Enhanced Smart Process Control Switch Port Lockdown

The described process control switch addresses vulnerabilities in conventional lockdown mechanisms by mapping and authenticating physical addresses to lock down ports, enhancing security and preventing unauthorized access in complex network environments.

JP7815201B2Active Publication Date: 2026-02-17FISHER ROSEMOUNT SYST INC
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
JP2023223569
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Priority Date
2018-04-10
Filing Date
2023-12-28
Publication Date
2026-02-17
Estimated Expiration
2038-09-28

AI Technical Summary

Technical Problem

Conventional lockdown mechanisms for process control switches fail to secure ports connected to multiple devices, uplink switches, or devices with multiple physical addresses, leaving them vulnerable to malicious access and network disruptions.

Method used

Implement a process control switch with circuitry that maps known physical addresses to ports, generates a static address table, and authenticates source physical addresses to lock down ports, limiting traffic and dropping unknown messages, while allowing known devices to communicate.

Benefits of technology

Enhances network security by preventing unauthorized access and maintaining system integrity by locking down ports connected to multiple devices or uplink switches, thereby protecting against malicious attacks and ensuring secure communication.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007815201000001
    Figure 0007815201000001
  • Figure 0007815201000002
    Figure 0007815201000002
  • Figure 0007815201000003
    Figure 0007815201000003
Patent Text Reader

Abstract

To provide a smart process control switch that makes it possible to prevent new, potentially hostile devices from communicating with other devices to which the smart process control switch is connected.SOLUTION: A smart process control switch can implement an address mapping routine to identify "known pairs" of physical and network addresses for each device communicating via a port of the smart process control switch. Even if a new hostile device is able to spoof a known physical address in an attempt to bypass locked ports, the smart process control switch can detect the hostile device by checking the network address of the hostile device against the expected network address for the "known pair."SELECTED DRAWING: None
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present disclosure relates generally to process control systems, and more particularly to techniques for locking down ports of smart process control switches. [Background technology]

[0002] A process control system, such as a distributed or scalable process control system such as those used in power generation, chemical, petroleum, or other processes, typically includes one or more process controllers communicatively coupled to each other, to at least one host or operator workstation via a process control network, and to one or more field devices via a combination of analog, digital, or analog / digital buses.

[0003] Field devices may be, for example, valves, valve positioners, switches and transmitters (e.g., temperature, pressure and flow sensors) that perform functions within a process or plant, such as opening and closing valves, turning switches on and off, measuring process parameters, etc.

[0004] Typically, process controllers located within a process plant environment receive signals indicative of process measurements or process variables and / or other information about the field devices and execute controller applications or routines. Each controller uses the received information to execute a control routine and generate control signals that are sent over a bus to the field devices to control the operation of the process or plant. One or more controller routines implement control modules that make process control decisions and generate control signals based on the received information and interface with control modules or blocks embodied within field devices, such as HART® and Fieldbus field devices. The control modules within the process controller send the control signals over communication lines or signal paths to the field devices, thereby controlling the operation of the process.

[0005] Information from field devices and process controllers is typically made available over a process control network to one or more other hardware devices, such as maintenance workstations, personal computers, handheld devices, data historians, report generators, centralized databases, etc. The information communicated over the network allows an operator or maintainer to perform desired functions with respect to the process. For example, the information may allow an operator to change settings in process control routines, modify the operation of control modules in a process controller or smart field device, view the current state of a process or status of specific devices in a process plant, view alarms generated by field devices and process controllers, simulate the operation of a process for purposes of training personnel or testing process control software, or diagnose problems or hardware faults in a process plant.

[0006] Field devices typically communicate with hardware devices over a process control network, which may be an Ethernet-configured LAN. The network relays process parameters, network information, and other process control data to various network devices and various entities within the process control system. Network devices typically configure routing, frame rates, timeouts, and other network parameters. They facilitate the flow of data through a network by controlling network parameters, but do not modify the process data itself. Typical network devices include, for example, Layer 2 network switches, Layer 3 network switches, routers, and / or hubs. The layers referenced herein relate to the OSI model layers.

[0007] Typically, a Layer 2 network switch receives a message and forwards it through one of the ports associated with the MAC address of the destination device in the LAN (as identified by the message). Layer 2 network switches typically store a table that establishes an association between MAC addresses and corresponding switch ports. When a Layer 2 network switch receives a message, it identifies the destination MAC address of the message, identifies the port on the switch that corresponds to the MAC address in the table, and forwards the message through that port. When a Layer 2 network switch receives a message with a destination MAC address not stored in its table, it broadcasts the message to all ports on the switch until the message reaches the destination device and the destination device responds, thereby informing the switch of the appropriate port "mapped" to the destination MAC address. Notably, Layer 2 switches do not perform routing, do not use IP addresses in forwarding decisions, and do not keep track of intermediate nodes between the switch and the destination device. Rather, a Layer 2 switch simply consults a table to determine which port on the switch to use to forward the message.

[0008] Layer 3 devices (such as routers and Layer 3 switches), on the other hand, perform routing, identify intermediate nodes, and often use IP addresses for forwarding and / or routing. This routing capability and the ability to utilize network addresses allows Layer 3 devices to route data to destinations outside the LAN to which the Layer 3 device is attached. While routers and Layer 3 network switches may be able to route process control data within a process control network, routers and Layer 3 switches are significantly more expensive than Layer 2 switches (e.g., 2 to 3 times more expensive) when specifically designed or configured for operation in a process control environment.

[0009] As process control networks grow in size and complexity, the number and types of corresponding network devices increase. As a result of the growth of systems and networks, securing and managing these complex systems becomes increasingly difficult. For example, each network device may include one or more communication ports that provide access points or ports for physically interconnecting process control system components with other network devices over the network. These network device ports may become access points for network expansion by adding other devices, or they may allow entities, hostile or not, to access the network and initiate unwanted and harmful network traffic.

[0010] To address security concerns regarding hostile entities, some control switches include a disablement mechanism that disables ports (e.g., unused ports) so that devices cannot communicate through the disabled port. Additionally, some control switches have a lockdown mechanism that can "lock" a port to restrict communication through the locked port to a single device connected to that port during lockdown (e.g., as disclosed in U.S. Pat. No. 8,590,033). However, these conventional lockdown mechanisms are limited. In particular, conventional lockdown mechanisms fail to lock down (i) ports with more than two connected devices and / or (ii) ports connected to a second switch (sometimes referred to as "uplink ports"). Typically, uplink ports maintain functionality during lockdown, preventing overly restrictive operations that could disrupt plant operation. These ports are exempt from network security lockdown (i.e., remain unlocked) to avoid accidentally implementing a typical lockdown. Additionally, some switches classify ports connected to a daisy-chain of devices as "uplink ports" by identifying multiple devices connected to a port and assuming that the port is connected to a switch. Thus, while some control switches implement traditional lockdown mechanisms to prevent malicious devices from connecting to the network through ports that were previously unused (e.g., by disabling the port) or that were connected only to a single end device (e.g., by locking the port), these switches remain vulnerable with ports connected to uplink switches, more than two end devices, or a single device with multiple physical addresses (e.g., virtualization systems). Summary of the Invention [Problem to be solved by the invention]

[0011] The described methods and systems enable a process control switch to lock down its ports and / or all of its ports and / or identify a "known pair" of physical and network addresses for each device communicating through each port of the process control switch. [Means for solving the problem]

[0012] In one embodiment, a process control switch includes a plurality of ports and a set of circuitry communicatively connected to the plurality of ports. The set of circuitry may be configured to lock the plurality of ports, wherein the set of circuitry (i) maps known physical addresses of devices in the process control environment to one or more of the plurality of ports to which the devices are connected, and (ii) generates (A) a static address table that is not updated with new known physical addresses while the plurality of ports are locked, wherein the static address table maps the plurality of known physical addresses to a single port connected to a daisy chain of unlockable or unmanaged switches or devices, and / or the set of circuitry (B) may limit traffic on each of the plurality of ports, wherein the set of circuitry (i) controls the number of messages forwarded on each port to comply with a traffic threshold, and (ii) authenticates the source physical address included in each message received on each port. To authenticate the source physical address, the set of circuits may (a) analyze the message to identify the source physical address contained in the message, (b) forward the message through one of the multiple ports if the static address table lists the source physical address as a known physical address mapped to a single port, and (c) drop the message if the static address table does not list the source physical address as a known physical address mapped to a single port.

[0013] In one embodiment, a process control switch includes a plurality of ports and a set of circuits communicatively connected to the plurality of ports. The set of circuits may be configured to perform a lockdown operation, where the set of circuits may (a) detect that one of the plurality of ports is connected to a second switch, (b) analyze a handshake with the second switch to determine whether the second switch is lockable, (c) if the set of circuits determine that the second switch is lockable, forward messages received from the second switch without authenticating the source physical address of the message, and / or (d) if the set of circuits determine that the second switch is not lockable, authenticate a source physical address included in a message received at the port, such that the message is analyzed to determine whether the received message identifies a source physical address included in a list of known physical addresses.

[0014] It should be noted that this Summary is provided to introduce a selection of concepts that are further described below in the Detailed Description. As discussed in the Detailed Description, particular embodiments may include features and advantages that are not described in this Summary, and particular embodiments may omit one or more features and / or advantages described in this Summary.

