Industrial network system, network management method, and network service providing system

The industrial network system ensures secure separation and management of OT and IT networks by using a mobile closed network and centralized management to monitor and control communications, addressing security challenges and reducing costs.

JP7680946B2Active Publication Date: 2025-05-21HITACHI IND EQUIP SYST CO LTD
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
JP2021203725
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2021-12-15
Publication Date
2025-05-21
Estimated Expiration
2041-12-15

AI Technical Summary

Technical Problem

Existing network systems connecting OT and IT networks face challenges in ensuring security, particularly in separating and managing these networks due to varying security policies and outdated operating systems, leading to high costs and complexity in preventing spoofing and malware outbreaks.

Method used

An industrial network system is constructed with separate local area networks for OT and IT devices, utilizing a mobile closed network (such as 5G or LTE) to monitor and control communications, ensuring all traffic passes through a secure mobile closed network without external access, and employing centralized management to assign unique IP addresses and monitor devices for secure communication.

Benefits of technology

This configuration enables secure separation of OT and IT networks, reduces installation costs, improves communication performance, and allows for rapid response to equipment changes or malware threats, while maintaining network security and reducing the number of required firewalls.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007680946000001
    Figure 0007680946000001
  • Figure 0007680946000002
    Figure 0007680946000002
  • Figure 0007680946000003
    Figure 0007680946000003
Patent Text Reader

Abstract

To provide an industrial network system configured by connecting an OT network to an IT network while ensuring security in the OT network.SOLUTION: An industrial network system 100 includes: a first local area network (OT network) to which a first electronic device (device 11) is connected under a mobile closed network 70 in which communication using the network can be monitored; a second local area network (IT network) which is constructed separately from the OT network and to which a second electronic device (device 21) is connected; and a predetermined closed network (global WAN 40) for connecting the above networks. The OT network is connected to the predetermined closed network with the mobile closed network 70. The first electronic device may communicate with another first electronic device in the OT network or communicate with the second electronic device, through the mobile closed network 70 within the predetermined closed network.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

[Technical field]

[0001] The present invention relates to an industrial network system, a network management method, and a network service providing system, and is suitable for application to an industrial network system, a network management method, and a network service providing system that connect an OT network and an IT network. [Background technology]

[0002] In recent years, with the advancement of digital transformation (DX), there is a demand for network systems that connect on-site operational technology (OT) networks with office automation (OA) information technology (IT) networks, even at production sites such as factories.

[0003] For example, Patent Document 1 discloses a technology for a hot forging press equipped with a press body, a programmable logic controller (PLC) that holds an operation pattern program for the press body and performs sequence control of the press body in accordance with the program, and a wireless communication device that connects the PLC to a network via a public wireless communication line, whereby the operation pattern program held in the PLC is updated by remote control from a maintenance terminal connected to the network. [Prior art documents] [Patent documents]

[0004] [Patent Document 1] JP 2013-22626 A Summary of the Invention [Problem to be solved by the invention]

[0005] Incidentally, while it has traditionally been the norm for IT networks to be constructed by information systems departments in a way that conforms to security policies, there have been cases where it has been difficult to conform to the same security policies as IT networks at factory sites, as networking was not initially considered or the operating systems (OS) of devices and equipment are old and not supported. For this reason, in network systems that connect OT networks and IT networks, it is required to manage the two networks physically separated.

[0006] Here, in factories, etc., IT devices and OT devices are often installed together, and when separating the IT network from the OT network, it is necessary to determine whether each device is on the OT side or the IT side. For example, when realizing with a wired connection, it is necessary to determine and separate each cable, which is very cumbersome. Also, for example, when realizing with a wireless connection by wireless LAN or the like specified in the IEEE802.11 series, it is difficult to determine which device has joined the network, so stronger defense measures are required to prevent spoofing, etc. As a strong defense measure, for example, it is necessary to install a firewall at the boundary between the OT network and the IT network, and it is also necessary to install a firewall between each switch in the conventional OT network, which does not have a high security level, which is very costly and makes it difficult to build a practical network.

[0007] The conventional technology disclosed in Patent Document 1 connects to a network from a wireless communication device on the PLC side via an external public wireless communication line, but since no particular consideration is given to ensuring security at the connection point to the IT network and within the OT network, it was not possible to solve the above-mentioned problems.

