Terminal access locking equipment for industrial control system

By introducing the linkage control of interface detection and logic authentication modules into the industrial control system, the problem of combining physical access status with logical identity authentication is solved, achieving efficient security protection for terminal devices and enhancing the security strength of the system's first line of defense.

CN121968254APending Publication Date: 2026-05-01NINGBO ZHENGHANG INTELLIGENT SYSTEM CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
NINGBO ZHENGHANG INTELLIGENT SYSTEM CO LTD
Filing Date
2025-12-31
Publication Date
2026-05-01

AI Technical Summary

Technical Problem

Existing technologies cannot effectively combine physical access status with logical identity authentication, resulting in high risks of unauthorized access for terminal devices in industrial control systems. Traditional physical protection cannot determine the legitimacy of the identity, and logical authentication cannot perceive the physical connection status.

Method used

Design a terminal access locking device, including an interface detection module, a logic authentication module, and a linkage control module. By monitoring the physical interface connection status in real time and combining it with the logic authentication results, control commands are generated to determine whether communication is allowed or blocked, thus adopting a hardware-level proactive defense.

Benefits of technology

It achieves deep integration of physical interface connection and logical identity authentication, which can proactively isolate the device when the attacker fails to pass the legitimate identity authentication, shorten the threat dwell time, improve system security, and provide real-time alarms and logging.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121968254A_ABST
    Figure CN121968254A_ABST
Patent Text Reader

Abstract

The invention discloses terminal access locking equipment for an industrial control system. The terminal access locking equipment comprises a physical interface detection module, a logic authentication module, a linkage control module and a communication on-off execution module. The device senses the external physical connection state in real time through the physical interface detection module, and the logic authentication module verifies the identity of the access terminal. The linkage control module generates a communication permission instruction only when receiving the physical connection validity and identity authentication passing signals at the same time; otherwise, a communication blocking or alarm triggering instruction is generated immediately, and a communication on-off execution module executes on-off control on a physical layer or a protocol layer. According to the invention, hardware-level forced linkage of physical access and logic authentication is realized, two-factor authentication is deepened to the bottom layer of a communication link, unauthorized access can be actively blocked from the source, and the terminal access security and active defense capability of the industrial control system are remarkably improved.
Need to check novelty before this filing date? Find Prior Art

Description

A terminal access locking device for industrial control systems Technical Field

[0001] This invention belongs to the field of access control technology for industrial control systems, and specifically relates to a terminal access locking device for industrial control systems. Background Technology

[0002] Industrial control systems are widely used in critical national infrastructure sectors such as energy, manufacturing, and transportation, making their security paramount. With the development of the Industrial Internet, the interaction between industrial control systems and external networks is increasing, leading to increasingly severe security threats. Among these threats, unauthorized access to the physical ports of industrial control terminal equipment (such as engineering workstations, operator workstations, and servers) is a high-risk and difficult-to-defend attack vector.

[0003] Currently, security protection for industrial control terminal access mainly relies on two types of technologies: one is physical layer protection, such as locking the cabinet, disabling ports, or using physical locks, the main purpose of which is to prevent unauthorized personnel from directly accessing the equipment ports; the other is logical / network layer authentication and protection, such as operating system login passwords, digital certificate authentication, network firewall policies, or intrusion detection systems, the core of which is to verify the digital identity of users or devices and control network data flow.

[0004] However, traditional physical security measures (such as locks) only provide basic access restrictions and cannot verify the legitimacy of personnel or devices that have gained physical access. Once an attacker breaches the physical barrier (e.g., through internal personnel or stolen equipment), they can directly access the port. Conversely, simple logical authentication mechanisms (such as software passwords) cannot detect the legitimacy of the port's physical connection status. If legitimate credentials are stolen or authentication is performed on a physically compromised port, the system will still allow access.

[0005] Therefore, the industrial control field urgently needs a terminal access control device that can deeply and in real-time couple physical access status with logical identity authentication and can proactively execute security decisions at the hardware level to fill the current technological gap in the linkage of dual verification of "physical presence" and "legality of identity" and fundamentally improve the security strength of the first line of defense of industrial control systems. Summary of the Invention

[0006] To solve the above-mentioned technical problems, the present invention provides the following technical solution.

