the cloud for anomaly detection.

[0015] For example, if the collected data is not protected, a hacker could sniff and / or manipulate (e.g., change, delete, create) the data collected on DCU 106. For instance, a hacker might access DCU 106 via IT network 102 through multi-port 124 to sniff data on DCU 106. In some cases, multi-port 124 is used to send collected packets to IT network 102 via a TCP stream, which may not be resistant to network attacks. Therefore, a hacker could use a computing device connected to IT network 102 to directly or indirectly access DCU 106 to sniff data collected within DCU 106. Furthermore, a hacker might use the sniffed data to enhance their competitive advantage, for example, by identifying confidential logic or attributes associated with the data, in addition to the data itself.

[0016] In one exemplary embodiment, to prevent such sniffing and other potential vulnerabilities, DCU 106 generates anonymized data that can be analyzed by systems within IT network 102 or elsewhere (e.g., SIEM system 116). In some cases, anonymized data is defined as synthetic data generated based on real data, such that the synthetic data is defined with one or more statistical properties similar to or identical to the real data. Anonymized or synthetic data can be generated to protect the privacy of the original dataset while maintaining its utility. This document recognizes that other methods for protecting privacy, such as encoding, differential privacy, etc., may not be suitable for industrial environments including heterogeneous OT networks with different and / or traditional applications across the network. For example, other privacy technologies may need to be implemented at the data generation source (e.g., heterogeneous OT networks), which may make standardization across the network difficult or prohibitively costly.

[0017] refer to Figure 2 Example ICS 200 may include DCU 106. According to an exemplary embodiment, DCU 106 may include a first machine or transmitter 202 and a second machine or receiver 204, the receiver being configured to receive data from transmitter 202. DCU 106 may further include a unidirectional network interface 206 coupled to transmitter 202 and private OT network 104, such that transmitter 202 can receive data from private OT network 104 via unidirectional network interface 206. In an example, unidirectional network interface 206 includes Ethernet port 120. In some cases, transmitter 202 may include unidirectional network interface 206, which may be coupled to one or more devices of the private network, such as OT network 104. Therefore, in some instances, transmitter 202 may be configured to collect real or raw data from one or more devices of private OT network 104, and the raw data may define a data distribution, such as a first data distribution. As an example and not a limitation, the raw data can indicate various process variables related to the OT network 104, such as temperature, pressure, motor speed, heater variables, pump variables, valve variables, etc. As well, the raw data can include network traffic metadata, endpoint / host data (e.g., performance counters), system-specific data (e.g., PLC memory contents monitoring critical memory areas for malicious operations), personal health data (e.g., laboratory test data), building data (e.g., temperature, pressure, airflow, speed, humidity), or energy parameters (e.g., frequency, voltage, power consumption, load, current).

[0018] As further described herein, transmitter 202 can be configured to generate anonymized or synthetic data based on the data distribution of the original data, such that the anonymized or synthetic data represents the original data without disclosing the original data. Receiver 204 can be configured to receive anonymized or synthetic data from transmitter 202. In some cases, transmitter 202 is also configured to generate anonymized data corresponding to the original data when transmitter 202 receives the corresponding original data, thereby limiting continuous online data anonymization.

[0019] The multi-directional port 124 of DCU 106 can be coupled to receiver 204 and IT network 102, enabling receiver 204 to send data to or receive data from IT network 102. Specifically, receiver 204 can be configured to send synthesized data to an analysis system within public IT network 102, allowing analysis of the original data based on the synthesized data representing the original data. In some instances, unidirectional network interface 206 only allows data reception from OT network 104 without sending data to the OT network, thus allowing only unidirectional communication from OT network 104 to public IT network 102. OT or product network 104 can define critical or private networks, such as industrial automation networks, financial networks, railway automation and control networks, life-critical systems, etc. In some cases, OT network 104 obtains monitoring and evaluation services from service providers located in IT network 102, which can define insecure public networks, such as internet-based or cloud-based services capable of providing intensive data analysis related to security or diagnostics. DCU 106 can passively listen to unidirectional network interfaces 206, particularly Ethernet port 120, for example by performing sniffing operations to prevent active requests from being sent to devices within the OT network 104.

[0020] As described herein, DCU 106 can define a unidirectional communication device that supports one or more privacy protection mechanisms. Such privacy protection technologies can be activated for one or more data streams from one or more sources to ensure that the transmission of data output from receiver 204 in a network environment (e.g., IT network 102) is secure, even if the network environment from which the raw data is collected (e.g., OT network 104) is less secure.

