An industrial network adaptive security guard device
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Utility models(China)
- Current Assignee / Owner
- GUANGZHOU PORT DATA TECH CO LTD
- Filing Date
- 2025-08-18
- Publication Date
- 2026-08-07
AI Technical Summary
现有的网络安全设备将IT安全理念简单移植到工业场景,导致对工业协议解析不深、误报率高;或其防护策略过于刚性,自动化的阻断等响应措施可能与生产流程冲突,引发生产中断事故,不具备足够的生产环境适应性
[0017]本实用新型的有益效果是:本安全防护设备根据容器化微服务架构,将数据采集、数据解析、威胁检测、告警警示、配置维护、管理调试这些核心功能模块化部署,对工业协议进行深度解析,降低误报率,防护策略弹性伸缩,减少工业控制系统自动化阻断。
Smart Images

Figure CN224610813U_ABST
Abstract
Description
Technical Field
[0001] This utility model relates to the field of industrial control system security, and in particular to an industrial network adaptive security protection device. Background Technology
[0002] Currently, Industrial Control Systems (ICS) face increasingly severe cyber threats. Existing cybersecurity devices simply transplant IT security concepts to industrial scenarios, resulting in insufficient understanding of industrial protocols and high false alarm rates; or their protection strategies are too rigid, and automated blocking and other response measures may conflict with production processes, causing production interruptions and lacking sufficient adaptability to the production environment.
[0003] In addition, traditional security devices often adopt an integrated firmware architecture, which makes the system reliability overly dependent on hardware redundancy and lacks elasticity and rapid fault recovery capabilities at the business level. Utility Model Content
[0004] The purpose of this invention is to overcome the above-mentioned problems in the existing technology and provide an adaptive security protection device for industrial networks.
[0005] To achieve the above-mentioned technical objectives and effects, this utility model is implemented through the following technical solution:
[0006] An industrial network adaptive security protection device, comprising:
[0007] An industrial motherboard is used to carry out the core computing tasks of the entire device. The industrial motherboard integrates a multi-core processor, system main memory, and solid-state storage. The multi-core processor is electrically connected to the system main memory and solid-state storage respectively.
[0008] A redundant power supply module, wherein the redundant power supply module includes at least two power supply units that independently supply power to the industrial motherboard;
[0009] The hybrid hardware acceleration module communicates with the industrial motherboard via a peripheral interconnect bus. The hybrid hardware acceleration module integrates a programmable logic device and is connected to an industrial network interface for communicating with industrial equipment and a management network interface for sending and receiving industrial field management data.
[0010] An alarm and warning module is electrically connected to an industrial motherboard. The alarm and warning module includes a status indicator light for providing visual alarm signals and a physical alarm output device for signal linkage with an external industrial equipment control system or alarm device. The status indicator light and the physical alarm output device are electrically connected to the industrial motherboard.
[0011] The high availability interface module is used to establish an independent, point-to-point high-speed communication link between the primary device and the backup device. The high availability interface module is electrically connected to the industrial motherboard, the redundant power supply module, and the alarm warning module.
[0012] Furthermore, it also includes a passive cooling chassis, in which the industrial motherboard, redundant power supply module, hybrid hardware acceleration module, and physical alarm output device are all installed, and the industrial network interface, management network interface, and status indicator lights are all installed on the panel of the cooling chassis.
[0013] The passive cooling chassis has an array of heat dissipation fins on its outer surface and heat-conducting bumps on its inner side that contact and dissipate heat with the chips on the industrial motherboard and the chips on the hybrid hardware acceleration module.
[0014] Preferably, the passive cooling chassis also has a console serial interface installed on its panel for accessing the operating system's underlying console of the security protection equipment, and the console serial interface is electrically connected to the industrial motherboard.
[0015] Preferably, the passive cooling chassis also has an out-of-band management interface installed on its panel for configuring, monitoring and maintaining the safety protection equipment, and the out-of-band management interface is electrically connected to the alarm and warning module.
