Blockchain Network Security Server for Industrial Control Integrity

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Industrial control systems are vulnerable to unauthorized access, which can compromise the security of the entire platform if an unauthorized party gains access to the industrial controller, either physically or through a communications network, and existing network security services can be circumvented if compromised.

Innovation Solution

A network security server with a communication port that provides a network security service for client devices, utilizing a blockchain verification process to record security information and offer an integrity attestation service, ensuring secure software verification and protection against unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a network security service is used to verify integrity of software on client devices, then security protection is improved, but the system becomes vulnerable if the network security service itself is compromised

Engineering Contradiction:
Improvesecurity protectionVSAvoidvulnerability to compromise
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces blockchain technology as an intermediary between the network security service and the distributed network nodes. The blockchain ledger serves as a neutral, tamper-proof mediator that records and verifies security information, preventing any single point of failure from compromising the entire security system. This resolves the vulnerability by distributing trust across multiple independent nodes rather than relying on a centralized security service.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the security verification function across multiple distributed network nodes, each maintaining its own copy of the blockchain ledger. This segmentation ensures that compromise of one node does not affect the overall security system, as other nodes can continue to verify integrity independently. The security function is divided into multiple independent verification instances rather than a single centralized service.

Inventive Principle:
Principle #1Segmentation

2Stability of the object's composition

If blockchain verification process is implemented to record security information, then tamper-proof recording is improved, but system complexity increases

Engineering Contradiction:
Improvetamper-proof recordingVSAvoidsystem complexity
Core Design Contradiction:
Stability of the object's compositionVSDevice complexity

Solution Approach 1:

The patent implements a universal blockchain ledger that serves multiple functions: recording security information, verifying integrity, providing tamper-proof storage, and enabling distributed consensus. This multi-functional approach consolidates what would otherwise require separate systems into a single platform, reducing overall system complexity while maintaining tamper-proof recording capabilities.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent uses blockchain technology to create and distribute identical copies of the security information ledger across multiple network nodes. Each node maintains a copy of the entire ledger, ensuring consistency and tamper-proof recording without requiring complex centralized management. The copying mechanism simplifies verification by allowing any node to independently validate security information against the distributed copies.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS10489597B2Blockchain verification of network security service
Publication Date: 2019.11.26 GE DIGITAL HLDG LLC
  • US10489597B2 patent drawing
  • US10489597B2 patent drawing
  • US10489597B2 patent drawing

AI summary

According to some embodiments, a system may include a communication port to exchange information with a client device associated with an industrial control system. A network security server coupled to the communication port may include a computer processor adapted to provide a network security service for the client device. The computer processor may further be adapted to record security information about the client device via a blockchain verification process (e.g., by registering a validation result within a distributed ledger). The network security service might comprise, for example, an integrity attestation service providing software verification for the client device.