[0015] Each of the drawings described below illustrates one or more aspects of the disclosed system and / or method, according to one embodiment. The detailed description refers to the reference numerals included in the following figures. [Brief explanation of the drawings]

[0016] [Figure 1A] 1 is a schematic diagram of a process control system in a process plant implementing smart process control switches to enhance network security and facilitate network management and maintenance. [Figure 1B]FIG. 1B is a second schematic diagram of a process control system in a process plant implementing the smart process control switch shown in FIG. 1A to enhance network security and facilitate network management and maintenance. [Figure 1C] Refers to the basic unit of data or frame that can be communicated through a process control system that typically uses the Ethernet protocol. [Figure 2A] FIG. 2 is a network diagram of a process control network of a first embodiment implementing a set of smart process control switches similar to those shown in FIGS. 1A and 1B to improve lockdown performance and enhance network security. [Figure 2B] FIG. 1 is a network diagram of a process control network of a second embodiment that implements a set of smart process control switches to improve lockdown performance and enhance network security. [Figure 2C] FIG. 2B is a block diagram of the smart process control switch shown in FIGS. 1A, 1B, and 2A. [Figure 3A] 1A-2C illustrate an example method for locking down and unlocking ports for one or more smart process control switches shown in FIGS. 1A-2C. [Figure 3B] 1A-2C illustrate an exemplary method for locking a port of the smart process control switch shown in FIGS. 1A-2C after receiving a lockdown command. [Figure 3C] 1A, 1B, 2A, and 2B illustrate an example of a method for unlocking the smart process control switch shown in FIGS. 1A, 1B, 2A, and 2B. [Figure 4A] 1A-2C illustrate exemplary user interfaces that may be provided to facilitate locking and unlocking the smart process control switches illustrated in FIGS. [Figure 4B] 4B illustrates the example user interface shown in FIG. 4A with the set of switches unlocked. [Figure 4C]4C illustrates the example user interface shown in FIGS. 4A and 4B with a set of locked switches in place. [Figure 4D] 4A, 4B, and 4C are populated with a set of switches having a "lock pending" state. [Figure 5] FIG. 2D is a diagram showing an example of an address matching table shown in FIG. 2C. [Figure 6] 2C and 5 to improve security of process control systems within a process plant. [Figure 7] FIG. 1A illustrates a block diagram of an exemplary method for detecting security issues associated with the smart process control switches shown in FIGS. 1A-2C. DETAILED DESCRIPTION OF THE INVENTION

[0017] This disclosure provides: (i) a method for implementing ... 1A, 1B, and 2C, and sometimes referred to as "switch 146") that can implement (i) a lockdown operation or routine to lock down communication ports of the switch 146, and / or (ii) an address mapping operation or routine to identify a "known pair" of physical address and network address for each device communicating through the switch 146.

[0018] Switches are generally categorized into two types: configurable and non-configurable. Configurable switches (also called "managed switches") can have a variety of network settings (e.g., port speed, virtual LAN, redundancy, port mirroring, Quality of Service (QoS) for traffic prioritization, etc.) that are set by the user so that the switch can be tailored to a specific implementation. Non-configurable switches (also called "unmanaged switches") are typically configured to OEM specifications, with network settings that cannot be easily changed by the end user. Configurable switches are often found in environments where traffic entry and control are desired (e.g., industrial environments), while non-configurable switches are generally targeted at less sophisticated environments (e.g., the home or small office).

[0019] In general, as used herein, the phrase “managed switch” is not synonymous with the phrase “configurable switch” as described above, and the phrase “unmanaged switch” is not synonymous with the phrase “non-configurable switch” as described above. Rather, the terms “managed” and “unmanaged” refer to the lockability of a switch. That is, as used herein, a “managed switch” refers to a switch that has the lockdown functionality described herein, and an “unmanaged switch” refers to a switch that lacks the lockdown functionality described herein. Because switch 146 is configured to implement the described lockdown operations, switch 146 can be referred to as a “managed switch.”

[0020] A lockdown operation allows the switch 146 to lock its ports so that devices connected to the ports at the time of lockdown become “known” devices. “Known devices” are allowed to continue using the ports while “new” devices are not allowed to communicate through the ports. That is, the switch 146 “drops” communications received from “new” devices that connect to the switch 146 after the switch 146 is locked, allowing the switch 146 to protect the ports from attacks by newly connected malicious devices. Generally speaking, the term “connection,” when used in reference to a device and a port of the switch 146, refers to the physical connection between the port and the physical medium (e.g., an Ethernet cable, such as a CAT5 or CAT6 cable) that enables communication between the switch 146 and the device. The physical medium may be connected to the device directly or indirectly through one or more intermediate devices that facilitate communication with the device.

[0021] When implementing a lockdown operation, the switch 146 may generate a record (e.g., a static address table) of the physical addresses (e.g., MAC addresses) of all known devices connected (directly or indirectly) to each port of the switch 146. Unlike a conventional controlled switch, the switch 146 may generate a record of three or more physical devices connected to a single port. For example, if three, four, five, or more devices are daisy-chained to a single port, the switch 146 may generate a record of the physical addresses of each of the multiple devices daisy-chained to a single port. As a result, the switch 146 may "lock" all ports and allow communication through the switch 146 only for devices with known physical addresses (e.g., source physical addresses that match the physical addresses on record at the time the lockdown was initiated). In such a scenario, malicious devices may be able to communicate with each other. When a device physically connects to a port on switch 146 after lockdown, switch 146 will not forward messages from the malicious device (assuming the physical address does not match the physical address of the device connected to that port at the time of lockdown). Thus, switch 146 can prevent the malicious device from joining the control network, thereby preventing the malicious device from collecting sensitive information from the control network or from illegally controlling devices connected to the control network.

[0022] The lockdown operation may be implemented by switch 146 in response to receiving a lock command sent in response to a device detecting a security threat on the network to which switch 146 is connected. For example, the lock command may be sent by a device (e.g., a computer such as a server, workstation, or controller) within a control system (e.g., a Delta V control system) implemented in a plant associated with switch 146. As another example, the lock command may be sent by a security system (e.g., a set of specially designed hardware such as an ASIC or a computer running security software) that monitors network activity. The security system may include one or more systems for monitoring network activity, such as an access control system, an anti-keylogger system, an anti-malware system, an anti-spyware system, an anti-vandal system, an anti-virus system, a cryptosystem, a firewall system, an intrusion detection system (IDS), an intrusion prevention system (IPS), a security information management system, or a security information and event management (SIEM) system. One or more of these security systems may work in concert to generate the lock command. For example, a firewall system may detect a security threat and notify a SIEM (which may be configured to aggregate security threats from multiple sources), which may respond by sending a lock command. Exemplary security threats may be detected in any of a number of ways. For example, a security system may use signature-based detection (e.g., recognizing known network signatures of known threats such as malware) and / or anomaly-based detection (e.g., detecting deviations such as a new logical port being opened on a node where only certain logical ports, such as those associated with a particular protocol associated with the node, are expected to be open and used).

[0023] Lockdown routines can be utilized in conjunction with traffic control routines that limit traffic on each port to a predetermined threshold. Each threshold for each port may be determined based on the type of device connected to the port. For example, if a controller is connected to a port, the controller's traffic utilization may not exceed a certain amount of input / output traffic per port (e.g., 512 kbps input or 1500 packets / second output traffic), and the port's traffic threshold may be set accordingly. Because field devices may consume more or less traffic, ports connected to field devices may have different traffic thresholds. In some cases, traffic control is an important feature for process control switches. For example, given the specific communication requirements of a given process control system, a process control switch without traffic control will tolerate any amount of traffic exchanged between any type of device and therefore will not prevent basic denial-of-service attacks that are easily detected. Process control systems tend to be very predictable, and therefore, it is not difficult to set thresholds based on the protocols and device types used in these specific use cases.

[0024] Further referring to the lockdown operation, the switch 146 may lock down the port when it is connected to a second switch (e.g., when it receives Bridge Protocol Bridge Unit (BPDU) frames). The second switch may determine the physical address of the second switch 146 (using a lock-down feature) and may perform a handshake with the second switch to determine whether the second switch is the second switch 146 or an "unmanaged" switch (e.g., a switch without the disclosed lockdown functionality). If the second switch is an unlockable or "unmanaged" switch, the switch 146 may identify and record the physical addresses of all end devices connected to ports of the switch 146 through the unlockable or "unmanaged" switch.

[0025] If desired, switch 146 can leave certain ports unlocked during lockdown. For example, switch 146 determines when a port is connected to a second switch (such a port may be referred to as an “uplink port”) and performs a handshake to determine whether the second switch is “managed” (i.e., “lockable” like switch 146) or “unmanaged” (i.e., not “lockable” like switch 146). If the second switch is “managed,” switch 146 may leave the uplink port unlocked (and as a result, the source physical addresses of messages received through the uplink port cannot be inspected, and / or the source physical addresses of messages can be inspected but messages with unknown source physical addresses are not dropped). Such an uplink port may be referred to as a “managed uplink port.” If the second switch is “unmanaged,” switch 146 may identify and record the physical addresses of all end devices connected to the uplink port through an “unmanaged switch,” and the uplink port may be referred to as an “unmanaged uplink port.” The switch 146 can then lock the uplink port such that the switch 146 drops messages originating from unknown devices connected to the unmanaged switch, preventing unknown devices (e.g., malicious devices) from accessing the wider network to which the switch 146 is connected. The locked port of the switch 146 may continue to transmit broadcast and multicast messages from known devices, and in such a case, unknown or rogue devices (i.e., devices that do not have a known physical address for a given port) can hear these transmitted broadcast and multicast messages. However, in such a case, the rogue device cannot respond to these messages or otherwise transmit messages through the locked port of the switch 146.

[0026] The address mapping operation allows switch 146, after lockdown, to verify that a device with a known physical address is a known device by verifying that the device is not simply spoofing a known physical address. Switch 146 performs this verification by tracking the network address (e.g., IP address) for each known physical address. Thus, each known device for a given port should have a known address pair (i.e., physical address and network address) tracked by switch 146. As a result, even if a malicious device connects to a locked port of switch 146 and successfully spoofs the physical address of a known device for that locked port, switch 146 will detect that the network address of the malicious device does not match the network address on record that is paired with the physical address. As a result, switch 146 generates an alert and / or drops communications received from the malicious device.

[0027] The switch 146 can implement port mirroring, if desired. For example, the switch 146 can copy packets entering or leaving a particular port and send the copied packets to an analyzer (e.g., via an assigned port associated with the analyzer). The analyzer can be any machine configured (e.g., via software) to analyze the copied packets. The tagging allows diagnostics and / or debugging to be performed on the copied packets without significantly impacting the devices sending and / or receiving the original packets.