[0016] Preferably, the high availability interface module includes a heartbeat interface and a data synchronization interface mounted on the panel of the passive cooling chassis. The heartbeat interface is electrically connected to the industrial motherboard, the redundant power supply module, and the alarm module, respectively, and the data synchronization interface is electrically connected to the industrial motherboard.
[0017] The beneficial effects of this utility model are: This security protection device is based on a containerized microservice architecture, which modularly deploys core functions such as data collection, data parsing, threat detection, alarm warning, configuration maintenance, management and debugging. It performs in-depth parsing of industrial protocols, reduces false alarm rate, and allows the protection strategy to be flexibly scaled, thereby reducing the automation blockage of industrial control systems. Attached Figure Description
[0018] The accompanying drawings, which are included to provide a further understanding of the present invention and form part of this application, illustrate exemplary embodiments of the present invention and, together with the description thereof, serve to explain the present invention and do not constitute an undue limitation thereof. In the drawings:
[0019] Figure 1 This is a schematic diagram of the module connection relationship of the safety protection equipment in this utility model;
[0020] Figure 2 This is a schematic diagram of the longitudinal section of the passive cooling chassis in this utility model;
[0021] The labels in the diagram are as follows: 1. Passive cooling chassis; 2. Array-type heat sink fins; 3. Thermal conductive bumps. Detailed Implementation
[0022] The present invention will now be described in detail with reference to the accompanying drawings and embodiments.
[0023] like Figure 1 and Figure 2 As shown, an industrial network adaptive security protection device includes: a passive heat dissipation chassis 1, an industrial motherboard for carrying the core computing tasks of the entire device, a redundant power supply module, a hybrid hardware acceleration module, an alarm and warning module, and a high availability interface module for establishing an independent and point-to-point high-speed communication link between the primary device and the backup device. The industrial motherboard, redundant power supply module, and hybrid hardware acceleration module are all installed in the passive heat dissipation chassis.
[0024] The passive cooling chassis 1 has an array of heat dissipation fins 2 on its outer surface, which dissipate heat to the surrounding environment through natural convection and thermal radiation. The inner side of the passive cooling chassis 1 has thermally conductive bumps 3 that contact and dissipate heat with the chips on the industrial motherboard and the hybrid hardware acceleration module. During assembly, thermal grease is applied between the thermally conductive bumps and the chips on the industrial motherboard, and between the thermally conductive bumps and the chips on the hybrid hardware acceleration module, to improve heat transfer between the chips on the industrial motherboard and the chips on the hybrid hardware acceleration module and the thermally conductive bumps. This passive cooling chassis design ensures that the heat generated inside the equipment can be quickly and efficiently conducted to the external array of heat dissipation fins and dissipated, thus ensuring long-term stable operation of the equipment within a harsh, wide temperature range (e.g., -40°C to 75°C) without relying on any active cooling components.
[0025] Passive cooling chassis are made of aluminum alloy with high thermal conductivity through extrusion or die casting processes.
[0026] Industrial motherboards are selected from Mini-ITX motherboards that meet industrial-grade standards, such as, but not limited to, Advantech's AIMB-277 model, to ensure stability in harsh environments with wide temperature ranges and vibrations.
[0027] The industrial motherboard integrates a multi-core processor, system main memory, and solid-state storage. The multi-core processor is electrically connected to the system main memory and solid-state storage respectively.
[0028] The multi-core processor uses an embedded processor with low power consumption and high performance, such as the Intel® Core™ i7-1265UE. This processor's integrated 10-core, 12-thread architecture is sufficient to efficiently support the containerized platform and the parallel operation of multiple microservices described in this invention.
[0029] The system's main memory uses industrial-grade wide-temperature DDR5 memory with a capacity of at least 16GB, such as Innosilicon's M5S0 series products. This memory supports ECC (Error-Correcting Code) error correction function, which can significantly improve the data reliability of the system under 24 / 7 uninterrupted operation.
