Bastion Host Firewall Access Control for Secure ICS Remote Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Industrial control systems (ICS) face significant security risks due to lack of effective protection measures during remote access, making them vulnerable to unauthorized access, viruses, and network attacks, especially as they transition from closed to open systems and integrate with external networks for maintenance and support.

Innovation Solution

An access control device integrating firewall and bastion host functions, providing a plug-and-play, ease-of-use solution that prevents unauthorized access, determines remotely accessible resources, and configures secure remote access policies, while also monitoring and auditing network traffic to ensure secure remote diagnosis and maintenance.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If OT systems are connected with external systems for remote technical support, then ease of operation is improved, but security vulnerability increases

Engineering Contradiction:
Improveremote technical support accessibilityVSAvoidsecurity vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a remote access device as an intermediary component between external networks and OT systems. This device includes a firewall that filters and controls incoming remote access requests, allowing legitimate technical support while blocking malicious traffic. The intermediary device enables secure remote maintenance by mediating all communications between external engineers and internal OT equipment, thus resolving the contradiction between accessibility and security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If traditional closed OT systems evolve to open systems for internet connectivity, then adaptability is improved, but reliability deteriorates

Engineering Contradiction:
Improveinternet connectivity capabilityVSAvoidsystem security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent segments the network architecture into distinct zones: an external network zone, a remote access device zone, and an internal OT system zone. The firewall within the remote access device creates a segmentation boundary that allows controlled interaction between zones. This segmentation enables OT systems to gain internet connectivity adaptability while maintaining reliability through architectural isolation and controlled access points.

Inventive Principle:
Principle #1Segmentation

3Device complexity

If equipment suppliers provide remote technical support, then device complexity is reduced, but security risk increases

Engineering Contradiction:
Improveon-site support requirementVSAvoidunauthorized access risk
Core Design Contradiction:
Device complexityVSObject-affected harmful factors

Solution Approach 1:

The patent implements preliminary security actions by pre-configuring the firewall with authorized IP addresses and access control policies before remote support is needed. The remote access device is prepared in advance with security rules that automatically validate incoming connections. This preliminary configuration ensures that even though equipment suppliers provide remote support to reduce complexity, unauthorized access risks are prevented through pre-established security measures.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP3588908B1An access control device, an access control method, a computer program product and a computer readable medium
Publication Date: 2021.12.29 SIEMENS AG
  • EP3588908B1 patent drawingFigure 1~2
  • EP3588908B1 patent drawingFigure 3
  • EP3588908B1 patent drawingFigure 4

AI summary

The present invention relates to an access control device and method, which can provide an effective security protection during remote access to a system. The access control device (50) comprises a front-end firewall (501) providing a first network port (51) to connect a remote computer (20), a bastion host (502) connected with said front-end firewall (501), and a back-end firewall (503) connected with said bastion host (502) and providing a second network port (52) to connect said system (10) . Said back-end firewall 503 scans through said second network port (52) the resources which are remotely accessible in said system (10) and determines the resources said computer (20) can remotely access. Said bastion host (502) provides information about the resources said computer can remotely access through said first network port (51). The present invention has the advantages of security, simplicity and plug-and-play.