[0008] The present invention has been made in consideration of the above points, and aims to propose an industrial network system, a network management method, and a network service providing system that are capable of constructing a network in which an OT network and an IT network are connected while ensuring security in the OT network. [Means for solving the problem]

[0009] In order to solve the above problem, the present invention provides an industrial network system in which a plurality of local area networks are constructed separately, the industrial network system comprising: a first local area network to which a first electronic device is connected under a mobile closed network capable of monitoring communications passing through the first local area network; a second local area network constructed separately from the first local area network and to which a second electronic device is connected; and a predetermined closed network connecting the first local area network and the second local area network, the first local area network being connected to the predetermined closed network by the mobile closed network, and the industrial network system being configured such that communications by the first electronic device, whether communications with another first electronic device in the first local area network or communications with the second electronic device, pass through the mobile closed network and do not go outside the predetermined closed network.

[0010] In order to solve the above problem, the present invention provides a network management method for an industrial network system in which a plurality of local area networks are constructed separately, the industrial network system having a first local area network to which a first electronic device is connected under a mobile closed network capable of monitoring communications passing through the industrial network system, a second local area network constructed separately from the first local area network and to which a second electronic device is connected, and a predetermined closed network connecting the first local area network and the second local area network, the first local area network being connected to the predetermined closed network by the mobile closed network, and the network management method is configured so that communication by the first electronic device, whether it is communication with another first electronic device in the first local area network or communication with the second electronic device, passes through the mobile closed network and does not go outside the predetermined closed network.

[0011] In order to solve the above problem, the present invention provides a network service providing system that provides a network service that constructs a first local area network used by a customer within a specified closed network, the network service comprising a mobile closed network that is connected to the specified closed network and capable of monitoring communications passing through it, and a second local area network that is connected to the specified closed network and constructed separately from the first local area network, and when providing the network service to the customer, the first local area network is connected to the mobile closed network, and communication by an electronic device connected to the first local area network, whether it is communication with another electronic device in the first local area network or communication with an electronic device in the second local area network, passes through the mobile closed network and does not go outside the specified closed network. Effect of the Invention

[0012] According to the present invention, it is possible to build and provide an industrial network in which an OT network and an IT network are connected while ensuring security in the OT network. [Brief description of the drawings]

[0013] [Figure 1] 1 is a diagram showing an example of the configuration of an industrial network system 100 according to a first embodiment of the present invention. [Diagram 2] 2 is a block diagram showing an example of the hardware configuration of a centralized management device 31. FIG. [Diagram 3] FIG. 1 is a diagram illustrating an example of a configuration of an industrial network system 200 according to a second embodiment of the present invention. [Figure 4] FIG. 11 is a diagram illustrating an example of a configuration of an industrial network system 300 according to a third embodiment of the present invention. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS

[0014] Hereinafter, an embodiment of the present invention will be described in detail with reference to the drawings.

[0015] In the following, each embodiment will be described assuming a case where an IT network is constructed in the office area of ​​a production facility and an OT network is constructed in the production area of ​​the production facility, isolated from the IT network, in a wide area network (global WAN 40) service used throughout a single company, as an example of an industrial network system in which multiple local area networks (OT network, IT network) are constructed separately. However, the application of the industrial network system according to the present invention is not limited to this, and the present invention can be applied to general network services in which a specific local area network (OT network) is constructed separately. Specifically, for example, the present invention can be applied to a service providing system in which a service provider that provides a closed network provides an industrial network system according to each embodiment to a customer who requires a secure OT network. In this case, the production area described in each embodiment corresponds to the customer's environment, and the head office area (and office area) corresponds to the service provider's environment.

[0016] (1) First embodiment FIG. 1 is a diagram showing an example of the configuration of an industrial network system 100 according to a first embodiment of the present invention.

[0017] As described above in "Problems to be Solved by the Invention," in factories and the like where IT and OT devices may be installed together, if the OT network is wired, handling of cables during placement and switching becomes cumbersome, and so there is a high demand for wireless connections. On the other hand, simply building an OT network using a conventional wireless network poses the problem of high costs due to the need to prevent spoofing and respond to malware outbreaks. Therefore, in the first embodiment of the present invention, and in the second and third embodiments described below, an OT network is built using wireless connections while ensuring security.