[0021] DCU 106 may also include a monitoring device 208 configured to transmit data (e.g., synthesized data) from transmitter 202 to receiver 204, but not to transmit data from receiver 204 back to transmitter 202. In some instances, monitoring device 208 may define a data copier or network splitter to provide unidirectional data transmission from transmitter 202 to receiver 204 without hard-wiring transmitter 202 and receiver 204 together. In one instance, monitoring device 208 may include a looped conductor 210 connected to an output 212 defined by transmitter 202 and an input 214 defined by transmitter 202. Thus, data can be transmitted from transmitter 202 at output 212 along conductor 210 and returned to transmitter 202 at input. Input 214 and output 212 of transmitter 202 may be isolated from unidirectional network interface 206. In the example, monitoring device 208, particularly wire 210, can define an inductor to transmit data from transmitter 202 to receiver 204 without a connecting wire or cable between transmitter 202 and receiver 204. For example, monitoring device 208 can also include an interceptor 216 connected to receiver 204. In some instances, interceptor 216 can define a wire such that the wire and the defined loop wire 210 can be inductively coupled to each other.

[0022] Therefore, in this example, the data flow can loop from output 212 through wire 210 to input 214. This data flow can be sensed and copied by interceptor 216 and transmitted to receiver 204 via the connection between interceptor 216 (e.g., the wire) and receiver 204. The original data flow looping through the loop from output 212 to input 214 remains unchanged. Therefore, monitoring device 208 can define a sensing configuration that connects transmitter 202 to receiver 204, thereby connecting OT network 104 to IT network 102. Specifically, monitoring device 208 can define a physically separate connection between OT network 104 and IT network 102. In some cases, due to the sensing configuration of monitoring application 208, only copied data from the wire 210 of the defined loop can be transmitted unidirectionally to receiver 204. That is, in various instances, data cannot flow from interceptor 216 to the wire 210 of the defined loop, thus protecting OT network 104 from interference from IT network 102. In one example, interceptor 216 acts as a network test access point (TAP), intercepting transmissions between output 212 and input 214 defined by transmitter 202 and copying the data to the monitoring port of receiver 204. In another example, interceptor 216 can be implemented as a Switched Port Analyzer (SPAN), which performs port mirroring of the intercepted transmission on wire 210 of the defined loop. In yet another example, data can be sent directly to DCU 106, specifically transmitter 202, for anonymization. In some instances, data can be anonymized, and the anonymized data can be made available on receiver 204 upon request.

[0023] Still referencing Figure 2 The transmitter 202 may also include a bootloader 218 and firmware 220, which may include operating instructions for the transmitter 202 and DCU 106. Similarly, the receiver 204 may also include a bootloader 222 and firmware 224, which may include operating instructions for the receiver 204 and DCU 106. The DCU 106 may also include one or more databases. For example, the transmitter 202 may include a first transmitter or raw data database 226 and a second transmitter or sanitized synthetic data database 227. The receiver 204 may include a receiver database 228. In this example, data copied from the transmitter 202 may be cached in the receiver database 228. Similarly, data received by the transmitter 202 from the OT network 104 may be cached, for example, in the raw data database 226, so that the data can be processed to protect privacy. As described herein, data from the raw data database 226 can be processed to define sanitized data. Before transmitting the purification data via the wire 210 of the monitoring device 208 at regular intervals and at predetermined times, the purification data can be cached in the synthetic data database 227.

[0024] In various instances, DCU 106 can include one or more processors, which can include one or more central processing units (CPUs), graphics processing units (GPUs), or any other processor known in the art. More generally, a processor as described herein is a device for executing machine-readable instructions stored on a computer-readable medium to perform a task, and can include any one or a combination of hardware and firmware. In one instance, any software and firmware deployed in receiver 204 can be executed by the processor of receiver 204. In another instance, any software and firmware deployed in transmitter 202 can be executed by the processor of transmitter 202 to maintain physical isolation between public IT network 102 and private OT network 104 and to ensure one-way communication. The processor of DCU 106 can also include memory storing machine-readable instructions that can be executed to perform a task. The processor of DCU 106 can use or include the capabilities of, for example, a computer, controller, or microprocessor, and can be modulated using executable instructions to perform private functions that general-purpose computers do not perform. The DCU106 can include one or more processors, comprising any suitable type of processing unit, including but not limited to a central processing unit, microprocessor, Reduced Instruction Set Computer (RISC) microprocessor, Complex Instruction Set Computer (CISC) microprocessor, microcontroller, ASIC, FPGA, System-on-Chip (SoC), Digital Signal Processor (DSP), etc. Furthermore, the DCU106 processor can have any suitable microarchitecture design, including any number of components such as registers, multiplexers, arithmetic logic units, cache controllers for controlling read / write operations on the cache, branch predictors, etc. The processor's microarchitecture design can support any of a variety of instruction sets.