[0030] Solid-state storage uses industrial-grade M.2 solid-state drives based on the NVMe protocol, such as Swissbit's N-30m2 series products. Their high-speed read and write performance ensures fast response of the operating system and applications, while their wide temperature range meets the requirements of industrial environments.
[0031] The redundant power module includes at least two power supply units that independently power the industrial motherboard, aiming to achieve uninterrupted operation at the hardware power supply level and thus improve equipment availability. The redundant power module adopts a 1+1 redundant power supply conforming to the CRPS (Common Redundant Power Supply) standard, such as Mean Well's RCP series products. Its structure supports the insertion or removal of any power supply unit while the system is running, i.e., hot-swappable. When one power supply unit fails due to a fault or external power interruption, the other power supply unit can instantly and seamlessly take over the entire power load, ensuring continuous equipment operation. Simultaneously, this redundant power module has a status monitoring function, reporting its health status to the main system via the PMBus protocol for timely maintenance.
[0032] An industrial-grade power connector with a mechanical locking device is installed on the passively cooled chassis. The redundant power module is connected to this industrial-grade power connector, and then a power cable with an industrial-grade power plug is connected to the factory's power grid. The industrial-grade power connector uses either Phoenix terminals or aviation connectors. The mechanical locking device on the industrial-grade power connector securely fixes the industrial-grade power plug on the power cable into the connector, reducing the risk of power connection interruption due to physical vibration or accidental contact.
[0033] The hybrid hardware acceleration module communicates with the industrial motherboard via a peripheral interconnect bus. Integrating a programmable logic device, the module is a pluggable hardware processing card configured to perform protocol parsing and field extraction operations on network packets flowing through a specific network interface. It is also configured to write processed structured data to the system's main memory via direct memory access (DMA). The programmable logic device is a field-programmable gate array (FPGA) chip, such as AMD's Zynq® UltraScale+™ MPSoC series (e.g., the ZU5EV model).
[0034] The hybrid hardware acceleration module is connected to an industrial network interface for communicating with industrial equipment and a management network interface for sending and receiving industrial field management data. The industrial network interface and the management network interface are mounted on the front panel of the heat sink chassis.
[0035] The industrial network interface is a physical network port. When the security device is deployed in cascade mode, the industrial network interface provides at least one input port and one output port to form the transmission path for the service data flow. When the security device is deployed in bypass mode, the industrial network interface connects to one or more mirror ports of the network switching device to receive copies of the service data.
[0036] The alarm and warning module is electrically connected to the industrial motherboard.
[0037] The alarm module includes status indicator lights for providing visual alarm signals and physical alarm output devices for signal linkage with external industrial equipment control systems or alarm devices. The status indicator lights are all mounted on the panel of the heat sink, and the physical alarm output devices are mounted in the passive heat sink. The status indicator lights and physical alarm output devices are electrically connected to the industrial motherboard.
[0038] When the industrial motherboard detects a preset operational fault in the safety protection equipment, it controls the status indicator light to provide a visual alarm signal by changing the light color or light mode. On the other hand, it controls the physical alarm output device to output a switch signal to achieve signal linkage with the external industrial control system or alarm device.
[0039] The preferred physical alarm output device is a dry contact relay, which outputs a switching signal by changing the on / off state of the contacts of the dry contact relay.
[0040] The passive cooling chassis also has a console serial interface on its front panel for accessing the operating system's underlying console of the security protection equipment. The console serial interface is electrically connected to the industrial motherboard.
[0041] The console serial interface uses an RS-232 interface. This console serial interface provides a communication path independent of the network protocol stack for accessing the operating system's underlying console of the security protection device. In scenarios involving network malfunctions or low-level maintenance, this interface can serve as a redundant management and debugging tool to improve the overall maintainability of the device.
[0042] The passive cooling chassis also has an out-of-band management interface on its front panel for configuring, monitoring and maintaining the safety protection equipment. The out-of-band management interface is electrically connected to the alarm and warning module.
[0043] The out-of-band management interface is physically isolated from the management network interface and is a management channel independent of the business data plane. By separating management traffic from business traffic at the physical layer, it aims to avoid potential interference of management activities to real-time industrial business and improve the management security of the device itself.
