Dedicated Cellular Network Control for Secure Industrial ICS

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Industrial control systems (ICS) face inadequate cybersecurity, particularly in ICS-cloud networks, with existing solutions lacking end-to-end encryption and CC-EAL3 protection, leading to vulnerabilities that can result in significant cyber incidents and financial losses.

Innovation Solution

A system for securely deploying software components to control devices in ICS, involving the generation and validation of validation credentials, establishment of secure communication channels using private and public credentials, and implementation of a root of trust, along with blockchain transactions for secure data management and authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If existing cybersecurity solutions are implemented in ICS-cloud networks, then some level of security is provided, but end-to-end encryption and CC-EAL3 protection are lacking, leaving vulnerabilities exposed

Engineering Contradiction:
Improvecybersecurity protection levelVSAvoidcyber vulnerabilities
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the security architecture into multiple independent components: edge devices with local security credentials, blockchain network for decentralized verification, smart contracts for automated security policies, and cloud services. This segmentation allows each component to provide specific security functions (end-to-end encryption, CC-EAL3 validation) without requiring complete system redesign, thereby addressing the vulnerability gap in existing solutions.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a blockchain-based intermediary layer between ICS devices and cloud services. This intermediary implements CC-EAL3 certified security credentials and smart contracts that mediate authentication and data transmission, providing end-to-end encryption protection that neither traditional ICS security nor standard cloud security can achieve alone.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If secure communication channels are established using validation credentials, then data integrity is protected, but communication complexity increases

Engineering Contradiction:
Improvedata integrityVSAvoidcommunication protocol complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements self-service security where edge devices automatically generate and manage their own validation credentials through hardware security modules, and automatically verify credentials through blockchain smart contracts. This eliminates the need for complex manual credential management and reduces communication overhead despite the enhanced security protocols.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The blockchain network serves multiple functions simultaneously: it acts as a decentralized credential verification system, provides timestamping for data integrity, enables smart contract-based security policy enforcement, and offers a distributed ledger for audit trails. This multi-functionality reduces the need for separate systems for each security function, thereby managing complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If blockchain transactions are implemented for secure data management, then cybersecurity protection is enhanced, but system complexity and computational requirements increase

Engineering Contradiction:
Improvecybersecurity protectionVSAvoidsystem architecture complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments blockchain functionality into lightweight smart contracts deployed on the blockchain network, separate from the edge devices and cloud services. Edge devices only need to interact with the blockchain through standardized API calls for credential verification and data hashing, while the complex blockchain consensus and storage operations are handled by dedicated blockchain nodes, reducing overall system complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces gateway services as intermediaries between traditional ICS/cloud systems and the blockchain network. These gateways handle complex blockchain operations (transaction creation, consensus participation, state management) and present simplified interfaces to ICS devices and cloud services, thereby shielding them from blockchain complexity while maintaining enhanced security.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If end-to-end encryption is implemented from ICS to cloud storage, then data security is improved, but communication overhead and processing time increase

Engineering Contradiction:
Improvedata securityVSAvoidcommunication processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements preliminary encryption of data at the edge device before transmission, using validation credentials established through blockchain verification. Data is encrypted end-to-end before leaving the edge device, and decryption occurs only at the destination. This preliminary action eliminates the need for repeated encryption/decryption operations during transmission and intermediate handling, reducing overall processing time despite the enhanced security.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

Edge devices autonomously manage their own encryption keys and credentials through hardware security modules and blockchain verification. This self-service approach eliminates the need for centralized key management servers and complex key distribution protocols, reducing communication overhead and processing time while maintaining strong end-to-end encryption.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP3849217A1Management of a reliable industrial control system via dedicated cellular network
Publication Date: 2021.07.14 MYOMEGA SYST GMBH
  • EP3849217A1 patent drawingFigure 1
  • EP3849217A1 patent drawingFigure 2A
  • EP3849217A1 patent drawingFigure 2B~2C

AI summary

Communicating between components that are part of an IP network and a control device includes coupling the IP network to a dedicated cellular network, the control device communicating directly with network components of the dedicated cellular network, and transferring data between the components and the control device at a quality of service levels that corresponds to a quality of service level provided for voice communications in a non-dedicated cellular network. The IP network may include a cloud having core services that provide control signals to the control device. Quality of service parameters may be prioritized by an ICS management component of the core services of the cloud. The ICS management component may provide cellular network services parameters that are used to control the core services of the cloud and the quality of service parameters. A subset of resources of the dedicated cellular network may be reserved for industrial control systems.