[0028] 1A and 1B are schematic diagrams of a process control system 100 in a process plant that implements a switch 146 to enhance network security and facilitate network management and maintenance. The process control system 100 includes a process control network 150 and communication links connected to enable electrical communication between the nodes. The process control network 150 is a collection of nodes (e.g., devices or systems that can send, receive, and / or forward information). The nodes of the network 150 include one or more switches 146, one or more process controllers 110, one or more host workstations or computers 120-122 (e.g., authorized workstations and / or servers), at least one of which includes a display screen, one or more input / output (I / O) cards 140, one or more field devices 130, 133, and / or 142, a gateway 143, and / or a data historian 145. Some embodiments do not include the field devices 142 and the gateway 143.

[0029] Network 150 is a local area network (LAN). In some cases, a wide area network (WAN) and / or a telecommunications network may be part of the plant network, but in some cases may not be an integral part of network 150. Network 150 may be configured for Ethernet communications and / or any suitable communications protocol (e.g., TCP / IP, proprietary protocols, etc.) and may be implemented using hardwired (preferred) or wireless technology. Additional aspects of network 150 are described in more detail at the end of the detailed description.

[0030] One or more process controllers 110 (each of which may be, for example, a DeltaV™ controller sold by Fisher Rosemount Systems, Inc.) are communicatively connected to a network 150 and one or more host workstations or computers 120-122 via one or more switches 146. Each controller 110 may include one or more network interface cards (sometimes referred to as “communications interfaces”) and may connect to field devices 130 via I / O cards 140, each of which may be communicatively connected to one of the controllers 110 via a backplane. The field devices 130 may be communicatively coupled to the network 150 (e.g., using DeltaV Electronic Marshalling technology). The network 150 may also be used to connect Ethernet-based I / O nodes, such as DeltaV CHARM I / O cards (CIOCs), wireless I / O cards (WIOCs), and Ethernet I / O cards (EIOCs), which use open protocols to connect to field devices and send data back to the one or more process controllers 110. In this case, communication between the controller 110 and the I / O nodes may be explicitly proprietary.

[0031] I / O network 155, which may be a subnetwork of network 150, facilitates communication between controller 110 and field devices 130, 133, and 142 (e.g., via I / O cards 140). I / O network 155 may include intermediate nodes not shown in FIG. 1A, such as additional switches 146 (see FIG. 1B). I / O network 155 may be configured for Ethernet communications and / or any suitable communications protocol (e.g., TCP / IP, ModbusIP, etc.), and may be implemented using wired or wireless technology, depending on the implementation. In some implementations, Configurations may not include an I / O network 155 or may include modified versions of an I / O network 155 (eg, some embodiments may not include switches between the controller 110 and the field devices).

[0032] The I / O cards 140 are communicatively connected to the field devices 130 using any desired hardware and software, such as those associated with standard 4-20 mA devices, standard Ethernet protocols and / or any smart communication protocols such as the FOUNDATION Fieldbus protocol (Fieldbus), the HART protocol, or any other desired communication or controller protocol.

[0033] 1A, field device 130 is a HART device that communicates with HART modem 140 over a standard analog 4-20 mA line 131, while field device 133 is a smart device such as a Fieldbus field device that communicates with I / O card 140 over digital bus 135 or I / O network 155 using Fieldbus protocol communication. Of course, field devices 130 and 133 may conform to any other desired standard(s) or protocol, including any standards or protocols developed in the future.

[0034] The field devices 142 can be connected to the digital bus 135 through a specialized network device, such as a gateway 143. For example, the field devices 142 may only understand Profibus-PA commands, while the I / O network 135 implements the PROFIBUS-DP protocol. To this end, the gateway 143 can provide bidirectional PROFIBUS-DP / PA conversion. A switch 146 can also be located at or near the gateway 143.

[0035] The controller 110, which may be one of many distributed controllers within a plant having one or more processors therein, implements or manages one or more process control routines. The routines may include one or more control loops stored in or associated with the controller. The controller 110 also communicates with devices 130 or 133, host computers 120-122, and a data historian 145 via a network 150 and associated network devices 146 to control the process in any manner. Note that any control routine or element described herein may be implemented or executed in part by a different controller or other device, if so desired. Similarly, the control routines or elements described herein that may be implemented within the process control system 100 may take any form, including software, firmware, hardware, etc. For purposes of this discussion, a process control element may be any portion or part of a process control system, including, for example, a routine, block, or module stored on any computer-readable medium. A control routine may be any portion of a module or control procedure, such as a subroutine, a portion of a subroutine (e.g., a line of code), or the like, and may be implemented in any desired software format, such as using ladder logic, sequential function charts, functional block diagrams, object-oriented programming, or any other software programming language or design paradigm. Similarly, a control routine may be hard-coded into, for example, one or more EPROMs, EEPROMs, application-specific integrated circuits (ASICs), or any other hardware or firmware elements. Additionally, a control routine may be designed using any suitable programming language, including graphical design tools or any other type of software / hardware / firmware programming or design tool. The controller 110 can be designed using any design tool, including a control strategy or control routine. Thus, the controller 110 can be configured to implement a control strategy or control routine in any desired manner.

[0036] Data historian 145 may be any desired type of data storage or collection unit having any desired type of memory and any desired or known software, hardware, or firmware for storing data, and may be separate from or part of one of workstations 120-122. Data historian 145 may be communicatively coupled to network 150 and / or hosts 120 and 122 via switch 146.

[0037] FIG. 1C illustrates a basic unit of data or frame 175 that may be communicated generally through the process control system 100 and across the process control network 150 using the Ethernet protocol. The Ethernet frame 175 includes seven fields, each of which carries information between devices, such as the switch 146 or other process control system 100 components. The fields may contain multiple data bytes 178 that are interpreted and processed by the receiving device. For example, the destination MAC address field 180 may contain the physical address of an intermediate or destination node in the process control network 100, and the source MAC address field 182 may contain the physical address of the sending or intermediate node in the process control system 100. The destination MAC address 180 and source MAC address 182 fields may be used in conjunction with data from the switch 146 to process the data transmitted over the process control network 150. In some embodiments, the fields 180 and 182 may be compared to one or more tables stored in the receiving network device when the device is in a “locked down” state. The results of the comparison can be used to reject or otherwise deny received data or other physical or logical connections to the locked network device.

[0038] 2A is a network diagram of an example process control network 200A in which a set of switches 146A-D, each representing an example of a switch 146, is implemented to improve lockdown performance and enhance network security, as shown in FIG. 2C. Solid lines represent communication links connected to locked ports, and dotted lines represent communication links connected to unlocked ports. Advantageously, each port of the switches 146A-D can be locked down. As a result, even if a malicious device connects to a process control device, hub, or unmanaged switch connected to one port of the switches 146A-D, when each switch 146A-D is locked down, the malicious device cannot communicate through that port.

[0039] In addition to switches 146A-D, network 200A includes devices 111A-111L (collectively referred to as "devices 111"), devices 113A-113D (collectively referred to as "devices 113"), and a hub 112. Devices 111 are process control devices specifically configured to operate within a process control plant and communicate over a process control network. Each device 111 has one or two physical addresses (e.g., for redundancy). Typically, the physical address of a device 111 is a MAC address that is specifically configured to allow the device 111 to be recognized by other process control devices on the process control network 100D. For example, the physical address of each device 111 may begin or end with a specific, recognized pattern of characters (e.g., F9-C3-XX-XX-XX-XX) so that each is recognizable as a device specifically configured for implementation in a process control environment. Exemplary devices 111 include process controllers, I / O cards, workstations, data historians, and the like. Anne, and specially configured network devices.

[0040] The devices 113 include (i) devices that are not specifically configured for a process control network (also called "off-the-shelf devices" or "general-purpose devices") and / or (ii) devices that have more than two physical addresses (which can include both specially configured process control devices and "general-purpose" devices). The hub 112 is a general-purpose network hub.

[0041] The switches 146A-D can lock all ports, regardless of the type or number of devices connected to the ports, preventing attacks by malicious devices connecting (directly or indirectly) to any of the ports of the switches 146A-D. FIG. 2A illustrates several examples in which the switches 146A-D improve upon current process control switches. Four specific examples illustrating the benefits of the switches 146A-D are described below. The four examples are: (i) locking ports connected to "general purpose devices" or devices (process control or "general purpose") with three or more physical addresses; (ii) locking ports connected to unmanaged switches; (iii) locking ports connected to a series of daisy-chained devices; and (iv) locking ports connected to unmanaged network devices, such as a hub connected to multiple devices.

[0042] A first example involves switch 146A including port 201 that can be locked when connected to device 113A. Device 113A may be (i) a "generic device" with any number of physical addresses or (ii) a process control device with more than two physical addresses. During operation, switch 146A implements a lockdown routine to lock port 201. After lockdown, switch 146A does not allow devices with physical addresses different from the physical address of device 113A to communicate through port 201. In other words, switch 146A analyzes any message received on port 201 to identify the source physical address contained in the message. If the message does not contain a source physical address that matches the physical address of device 113A known by switch 146A at the time of lockdown, switch 146A "drops" the message rather than forwarding it through one of its other ports, and a port violation alert is generated by switch 146A. In comparison, a typical process control switch may not be able to lock the port connected to device 113A because device 113A is either a "generic" device or a device with more than two physical addresses, and the process control switch typically does not lock such a port even when a lockdown procedure is initiated.

[0043] Switch 146A also includes port 211 connected to switch 146B. Port 211 is locked, as indicated by the solid line connected to port 211. Thus, switch 146A can store the physical addresses of all devices communicating through port 211 when locked, including any physical addresses of devices connected to any of switches 146B-D. In some cases, each of switches 146B-D can receive notification that it is connected to an upstream switch 146 (e.g., switch 146A), and as a result, it cannot authenticate the physical addresses during lockdown, assuming that the upstream switch 146 authenticates the physical addresses listed in the message to ensure that the listed physical addresses are known addresses. In other examples, one or more of switches 146B-D authenticate the physical addresses during lockdown together with switch 146A.