[0007] A terminal access locking device for an industrial control system includes:

[0008] The interface detection module is used to monitor the connection status of at least one external physical interface in real time and generate the corresponding physical connection signal.

[0009] The logical authentication module is used to authenticate the identity of the terminal requesting access and generate a logical authentication result.

[0010] The linkage control module is communicatively connected to the interface detection module and the logical authentication module, and is used to receive the physical connection signal and the logical authentication result. The linkage control module is configured to generate a control command to allow communication only when it simultaneously receives a physical connection signal indicating that the physical interface is connected and a logical authentication result indicating that the terminal has passed the identity authentication; otherwise, it generates a control command to block communication or trigger an alarm.

[0011] The communication on / off execution module is connected to the linkage control module and is used to connect or disconnect the data communication link between the external physical interface and the internal protected industrial control system according to the control command.

[0012] Furthermore, the physical interface types monitored by the interface detection module include at least one of USB interface, Ethernet interface, and serial communication interface.

[0013] Furthermore, the authentication methods supported by the logical authentication module include at least one of digital certificate-based authentication, dynamic token-based authentication, and biometric authentication.

[0014] Furthermore, the linkage control module includes a timing unit; the linkage control module is further configured to: upon receiving a physical connection signal indicating that the physical interface has been connected, activate the timing unit; if no logical authentication result indicating that the terminal has passed authentication is received within a preset time, directly generate a control command to trigger an alarm and / or block communication.

[0015] Furthermore, it also includes a status indication module, which is connected to the linkage control module and is used to provide indication signals according to the current control command or equipment status.

[0016] Furthermore, the communication connection / disconnection execution module includes a physical switch circuit and / or a logic switch unit; the physical switch circuit is used to connect or disconnect the data line at the physical layer; the logic switch unit is used to allow or block data packets at the protocol layer.

[0017] Furthermore, it also includes an alarm signal output module connected to the linkage control module; when the linkage control module generates a control command to trigger an alarm, the alarm signal output module sends an alarm signal to the external monitoring system.

[0018] Furthermore, it also includes a network communication module; the linkage control module uploads device operation logs, authentication events and alarm information to the remote security management platform through the network communication module.

[0019] Furthermore, it also includes a local storage module for storing preset authentication policies, valid identity credential information, and device operation logs.

[0020] The terminal access locking device for industrial control systems provided by this invention achieves dual active defense through innovative hardware structure design and modular collaboration. Its main technical effects are reflected in the following aspects:

[0021] 1. By binding the connection status of the physical interface (physical layer signal) with the authentication result of the terminal device (logic layer signal), even if an attacker physically contacts and connects to the interface, the system will be actively isolated if it cannot pass legitimate authentication, effectively defending against unauthorized physical access attacks caused by device loss, interface misuse, etc.

[0022] 2. The communication connection / disconnection execution module embedded in the device can directly and quickly cut off the data communication link according to the instructions of the linkage control module. It can achieve "circuit breaking" at the initial access stage of the attack chain, greatly shortening the threat dwell time and preventing attack traffic from penetrating into the core control network.

[0023] 3. Through auxiliary modules such as status indication, local log storage, and network alarm reporting, system administrators can perceive the status of access attempts in real time (such as waiting for authentication, authentication success / failure), receive immediate alarms, and trace all physical connection and authentication events through logs. Attached Figure Description

[0024] Figure 1 is a structural block diagram of the terminal access locking device.

[0025] Figure 2 is a flowchart of the control logic for terminal access to the locking device. Detailed Implementation

[0026] The present invention will now be described in further detail with reference to the accompanying drawings and specific embodiments.

[0027] In the following embodiments, the same or similar reference numerals denote the same or similar components or components having the same or similar functions throughout. The embodiments described below with reference to the accompanying drawings are exemplary and are only used to explain the present invention, and should not be construed as limiting the present invention.