[0018] In the industrial network system 100 shown in FIG. 1, the production facility 1 includes one or more production areas 10 in which an OT network is established, and one or more office areas 20 in which an IT network is established. Although only one production facility 1 is shown in FIG. 1, there may be multiple production facilities 1. The production area 10 and the office area 20 shown in FIG. 1 (and FIGS. 3 and 4 described later) are areas classified based on the type of network (OT network, IT network) and the electronic devices connected to the network, and the locations where the electronic devices are installed in each area do not necessarily need to be physically separated. The head office area 30 is an example of a management area that handles the management function for the industrial network system 100, and the core network of the industrial network system 100 is established therein.

[0019] In the first embodiment, each network established in the production area 10, the office area 20, and the head office area 30, as well as the external network 50, are connected to other networks via a global WAN 40. The external network 50 is, for example, the Internet, and can be connected to a cloud 60 or the like as shown in Fig. 1. For example, by linking with the cloud 60 via the external network 50, the customer can configure a data lake 61 that manages quality information such as inspection data and manufacturing data generated at the customer's production facility 1.

[0020] First, the production area 10 will be described in detail.

[0021] In FIG. 1, one production area 10 means one segment. In this description, a "segment" is a division for separating and managing a communication range, and an OT network is constructed for each segment. Although details will be described later, different segments (i.e., OT networks) are managed by a centralized management device 31 so that direct communication is not possible between them. Specifically, allocation of segments can be, for example, by building or by department, but is not limited to these, and can be performed by any classification, such as by product or process.

[0022] As shown in FIG. 1, in each production area 10 (each segment), one or more devices 11 are connected to the nearest 5G terminal 13 via a wired LAN.

[0023] The device 11 is, for example, an electronic device such as a manufacturing device or quality control device used in the production area 10, and is an OT device connected to an OT network in the production area 10. A subscriber identity module (SIM) is incorporated in the device 11 in order to assign a different IP address to each device. The SIM incorporated in the device 11 may be an eSIM to which information can be written (or rewritten) remotely. When an eSIM is incorporated, a centralized management device 31 (described later) can write (or rewrite) the IP address assigned to the eSIM. The inspection device 12 is an example of a device that does not have a network communication function, and does not need to incorporate a SIM into such an inspection device 12, and is connected to the OT network via the device 11.

[0024] The 5G terminal 13 is one of the communication devices in the mobile closed network 70 constructed to cover the production area 10, and has a communication function by a 5G line (a function to perform wireless communication in a frequency band for 5G). The 5G terminal 13 exchanges transmission and reception packets of communication by one or more devices 11 installed in the vicinity with the base station 14 by performing 5G communication with a 5G-compatible base station 14 installed in the same segment in the mobile closed network 70. Note that, as a modified example of the configuration in FIG. 1, some or all of the devices 11 may be configured to have a function as a 5G terminal.

[0025] The base station 14 is a base station having a function of performing 5G communication with the 5G terminal 13 in the mobile closed network 70, and in the first embodiment, one base station is installed per segment (production area 10). Furthermore, the base station 14 is wired connected to the global WAN 40 via a gateway 15 in the same segment. Although not shown in FIG. 1 (and FIGS. 3 and 4 described later), an L3 switch or the like may be installed instead of or in addition to the gateway 15.

[0026] As described above, the production area 10 is covered by the mobile closed network 70. In particular, in the first embodiment, the mobile closed network 70 has a plurality of devices 11 under its control in segments, and is connected to the global WAN 40 via a firewall 80 installed for each segment.

[0027] The mobile private network 70 is a core network constructed independently by a telecommunications carrier, and performs communication between devices 11 connected thereto without passing through an external network. The mobile private network 70 is a secure network that does not accept access from any device other than that of a customer who has contracted for the industrial network system 100 service (devices in the production area 10, office area 20, and head office area 30). The mobile private network 70 may be provided by a network service provider on loan from a telecommunications carrier. The mobile private network 70 is physically or logically separated (isolated) from the outside, and all communications passing through the mobile private network 70 are monitored according to specifications.

[0028] In the following description, the mobile closed network 70 is described as a local 5G network, which is one of carrier wireless communication networks. However, the mobile closed network 70 used to construct an OT network in the present invention is not limited to a local 5G network, and may be another carrier wireless communication network. Specific examples include a private LTE network. When the mobile closed network 70 is a private LTE network, the "5G terminal 13" is replaced with an LTE terminal having an LTE (4G) communication function, and the "base station 14" having a 5G communication function is replaced with a base station having an LTE communication function.

