Cloud Access Broker for IT/OT Domain Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The integration of IT/OT domains with public clouds poses security challenges, including malicious attacks and data breaches, due to the need for secure communication and isolation between these domains and the cloud environment.

Innovation Solution

The implementation of fognodes with foglets hosting virtual machines and switches, along with a forwarder service, provides secure domain-to-domain messaging and one-way data publishing to the cloud, ensuring isolation and preventing malicious attacks by using a trusted platform module (TPM) for secure booting and encryption, and virtualization for device application isolation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If IT/OT domains are integrated with public cloud for data publishing, then data accessibility and cloud services are improved, but security risks and vulnerability to malicious attacks increase

Engineering Contradiction:
Improvedata accessibilityVSAvoidsecurity risks
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

A cloud access broker is introduced as an intermediary component that sits between the IT/OT domains and the public cloud. The broker enforces security policies, filters data publications, and manages cloud connections, thereby enabling data accessibility while mitigating security risks by preventing direct exposure of domain devices to the cloud environment

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system segments the network into isolated IT and OT domains with strict boundary controls. Each domain is separated and managed independently, with the cloud integration occurring only through controlled interfaces. This segmentation prevents attacks from spreading across domains while maintaining cloud connectivity for data publishing

Inventive Principle:
Principle #1Segmentation

2Reliability

If domain isolation is enforced between IT and OT domains, then security and protection are improved, but communication flexibility and data sharing between domains are reduced

Engineering Contradiction:
ImprovesecurityVSAvoidcommunication flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The cloud access broker serves as a mediator that enables controlled communication between isolated IT and OT domains. It provides a secure interface for data exchange without breaking domain isolation, allowing flexible data sharing while maintaining security boundaries through policy enforcement and filtered communication channels

Inventive Principle:
Principle #24Intermediary (Mediator)

3Productivity

If cloud services are allowed to publish data from IT/OT domains, then data publishing capability is improved, but vulnerability to cloud-originated attacks and data breaches increases

Engineering Contradiction:
Improvedata publishing capabilityVSAvoidmalicious attacks
Core Design Contradiction:
ProductivityVSObject-generated harmful factors

Solution Approach 1:

The cloud access broker implements preliminary security measures by pre-configuring security policies, authentication mechanisms, and data filtering rules before cloud publication occurs. It proactively blocks malicious content and unauthorized access attempts, preventing cloud-originated attacks before they can reach IT/OT domains while maintaining data publishing functionality

Inventive Principle:
Principle #9Preliminary anti-action

Data Source

PatentUS10798063B2Enterprise grade security for integrating multiple domains with a public cloud
Publication Date: 2020.10.06 TTTECH COMPUTERTECHNIK AG
  • US10798063B2 patent drawing
  • US10798063B2 patent drawing
  • US10798063B2 patent drawing

AI summary

Enterprise grade security for integrating multiple computing domains with a public cloud is provided herein. An example system a forwarder that provides one-way data publishing to a public cloud and a data bus that provides domain-to-domain messaging between a plurality of domains. At least one of the plurality of domains includes operational technology infrastructure devices and operational technology virtual machines. The operational technology virtual machines are communicatively coupled to the operational technology infrastructure devices using one or more operational technology switches. The operational technology switches isolates the operational technology infrastructure devices and facilitates one-way communication and prevents bidirectional communication to the operational technology infrastructure devices from the public cloud.