[0044] The second example is an unmanaged switch (i.e., a switch that does not have the lockdown features described). The switch 146A includes a switch 146B that includes a port 203 that is lockable when connected to a second switch (e.g., a switch that is not capable of sending BPDU frames, or a switch that is not capable of sending BPDU frames). Port 203, and any other ports connected to a second switch (e.g., port 211 and ports 213, 215, and 217 of switch 146A), may be referred to as "uplink ports." Note that in some circumstances, switch 146A may be configured to identify only managed uplink ports when identifying uplink ports, and thus switch port 203 may not be classified as an uplink port by switch 146B (e.g., switch 146B may be configured to only classify ports connected to other switches 146A as uplink ports). Devices 111G-I are connected to unmanaged switches 109 that are physically connected to port 203. In particular, because unmanaged switch 109 cannot lock down its ports (as indicated by the dotted lines connecting switch 109 to devices 111G-111I), a malicious device can connect to switch 109 and communicate with other devices (e.g., devices 111G-111I) connected to switch 109. In other words, even if someone were to lock down all of the lockable switches in network 200A (e.g., switches 146A-146D), a new, unknown physical device could connect to switch 109, and switch 109 would forward messages from the malicious device to the port of switch 109 that is mapped to the destination address included in the message from the malicious device.

[0045] However, because port 203 is locked by switch 146B (as indicated by the solid line connecting switch 146B to switch 109), messages from new, unknown devices received on port 203 are dropped by switch 146B. When switch 146B is locked, messages are dropped because a record of the known physical addresses of all known devices communicating through port 203 is created (switch 146B can create this record by monitoring and recording the source and destination addresses of messages sent and received through port 203). Thus, in the illustrated example, switch 146B “locks” the record of known physical addresses so that only the physical addresses of devices 111G-I are associated with port 203. As a result, any device connecting to switch 109 (e.g., via a wired or wireless connection) will be unable to communicate with other devices on network 200A through port 203 of switch 146B (if the new device has a physical address that matches that of one of devices 111G-I, switch 146 will utilize address mapping table 222 to detect that the new device is not one of devices 111G-I). In short, even if port 203 is connected to an unmanaged switch (i.e., switch 109) that does not lock its ports, switch 146B can lock port 203 so that only devices connected to switch 109 can communicate through switch 146B during lockdown.

[0046] Moving to a third example, FIG. 2A illustrates switch 146C including port 205 that can be locked when a pair of daisy-chained devices 111E and 111F are connected to port 205. Device 111E is physically connected to port 205, and device 111F is daisy-chained to device 111E, allowing device 111F to communicate with other devices on network 200A via device 111E and its connection to port 205. Generally, the daisy-chain connection is a pass-through connection, allowing all daisy-chained devices (i.e., 111E and 111F) to directly access port 205. Notably, device 111E does not lock down the access point connected to device 111F, as indicated by the dotted line between devices 111E and 111F. Thus, a malicious device could potentially access device 111E or 111F. 111E and 111F, any of which may forward messages received from the malicious device. However, if a new device is connected to the same daisy chain connected to port 205 or if a device in the daisy chain is replaced with a new device, switch 146C may flag a port violation for port 205 and disallow communication from any device connected to the daisy chain. In some examples, switch 146C may simply drop messages from the new device during lockdown. When locking down port 205, switch 146C creates a record of the known physical addresses of all known devices communicating through port 205 (e.g., devices 111E and 111F) and discards any messages that identify a source physical address (e.g., the physical address of a malicious device) that is different from the known physical addresses, causing the message to be dropped. Thus, while the malicious device is connected to device 111E or 111F, any messages from the malicious device are dropped by switch 146C (i.e., not forwarded through other ports of switch 146C).

[0047] Finally, as a fourth example, FIG. 2A shows switch 146D, which includes lockable port 207 when connected to unlockable hub 112, which is connected to multiple devices. In essence, switch 146D treats hub 112 similarly to how switch 146B treats unmanaged switch 109. Devices 113D, 111K, and 111L are connected to hub 112, which is physically connected to port 207. Because hub 112 cannot lock down its port (as indicated by the dotted line connecting hub 112 to devices 113D, 111K, and 111L), a malicious device can connect to hub 112 and communicate with other devices connected to hub 112. However, because port 207 is locked by switch 146D, messages from new, unknown devices received on port 207 are dropped by switch 146D.

[0048] In particular, devices 113D, 111K, and 111L can communicate over network 200 because their physical addresses are registered in the memory of switches 146D and / or 146B. In some cases, for ease of use and convenience, the uplink ports of switches 146A-D (e.g., ports 213 and 215) are not locked, but all physical addresses mapped to the uplink ports are registered (e.g., in switches 146B and / or 146D), and changes to the address table are flagged and alerts are generated by the switches. For example, if someone attempts to disconnect switch 146D from switch 146B and connect a new hub to port 215, switch 146B will detect the unknown address of the device attempting to communicate through the new hub and switch 146B. If someone attempts to insert a new hub as an intermediate device between switch 146B and switch 146D, both switches 146B and 146D can detect the new hub (and / or any new addresses of new devices connected to the hubs), and one or both can generate an alert about the new physical addresses now connected to switches 146B and 146D. The uplink port detection mechanism allows users to identify when such physical access intervention is taking place.

[0049] 2B is a network diagram of an example process control network 200B implemented with a set of switches 146A-D. Network 200B is similar to network 200A. Each switch 146A-D in network 200B is configured to detect when one of its ports is connected to a second switch (i.e., an uplink port) and lock the uplink port only when the second switch is unmanaged. Each switch 146A-D analyzes the handshake with the second switch and locks the uplink port only when the second switch is unmanaged. Determine whether the switch is managed (e.g., determine whether the second switch is switch 146). During lockdown, each switch 146A-D can process messages received via its uplink port differently depending on whether the connected second switch is lockable. In other words, each switch 146A-D can unlock or lock its uplink port depending on whether the second switch is lockable.

[0050] For example, switch 146A includes uplink port 211 connected to switch 146B. Because switch 146B is lockable, switch 146A keeps uplink port 211 unlocked. Similarly, switch 146B keeps uplink ports 213 and 215 unlocked because they are connected to lockable switches 146C and 146D. Switch 146A can forward messages received from switch 146B without authenticating the source physical address contained in the message. Switch 146A may "assume" that switch 146B is processing a lockdown for that port and therefore cannot lock uplink port 211, even during the lockdown. Switch 146B may similarly keep ports 213 and 215 unlocked. In some cases, switches 146A and 146B may continue to monitor the source physical addresses of messages received through uplink ports 211-215 and compare the source physical addresses to known physical addresses. Switches 146A and 146B can generate a port violation alarm when monitoring reveals that the source physical address is unknown.

[0051] If the second switch is not lockable (e.g., a generic or "off-the-shelf" switch), the switches 146A-D can lock the uplink port in the same manner as described with reference to FIG. 2A. For example, the switch 146B can lock the uplink port 203 (connected to the unmanaged or unlockable switch 109) as described with reference to FIG. 2A. In some cases, when the uplink port is locked, the switches 146A-D drop messages with unknown source physical addresses. In other examples, when the uplink port is locked, the switches 146A-D generate a port violation alarm or alert while continuing to forward messages with unknown physical addresses.

[0052] FIG. 2C is a block diagram of switch 146, which may be a DeltaV smart switch for use in a DeltaV® process control network (there are different families to address different use cases). Switch 146 is a Layer 2 switch, meaning that switch 146 operates at Layer 2 (the data link layer) of the OSI model. In operation, switch 146 selects a transport port for a message by (i) identifying the destination physical address contained in the message and (ii) referencing a switching table to identify the transport port associated with the destination physical address. Switch 146 does not track intermediate nodes. For example, if switch 146 receives a message intended for an end device connected to switch 146 through four intermediate nodes, switch 146 does not have a record of the “next node” or any of the other intermediate nodes. Rather, it consults a switching table to determine which port should be used to forward the message. Furthermore, switch 146 does not track network addresses or utilize IP routing tables for message forwarding purposes.

[0053] In contrast, Layer 3 network devices such as routers operate at Layer 3 (the network layer) of the OSI model and typically use routing tables. When a router receives a message, it identifies the destination network address contained in the message. The router then consults its routing table to determine the best route to reach the destination network address, identifies the "next hop" network address listed for the best route, and forwards the message to the device with the "next hop" network address. Layer 3 switches typically have network routing intelligence similar to that of routers. In some cases, switch 146 may be a Layer 3 switch. That is, in some embodiments, switch 146 can utilize network addresses for routing and / or forwarding.

[0054] As previously mentioned, the switch 146 is a "smart process control switch," meaning that the switch 146 is specifically configured for a process control environment and configured to communicate with devices specific to a process control system, such as process controllers, field devices, I / O cards, process control workstations, and process control historians. The firmware of the switch 146 may include specific configurations to address DeltaV communication requirements, such as storm control (limiting data transfer for certain communications) and / or loop prevention. The switch 146 can be configured for process control operation by downloading firmware to the switch 146 specifically designed for the process control system 100. The specialized firmware uses a case specific to the process control system 100 and is generally not user-modifiable. Generally, the firmware used is designed to prevent network loops, prevent network storms, and lock down unused switch ports.

[0055] The switch 146 includes one or more communication ports 202, a console access port 204, and a status light 206. The communication ports 202 are used to interconnect various other network devices and process control system components for communication over the network 150, and the status lights 206 indicate the current operation of the network devices and can be used for diagnostic purposes. Generally, the ports 202 are configured to receive a wired physical connection, such as an Ethernet connection (e.g., utilizing CAT5 ScTP cable or CAT6 cable) or a fiber optic connection.