[0029] A local 5G network is a network of a fifth generation mobile communication system (5G network) deployed as a dedicated network in a limited local environment, and is characterized by ultra-high speed and ultra-low latency compared to a wireless LAN network that is widely used as a wireless network, and by the ability to connect multiple devices simultaneously. A private LTE (Long Term Evolution) network is a network of a LTE network deployed as a dedicated network in a limited local environment, and is characterized by high speed and low latency compared to a wireless LAN network, and by the ability to connect multiple devices simultaneously. A private LTE network is characterized by a wide coverage area per base station 14 and inexpensive network services, although it is inferior in communication speed and latency performance compared to a local 5G network.

[0030] With the above-mentioned configuration, the OT network in the production area 10 in the first embodiment is closed by the mobile closed network 70 for each segment, and is connected to the global WAN 40 by one route per segment. Incidentally, since an OT network generally has a lower security level than an IT network, etc., it is preferable to install a firewall in order to increase the security level (for example, to prevent malware from spreading in an IT network to which a high security policy is applied). In this case, the firewall may be installed at the point (boundary) where the OT network connects to the global WAN 40. That is, in the first embodiment, since the connection route between the OT network and the global WAN 40 is limited to one per segment, the firewall 80 may be installed at one location per segment.

[0031] Next, the office area 20 and the head office area 30 will be described.

[0032] An IT network using general wired connections is constructed in the office area 20. Specifically, for example, one or more devices 21 are connected to a hub 23 via a wired LAN, and the hub 23 is wired-connected to a global WAN 40 via a gateway 24 or an L3 switch (not shown). The devices 21 are electronic devices that have been subjected to Office Automation (OA), and are IT devices that are connected to the IT network in the office area 20. The IT network in the office area 20 may be considered to be a known IT network, and is operated in accordance with a security policy appropriately formulated by an information systems department.

[0033] In the head office area 30, as in the office area, a centralized management device 31 and an administrator terminal 32 connected to an internal network are wired to a global WAN 40 via a hub 33, a gateway 34, and an L3 switch (not shown).

[0034] The centralized management device 31 is an information processing device having a centralized management function for centrally managing communication for each device (e.g., each device 11 in the OT network) that communicates via the mobile closed network 70, and is realized by a server or the like on which dedicated management software (management software 317 shown in FIG. 2) runs. The centralized management device 31 monitors all communications that pass through the mobile closed network 70 by executing the management software. Specifically, for example, the centralized management device 31 uses a SIM embedded in the device 11 in the production area 10 as an authentication device for connection to the OT network. Also, for example, the centralized management device 31 identifies and manages devices that communicate via the mobile closed network 70 based on an IP address assigned to each device in each area.

[0035] The manager terminal 32 is a terminal operated by a manager who monitors and manages communications. By operating the manager terminal 32, the centralized management function of the centralized management device 31 can be executed.

[0036] Fig. 2 is a block diagram showing an example of a hardware configuration of the centralized management device 31. As shown in Fig. 2, the centralized management device 31 has a processor 311, a storage device 312, an input device 313, an output device 314, and a communication interface (communication IF) 315. The processor 311, the storage device 312, the input device 313, the output device 314, and the communication IF 315 are connected by a bus 316 which is an internal communication line.

[0037] The processor 311 is a processor that controls the centralized management device 31, and is, for example, a central processing unit (CPU) or a graphics processing unit (GPU). The storage device 312 is a device that provides a working area for the processor 311, and is a non-temporary or temporary recording medium that stores various programs (for example, management software 317) and data. Specifically, the storage device 312 is, for example, a read only memory (ROM), a random access memory (RAM), a hard disk drive (HDD), or a flash memory. Note that the storage device 312 does not necessarily need to be a recording medium mounted inside the centralized management device 31, and may be configured such that some or all of the various programs and data are stored outside (for example, the cloud 60) where security is sufficiently ensured. The centralized management function of the centralized management device 31 is realized by the processor 311 reading and executing the management software 317. The input device 313 is a device for inputting data, and is, for example, a keyboard, a mouse, a touch panel, a numeric keypad, a scanner, a microphone, or a biosensor. The output device 314 is a device for outputting data, and specifically, for example, a display, a printer, a speaker, etc. The communication IF 315 is an interface that connects to a network and transmits and receives data to and from the outside of the centralized management device 31, and specifically, for example, a NIC (Network Interface Card).