[0044] The high availability interface module includes a heartbeat interface and a data synchronization interface mounted on the front panel of the passive cooling chassis. The heartbeat interface is electrically connected to the industrial motherboard, the redundant power supply module, and the alarm module, respectively, while the data synchronization interface is electrically connected to the industrial motherboard.
[0045] In a dual-machine hot standby deployment architecture, the high availability interface module is used to establish an independent, point-to-point high-speed communication link between the primary and standby devices, which is dedicated to the synchronization of status information between the two devices and the negotiation of primary / standby switchover.
[0046] The core software system of this security protection device adopts a containerized microservice architecture. All functional services are independent containerized services, with unified lifecycle management and status monitoring handled by a central orchestration and web management platform. This containerized microservice architecture ensures isolation between functional services and strong overall system reliability. Details of each functional service are as follows:
[0047] The network packet capture service runs as a strictly isolated container with high system privileges. Its responsibility is to capture bidirectional network packets at high speed directly from the hardware queue of the high-availability interface module using kernel bypass technology. To minimize interference with the core software system of the security protection device and ensure line-speed capture performance, the network packet capture service directly injects the captured raw packet data into a high-speed memory message queue shared across containers. This achieves asynchronous decoupling from downstream analysis services, forming a stable and reliable source for the entire data processing pipeline.
[0048] The Deep Packet Parsing Service is deployed as a backend microservice and can be dynamically scaled to one or more container instances based on the load of the core software system of the security protection device. The Deep Packet Parsing Service continuously consumes raw packets from a high-speed in-memory message queue. At its core is an independently updatable industrial protocol parsing engine library. This library can accurately parse complex industrial control protocol (such as Modbus-TCP, S7, OPC UA, etc.) packets into unified, structured data objects containing instruction details, thereby shielding the diversity of underlying protocols and providing a standardized data foundation for unified, protocol-independent security policy analysis at the upper layer.
[0049] The Threat Detection and Policy Enforcement Service, serving as the core security computing engine, runs in parallel with multiple stateless container instances, integrating both static rule-based and dynamic behavior analysis detection capabilities. During runtime, this service first performs efficient static detection based on preset rules such as five-tuple access control, industry-level instruction whitelists, and malicious signature codes. Subsequently, the service's built-in multi-dimensional dynamic baseline learning unit intervenes. This unit extracts multi-dimensional features such as communication five-tuples, function codes, and access addresses, and preferentially employs the Isolation Forest unsupervised algorithm for learning, thereby establishing a dynamic baseline model capable of calculating "anomaly scores" for real-time communication behavior to identify unknown threats deviating from normal behavior. Finally, this service integrates the two detection results to generate clear handling decisions for packets, such as "allow," "block," or "alert," and transmits these decisions to downstream services for execution.
[0050] The Log, Configuration, and Event Distribution Service serves as the unified configuration and log center for the core software system of the security protection equipment. Deployed using a highly available database cluster, it is responsible for persistently storing the system's operational logs, alarm events, and all security policies. At its core lies a digital twin baseline verification unit, designed to provide ground-based verification of the engineering design for dynamic behavioral baselines. Through a built-in dedicated parsing engine, the digital twin baseline verification unit can directly read and parse DCS / PLC configuration engineering files from mainstream manufacturers. Through parsing, it automatically constructs a deterministic communication whitelist model that includes device assets, master-slave communication relationships, command-level operation permissions, and variable access scope. This deterministic communication whitelist model serves two key purposes: first, when the threat detection and policy enforcement service reports suspected anomalies, the digital twin baseline verification can perform cross-validation to eliminate false alarms for normal engineering operations (such as program downloads); second, this deterministic communication whitelist model can serve as an initial seed, significantly accelerating the convergence speed and accuracy of machine learning baselines.