[0056] Switch 146 also includes circuit 230, which is an application specific integrated circuit (ASIC) specifically configured to perform the operations and functions performed by switch 146. At a high level, circuit 230 controls port 202. In particular, circuit 230 enables and disables port 220, locks and unlocks port 220, and processes messages received on port 220. Although FIG. 2B depicts circuit 230 as a single circuit, in some implementations switch 146 may include multiple circuits that perform the functions described with respect to circuit 230.

[0057] Additionally, switch 146 may include memory 208 (which may include volatile memory 210 and / or non-volatile memory 212). Memory 208 includes (i) one or more standard and private management information bases (MIBs) 214, (ii) switching tables 216 (sometimes referred to as "forwarding database tables" or "FDB tables"), (iii) dynamic address tables 218, (iii) static address tables 220, and (iv) address match tables 222. In some examples, memory 208 may include a content-addressable memory (CAM), and one or more of tables 214-222 may be stored in the CAM.

[0058] Generally, each MIB 214 is a database of objects or variables that can be manipulated to manage the device (e.g., switch 146) that corresponds to the particular MIB 214. The MIB 214 manages the switch 146 and is specific to the process control network 150. The circuit 230 may include a collection of objects accessible via a command line interface (CLI) for implementing the functionality. One or more private MIBs 214 may contain objects that can be managed by the circuit 230 to control the lockdown and unlock functionality described herein. Additionally, the circuit 230 may utilize the private MIBs 214 to provide an interface for DeltaV® network security functionality via a runtime API that communicates with the switch 146. The process control network 150 may be configured to include a mixture of network devices, each including a private MIB for controlling the lockdown and unlock functionality (i.e., a "lock device") and off-the-shelf network devices that do not have lockdown or unlock functionality.

[0059] For each physical address, the switching table 216 includes one or more physical addresses (e.g., MAC addresses) and corresponding ports of the switch 146. During operation, the switch 146 receives a message on one of the ports 202. The circuit 230 analyzes the message to identify the destination physical address contained in the message and consults the switching table 216 to identify the port 202 corresponding to the destination physical address. If the switching table 216 does not include the destination physical address, the circuit 230 may execute a flooding routine, during which the switch 146 transmits the message through all ports 202. Assuming that a device having the destination physical address is connected (directly or indirectly) to one of the ports 202, the device responds to the received message. After the switch 146 receives the response, the circuit 230 records in the switching table 216 the destination physical address and the port 202 from which the circuit 230 received the response from the destination device.

[0060] Generally, switch 146 does not use dynamic address table 218 to make decisions regarding message forwarding or discarding. Rather, dynamic address table 218 represents a record of devices connected to ports that may be continuously updated over time. Dynamic address table 218 lists the physical addresses of end devices currently connected to each port 202 of switch 146. For example, switch 146 can dynamically learn the mapping of a physical address to a particular port 202 by analyzing frame 175 (shown in FIG. 1C ) received from a device and identifying the device's source MAC address 180. Switch 146 adds source MAC address 180 to dynamic address table 218 as a physical address mapped to the particular port 202. Furthermore, switch 146 can dynamically learn the mapping of a physical address to a second port by (i) analyzing frame 175 to identify the destination MAC address 182 of the destination device, (ii) performing the flooding routine described with respect to switching table 216, and (iii) identifying the port 202 on which a response message from the destination device is received. In some cases, dynamic address table 218 may be updated periodically by copying information from forwarding table 216. Additionally, in some implementations, switch 146 uses one of tables 216 and 218 only to forward decisions and track the physical addresses of connected devices.

[0061] Circuitry 230 may update dynamic address table 218 as nodes are connected to or disconnected from switch 146 by mapping new physical addresses to ports 202 to which new devices are connected and aging out currently unused physical addresses (e.g., by tracking the time or number of messages that pass to or from a particular physical address without being successfully transmitted). For example, upon expiration of an aging time, circuitry 230 may remove a physical address from dynamic address table 218.

[0062] Similar to dynamic address table 218, static address table 220 lists the physical addresses of end devices associated with each port 202. However, the physical addresses in table 220 are not dynamically learned or aged. Rather, they are explicitly entered by copying dynamic table 218 when switch 146 is locked. A function implemented in firmware of switch 146 can compare switching table 216 with tables 218 and 220 to process incoming messages. Static address table 220 may be utilized by circuit 230 when performing authentication operations to authenticate source physical addresses contained in messages received at port 202. In particular, if the source physical address of a received message is not identified as a known physical address mapped to the receiving port in static address table 220, circuit 230 can drop the message.

[0063] Generally, physical addresses may be added to switch table 216 while switch 146 is in a normal or “unlocked” state. For example, in the “unlocked” state, when switch 146 receives an Ethernet frame 175, circuit 130 examines the destination MAC address 180 and consults switching table 216 to identify the appropriate port 202 to forward frame 175 to. If switch table 216 does not contain information about the received destination MAC address 180, switch 146 broadcasts the Ethernet frame 175 to all ports in network 150. Upon recognizing the broadcasted MAC address on another network device, the other frame is sent to broadcast switch 146, which adds the discovered MAC address to dynamic address table 218 and FDB table 216. However, in a “locked down” state (as described below), switching table 216 may be frozen in its current configuration to prevent further changes or additions. When locked, previously learned physical addresses and other information contained in the dynamic address table 218 are moved to the static address table 220 and learning is disabled for the switch 146. In the lockdown state, the switching table 216 cannot be modified, preventing the switch 146 from accepting and forwarding frames 175 received from unknown or unlearned MAC addresses 182.

[0064] The address match table 222 lists a network address for each known physical address stored in one or more of the tables 216, 218, and 220. The switch 146 can determine the network address of a known physical address by sending an ARP request for the network address. Alternatively, in some cases, a database can store a list of network addresses for nodes on the process control network 150, and the switch 146 can download from the database network addresses for known physical addresses. While the switch 146 does not utilize the address match table 222 to select a forwarding port for received messages, the switch 146 can use the table 222 to prevent Address Resolution Protocol (ARP) spoofing. In particular, when the switch 146 is locked down, the identity of a source device that sent a message to the switch 146 can be verified by verifying that the source device has a network address that matches a known network address in the address match table 222. This verification is useful if a malicious device spoofs the physical address of a known device. The address match table 222 is described in more detail below with reference to FIG. 5.

[0065] If switch 146 has an uplink port (i.e., a port connected to a second switch), switch 146 can perform a handshake with the second switch to determine whether the second switch is a "managed" or "unmanaged" switch. Generally, a "managed" switch can lock its ports and not an "unmanaged" switch. The "managed" switch cannot lock its port. During the handshake, the switch 146 can receive an indication from the second switch regarding its "lockability" or state, whether it is managed or unmanaged. In some cases, the switch 146 can send a query to the second switch, and the second switch can respond with an indication that the second switch is managed. The second switch may also respond with an indication that the second switch is unmanaged or may simply be unresponsive. Failure to receive a response within a certain period of time (e.g., 1 second, 5 seconds, 30 seconds, etc.) can act as an indication to the switch 146 that the second switch is unmanaged.

[0066] When switch 146 receives an indication that the second switch is being managed, switch 146 can bypass the lock on the second switch, assuming that the second switch handles the lock on the port of the second switch. This allows switch 146 to monitor the source physical addresses of devices communicating through the second switch and compare these monitored source physical addresses with a record of known physical addresses. If switch 146 detects a monitored source physical address connected to the second switch that is not a known physical address, switch 146 can generate an alarm (e.g., a port violation alarm that can be sent to one of workstations 120 or 122 for display via a user interface).

[0067] FIG. 3A illustrates an example method 300 for locking and unlocking ports 202 of one or more switches 146. Generally, the method 300 allows a user of the process control system 100 to lock down a switch 146, causing the switch 146 to drop messages received from an “unknown” device. For example, if a user unplugs a device from a port 202 of the switch 146 and plugs another device in its place, the switch 146 will reject messages from the different device and alert a user interface, monitoring service, and / or other application running on a workstation 120, 122 of the system 100. In the lockdown state, all ports 202 in the networks 150 and / or 155 may be locked, preventing new devices with “unknown” physical addresses from communicating through the ports 202. The following method generally references the user interface 400 shown in FIGS. 4A-4D, although it will be understood that any suitable user interface for performing the described functions may be utilized.

[0068] In block 302, a user may launch a process control network security application that displays a user interface 400 (shown in FIGS. 4A-D) to initiate the lockdown process. One of the workstations 120 or 122 may provide the user interface 400 that can utilize the MIB 214 in the switch 146 to initiate the lockdown and unlock procedures.

[0069] In block 304, the application may initiate switch discovery automatically (e.g., upon startup) or in response to input from a user. The user interface 400 may display a status indication 402 of "Discover Switch" or another indication that one or more switches 146 of the process control network 150 have been identified. In some embodiments, the application may disable one or more function buttons of the user interface 400 upon initiating network device discovery. A user may also manually initiate network device discovery. In some cases, the application may discover any switches (managed or unmanaged) present in the process control network 150. In other examples, the application may The application can identify only network devices, such as switches 146, that include lockdown functionality.

[0070] An application can discover switch 146 by searching network 150 using one or more parameters. In some cases, the application can additionally or alternatively search network 155. Switch 146 may be initially discovered using its physical address. Switch 146 can be configured with a network address during a commissioning process. After this commissioning process, communication with switch 146 is possible via MIB 214 (e.g., switch 146 can be identified by identifying switch 146's private MIB 214), and devices outside the LAN can send messages to switch 146 by addressing the messages to switch 146's network address. An application can discover switch 146 by searching a specified range of physical and / or network addresses. Note that while switch 146 itself may have a network address, switch 146 generally does not rely on the network addresses of other devices when selecting a forwarding port for a received message.