[0038] The global WAN 40 is a wide area network (WAN) used by the client company across multiple bases, and communications between the production area 10, office area 20, and head office area 30 and the external network 50 are always conducted via the global WAN 40. The global WAN 40 is a wide area communication network that is connected only to related parties of the client's organization, and is a type of closed network.

[0039] In the industrial network system 100 of this embodiment having the above configuration, communication between each device 11 in the OT network (production area 10) is configured to always return via the mobile closed network 70 (return communication within the closed network). By realizing return communication within the closed network, peer-to-peer (P2P) communication can be eliminated, and all communications within the OT network can be monitored by the mobile closed network 70.

[0040] Furthermore, in the industrial network system 100, communication between each device 11 in the OT network (production area 10) and each device 21 in the IT network (office area 20) is always performed via the mobile closed network 70 and within the global WAN 40. With this configuration, it is possible to limit the connection points between the OT network and the IT network.

[0041] Here, when monitoring communications within an OT network, it is necessary to be able to identify OT devices (devices 11) connected to the OT network.

[0042] To achieve this, first, a SIM is built into each device 11 that connects to the OT network, and a different IP address is assigned to the SIM for each device. By using this SIM as an authentication device, only devices 11 equipped with an authentication device issued, distributed, or written by an administrator can join the OT network. In other words, since only devices approved by SIM authentication of devices 11 can connect to the OT network, simply procuring a device does not allow it to connect to the OT network, and spoofing can be prevented.

[0043] The centralized management device 31 manages the IP addresses assigned to the SIM of each device 11 by registering them in an IP address allocation table. Furthermore, the centralized management device 31 manages the IP addresses of each device 11 by dividing them into segments using the IP addresses assigned to the SIM of each device 11. The centralized management device 31 then controls so that IP communication (opposite communication) is possible between devices 11 in the same segment.

[0044] The method of allocating and managing IP addresses and segments by the centralized management device 31 is not limited to a specific method, and various known methods may be adopted. As an allocation method, for example, an IP address allocation range may be set for each segment, and an IP address for the segment belonging to each device 11 may be allocated. In this case, IP addresses may be automatically allocated within the IP address allocation range set for each segment. As a management method, for example, a segment management table that manages the IP address allocation range for each segment may be held separately from the IP address allocation table, or segment allocation information may be added to and held in the IP address allocation table.

[0045] Furthermore, the unit for allocating segments may be appropriately determined according to the operational environment as described above, and may be by building, by department, by product, by process, etc. For example, if the segments allocated to the devices 11 are divided for each product, even devices 11 that are physically located next to each other will be in different segments if they are for different products, and therefore communications between the devices 11 can be managed for each segment without physical constraints.

[0046] As described above, in the industrial network system 100 according to this embodiment, the mobile closed network 70 is placed between the OT network and the IT network, and not only communication between the OT network and the IT network but also communication within the OT network must go through the mobile closed network 70, so that the OT network and the IT network can be constructed safely and separately. Furthermore, by incorporating a SIM into the device 11 in the OT network and managing the IP address assigned to the SIM and the segment to which the IP address belongs by the centralized management function of the centralized management device 31, it is possible to monitor the communication in the OT network for each device individually, thereby realizing a secure OT network.

[0047] In addition, since the industrial network system 100 uses 5G communication, which is ultra-fast and has ultra-low latency compared to conventional wireless communication in the OT network, the communication performance of the OT network can be significantly improved.

[0048] In addition, the centralized management device 31 centrally manages communications of OT devices (devices 11) connected to the OT network using the mobile closed network 70. If any of the devices 11 becomes infected with malware, the IP address assigned to the SIM of that device 11 can be changed to an IP address that is not approved by SIM authentication, making it easy to disconnect each device individually from the OT network.

[0049] As another isolation method, the centralized management device 31 may temporarily disable communication with the IP address assigned to the segment to which the malware-infected device 11 belongs, either alone or prior to the above isolation method. Disabling communication on a segment-by-segment basis not only makes it possible to prevent the spread of malware infection from the OT network to other networks (the IT network in the office area 20 and the core network in the head office area 30), but also makes it possible to prevent the spread of malware infection between devices within the OT network.

[0050] In addition, in cases where the target equipment within a segment is replaced due to rearrangement of equipment 11 at the production site, the centralized management device 31 assigns an IP address belonging to that segment to the equipment 11 being newly placed within the segment, and changes the IP address of equipment 11 being removed from the segment to one other than that belonging to the segment, thereby enabling a secure OT network to be built immediately in response to the rearrangement.

