Bastion Host Firewall Access Control for Secure ICS Remote Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Industrial control systems (ICS) face significant security risks due to lack of effective protection measures during remote access, making them vulnerable to unauthorized access, viruses, and network attacks, especially as they transition from closed to open systems and integrate with external networks for maintenance and support.
Innovation Solution
An access control device integrating firewall and bastion host functions, providing a plug-and-play, ease-of-use solution that prevents unauthorized access, determines remotely accessible resources, and configures secure remote access policies, while also monitoring and auditing network traffic to ensure secure remote diagnosis and maintenance.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If OT systems are connected with external systems for remote technical support, then ease of operation is improved, but security vulnerability increases
Solution Approach 1:
The patent introduces a remote access device as an intermediary component between external networks and OT systems. This device includes a firewall that filters and controls incoming remote access requests, allowing legitimate technical support while blocking malicious traffic. The intermediary device enables secure remote maintenance by mediating all communications between external engineers and internal OT equipment, thus resolving the contradiction between accessibility and security.
2Adaptability or versatility
If traditional closed OT systems evolve to open systems for internet connectivity, then adaptability is improved, but reliability deteriorates
Solution Approach 1:
The patent segments the network architecture into distinct zones: an external network zone, a remote access device zone, and an internal OT system zone. The firewall within the remote access device creates a segmentation boundary that allows controlled interaction between zones. This segmentation enables OT systems to gain internet connectivity adaptability while maintaining reliability through architectural isolation and controlled access points.
3Device complexity
If equipment suppliers provide remote technical support, then device complexity is reduced, but security risk increases
Solution Approach 1:
The patent implements preliminary security actions by pre-configuring the firewall with authorized IP addresses and access control policies before remote support is needed. The remote access device is prepared in advance with security rules that automatically validate incoming connections. This preliminary configuration ensures that even though equipment suppliers provide remote support to reduce complexity, unauthorized access risks are prevented through pre-established security measures.
Data Source
Figure 1~2
Figure 3
Figure 4
AI summary
The present invention relates to an access control device and method, which can provide an effective security protection during remote access to a system. The access control device (50) comprises a front-end firewall (501) providing a first network port (51) to connect a remote computer (20), a bastion host (502) connected with said front-end firewall (501), and a back-end firewall (503) connected with said bastion host (502) and providing a second network port (52) to connect said system (10) . Said back-end firewall 503 scans through said second network port (52) the resources which are remotely accessible in said system (10) and determines the resources said computer (20) can remotely access. Said bastion host (502) provides information about the resources said computer can remotely access through said first network port (51). The present invention has the advantages of security, simplicity and plug-and-play.