[0071] In block 306, one or more switches 146 (FIG. 4B) discovered in block 304 may be displayed by the user interface 400 via an expandable drop-down menu 406 (FIG. 4A), and parameters of one of the discovered switches may be displayed for a selected switch 146 from the expandable drop-down menu 406 (FIG. 4C). For example, security parameters such as lock status, lock timer, and password age may be displayed in a window of the user interface 400. The window may also display switch alarms (e.g., COMM, FAILED, MAINT, ADVISE) and component status parameters (e.g., power supply status, chassis temperature, etc.). The ports of the switch may also be listed along with a number of parameters for each port (e.g., indicating whether the port is available, identifying the node name of the connected end node, identifying the port lock address, and / or indicating whether a port lock violation exists).

[0072] Once all of the discoverable switches 146 have been discovered, the user interface 400 may indicate that the search is complete. In some embodiments, when the method 300 first begins, the switch 146 may be displayed only by its physical address in the closed switch list of the interface 400. If the discovered switch is not otherwise locked down, the locked state may indicate that the discovered switch 146 is in an “unlocked” state. In the unlocked state, the switch 146 can perform all normal functions within the network 150. In some embodiments, a port 202 in the unlocked state can perform the basic transparent bridging functions of learning, aging, and forwarding. The default aging time may be set to 600 seconds (10 minutes), although other default times may be set depending on the configuration of the switch 146 and the network 150. Upon completion of the search, one or more function buttons 434 may be available by user selection or an automated process.

[0073] In block 308, a user or an automated process may select one or more of the "unlock" switches listed on the user interface 400 shown in Figure 4A. The user may make this selection by utilizing an input device (e.g., a mouse or touch screen) of the workstation to select one or more desired switches, causing the user interface 400 to display a drop-down menu with selectable buttons for locking the switches. 4B, a user can also select an entire network (e.g., by right-clicking on the desired network) to lock down (i.e., all switches 146 in the selected network are locked down). In some examples, one or more switches 146 may include a hardware actuator (e.g., a button) that can be activated to initiate a lockdown. Additionally, an automated process can select switches for lockdown based on a trigger, such as the detection of a malicious device connecting to the network 150 in a certain capacity.

[0074] In block 310, the workstation initiates a lockdown process (e.g., method 325 shown in FIG. 3B) in response to detecting that a user has selected a lock button, such as the lock button 436 shown in FIG. 4F. The lock buttons provided by the user interface 400 can initiate a process to selectively initiate lockdown for different portions of the process control network 150. For example, separate buttons can provide the ability to selectively lock the entire network, the primary network, the secondary network, individual switches 146, or specific ports 202 on one or more selected switches 146. For additional security, the lockdown process may be initiated only from selected workstations 120, 122, and not over the Internet, for example, using a remote workstation that is not physically part of the process control network 150, or may be initiated only from one or more pre-approved MAC or IP addresses. Selecting the lock button to initiate the lockdown process initiates an authentication process. For example, the workstation may request a username and password or other personal identification information from the user to verify access to the lockdown process. The application 400 can utilize management access via the MIB 214 to lock and unlock the switch 146. Communications may be encrypted, and the keys or passwords used may be unknown to the user but known to the switch 146 and the application 400.

[0075] Upon authentication after selecting the lock button, the workstation may send a lock command to the selected switch 146 (e.g., by setting one or more variables in the private MIB 214 of the selected switch 146). In response to receiving the lock command, the switch 146 may lock all of its ports 202. Locking a port 202 generally involves not accepting any messages or frames 175 having a source MAC address 182 that is not included in the switching table 216 of the switch 146 at the time the lock state was activated. In some embodiments, unauthorized physical addresses may be recorded in the memory 208 of the switch 146 (e.g., known hostile MAC addresses, a range of MAC addresses belonging to rogue devices, etc.), and the switch 146 will drop any incoming messages that include one of the unauthorized physical addresses.

[0076] After performing the lockdown process 325 for one or more switches 146 in block 311, it may be necessary to unlock one or more switches 146, for example, during troubleshooting operations, routine maintenance, diagnostics, network reconfiguration, etc.

[0077] In block 312, a user or an automated process can select one or more switches 146 in the "locked" state, and in response to the user selecting an unlock button such as that shown in FIG. 4D, in block 314, the workstation used by the user can initiate an unlock process (such as method 350 shown in FIG. 3C). Similar to the lock button, the unlock button can also be used to unlock one or more private By utilizing the port MIB 214, an unlocking process can be initiated for different portions of the process control network 150 that were previously locked. For additional security, the unlocking process may be configured with a lockdown timer that automatically relocks one or more previously locked ports 220. The lockdown timer may be configured with a default setting and may relock one or more of the unlock switches 146 (block 310) upon the expiration of a period of time (block 316) after completion of the unlocking process. In one embodiment, the lockdown timer is configured with a default setting of 60 minutes (i.e., 3600 seconds). The unlocking process may be initiated from a selected workstation 120, 122 and not over the Internet, for example, using a remote workstation that is not a physical part of the process control network 150, or may be initiated only from one or more pre-approved MAC addresses.

[0078] The unlocking process may also include an authentication process. For example, the workstation 120 or 122 and / or the user interface 400 may request a username and password or other personal identification from the user to verify access to the lockdown process. If the user is properly authenticated, the user may access the private MIBs 214 of one or more selected locked switches 146 and / or ports 202 to begin the unlocking process.

[0079] 3B illustrates an example method 325 for locking a port 202 of a switch 146. The blocks described below may be implemented by the switch 146 and / or the workstations 120 or 122.

[0080] In block 326, switch 146 generates a static table, such as static address table 220. Generally, the static table is a record of known physical addresses connected to each port of switch 146 at the time lockdown was initiated. The port state and / or physical address mapping may be stored automatically or explicitly by a user (e.g., in non-volatile memory 212). If necessary, the record of known physical addresses can be used by switch 146 upon power cycle or reboot to prevent forcibly opening a locked port.

[0081] In some embodiments, the static table is generated by copying a list of physical addresses mapped to each port 202 from the dynamic address table 218. In some cases, known physical addresses and other data may be removed entirely from the dynamic address table 218 and moved to the static address table 220. In some embodiments, if the current number of learned addresses in the dynamic address table 218 is greater than a maximum number, only a subset of the addresses may be locked. The remaining addresses are then removed from the switching table 216, potentially resulting in connection errors. If connection problems occur, an error message may be sent to the user interface indicating the failure of the lockdown process.

[0082] In block 328, the switch 146 may analyze each message received on each port to identify the source physical address contained in each message (e.g., source MAC address 182 shown in FIG. 1C). The switch 146 may then determine whether the source physical address is contained in a static table (block 330). If not, the source physical address is an unknown address, and the message is dropped (block 332).

[0083] If the source address of the message is included in the static table, switch 146 , analyzes traffic on the port corresponding to the destination address included in the message (block 334). If the traffic on the forwarding port is below a traffic threshold stored in memory (e.g., input by a user or programmatically during switch configuration), the message is forwarded (block 306). Otherwise, the message is held until the traffic falls below the threshold, at which point the message is forwarded. In some implementations, the message may be dropped after a predetermined time or may be dropped immediately. In some embodiments, switch 146 additionally or alternatively analyzes traffic at the receiving port and analyzes the source address of the message only if the traffic is below a predetermined traffic threshold (block 328).

[0084] Note that in some examples, switch 146 may disable typical functions for switch 146 during lockdown. In one embodiment, switch 146 disables address learning and address aging functions for switch 146 or for specific ports 202. For example, dynamic address table 218 is disabled and no longer accepts any input, switch 146 can no longer flood network 150 to discover new addresses, and previously received addresses are not removed from dynamic address table 218 after an aging time has elapsed.

[0085] After initiating lockdown, the user interface 400 may change the lock state of one or more switches 146 from "unlocked" or "completed" to indicate that the selected device is locked or locked. Referring to FIG. 4C, once the lockdown process is complete, the user interface 400 may display the "lock state" of the locked switch as "locked."

[0086] 3C shows an example method 350 for unlocking a switch 146. A user's workstation can send an unlock command to the switch 146 (e.g., by changing the value of one object or variable in the private MIB 214 of the switch 146).

[0087] Address data in static table 220 that maps physical addresses to particular ports may be deleted at block 354. In some embodiments, static address data added by a user or other explicit process may be retained in static address table 220 during unlocking.

[0088] In block 356, the switch 146 may enable the unlocked state of the port 220. In particular, the switch 146 stops discarding messages with source addresses that do not match the static table 218.

[0089] In block 358, the switch 146 may resume normal port or device functions. For example, in the unlocked state, typical learning and aging functions that were suspended during lockdown may be resumed, and the switching table 216 and dynamic table 218 may be repopulated.

[0090] In block 360, the switch 146 may store the new switch or port configuration. For example, the port states and / or physical addresses may be stored automatically or explicitly by a user and implemented by the switch 146 upon a power cycle or reboot.

[0091] In some embodiments, after initiating the unlock process in block 314, the user interface 400 may change the lock state of one or more switches from "locked" to an indication that the selected switches are in a "lock pending" state. Additionally, if a lockdown timer was initialized in the unlock process, the remaining time status may indicate the time remaining until the device returns to a locked state. The remaining time may also be configured to never return to a locked state. For example, an object in the private MIB 214 may be accessed to configure the timer to a "never revert" state, or any other amount of time.

[0092] In some embodiments, the switch 146 can revert to a saved configuration upon power-on. For example, an entity may attempt to connect a rogue device to the process control network 150 by cycling power to one or more switches 146 to force open a locked port. Upon power-on, the switch 146 may be configured to access the saved configuration in its non-volatile memory 212 ( FIG. 2 ). Thus, regardless of whether the powered-on switch returns to a locked or unlocked state, all devices connected to the network 150 before the power cycle automatically re-establish communication with the system, and new devices added to the port while powered off will be rejected. If a device is powered on in an “unlocked” state and the lockdown timer is greater than zero, the device can automatically enter the locked state after that time has elapsed.

