Bus Security Monitoring Architecture for Authorized Control Data
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing control systems lack secure communication architecture, making them vulnerable to data hacking and unauthorized operations, as electronic devices are directly connected to buses without adequate security measures.
Innovation Solution
Implementing a control system with security monitoring managers between electronic devices and the bus, which snoops data based on predetermined protocols and authority management rules, and a central security manager to configure these protocols and rules, ensuring secure data transmission by allowing or blocking data based on compliance with set criteria.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If electronic devices are directly connected to the bus for data exchange, then communication efficiency is improved, but system security deteriorates due to vulnerability to hacking and unauthorized operations
Solution Approach 1:
The patent introduces a security monitoring manager as an intermediary component between electronic devices and the bus. This mediator intercepts and monitors all data transmissions, checking them against predetermined authority management rules before allowing passage. The security monitoring manager thus enables direct communication to continue while adding a security layer that prevents unauthorized operations and hacking attempts.
2Reliability
If security monitoring managers are introduced between electronic devices and the bus, then system security is improved, but device complexity increases due to additional components
Solution Approach 1:
The security monitoring manager is designed as a universal component that can be deployed between any electronic device and the bus, handling security for multiple devices through a single standardized interface. The central security manager further enhances this by centrally configuring authority management rules for all security monitoring managers, reducing individual device complexity while maintaining comprehensive security coverage across the entire system.
3Reliability
If data transmission is selectively allowed or blocked based on authority management rules, then unauthorized operations are prevented, but communication speed deteriorates due to additional verification steps
Solution Approach 1:
The system performs preliminary actions by pre-configuring authority management rules in the security monitoring managers before runtime. These rules define which devices can access which resources and under what conditions. During actual data transmission, the security monitoring managers simply check against these pre-established rules rather than performing complex real-time analysis, significantly reducing verification time while maintaining strict access control security.
Data Source
AI summary
The present application relates to a control system with a security management device. The control system comprises: a bus; one or more electronic devices coupled to the bus to transmit data with the bus through respective communication protocols; one or more security monitoring managers each coupled between an electronic device and the bus, wherein each of the security monitoring managers is configured to snoop data transmitted between the electronic device and the bus based on a predetermined transmission protocol, determine whether the data conforms to a predetermined authority management rule to generate a determination result, and selectively allow the data to be transmitted to the bus or the electronic device according to the determination result, and wherein the predetermined transmission protocol correspond to the communication protocol of the electronic device; and a central security manager coupled to the security monitoring managers, wherein the central security manager is configured to configure the predetermined transmission protocol and the predetermined authority management rule used by each of the security monitoring managers.