[0051] The Packet Processing and Event Generation Service, as the final execution unit for processing decisions, is responsible for translating abstract processing decisions (such as "blocking") from upstream sources into concrete network actions. The core innovation of this service lies in its embedded elastic adaptive protection response unit. This unit does not perform static blocking or allowing; instead, it dynamically adjusts its response strategy by comprehensively analyzing data from two dimensions: first, the threat severity level output by the threat detection and policy enforcement service; and second, the business importance level of the affected assets provided by the digital twin baseline verification unit. Based on this, the Packet Processing and Event Generation Service can execute a set of elastic and granular response strategies that match the risk level. For example, it can perform traffic shaping or high-priority alerts for low-risk anomalies, while for high-risk threats, it can coordinate with network devices to temporarily isolate the attack source or degrade access, thereby minimizing the potential impact on normal business operations while ensuring security. All processing actions are formatted into detailed event logs and archived by the log, configuration, and event distribution service.
[0052] The System Health Monitoring Service acts as a "sentinel" container, ensuring the platform's high reliability. Through API interaction with the underlying container engine, it independently and periodically monitors the liveness, resource consumption, and response status of all business service containers. Simultaneously, it monitors the physical status of the industrial motherboard. When a hardware failure or container instance anomaly is detected, it immediately invokes the alarm indication module to trigger a physical alarm and simultaneously reports a detailed status to the central orchestration and management platform, enabling automated fault recovery operations.
[0053] The Central Orchestration and Web Management Platform serves as the central control console for the entire system, integrating the container orchestration engine and the user-facing web server. The platform's backend services subscribe to the event bus of the logging, configuration, and event distribution services, enabling real-time acquisition of security alerts and system status updates. This platform provides users with the following core functionalities through an integrated web interface: a real-time alert dashboard that uses WebSocket long-connection technology to "push" security alerts received from the backend to the user's browser interface in milliseconds; a policy configuration center that allows users to define and deploy access control rules and whitelist policies graphically; and a system status view that displays the health of each container, allows manual restarts or scaling, and manages the platform's load balancing strategies.
[0054] The operating principle of this safety protection equipment is based on two parallel and collaborative workflows: data processing and status control.
[0055] The data processing flow begins at the high-availability interface module, where network packet capture services perform high-speed capture using kernel bypass technology and immediately inject the data into a shared-memory message queue to decouple the performance of the capture and processing stages. Multiple instances of the deep packet parsing service consume data from this queue in parallel, parsing the raw packets into structured standard data objects. Subsequently, the threat detection and policy enforcement service analyzes these data objects based on security policies dynamically obtained from the log, configuration, and event distribution services. Finally, the packet handling and event generation service executes allow or block operations based on the analysis results and asynchronously sends the event record of this handling action to the log, configuration, and event distribution services. This asynchronous design ensures that log generation does not block the forwarding performance of the main data path.
[0056] Meanwhile, state control flow ensures high system reliability and manageability. The system health monitoring service periodically performs state probing on all core services. If any service becomes unresponsive, it immediately notifies the central orchestration and web management platform, which then invokes the underlying container engine interface to automatically destroy and rebuild the faulty service instance, achieving system self-healing. Furthermore, the log, configuration, and event distribution service, serving as the core software system hub for security protection devices, not only stores all events and logs but also pushes security events requiring alerts to the central orchestration and web management platform in real time for administrator viewing. It also receives policy updates from the central orchestration and web management platform and distributes them to the threat detection service.
[0057] Through the close coupling of these two workflows, this security protection device not only achieves high-performance online processing of network traffic, but also constitutes a closed-loop control system integrating dynamic policy management, real-time status monitoring, and automated fault recovery.
[0058] The data processing flow follows the sequence of "collection-parsing-analysis-processing" to process network packets online. This process uses kernel bypass technology to collect packets at high speed, performs deep parsing, and then the threat detection service performs analysis based on dynamic policies, ultimately executing either allow or block the packet. Events are recorded asynchronously to ensure the performance of the main path.