[0093] 5 illustrates an example of an address match table 222 according to some embodiments. The address match table 222 illustrated in FIG. 5 may be a representation of data that may be stored in the switch 146 (e.g., using an associative memory) and / or another device in the process control system. Alternatively or additionally, a device (such as the switch 146, the workstations 120 or 122, or other devices) may cause at least a portion of the information contained in the address match table 146 to be presented on a user interface (e.g., the user interface 400) for access and review by a user. It should be understood that the address match table 222 is merely an example, includes exemplary information, and may include alternative and / or additional information.

[0094] The address matching table 222 may include a set of columns, each of which is configured with corresponding data and information. In particular, the address matching table 222 may include a port column 505, an IP address column 510, a MAC address column 515, a lockdown status column 520, and a security status column 525. The port column 505 may identify a set of communication ports 202 of the switch 146 (as shown, communication ports 1 through 6). Each communication port in the set of communication ports 202 may have a device or another switch connected to it. If a communication port is connected to another switch 146, the communication port may be considered an uplink port. Note that while FIG. 5 shows a single device (or no device) connected to each port, a single port may map to multiple devices, including a physical address (column 510), a network address (column 515), a lockdown status (column 520), and a security status (column 525).

[0095] The IP address column 510 can identify a set of network addresses (e.g., IP addresses) of a set of devices respectively connected to a set of communication ports 222, and the MAC address column 515 can identify a set of physical addresses (e.g., MAC addresses) of a set of devices respectively corresponding to a set of communication ports. For example, a device with an IP address of 10.10.10.2 and a MAC address of 00:0C:F5:09:56:E9 is connected to communication port "1." As shown in FIG. 5, Since no devices are connected to either port "3" or communication port "6," the corresponding IP and MAC addresses are zero.

[0096] The lockdown status field 520 may identify the lockdown status (e.g., “locked” or “unlocked”) of each of the set of communication ports 222. As shown in FIG. 5, each communication port 222 with a connected device (communication ports “1,” “2,” “4,” and “5”) is “locked,” while the unconnected communication ports (communication ports “3” and “6”) are “unlocked.” However, in a typical example, when the switch 146 is locked, all ports on the switch 146 are locked unless the switch port is identified as an uplink port or manually configured by the user to be ignored (always unlocked) via CLI configuration. In the embodiments discussed herein, the switch 146 (and specifically, the set of ASICs on the switch 146) may obtain the IP and MAC addresses of devices in connection with initiating lockdown of an occupied communication port.

[0097] Security status column 525 may identify the security status of each of the set of communication ports. According to an embodiment, switch 146 may automatically and continuously monitor information (e.g., as data packets) being sent and received over the set of communication ports between devices already connected to it and / or between any other devices that may connect to the switch after the switch is locked down.

[0098] The switch 146 may examine received data packets to determine whether the information contained in the data packets is consistent. In particular, the switch 146 may compare information contained in the data packets with information contained in the address match table 222 to identify inconsistencies. If the switch 146 does not identify inconsistencies in the data packet traffic for a particular communication port, the security status of the particular communication port may be "normal." In contrast, if the switch 146 identifies inconsistencies in the data packet traffic, the security status of the particular communication port 222 may change from "normal" to "abnormal."

[0099] 5 , the security status of communication ports “2” and “6” is “abnormal,” while the remaining communication ports have a security status of “normal.” In an exemplary embodiment, the security status of communication port “2” may be “abnormal” due to an attempted ARP spoofing attack. In this embodiment, the device originally connected to communication port “2” may be replaced (or the originally connected device may be compromised) by an attacking device that can send data packets to switch 146. Switch 146 may inspect the data packets and determine that one or both of the IP address and MAC address included in the data packets do not match the corresponding IP address and / or MAC address in address match table 222. Therefore, switch 146 may update the security status of the corresponding communication port to “abnormal.”

[0100] Similarly, in an exemplary embodiment, the security state of communication port "6" may also be "abnormal" due to an attempted ARP spoofing attack. In this embodiment, communication port "6" may be unlocked because there were no devices connected to it at the time of lockdown. Following lockdown, a device (which may or may not be an attacking device) can connect to the unlocked communication port "6" and the device can send a data packet to the switch. The switch 146 inspects the data packet and, because communication port "6" is unlocked, determines that communication is permitted via communication port "6." The switch can determine that the device is not present, and therefore update the security status of the communication port to "abnormal."

[0101] The switch 146 may facilitate communication and / or display of the detected alerts. In an embodiment, the switch 146 may be connected to another device in the process control system, which may have a user interface. The switch 146 may send an indication of the one or more detected alerts to the device, and the device may be configured to display or present the one or more detected warnings via the user interface. Thus, a user (e.g., an individual or manager) associated with the process control plant can access and review the information to facilitate appropriate corrective or diagnostic actions.

[0102] 6 illustrates a block diagram of an example method 600 for implementing the address match table 222 to improve security of a process control system, such as the process control system 100, in a process plant. The method 600 may be facilitated by the switch 146.

[0103] Method 600 may begin when switch 146 initiates (block 605) a lockdown of a set of communication ports of switch 146. In an embodiment, switch 146 may initiate a lockdown of some or all of the set of communication ports 146.

[0104] In connection with initiating lockdown of the set of communication ports, the switch 146 may obtain a set of network addresses (e.g., a set of IP addresses) of a set of devices connected to at least some of the set of communication ports (block 610). It should be appreciated that the switch may obtain the set of network addresses before, simultaneously with, or after initiating (and / or completing) the lockdown. In an embodiment, a set of ASICs embedded in the switch may obtain the set of network addresses using data associated with the connections of the set of devices to at least some of the set of communication ports. Additionally or alternatively, the set of devices may include one or more switches to which one or more devices and / or one or more additional devices (or additional switches) connect within the process plant. In certain embodiments, the switch 146 may obtain (i) a first network address of a first device connected to a first communication port (i.e., device connection) and (ii) multiple network addresses of multiple devices connected to a second communication port through an additional switch (i.e., switch connection). The network addresses may be obtained from another device on the process control network.

[0105] In connection with initiating the lockdown, the switch 146 optionally obtains a set of physical addresses (e.g., a set of MAC addresses) of a set of devices connected to at least some of the set of communication ports (block 615). It should be appreciated that the switch may obtain the set of physical addresses before, simultaneously with, or after initiating (and / or completing) the lockdown. For example, the switch may obtain and record the set of physical addresses before initiating the lockdown. In one embodiment, a set of ASICs (e.g., circuit 230) embedded in the switch 146 may obtain the set of physical addresses using data associated with the connections of the set of devices to at least some of the set of communication ports.

[0106] The switch 146 generates (block 620) an address match table 222 for the switch 146, which matches a set of physical addresses for a set of devices. , to a set of network addresses for a set of devices. The address matching table 222 can further match the set of physical addresses and the set of network addresses with at least a portion of a set of communication ports. That is, for all devices connected (directly or indirectly) to a particular port of the switch 146, the address mapping table 222 can list an address pair of a network address and a physical address for the particular port. Thus, a port connected to multiple devices will have multiple associated address pairs (i.e., one address pair for each connected device). The switch 146 can store the address matching table locally (e.g., using content-addressable memory) for access and review.

[0107] The switch 146 may receive a data packet from the device via one of the set of communication ports (block 625), where the data packet may indicate at least (i) the network address of the device and (ii) the physical address of the device. In an embodiment, the device may be connected to one of the set of communication ports before or after the switch 146 initiates lockdown. Additionally or alternatively, the device may replace another device previously connected to one of the set of communication ports (i.e., in the case of a cable replacement). Additionally or alternatively, the device may be connected to an unlocked communication port or a communication port that is part of the set of communication ports (i.e., a locked communication port).

[0108] According to an embodiment, the data packet may represent an ARP spoofing attack by a device, which switch 146 may be configured to determine by determining (block 630) whether the network address of the device and the physical address of the device are included in address match table 222. In particular, the network address and physical address of the device, as a pair, may not match the mapped network address and mapped physical address included in the address match table of the communication port to which the device is connected. For example, if a device is connected to communication port "3" and one or both of the device's network address and physical address do not match the corresponding mapped address of communication port "3," a mismatch exists.

[0109] If switch 146 determines that the addresses match (“YES”), processing ends and can repeat or proceed to other functions. In contrast, if switch 146 determines that the addresses do not match (“NO”), there has been an ARP spoofing attempt, and switch 146 can generate an alert (block 35). In embodiments, the alert can indicate one of a set of communication ports to which the device is connected and / or other information including the device's network address and / or physical address. Furthermore, switch 146 causes the alert to be displayed on a user interface (block 40), where the user interface may be included in another device or component within the process plant. Thus, a user (e.g., a plant engineer or manager) can review the contents of the alert and initiate appropriate action.

[0110] The switch 146 further determines whether to allow or deny transmission of the data packet (block 645). In an embodiment, the determination may be a default selection (e.g., always allow or always deny), or the switch 146 may dynamically determine whether to allow or deny transmission based on one or more factors, such as the contents of the data packet itself, the physical address of the device, the network address of the device, and / or other factors.

[0111] If the switch determines that the transmission should be permitted ("permit"), the switch permits the transmission of the data packet (block 50). In contrast, if the switch 146 determines that the transmission should be denied ("deny"), the switch may deny the transmission of the data packet (i.e., may drop the data packet).

[0112] 7 illustrates a block diagram of an example method 700 for detecting security issues associated with a switch 146. The method 700 may be facilitated by the switch 146.

[0113] Method 700 may begin when switch 146 optionally initiates (block 705) a lockdown of a set of communication ports of switch 146, as described herein. In an embodiment, switch 146 may initiate a lockdown of some or all of the set of communication ports, possibly such that one or more of the communication ports may remain unlocked as desired.

[0114] In connection with initiating lockdown of a set of communication ports, the switch 146 may obtain a set of network addresses (e.g., a set of IP addresses) of a set of devices connected to at least some of the set of communication ports. It should be understood that the switch 146 may obtain the set of network addresses before, simultaneously with, or after initiating (and / or completing) lockdown. In an embodiment, a set of ASICs embedded in the switch 146 may obtain the set of network addresses using data associated with the connections of the set of devices to at least some of the set of communication ports. Additionally or alternatively, the set of devices may include one or more switches to which one or more devices and / or one or more additional devices (or additional switches) connect within the process plant. In particular embodiments, the switch 146 may obtain (i) a first network address of a first device connected to a first communication port (i.e., a device connection) and (ii) multiple network addresses of multiple devices connected to a second communication port via an additional switch (i.e., a switch connection).

