Cloud Access Broker for IT/OT Domain Isolation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The integration of IT/OT domains with public clouds poses security challenges, including malicious attacks and data breaches, due to the need for secure communication and isolation between these domains and the cloud environment.
Innovation Solution
The implementation of fognodes with foglets hosting virtual machines and switches, along with a forwarder service, provides secure domain-to-domain messaging and one-way data publishing to the cloud, ensuring isolation and preventing malicious attacks by using a trusted platform module (TPM) for secure booting and encryption, and virtualization for device application isolation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If IT/OT domains are integrated with public cloud for data publishing, then data accessibility and cloud services are improved, but security risks and vulnerability to malicious attacks increase
Solution Approach 1:
A cloud access broker is introduced as an intermediary component that sits between the IT/OT domains and the public cloud. The broker enforces security policies, filters data publications, and manages cloud connections, thereby enabling data accessibility while mitigating security risks by preventing direct exposure of domain devices to the cloud environment
Solution Approach 2:
The system segments the network into isolated IT and OT domains with strict boundary controls. Each domain is separated and managed independently, with the cloud integration occurring only through controlled interfaces. This segmentation prevents attacks from spreading across domains while maintaining cloud connectivity for data publishing
2Reliability
If domain isolation is enforced between IT and OT domains, then security and protection are improved, but communication flexibility and data sharing between domains are reduced
Solution Approach 1:
The cloud access broker serves as a mediator that enables controlled communication between isolated IT and OT domains. It provides a secure interface for data exchange without breaking domain isolation, allowing flexible data sharing while maintaining security boundaries through policy enforcement and filtered communication channels
3Productivity
If cloud services are allowed to publish data from IT/OT domains, then data publishing capability is improved, but vulnerability to cloud-originated attacks and data breaches increases
Solution Approach 1:
The cloud access broker implements preliminary security measures by pre-configuring security policies, authentication mechanisms, and data filtering rules before cloud publication occurs. It proactively blocks malicious content and unauthorized access attempts, preventing cloud-originated attacks before they can reach IT/OT domains while maintaining data publishing functionality
Data Source
AI summary
Enterprise grade security for integrating multiple computing domains with a public cloud is provided herein. An example system a forwarder that provides one-way data publishing to a public cloud and a data bus that provides domain-to-domain messaging between a plurality of domains. At least one of the plurality of domains includes operational technology infrastructure devices and operational technology virtual machines. The operational technology virtual machines are communicatively coupled to the operational technology infrastructure devices using one or more operational technology switches. The operational technology switches isolates the operational technology infrastructure devices and facilitates one-way communication and prevents bidirectional communication to the operational technology infrastructure devices from the public cloud.