[0028] In the description of this invention, it should be understood that terms such as center, longitudinal, transverse, length, width, thickness, upper, lower, front, rear, left, right, vertical, horizontal, top, bottom, inner, outer, clockwise, counterclockwise, etc., indicating orientation or positional relationships, are based on the orientation or positional relationships shown in the accompanying drawings and are only for the convenience of describing and simplifying the description of this invention; therefore, they should not be construed as limiting this invention. Furthermore, terms such as first, second, etc., are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of technical features shown. In the description of this invention, unless otherwise expressly specified and limited, terms such as installation, connection, linking, etc., should be interpreted broadly, and those skilled in the art can understand the specific meaning of the above terms in this utility model according to the specific circumstances.

[0029] Referring to Figures 1 and 2, a terminal access locking device for industrial control systems is described. This device is typically a hardware board integrating dedicated circuitry, designed to conform to industrial module standards. It can be embedded into industrial control terminal equipment (such as engineering workstations or industrial servers) via slots or dedicated interfaces, directly connecting to the bus or physical port lines on its motherboard. Logically, this device constitutes a security co-processing unit independent of the host operating system. Its core functions are collaboratively performed by the integrated interface detection module, logic authentication module, linkage control module, and communication on / off execution module.

[0030] The interface detection module consists of multiple digital signal detection circuits, each monitoring a specific external physical interface, such as a USB port, RJ45 Ethernet port, or RS-232 / 485 serial communication port. This module continuously samples the specific pin levels or differential signal states of the interface connector. When a device is plugged into a USB port, the detection circuit senses a pull-up change on the power pin; when a network cable is plugged into an Ethernet port, the circuit detects a link pulse signal. Once a physical connection event is confirmed, the module generates a high-level physical connection signal and sends it to the linkage control module via the internal data bus. This process is purely hardware-based real-time detection, independent of the host operating system driver, ensuring immediate and reliable response.

[0031] The logic authentication module comprises a secure microprocessor and a corresponding encrypted storage unit. This microprocessor embeds a secure boot program and pre-configures multiple authentication protocol stacks. When the interface detection module is triggered, this module initiates an authentication process by handshaking with the external terminal attempting to connect via a controlled data channel. For example, in digital certificate authentication, the module requests the terminal to submit its device certificate and then verifies it using the locally stored root certificate, including checking the certificate chain, validity period, and digital signature. All cryptographic operations in the authentication process are performed internally by the secure microprocessor; sensitive information such as the private key remains within the storage unit, thus ensuring the security of the authentication process. Finally, the authentication result ("pass" or "fail") is encapsulated into a logic authentication result signal and sent to the linkage control module.

[0032] The linkage control module is implemented using a programmable logic device (such as an FPGA) or microcontroller. This module simultaneously monitors signals from both the interface detection module and the logic authentication module. Its decision logic is a strict AND gate relationship: it generates a "allow communication" control command only if it simultaneously receives a physical connection signal indicating "physical interface connected" and a logic authentication result signal indicating "authentication successful." Any other combination of conditions, such as a physical connection but authentication failure, or successful authentication but the physical connection signal not being activated (theoretically abnormal), will result in the generation of a "block communication and trigger alarm" control command. For finer control, a timing unit can also be integrated within the module. Once a physical connection signal is received, the timing unit begins a countdown; if no authentication success signal is received within a preset reasonable time window (e.g., 10 seconds), the linkage control module will directly determine a timeout failure, immediately generating an alarm and blocking command to counter denial-of-service attacks or malicious probing.

[0033] The communication enable / disable execution module is the final executor of the security policy, receiving control commands from the linkage control module. This module typically contains two parallel mechanisms to achieve defense in depth. The first is a physical switching circuit, such as a miniature electromagnetic relay or solid-state relay, directly connected in series on the data line between the controlled physical interface and the host internal system. When a blocking command is received, the relay contacts physically disconnect, completely severing the electrical connection and providing the highest level of isolation. The second is a logic switching unit, implemented by a network processor or a chip with packet filtering capabilities. The logic switching unit operates at the data link layer or network layer. Upon receiving a control command, this unit dynamically loads or unloads packet filtering rules, such as discarding all data frames from that port or allowing only authentication handshake messages while blocking all other application data. These two mechanisms can work individually or in combination to ensure effective blocking of unauthorized communication at any layer.