[0025] Continue to refer to Figure 2Receiver 204 can include various applications or modules, such as embedded network security applications for supporting security monitoring and diagnostics related to OT network 104. For example, transmitter 202 can include transceiver module 232, configured to send and receive data to and from devices in various networks such as GPRS, LTE, or 5G networks. Additionally or alternatively, receiver 204 can include data management application 230, which can be configured with a given data processing policy and can process data according to the policy. In an example, data management application 230 can read and / or delete data from receiver database 228. In some cases, data management application 230 can filter and / or compress data according to a policy. Furthermore, data management application 230 can transmit copied data from transmitter 202 to IT network 102, particularly, for example, to IDS 114, SIEM system 116, or forensic analysis system 118. The copied data can be transmitted via transceiver module 232 or multi-port 124. In some cases, data received in receiver 204 can be transmitted to systems within IT network 102 via a push mechanism (e.g., through a publish-subscribe method). Alternatively or additionally, data can be buffered in receiver database 228 and can be transmitted by systems within IT network 102 via a pull mechanism. For example, a system can actively request data from receiver database 228 or receiver 204, for example, via multi-port 124.

[0026] Transmitter 202 may also include various applications or modules according to various embodiments. In some instances, transmitter 202 may include a data collection application 234 configured to receive data from a data capture port (e.g., Ethernet port 120) of unidirectional network interface 206. In some cases, data collection application 234 may be configured to filter data according to a policy. In some instances, such a policy or configuration may be obtained by data collection application 234 from transmitter database 226. Transmitter 202 may further include various privacy-preserving applications. In particular, for example, transmitter 202 may be configured to include a neural network application or module 236 configured to protect the privacy of information related to data collected from OT network 104 and stored in raw data database 226, as further described herein.

[0027] In some instances, neural network module 236 includes a generative adversarial network (GAN) or access-based GAN, which can learn attributes associated with raw data collected from OT network 104 to generate sanitized data. For example, data collection application 234 can collect raw data from one-way network interface 206 and provide the raw data to neural network module 236. Neural network module 236 can learn the distribution of the collected raw data. Based on the learned data distribution associated with the raw data, neural network module 236 can generate data samples with a distribution similar to the given raw data. Such data samples can define sanitized data corresponding to the raw data. For example, sanitized data can be sent from transmitter 202 to receiver 204, and receiver 204 can transmit the sanitized data to IT network 102, such as to SIEM system 116 for analysis. Therefore, in this configuration, the data leaving DCU 106 is different from the actual data collected from OT network 104. This paper recognizes that because the actual raw data is not transmitted to receiver 204 or outside of DCU 106, privacy protection is enhanced, enabling various data owners or customers associated with the OT network to share their data with greater confidence for combined analysis in various systems, such as SIEM system 116. Furthermore, the increased sharing and analysis of data, for example, on SIEM system 116, can enhance anomaly detection capabilities, as well as other capabilities based on the analyzed data.

[0028] Now for reference Figure 3The exemplary system 300 includes a DCU 106 deployed at a factory, such as a first factory 302. Factory 302 may also include an OT network 104. The DCU 106, particularly a transmitter 202, may include one or more containers, each defining its own operating environment for an application or module. For example, transmitter 202 may include a first container 304 and a second container 306 separate from the first container 304. The containers can be protected so that the first container 304 and the second container 306 cannot be configured by different users of the DCU 106. The first container 304 may include a data collection application 234 and a raw data database 226. The second container 306 may include one or more data privacy protection applications or modules. In an exemplary embodiment, the second container 306 includes a neural network module 236 configured to generate synthetic data based on the raw data. Specifically, the raw data collected by the data collection application 234 may define a first data distribution, and the neural network module 236 may generate synthetic data based on the first distribution of the raw data, such that the synthetic data defines a second data distribution falling within a predetermined tolerance of the first data distribution. For example, the data distributions of synthetic data and real data can each be defined by an average value, and this average value can be compared with a predetermined tolerance to determine whether they are close enough to each other that the synthetic data adequately represents the original data. The predetermined tolerance can vary as needed. For example, the predetermined tolerance can vary depending on the data type being generated and compared. In another instance, the predetermined tolerance can also indicate the maximum precision with which the synthetic data can be used to represent the original data. For example, in some cases, if the synthetic data is too close to the original data (e.g., greater than the upper limit of the predetermined tolerance), privacy related to the original data may be involved. Subsequently, the synthetic data representing the original data can be analyzed, thereby performing the analysis of the original data without having to send the original data to receiver 204, thus eliminating the need to send the original data to any receiver analysis system.

[0029] In some cases, one or more statistical properties of the raw data are identified and compared with one or more statistical properties of the corresponding synthetic data. Statistical properties can include, for example, but not limited to, mean, mean pattern, standard deviation, population data distribution (e.g., defined by linear or nonlinear regression), kurtosis, and skewness. Transmitter 202 can anonymize or synthesize the data to preserve one or more statistical properties of interest. Therefore, transmitter 202 can be configured to store one or more selected statistical attributes, depending on the type of raw data collected. Furthermore, in some cases, the statistical attribute of interest can be changed during data collection.