[0051] As described above about the firewall 80, in this embodiment, the connection path between the OT network and the global WAN 40 is limited to one per segment, so that the firewall 80 only needs to be installed at one location per segment. In this case, the number of firewalls 80 required can be significantly reduced compared to a configuration in which the firewall 80 or a security device equivalent thereto must be installed in each of the devices 11, and in addition to the effect of reducing the installation effort, security investment and security monitoring points can be concentrated. As a result, the cost required for network construction can be reduced while increasing the security of the entire industrial network system 100.

[0052] (2) Second embodiment 3 is a diagram showing an example of the configuration of an industrial network system 200 according to a second embodiment of the present invention. Note that in the second embodiment, the configuration is the same as that of the first embodiment, except for the internal configuration in the production area 10 and the connection configuration between the OT network in the production area 10 and the global WAN 40. Therefore, the same reference numerals are used for the common configuration, and the description thereof will be omitted. This also applies to the third embodiment described later.

[0053] As shown in FIG. 3, in the industrial network system 200, the production area 10 in which the OT network is constructed is managed in segments as in the first embodiment. However, the mobile closed network 70 in the second embodiment connects each OT network (the equipment 11 in the production area 10) to the global WAN 40 in a wider area unit than in the first embodiment. In FIG. 3, as an example of this wider area unit, the mobile closed network 70 covers the entirety of a plurality of production areas 10, but is not limited thereto, and may cover the entirety of the production facility 1, for example. Considering the expansion of the coverage area in this way, it is assumed that the mobile closed network 70 in the second embodiment may be a private LTE network rather than a local 5G network in some cases.

[0054] As described above, in the second embodiment, since the OT network and the global WAN 40 are connected in wide-area units, a set of the base station 14 and the gateway 15 (including an L3 switch, etc.) is installed in multiple production areas 10 (or the entire production facility 1) rather than for each segment. That is, in the second embodiment, the route from the equipment 11 in the production area 10 to the global WAN 40 is various until it passes through the nearest 5G terminal 13, but thereafter, the route from the base station 14 to the gateway 15 is limited to one.

[0055] In the industrial network system 200, similarly to the first embodiment, communication between the devices 11 in the OT network (production area 10), and communication between the devices 11 in the OT network and the devices 21 in the IT network (office area 20) are all configured to pass through the mobile closed network 70 and to be performed within the global WAN 40.

[0056] Furthermore, in the industrial network system 200, as in the first embodiment, a SIM is embedded in each device 11 in the production area 10, and an individual IP address is assigned corresponding to the segment to which the device belongs. Then, the centralized management device 31 identifies each device 11 based on the IP address assigned to the SIM and the segment to which the IP address belongs, and centrally manages the communications of the devices 11.

[0057] According to the above-described industrial network system 200, like the industrial network system 100 according to the first embodiment, an OT network and an IT network can be safely separated and constructed, and communications in the OT network can be monitored individually for each device, thereby realizing a secure OT network. Also, the communication performance of the OT network can be improved.

[0058] Furthermore, in the industrial network system 200, the number of base stations 14, gateways 15, L3 switches, etc. installed between the OT network and the global WAN 40 only needs to be one set for the entire production area 10 (or one production facility 1), which is expected to further reduce the installation effort and costs compared to the first embodiment.

[0059] Furthermore, since the firewall 80 only needs to be installed at the boundary between the mobile closed network 70 and the global WAN 40, the number of firewalls that need to be installed can be limited to one for each production facility 1. This not only reduces the installation effort, but also allows security investment and security monitoring to be concentrated at one point for each production facility 1, which is expected to result in further improving the security of the entire industrial network system 300.

[0060] (3) Third embodiment FIG. 4 is a diagram showing an example of the configuration of an industrial network system 300 according to the third embodiment of the present invention.

[0061] In the second embodiment, the mobile closed network 70 is configured to connect the OT network and the global WAN 40 for multiple production areas 10 (or the entire production facility 1), but the industrial network system 300 according to the third embodiment shows a configuration example in which the coverage is further expanded. That is, in the industrial network system 300, the mobile closed network 70 is constructed for a wide range of units including multiple production facilities 1 and even the outside of them (referred to as the central area).