[0115] In connection with initiating lockdown, switch 146 optionally obtains a set of physical addresses (e.g., a set of MAC addresses) of a set of devices connected to at least some of the set of communication ports. It should be appreciated that the switch may obtain the set of physical addresses before, simultaneously with, or after initiating (and / or completing) lockdown. For example, switch 146 may obtain and record the set of physical addresses before initiating lockdown. In one embodiment, a set of ASICs embedded in switch 146 may obtain the set of physical addresses using data associated with the connections of the set of devices to at least some of the set of communication ports.

[0116] The switch 146 further generates and accesses (block 710) an address match table 222, which can match a set of physical addresses of a set of devices to a set of network addresses of the set of devices. The address match table 222 can further match the set of physical addresses and the set of network addresses to at least a portion of a set of communication ports. Thus, each communication port having a connected device can have an associated physical address and network address of the device. In an implementation, a set of ASICs embedded in the switch 146 can generate the address match table 222. The switch 146 can store the address match table locally (e.g., using content-addressable memory) for access and review.

[0117] The switch 146 selects a set of network addresses contained in the address match table. A mapping request specifying a matching destination network address may be broadcast (block 615). In an embodiment, the mapping request may be in the form of an ARP request containing an IP address from an address mapping table, the ARP request intended to find the MAC address corresponding to the IP address, and the ARP request may be sent to each device connected to the switch.

[0118] Switch 146 receives a response to the mapping request from the responding device via one of the set of communication ports (block 720), where the response may indicate (i) a destination network address and (ii) a physical address of the responding device. According to an embodiment, the response from the responding device may represent an attempted ARP spoofing attack by the responding device that switch 146 is configured to determine.

[0119] Thus, switch 146 may determine whether the physical address of the responding device matches any of the set of physical addresses of the set of devices included in the address match table (block 725). In particular, the physical address of the responding device may not match a mapped physical address included in address match table 222 for the communication port to which the responding device is connected. For example, if a responding device is connected to communication port "3" and the physical address of the responding device does not match the corresponding mapped physical address for communication port "3," a mismatch exists. In an embodiment, a set of ASICs embedded in the network may make the determination.

[0120] If the switch 146 determines that the physical addresses match (“YES”) (i.e., there has been no attempted ARP spoofing attack), processing ends and may repeat or proceed to other functions. In contrast, if the switch 146 determines that the physical addresses do not match (“NO”), there has been an ARP spoofing attempt, and the switch may generate an alert (block 730). In an embodiment, the alert may indicate one of a set of communication ports to which the responding device is connected and / or other information including the network address and / or physical address of the responding device. Additionally, the switch 146 causes the alert to be displayed on a user interface (block 735), where the user interface may be included in another device or component within the process plant. Thus, a user (e.g., a plant engineer or manager) may review the contents of the alert and initiate appropriate action.

[0121] The lockdown routines and address mapping routines described herein may be implemented in software, hardware, firmware, or some combination thereof. Accordingly, methods 300, 325, 350, 500, 600, and 700 described herein may be implemented on specially designed hardware or firmware, such as standard general-purpose CPUs and / or ASICs. If implemented in software, the software may be stored on any computer-readable memory, such as a magnetic disk, laser disk, optical disk, or other storage medium, RAM, or ROM of a computer or processor. Similarly, the software may be distributed to a user or process control system via any known or desired distribution method, for example, on a computer-readable disk or other transportable computer storage mechanism, or modulated over a communications channel, such as a telephone line or the Internet. (This is considered the same as, or interchangeable with, providing such software via a transportable storage medium.)

[0122] Generally, as used herein, the phrase "memory" or "memory device" refers to a system or device that includes a computer-readable medium ("CRM"). A "CRM" is a medium that stores information (e.g., data, computer-readable instructions, program modules, etc.). "CRM" refers to a medium or media accessible by an associated computing system for placing, maintaining, and / or retrieving content (e.g., applications, routines, etc.). Note that "CRM" actually refers to a non-transitory medium, and not to an intangible, transitory signal such as radio waves.

[0123] As described with reference to FIG. 1A , network 150 is a collection of nodes (e.g., devices or systems that can send, receive, and / or forward information) and communication links connected to enable communication between the nodes. In general, the term “node” refers to a connection point, a redistribution point, or a communication endpoint. A node may be any device or system (e.g., a computer system) that can send, receive, and / or forward information. For example, an end device or end system that originates and / or ultimately receives a message is a node. Intermediate devices that receive and forward messages (e.g., between two end devices) are also generally considered to be “nodes.” A “communication link” or “link” is a path or medium that connects two or more nodes. A link may be a physical link and / or a logical link. A physical link is an interface and / or medium over which information is transferred and may be wired or wireless in nature. Examples of physical links may include a cable having conductors for the transmission of electrical energy, a fiber optic connection for optical transmission, and / or a wireless electromagnetic signal that conveys information via a modification made to one or more properties of an electromagnetic wave.

Claims

1. Multiple ports and a set of circuits configured to perform a lockdown operation and communicatively connected to the plurality of ports; 1. A process control switch comprising: (a) detecting that one of the plurality of ports is connected to a second switch; (b) determining whether the second switch is lockable by analyzing a handshake with the second switch; (c) if the second switch is determined to be lockable, forwarding the message received from the second switch without authenticating the source physical address of the message; (d) if the second switch is determined to be not lockable, authenticating a source physical address included in a message received at the port by determining whether the received message identifies a source physical address included in a list of known physical addresses; It is configured as follows: Process control switches.

2. 2. The process control switch of claim 1, wherein the set of circuits is further configured to drop a message received at the port if the set of circuits determines that (i) the second switch is not lockable, and (ii) the message identifies a source physical address that is not included in a list of known physical addresses.

3. 3. The process control switch of claim 1, wherein the set of circuits is further configured to generate a port violation alarm if the set of circuits determines that (i) the second switch is not lockable, and (ii) the message identifies a source physical address that is not included in a list of known physical addresses.

4. The handshake by the second switch is performed via the plurality of ports.

4. The process control switch of claim 1, further comprising the set of circuits transmitting a query regarding the lockability of two switches.

5. 4. The process control switch of claim 1, wherein the handshake with the second switch comprises the second switch sending an indication regarding lockability without receiving a query from the process control switch.

6. 6. The process control switch of claim 1, wherein the set of circuits is configured to forward messages received on the plurality of ports without using network addresses based on a switching table that maps physical addresses to the plurality of ports.

7. (a) detecting, by a process control switch, that a port from a plurality of ports of the process control switch is connected to a second switch; (b) the process control switch determining whether the second switch is lockable by analyzing a handshake between the process control switch and the second switch; (c) operating the process control switch in a locked state; 1. A method for a process control switch to implement a lockdown operation for the process control switch, comprising: (1) if the second switch is determined to be lockable, the process control switch forwards the message received at the process control switch from the second switch without authenticating the source physical address of the message; (2) if it is determined that the second switch is not lockable, the process control switch authenticates the source physical address included in the message received at the port by determining whether the received message identifies a source physical address included in a list of known physical addresses. A method for a process control switch to implement a lockdown operation for the process control switch.

8. 8. The method of claim 7, further comprising: if the results of the analysis indicate that (i) the second switch is not lockable, and (ii) the message identifies a source physical address that is not included in a list of known physical addresses, the process control switch dropping the message received at the port.

9. The method of claim 7 or 8, wherein the handshake with the second switch comprises the process control switch sending a query to the second switch regarding the lockability of the second switch.

10. 10. The method of claim 9, wherein the process control switch analyzing the handshake with the second switch comprises identifying a failure by the second switch to respond to the query within a specified period of time.

11. The method of claim 7 or 8, wherein the handshake with the second switch comprises the second switch sending an indication regarding lockability without receiving a query from the process control switch.

12. Forwarding a message received at the process control switch from the second switch without authenticating a source physical address of the message comprises: forwarding the message without using a network address based on a switching table that maps physical addresses to the plurality of ports; 12. The method of claim 7, comprising:

13. Forwarding a message received at the process control switch from the second switch without authenticating a source physical address of the message comprises: forwarding said message based on an analysis of a network address; 12. The method of claim 7, comprising:

14. 14. The method of claim 7, further comprising receiving, by the process control switch, the lock command transmitted to the process control switch in response to a user interacting with a user interface to manually initiate the lock command, the receiving occurring before operating the process control switch in the locked state.

15. 15. The method of claim 7, further comprising receiving, by the process control switch, a lock command transmitted to the process control switch in response to a device detecting a security threat on a network to which the process control switch is connected, the receiving occurring before operating the process control switch in the locked state.

16. 1. A method of locking a process control switch, comprising: detecting, by the process control switch, the initiation of a lockdown of the process control switch; the process control switch detecting a second switch connected to a port of the process control switch; the process control switch detecting whether the second switch is lockable; In response to the process control switch detecting that the second switch is not lockable, (i) receiving from the second switch a set of addresses for a set of known devices that communicated through the second switch; and (ii) changing the process control switch to a locked state in which the port is locked so that traffic on the port is limited to messages received from or addressed to addresses included in the set of addresses received from the second switch. In response to the process control switch detecting that the second switch is lockable, changing the process control switch to a locked state in which the port is unlocked; A method comprising:

Citation Information

Patent Citations

  • Network, relay transmission apparatus, switch apparatus, and optical signal control method employed for them

    JP2005110068A

  • Method and apparatus for secure communication of process control data

    JP2010081610A

  • Communication device

    JP2017046149A

  • Synchronous change of switchplane

    US7054263B1

  • Automatic switching of setting associated with network

    WO2005029783A1