[0030] The data collection application 234 within the first container 304 can be configured to listen to the one-way network interface 206 to collect raw data from one or more devices on the private OT network 104. In an exemplary configuration, the data collection application 234 is located in a separate container from the neural network module 236, or otherwise separated from the neural network module 236, allowing the data collection application 234 to be updated or scaled without interrupting the neural network module 236.

[0031] In addition, continue to refer to Figure 3 System 300 can include multiple sites or plants, each providing data to a central system or server 314, for example, enabling the data to be aggregated and analyzed jointly. Each site or plant can include one or more DCUs 106, which provide synthetic data to the central server 314. Therefore, multiple DCUs can be configured to operate as unidirectional communication connections between the central server 314 and corresponding private networks of multiple private networks of system 300. In an example, SIEM system 116 and / or IDS 114 can retrieve synthetic data from the central server 314 for analysis. Exemplary system 300 includes a first plant 302, a second plant 308, and a third plant 310, but it should be understood that any number of sites or plants, and therefore any number of DCUs, can be coupled to the central server 314 as needed. Each DCU 106 receiver 204 in system 300 can be configured to send corresponding synthetic data to central server 314, enabling analysis of raw data from multiple private OT networks based on synthetic data representing the raw data, without the need for the central server to obtain the raw data.

[0032] This paper recognizes that, in addition to the raw data itself, generating synthetic data and providing it, rather than the raw or real data, to the central server of the analysis system can protect various information associated with the raw data. In some cases, synthetic data can be generated to mask values ​​associated with the corresponding raw data. In other instances, but not limited to, the identities of various asset owners associated with each plant, logical or trade secrets related to the plant, and the components or systems of various plants can be protected by generating synthetic data that represents the raw data. This paper also recognizes that such privacy protection derived from synthetic data can, in some cases, enable or allow various plants to combine their data together for analysis on the central server 314, thereby improving the data samples that can be analyzed and enhancing the data analysis that can be performed.

[0033] Continue to refer to Figure 3The neural network module 236 can include a generator 316 and a discriminator 318 to define a generative adversarial network (GAN) or a convolutional neural network (CNN). The transmitter 202 can be configured to train the neural network based on real or raw data from one or more devices of the private OT network 104. When the neural network is trained, the neural network module 236 can generate synthetic data based on the corresponding raw data, which defines a data distribution similar to the data distribution defined by the corresponding raw data. For example, the synthetic data can define a data distribution falling within a predetermined tolerance of the data distribution defined by the corresponding raw data. In some cases, a noise vector 320 is input to the generator 316. In an example, the noise vector 320 can define a random number generator. Based on the noise vector 320, the generator 316 can generate fake or synthetic data, which can be stored in a cleaned synthetic data database 227. During training, fake and real data can be input to the discriminator 318 from the synthetic data database 227 and the raw data database 226, respectively. The discriminator 318 can learn real data from fake data, and its output can be fed back to the generator 316, allowing the neural network module 236 to be fine-tuned. Subsequently, the generator 316 can generate synthetic data that more closely approximates the original data, or select statistical properties that more closely approximate the original data.

[0034] Therefore, the training phase can include collecting raw source data for subscribed variables or statistical properties of interest. For example, such variables or properties of interest can be configured on the DCU 106 via a configuration file or user interface. The source data can be input to the generator 316 and the discriminator 318. The discriminator 318 can use the source data as a training dataset (e.g., sample from it) and can control the training process until a predetermined level of accuracy is reached. In some cases, instead of randomized data from a normal distribution, the generator 316 can use these samples to generate seed data. The generator 316 can deduce the distribution of the data and then use this distribution to augment the random data to increase the error rate of the discriminator 318 (e.g., tricking the discriminator into thinking an incorrect candidate has been selected). In some cases, the neural network can be configured to be in continuous training mode, where its output parameters are adjusted as input data arrives.

[0035] Now for reference Figure 4Exemplary operation 400 can be performed by DCU 106, which includes a transmitter 202 and a receiver 204 physically isolated from the transmitter 202. A monitoring device 208 can be positioned between the transmitter 202 and the receiver 204, and DCU 106 can be positioned between a private network and a public network. Therefore, the monitoring device 208 can be positioned between the private network and the public network. At 402, the transmitter 202 can collect real or raw data from one or more devices on the private network. In some cases, the data collection application 234 listens on the unidirectional network interface 206 to collect data from the private network. At 404, the data collection application 234 can store the raw data in a container. For example, the data collection application 234 can store the raw data in a raw data database 226 within a first container 304. At 406, in this example, a neural network module 236 located in a different container than the raw data database 226 can obtain the raw data. For example, the neural network module 236 within the second container 306 can retrieve raw data from the raw data database 226. Based on the retrieved raw data, at 408, the neural network module 236 can generate synthetic data corresponding to the raw data. At 410, the neural network module 236 can verify that the generated synthetic data accurately represents the raw data. For example, the data distribution of the raw data can be compared with the data distribution of the synthetic data, and if the data distributions are within a predetermined tolerance range, the synthetic data can be verified. If the synthetic data is not verified, the data can be fed back to the generator 316 so that updated synthetic data can be generated. In this example, when the synthetic data is verified at 410, it can be transmitted to an external system, such as the IT network 102 or the central server 314. Specifically, the transmitter 202 can transmit the verified synthetic data to the receiver 204 via the monitoring device 208, and the receiver 204 can transmit the synthetic data outward from the DCU 106.