[0062] In the third embodiment, since the coverage area required for the mobile closed network 70 is significantly expanded, a predetermined industrial communication service provided by a service provider may be used instead of the above-mentioned local 5G network or private LTE network. Such industrial communication services generally have a set number of available lines and IP addresses, so that a customer contracts for a service content that meets his or her needs.

[0063] As shown in FIG. 4, in the industrial network system 300, the production area 10 in which the OT network is constructed is managed as one or more segments, similarly to the first to third embodiments.

[0064] In the industrial network system 300 shown in Fig. 4, a single base station 91 is installed in a central area, with multiple production facilities 1 (for example, the entire company) being covered by the mobile closed network 70. As described above, the third embodiment has the potential to further reduce the number of base stations required throughout the entire company, as compared with the first and second embodiments. Note that the number of base stations 91 installed is not necessarily limited to one, and a configuration may be adopted in which multiple base stations 91 are installed so long as the number does not exceed the total number of production facilities 1.

[0065] As shown in Fig. 4, the 5G terminal 13 installed in the production area 10 of each production facility 1 performs wireless communication with the 5G terminal 92 installed on the central area side via a base station 91 in the mobile closed network 70. The number of 5G terminals 92 to be installed is determined based on the number of devices 11 on the OT network side as a required number (this is the minimum number required, and may be more than this number). For example, one 5G terminal 92 is prepared for every 10 devices 11. The number of 5G terminals 13 to be installed on the OT network side may be considered in the same manner.

[0066] The multiple 5G terminals 92 are connected to the global WAN 40 via one gateway 93 (including an L3 switch, not shown). Considering the same as the first and second embodiments, it is sufficient to install one firewall 80 near the gateway 93.

[0067] In the industrial network system 300, similarly to the first and second embodiments, communication between the devices 11 in the OT network (production area 10), and communication between the devices 11 in the OT network and the devices 21 in the IT network (office area 20) are all configured to pass through the mobile closed network 70 and to be performed within the global WAN 40.

[0068] Furthermore, in the industrial network system 300, as in the first and second embodiments, a SIM is embedded in each device 11 in the production area 10, and an individual IP address is assigned corresponding to the segment to which the device belongs. Then, the centralized management device 31 identifies each device 11 based on the IP address assigned to the SIM and the segment to which the IP address belongs, and centrally manages the communications of the devices 11.

[0069] According to the above-described industrial network system 300, like the industrial network systems 100 and 200 according to the first and second embodiments, an OT network and an IT network can be safely separated and constructed, and communications in the OT network can be monitored individually for each device, thereby realizing a secure OT network. Also, the communication performance of the OT network can be improved.

[0070] Furthermore, in the industrial network system 300, the number of base stations 91 and gateways 93 installed between the OT network and the global WAN 40 needs to be one set for all of the multiple production plants 1, and the number of 5G terminals 13, 92 installed can be significantly smaller than the number of devices 11. Therefore, the third embodiment can be expected to have an effect of reducing installation effort and costs even more than the other embodiments.

[0071] Furthermore, since the firewall 80 only needs to be installed at the boundary between the mobile closed network 70 and the global WAN 40, the number of firewalls required can be reduced to a minimum of one for multiple production facilities 1 (the entire company). This not only reduces the installation time, but also allows security investment and security monitoring to be concentrated at one point for the entire company (all of the multiple production facilities 1), which is expected to result in improved security for the entire industrial network system 300.

[0072] The present invention is not limited to the above-described embodiment, but includes various modified examples. For example, the above-described embodiment has been described in detail to clearly explain the present invention, and is not necessarily limited to those including all of the configurations described. It is also possible to replace a part of the configuration of one embodiment with the configuration of another embodiment, and it is also possible to add the configuration of another embodiment to the configuration of one embodiment. It is also possible to add, delete, or replace a part of the configuration of each embodiment with another configuration.