[0059] The parallel state control flow is responsible for the system's reliability and policy consistency. It achieves automatic recovery of faulty services through the linkage between health monitoring and the central orchestration platform; at the same time, the central orchestration and web management platform, as the control hub, complete the unified distribution of security policies and the centralized reporting of incident handling, forming a management closed loop.
[0060] There are two deployment methods for security protection equipment: The first is serial deployment, which physically connects to the network link, performs real-time traffic detection and blocking, and provides proactive online protection. The second is bypass deployment, which performs passive analysis through traffic mirroring, only performing monitoring and alarms without affecting the original network link.
[0061] In this utility model, unless otherwise explicitly specified and limited, the terms "installation," "connection," "joining," and "fixing," etc., should be interpreted broadly. For example, they can refer to a fixed connection, a detachable connection, or an integral part; they can refer to a mechanical connection, an electrical connection, or a connection that allows communication between them; they can refer to a direct connection or an indirect connection through an intermediate medium; they can refer to the internal communication of two components or the interaction between two components, unless otherwise explicitly limited. Those skilled in the art can understand the specific meaning of the above terms in this utility model according to the specific circumstances.
[0062] The foregoing has shown and described the basic principles, main features, and advantages of this utility model. Those skilled in the art should understand that this utility model is not limited to the above embodiments. The embodiments and descriptions in the specification are merely illustrative of the principles of this utility model. Various changes and modifications can be made to this utility model without departing from its spirit and scope, and all such changes and modifications fall within the scope of the claimed utility model.
Claims
1. An industrial network adaptive security protection device, characterized in that, include: An industrial motherboard is used to carry out the core computing tasks of the entire device. The industrial motherboard integrates a multi-core processor, system main memory, and solid-state storage. The multi-core processor is electrically connected to the system main memory and solid-state storage respectively. A redundant power supply module, wherein the redundant power supply module includes at least two power supply units that independently supply power to the industrial motherboard; The hybrid hardware acceleration module communicates with the industrial motherboard via a peripheral interconnect bus. The hybrid hardware acceleration module integrates a programmable logic device and is connected to an industrial network interface for communicating with industrial equipment and a management network interface for sending and receiving industrial field management data. An alarm and warning module is electrically connected to an industrial motherboard. The alarm and warning module includes a status indicator light for providing visual alarm signals and a physical alarm output device for signal linkage with an external industrial equipment control system or alarm device. The status indicator light and the physical alarm output device are electrically connected to the industrial motherboard. The high availability interface module is used to establish an independent, point-to-point high-speed communication link between the primary device and the backup device. The high availability interface module is electrically connected to the industrial motherboard, the redundant power supply module, and the alarm warning module.
2. The safety protection equipment according to claim 1, characterized in that: It also includes a passive cooling chassis, in which the industrial motherboard, redundant power supply module, hybrid hardware acceleration module, and physical alarm output device are all installed, and the industrial network interface, management network interface, and status indicator light are all installed on the panel of the cooling chassis.
3. The safety protection equipment according to claim 2, characterized in that: The outer surface of the passive cooling chassis is provided with an array of heat dissipation fins, and the inner side of the passive cooling chassis is provided with heat-conducting bumps that contact and dissipate heat with the chips on the industrial motherboard and the chips on the hybrid hardware acceleration module.
4. The safety protection equipment according to claim 2, characterized in that: The passive cooling chassis also has a console serial interface installed on its front panel for accessing the operating system's underlying console of the security protection equipment. This console serial interface is electrically connected to the industrial motherboard.
5. The safety protection equipment according to claim 2, characterized in that: The passive cooling chassis also has an out-of-band management interface installed on its panel for configuring, monitoring and maintaining the safety protection equipment. The out-of-band management interface is electrically connected to the alarm and warning module.
6. The safety protection equipment according to claim 2, characterized in that: The high availability interface module includes a heartbeat interface and a data synchronization interface mounted on the panel of a passive cooling chassis. The heartbeat interface is electrically connected to the industrial motherboard, the redundant power supply module, and the alarm module, respectively, and the data synchronization interface is electrically connected to the industrial motherboard.