[0036] Unbound by theory, this paper recognizes that, according to various embodiments, if data is hacked in some way while being sent to or from receiver 204 to an external system, the hacker can access falsified or synthetic data. Therefore, in certain circumstances, even if communication is intercepted, the secrets associated with the original data can still be protected and kept confidential.

[0037] Figure 5An example of a computing environment in which embodiments of the present invention can be implemented is illustrated. The computing environment 500 includes a computer system 510, which may include a communication mechanism such as a system bus 521 or other communication mechanisms for transmitting information within the computer system 510. The computer system 510 also includes one or more processors 520 coupled to the system bus 521 for processing information. The robotic device 104 may include one or more processors 520 or be coupled to one or more processors.

[0038] Processor 520 may include one or more central processing units (CPUs), graphics processing units (GPUs), or any other processor known in the art. More generally, a processor as described herein is a device for performing tasks by executing machine-readable instructions stored on a computer-readable medium, and may include any one or a combination of hardware and firmware. The processor may also include memory storing machine-readable instructions that can be executed to perform tasks. The processor operates on information by manipulating, analyzing, modifying, transforming, or transferring information for use by an executable program or information device, and / or by routing information to an output device. The processor may use or include the capabilities of, for example, a computer, controller, or microprocessor, and may be modulated using executable instructions to perform private functions that a general-purpose computer does not perform. The processor may include any type of suitable processing unit, including but not limited to central processing units, microprocessors, reduced instruction set computer (RISC) microprocessors, complex instruction set computer (CISC) microprocessors, microcontrollers, application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), system-on-a-chip (SoCs), digital signal processors (DSPs), etc. Furthermore, the processor 520 can have any suitable microarchitecture design, including any number of components such as registers, multiplexers, arithmetic logic units, cache controllers for controlling read / write operations on the cache, branch predictors, etc. The processor's microarchitecture design can support any instruction set from a variety of instruction sets. The processor can be coupled (electrically coupled and / or as an included executable component) to enable interaction and / or communication between them. The user interface processor or generator is a known element, including electronic circuitry or software, or a combination of both, for generating display images or portions thereof. The user interface includes one or more display images that enable the user to interact with the processor or other devices.

[0039] System bus 521 may include at least one of a system bus, memory bus, address bus, or message bus, and may allow the exchange of information (e.g., data (including computer-executable code), signaling, etc.) between various components of computer system 510. System bus 521 may include, but is not limited to, a memory bus or memory controller, a peripheral bus, an accelerated graphics port, etc. System bus 521 may be associated with any suitable bus architecture, including but not limited to Industry Standard Architecture (ISA), Micro Channel Architecture (MCA), Enhanced ISA (EISA), Video Electronics Standards Association (VESA) architecture, Accelerated Graphics Port (AGP) architecture, Peripheral Component Interconnect (PCI) architecture, PCI-Express architecture, Personal Computer Memory Card International Association (PCMCIA) architecture, Universal Serial Bus (USB) architecture, etc.

[0040] Continue to refer to Figure 5 The computer system 510 may also include a system memory 530 coupled to a system bus 521 for storing information and instructions to be executed by the processor 520. The system memory 530 may include computer-readable storage media in the form of volatile and / or non-volatile memory, such as read-only memory (ROM) 531 and / or random access memory (RAM) 532. RAM 532 may include other dynamic storage devices (e.g., dynamic RAM, static RAM, and synchronous DRAM). ROM 531 may include other static storage devices (e.g., programmable ROM, erasable PROM, and electrically erasable PROM). Furthermore, the system memory 530 may be used to store temporary variables or other intermediate information during instruction execution by the processor 520. A basic input / output system 533 (BIOS) contains basic routines that facilitate the transfer of information between internal components of the computer system 510; for example, during startup, the BIOS may be stored in ROM 531. RAM 532 may contain data and / or program modules that the processor 520 can immediately access and / or are currently running on the processor. The system memory 530 may also include, for example, an operating system 534, application programs 535, and other program modules 536. The application programs 535 may also include a user portal for developing applications, allowing input parameters to be entered and modified as needed.