[0073] In addition, although the centralized management functions of the centralized management device 31 are realized by management software in which a processor interprets and executes a program that realizes the function, a part or all of them may be realized by hardware, for example, by designing an integrated circuit. Also, information such as programs, tables, and files that realize the functions may be stored in a memory, a recording device such as a hard disk or SSD (Solid State Drive), or a recording medium such as an IC card, SD card, or DVD. [Explanation of symbols]

[0074] 1. Production facility 10 Production Area 11,21 equipment 12 Inspection equipment 13,92 5G devices 14,91 base station 15,24,34,93 Gateway 20 Office Area 23,33 Hub 30 Headquarters Area 31 Central control device 32 Administrator terminal 40 Global WAN 50 External Network 60 Cloud 61 Data Lake 70 Mobile closed network 80 Firewall 100,200,300 Industrial Network System 311 Processor 312 Storage Devices 313 Input Devices 314 Output Devices 315 Communication Interface 316 Bus 317 Management Software

Claims

1. An industrial network system in which a plurality of local area networks are constructed separately, a first local area network to which a first electronic device is connected under a mobile closed network capable of monitoring communications passing through the first local area network; a second local area network that is constructed separately from the first local area network and to which a second electronic device is connected; a predetermined closed network connecting the first local area network and the second local area network; a centralized management device that executes a program for centrally managing communications via the mobile closed network; Equipped with the first local area network is connected to the predetermined closed network by the mobile closed network; the centralized management device manages the communication range of the first local area network by dividing it into segments and restricting communication between the first electronic devices belonging to different segments; A first communication device which performs wireless communication in the mobile closed network on behalf of the first electronic device of the segment, a second communication device which performs the wireless communication with the first communication device on the side of the predetermined closed network, and a third communication device which performs the wireless communication with the first communication device on the side of the predetermined closed network using the second communication device as a repeater are connected to the mobile closed network; a predetermined number or more of the first communication devices and the third communication devices are installed based on a total number of the first electronic devices, a firewall is installed between the second communication device in the mobile closed network and the predetermined closed network; The communication by the first electronic device is configured to pass through the mobile closed network and not go outside the predetermined closed network, whether the communication is with another first electronic device in the first local area network or with the second electronic device.

1. An industrial network system comprising:

2. Each of the first electronic devices is equipped with a Subscriber Identity Module (SIM) capable of assigning an IP address, The centralized control device uses a SIM embedded in the first electronic device to authenticate the first electronic device's connection to the first local area network.

2. The industrial network system according to claim 1, wherein:

3. Each of the first electronic devices is assigned a different IP address to the SIM from within an IP address assignment range set for the segment to which the first electronic device belongs; The centralized management device identifies the first electronic device connected to the first local area network based on the IP address and manages the connection.

3. The industrial network system according to claim 2, wherein:

4. When a malware infection is detected in any of the first electronic devices, The centralized management device changes the IP address assigned to the SIM of the first electronic device, thereby isolating the first electronic device from the first local area network.

4. The industrial network system according to claim 3.

5. One of the second communication devices is installed for each of the segments.

2. The industrial network system according to claim 1, wherein:

6. One second communication device is installed for each of the segments.

2. The industrial network system according to claim 1, wherein:

7. The mobile closed network is a local 5G network.

2. The industrial network system according to claim 1, wherein:

8. The mobile closed network is a private LTE network.

2. The industrial network system according to claim 1, wherein:

9. A network management method for an industrial network system in which a plurality of local area networks are constructed separately, comprising the steps of: The industrial network system includes: a first local area network to which a first electronic device is connected under a mobile closed network capable of monitoring communications passing through the first local area network; a second local area network that is constructed separately from the first local area network and to which a second electronic device is connected; a predetermined closed network connecting the first local area network and the second local area network; a centralized management device that executes a program for centrally managing communications via the mobile closed network; having the first local area network is connected to the predetermined closed network by the mobile closed network; the centralized management device manages the communication range of the first local area network by dividing it into segments and restricting communication between the first electronic devices belonging to different segments; A first communication device which performs wireless communication in the mobile closed network on behalf of the first electronic device of the segment, a second communication device which performs the wireless communication with the first communication device on the side of the predetermined closed network, and a third communication device which performs the wireless communication with the first communication device on the side of the predetermined closed network using the second communication device as a repeater are connected to the mobile closed network; a predetermined number or more of the first communication devices and the third communication devices are installed based on a total number of the first electronic devices, a firewall is installed between the second communication device in the mobile closed network and the predetermined closed network; The communication by the first electronic device is configured to pass through the mobile closed network and not go outside the predetermined closed network, whether the communication is with another first electronic device in the first local area network or with the second electronic device. A network management method comprising:

Citation Information

Patent Citations

  • Hot forging press

    JP2013022626A

  • Method and apparatus for enabling data transmission between a mobile device and a static destination address

    JP2013545412A

  • Control system and control method

    JP2016184854A

  • Address change method, route change method, server unit and security device

    JP2019029939A

  • JPP6888179B