[0034] The device can also integrate several auxiliary modules to enhance its functionality and manageability. The status indicator module consists of several LEDs that visually display different statuses such as device power-on, port connection, authentication in progress, and authentication success / failure. The alarm signal output module converts alarm commands generated by the linkage control module into standard formats (such as dry contact signals or Modbus TCP messages) and sends them to an external central monitoring system or industrial LED signage. The network communication module allows the device to upload operation logs, all authentication event records, and alarm information to a remote security information and event management platform via a separate management port. All critical configurations and logs are simultaneously stored in the onboard memory, ensuring that logs are not lost in the event of a network outage.

[0035] The device's workflow is illustrated below: When a maintenance worker attempts to connect their laptop to the engineering station via a USB port, the interface detection module first detects the connection event and reports it. The linkage control module then activates the logic authentication module, which initiates a certificate authentication request to the laptop via the USB channel. The maintenance worker must confirm and submit a valid certificate on their computer. After successful verification, the logic authentication module sends a successful authentication signal to the linkage control module. Once the linkage control module confirms that both the physical and logical signals are valid, it commands the communication connection / disconnection execution module to connect the USB data path. At this point, the engineering station and the laptop can establish normal communication. If an unauthorized device is inserted, it will fail certificate authentication. Upon receiving an authentication failure signal or after a timeout, the linkage control module will keep the communication connection / disconnection execution module disconnected and trigger local indicator alarms and remote notifications, thus preventing the attack at the hardware level before it takes effect.

[0036] The scope of protection of this invention includes, but is not limited to, the above embodiments. The scope of protection of this invention is defined by the claims. Any substitutions, modifications, or improvements to this technology that are easily conceived by those skilled in the art fall within the scope of protection of this invention.

Claims

1. A terminal access locking device for an industrial control system, characterized in that, include: The interface detection module is used to monitor the connection status of at least one external physical interface in real time and generate the corresponding physical connection signal. The logical authentication module is used to authenticate the identity of the terminal requesting access and generate a logical authentication result. The linkage control module is communicatively connected to the interface detection module and the logical authentication module, and is used to receive the physical connection signal and the logical authentication result. The linkage control module is configured to generate a control command to allow communication only when it simultaneously receives a physical connection signal indicating that the physical interface is connected and a logical authentication result indicating that the terminal has passed the identity authentication; otherwise, it generates a control command to block communication or trigger an alarm. The communication on / off execution module is connected to the linkage control module and is used to connect or disconnect the data communication link between the external physical interface and the internal protected industrial control system according to the control command.

2. The terminal access locking device according to claim 1, characterized in that, The physical interface types monitored by the interface detection module include at least one of USB interface, Ethernet interface, and serial communication interface.

3. The terminal access locking device according to claim 1, characterized in that, The authentication methods supported by the logical authentication module include at least one of digital certificate-based authentication, dynamic token-based authentication, and biometric authentication.

4. The terminal access locking device according to claim 1, characterized in that, The linkage control module includes a timing unit; the linkage control module is further configured to: activate the timing unit upon receiving a physical connection signal indicating that the physical interface is connected; and if no logical authentication result indicating that the terminal has passed authentication is received within a preset time, directly generate a control command to trigger an alarm and / or block communication.

5. The terminal access locking device according to claim 1, characterized in that, It also includes a status indication module, which is connected to the linkage control module and is used to provide indication signals according to the current control command or equipment status.

6. The terminal access locking device according to claim 1, characterized in that, The communication connection / disconnection execution module includes a physical switch circuit and / or a logic switch unit; the physical switch circuit is used to connect or disconnect data lines at the physical layer; the logic switch unit is used to allow or block data packets at the protocol layer.

7. The terminal access locking device according to claim 1, characterized in that, It also includes an alarm signal output module, which is connected to the linkage control module; when the linkage control module generates a control command to trigger an alarm, the alarm signal output module sends an alarm signal to the external monitoring system.

8. The terminal access locking device according to claim 1, characterized in that, It also includes a network communication module; the linkage control module uploads the device operation log, authentication events and alarm information to the remote security management platform through the network communication module.

9. The terminal access locking device according to claim 1, characterized in that, It also includes a local storage module for storing preset authentication policies, valid identity credentials, and device operation logs.