[0041] Operating system 534 can be loaded into memory 530 and provides an interface between other application software executing on computer system 510 and the hardware resources of computer system 510. More specifically, operating system 534 can include a set of computer-executable instructions for managing the hardware resources of computer system 510 and for providing common services to other applications (e.g., managing memory allocation among various applications). In some exemplary embodiments, operating system 534 can control the execution of one or more program modules depicted as being stored in data memory 540. Operating system 534 can include any operating system now known or that may be developed in the future, including but not limited to any server operating system, any mainframe operating system, or any other proprietary or non-proprietary operating system.

[0042] Computer system 510 may also include a disk / media controller 543 coupled to system bus 521 to control one or more storage devices, such as hard disk 541 and / or removable media drives 542 (e.g., floppy disk drives, optical disk drives, tape drives, flash drives, and / or solid-state drives), for storing information and instructions. Storage devices 540 can be added to computer system 510 using appropriate device interfaces (e.g., Small Computer System Interface (SCSI), Integrated Device Electronics (IDE), Universal Serial Bus (USB), or FireWire). Storage devices 541 and 542 may be external to computer system 510.

[0043] Computer system 510 may also include a field device interface 565 coupled to system bus 521 to control field devices 566, such as equipment used in a production line. Computer system 510 may include a user input interface or GUI 561, which may include one or more input devices, such as a keyboard, touchscreen, tablet computer, and / or click devices, for interacting with a computer user and providing information to processor 520.

[0044] Computer system 510 is capable of performing some or all of the processing steps of embodiments of the present invention in response to processor 520 executing one or more sequences of instructions contained in memory (such as system memory 530). Such instructions can be read into system memory 530 from another computer-readable storage medium 540, such as magnetic hard disk 541 or removable media drive 542. Magnetic hard disk 541 and / or removable media drive 542 can contain one or more data storage devices and data files used in embodiments of the present invention. Data storage device 540 can include, but is not limited to, databases (e.g., relational databases, object-oriented databases, etc.), file systems, flat files, distributed data storage (in which data is stored on more than one node of a computer network), peer-to-peer network data storage, etc. Data storage can store various types of data, such as skill data, sensor data, or any other data generated according to embodiments of the present invention. Data storage contents and data files can be encrypted to improve security. Processor 520 can also be used in a multiprocessing arrangement to execute one or more sequences of instructions contained in system memory 530. In alternative embodiments, hard-wired circuitry can be used in place of or in combination with software instructions. Therefore, the embodiments are not limited to any particular combination of hardware circuitry and software.

[0045] As described above, computer system 510 can include at least one computer-readable medium or memory for storing instructions programmed according to embodiments of the present invention and for containing data structures, tables, records, or other data described herein. The term "computer-readable medium" as used herein refers to any medium that participates in providing instructions to processor 520 for execution. Computer-readable media can take many forms, including but not limited to non-transitory, non-volatile, volatile, and transmission media. Non-limiting examples of non-volatile media include optical discs, solid-state drives, magnetic disks, and magneto-optical discs, such as magnetic hard disk 541 or removable media drive 542. Non-limiting examples of volatile media include dynamic memory, such as system memory 530. Non-limiting examples of transmission media include coaxial cables, copper wires, and optical fibers, including conductors constituting system bus 521. Transmission media can also take the form of acoustic or optical waves, such as those generated during radio wave and infrared data communication.

[0046] Computer-readable medium instructions for performing the operations disclosed herein can be assembler instructions, instruction set architecture (ISA) instructions, machine instructions, machine-dependent instructions, microcode, firmware instructions, state setting data, or any source code or object code written in any combination of one or more programming languages, including object-oriented programming languages ​​such as Smalltalk, C++, etc., and conventional procedural programming languages ​​such as the "C" programming language or similar programming languages. The computer-readable program instructions can be executed entirely on the user's computer, partially on the user's computer, as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the latter case, the remote computer can be connected to the user's computer via any type of network, including a local area network (LAN) or a wide area network (WAN), or can be connected to an external computer (e.g., via the Internet provided by an Internet service provider). In some embodiments, electronic circuitry including, for example, programmable logic circuitry, field-programmable gate arrays (FPGAs), or programmable logic arrays (PLAs) can be personalized to execute the computer-readable program instructions by utilizing state information from the computer-readable program instructions in order to perform the aspects disclosed herein.

[0047] Aspects of the present invention are described herein with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments disclosed herein. It should be understood that each block of the flowcharts and / or block diagrams, and combinations of blocks in the flowcharts and / or block diagrams, can be implemented by computer-readable medium instructions.

