Bastion Host Access Control Device for OT Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Industrial control systems (ICS) face significant security risks due to the lack of effective protection measures during remote access, particularly in OT systems, which can lead to unauthorized access, virus infections, and man-in-the-middle attacks, compromising network security.

Innovation Solution

An access control device and method that integrates a front-end firewall, a bastion host, and a back-end firewall to provide secure remote access by determining and controlling remotely accessible resources based on preconfigured policies, ensuring secure communication and authentication, and utilizing a management module for policy configuration and auditing.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If remote access is enabled for technical support, then equipment maintenance efficiency is improved, but security risks increase

Engineering Contradiction:
Improveequipment maintenance efficiencyVSAvoidsecurity risks
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an access control device as an intermediary component between the external computer and the OT system. This device includes a front-end firewall for initial access control, a bastion host for authenticated access, and a back-end firewall for resource-level access control. The intermediary structure allows remote technical support while preventing direct exposure of critical OT systems to external networks, thus enabling maintenance efficiency while mitigating security risks.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The access control device segments the network into distinct security zones: an external network zone, a demilitarized zone with firewalls, and an internal OT system zone. By dividing the network into separate segments with controlled communication paths, the system enables remote access functionality while isolating critical systems from potential threats, resolving the contradiction between maintenance accessibility and security protection.

Inventive Principle:
Principle #1Segmentation

2Reliability

If multiple firewalls and bastion hosts are deployed, then access security is improved, but device complexity increases

Engineering Contradiction:
Improveaccess securityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the functions of multiple security components (front-end firewall, bastion host, back-end firewall) into a single integrated access control device. This consolidation combines access control, authentication, and resource management functionalities in one device, reducing the physical and configuration complexity that would otherwise result from deploying separate security components while maintaining multi-layer security effectiveness.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The access control device is designed as a universal platform that performs multiple functions: the front-end firewall handles network-level access control, the bastion host provides authenticated user access, and the back-end firewall manages resource-specific access policies. This multi-functional design eliminates the need for separate dedicated devices for each security function, reducing overall system complexity while enhancing comprehensive access security.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11483285B2Access control device, an access control method, a computer program product and a computer readable medium
Publication Date: 2022.10.25 SIEMENS AG
  • US11483285B2 patent drawing
  • US11483285B2 patent drawing
  • US11483285B2 patent drawing

AI summary

An access control device provides a secure access control mechanism for a system being remotely accessed. An embodiment of the access control device includes a front-end firewall to provide a first network port to connect a computer to remotely access the system; a bastion host connected with the front-end firewall; and a back-end firewall, connected with the bastion host, to provide a second network port to connect the system. The back-end firewall determines remotely accessible resources in the system and determines resources remotely accessible by the computer, among the remotely accessible resources in the system, according to remote access control policies. The bastion host provides the computer with information provided by the back-end firewall about the resources remotely accessible by the computer through the first network port of the front-end firewall, to permit the resources to be remotely accessible by the computer. Advantages may include security, simplicity and plug-and-play.