[0048] The computing environment 500 may also include a computer system 510 operating in a network environment, which is logically connected to one or more remote computers, such as remote computing devices 580. A network interface 570 enables communication, for example, via a network 571 with other remote devices 580 or systems and / or storage devices 541, 542. The remote computing device 580 may be a personal computer (laptop or desktop), mobile device, server, router, network PC, peer-to-peer device, or other public network node, and typically includes many or all of the elements described above with respect to computer system 510. When used in a network environment, computer system 510 may include a modem 572 for establishing communication via network 571 (e.g., the Internet). The modem 572 may be connected to system bus 521 via user network interface 570 or via another suitable mechanism.

[0049] Network 571 can be any network or system known in the art, including the Internet, intranet, local area network (LAN), wide area network (WAN), metropolitan area network (MAN), direct connection or a series of connections, cellular telephone network, or any other network or medium that facilitates communication between computer system 510 and other computers (e.g., remote computing device 580). Network 571 can be wired, wireless, or a combination thereof. Wired connections can be implemented using Ethernet, Universal Serial Bus (USB), RJ-6, or any other wired connection known in the art. Wireless connections can be implemented using Wi-Fi, WiMAX and Bluetooth, infrared, cellular networks, satellite, or any other wireless connection method known in the art. Furthermore, several networks can operate independently or communicate with each other to facilitate communication within network 571.

[0050] It should be understood that Figure 5 The program modules, applications, computer-executable instructions, code, etc., depicted in system memory 530 are merely illustrative and not exhaustive, and are described as being such that processing supported by any particular module can alternatively be distributed across multiple modules or executed by different modules. Furthermore, various program modules, scripts, plug-ins, application programming interfaces (APIs), or any other suitable computer-executable code locally hosted on computer system 510, remote device 580, and / or hosted on other computing devices accessible via one or more networks in network 571, can be provided to support processing by… Figure 5 The functions and / or additional or alternative functions provided by the described program modules, applications, or computer-executable code. Furthermore, functions can be modularized differently, allowing them to be described as being provided by… Figure 5 The processing collectively supported by the described set of program modules can be executed by fewer or more modules, or a function described as being supported by any particular module can be at least partially supported by another module. Furthermore, the program modules supporting the functionality described herein can form part of one or more applications that can be executed on any number of systems or devices according to any suitable computational model (e.g., client-server model, peer-to-peer model, etc.). Additionally, any program modules described as being supported by… Figure 5 The functionality supported by any program module described herein can be implemented, at least in part, across any number of devices in the form of hardware and / or firmware.

[0051] It should also be understood that, without departing from the scope of this invention, computer system 510 may include alternative and / or additional hardware, software, or firmware components beyond those described or depicted. More specifically, it should be understood that the software, firmware, or hardware components depicted as part of computer system 510 are merely illustrative, and some components may be absent or additional components may be provided in various embodiments. While various illustrative program modules have been depicted and described as software modules stored in system memory 530, it should be understood that the functionality described as being supported by program modules can be enabled by any combination of hardware, software, and / or firmware. It should also be understood that, in various embodiments, each of the above modules can represent a logical partition of supported functionality. Such logical partitioning is depicted for ease of interpretation of functionality and may not represent the structure of the software, hardware, and / or firmware implementing the functionality. Therefore, it should be understood that, in various embodiments, functionality described as being provided by a particular module can be provided at least partially by one or more other modules. Furthermore, in some embodiments, one or more of the depicted modules may not be present, while in other embodiments, additional modules not depicted may be present and capable of supporting at least a portion of the described functionality and / or additional functionality. Furthermore, while some modules can be described and depicted as submodules of another module, in some embodiments, such modules can be provided as independent modules or submodules of other modules.

[0052] Although specific embodiments of the invention have been described, those skilled in the art will recognize that many other modifications and alternative embodiments are within the scope of this disclosure. For example, any functionality and / or processing capability described with respect to a particular device or component can be performed by any other device or component. Furthermore, while various illustrative implementations and architectures have been described according to the embodiments disclosed herein, those skilled in the art will understand that many other modifications to the illustrative implementations and architectures described herein are also within the scope of this disclosure. Moreover, it should be understood that any operation, element, component, data, etc., described herein as being based on another operation, element, component, data, etc., can also be based on one or more other operations, elements, components, data, etc. Therefore, the term "based on" or variations thereof should be interpreted as "at least partially based on".

[0053] Although embodiments have been described using language specific to structural features and / or methodological actions, it should be understood that the disclosure of this invention is not necessarily limited to the specific features or actions described. Rather, specific features and actions are disclosed as illustrative forms of implementing embodiments. Conditional language, such as “can,” “could,” “might,” or “may,” unless specifically stated otherwise or otherwise understood in the context, is generally intended to convey that certain embodiments can include certain features, elements, and / or steps, while other embodiments do not. Therefore, such conditional language generally does not imply that one or more embodiments require features, elements, and / or steps in any way, or that one or more embodiments must include logic for determining whether such features, elements, and / or steps are included in or will be performed in any particular embodiment, with or without user input or prompting.

[0054] The flowcharts and block diagrams in the figures illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments disclosed in the present invention. In this regard, each block in a flowchart or block diagram can represent a module, segment, or portion of instructions, including one or more executable instructions for implementing a specified logical function. In some alternative embodiments, the functions marked in the blocks may occur in a non-consecutive order. For example, two blocks shown consecutively may actually execute substantially simultaneously, or these blocks may sometimes execute in reverse order, depending on the functions they involve. It should also be noted that each block illustrated in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, can be implemented by a dedicated hardware-based system that performs a specific function or action or executes a combination of dedicated hardware and computer instructions.

Claims

1. A data collection apparatus configured to operate as a one-way communication link between a private network and a public network, the data collection apparatus comprising: a transmitter comprising a one-way network interface coupled to one or more devices of the private network, the transmitter configured to collect raw data from the one or more devices of the private network, the raw data defining a first data distribution; an input coupled to a wire; and an output coupled to the wire; a receiver configured to receive anonymized data from the transmitter over the one-way communication link; and a monitoring apparatus comprising the wire coupled to the output and the input of the transmitter to define a loop, the monitoring apparatus further comprising an interceptor inductively coupled to the loop to define the one-way communication link, wherein the transmitter is configured to generate the anonymized data based on the first data distribution of the raw data such that the anonymized data is representative of the raw data without disclosing the raw data, and the receiver is coupled to the interceptor and the public network, the receiver configured to listen to the interceptor at one or more specific times to receive the anonymized data from the transmitter over the one-way communication link defined by the monitoring apparatus, the transmitter further comprising a neural network configured to generate the anonymized data based on the raw data such that the anonymized data defines synthetic data having a second data distribution that falls within a predetermined tolerance of the first data distribution.

2. The data acquisition device of claim 1, wherein, the receiver configured to transmit the anonymized data to an analysis system within the public network such that the raw data can be analyzed based on the anonymized data that is representative of the raw data.

3. The data acquisition device of claim 1, wherein, the transmitter further configured to generate the anonymized data corresponding to the raw data as the raw data is received by the transmitter so as to define continuous online data anonymization.

4. The data acquisition device of claim 1, wherein, the transmitter configured to train the neural network based on real data from the one or more devices of the private network.

5. The data acquisition device of claim 1, wherein, the transmitter comprising a first container and a data collection application within the first container, the data collection application configured to listen to the one-way network interface to collect the raw data from the one or more devices of the private network.

6. The data acquisition device of claim 5, wherein, the transmitter further comprising a second container separate from the first container, the neural network within the second container.

7. A method performed by a data collection apparatus comprising a transmitter comprising an input and an output coupled to a wire to define a loop, a receiver physically isolated from the transmitter, and a monitoring apparatus between the transmitter and the receiver, the monitoring apparatus comprising the wire and an interceptor coupled to the loop to define a one-way communication link, the data collection apparatus disposed between a private network and a public network, the method comprising: The transmitter collects raw data from one or more devices of the private network, the raw data defining a first data distribution; based on the first data distribution of the raw data, generates, without disclosing the raw data, anonymized data representative of the raw data; and The receiver listens to the interceptor at one or more particular times to receive the anonymized data from the transmitter over the unidirectional communication connection defined by the monitoring device, wherein the transmitter includes a neural network through which the anonymized data is generated based on the raw data such that the anonymized data defines synthetic data having a second data distribution that falls within a predetermined tolerance of the first data distribution.

8. The method of claim 7, further comprising: The receiver sends the anonymized data to an analytics system within the public network such that the analytics system can analyze the raw data based on the anonymized data representative of the raw data without the analytics system needing to obtain the raw data.

9. The method of claim 7, wherein, Generating anonymized data further comprises: generating the anonymized data corresponding to the raw data as the raw data is received by the transmitter to define continuous online data anonymization.

10. The method of claim 7, further comprising: training the neural network based on real data from the one or more devices of the private network.

11. The method of claim 10, wherein, The transmitter includes a first container and a data collection application within the first container, the method further comprising: listening, by the data collection application, to a unidirectional network interface of the transmitter to collect the raw data from the one or more devices of the private network.

12. The method of claim 11, wherein, The transmitter further includes a database within the first container, the method further comprising: storing, by the data collection application, the raw data in the database within the first container.

13. The method of claim 12, wherein, The transmitter further includes a second container separate from the first container, the neural network being within the second container, the method further comprising: retrieving, by the neural network, the raw data from the database within the first container; and storing the synthetic data in a second database within the second container.

Citation Information

Patent Citations

  • Adaptive anonymization of data using statistical inference

    US20200082290A1

  • Data capture apparatus with embedded security applications and unidirectional communication

    WO2020061388A1