Cloud Interface Isolation Using Dual FCUs Against Malware
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing systems are vulnerable to malware entering from the cloud, which can cause failures in essential functions of technical systems, necessitating malware detection programs and risking system integrity.
Innovation Solution
An interface system with two fault containment units (FCU_1 and FCU_2) is implemented, where FCU_1 prevents data from FCU_2, including malware, from being written into its command registers, and enforces a restrictive data flow using periodic message instances with predefined formats, ensuring only valid data is processed.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If the technical system is connected to the cloud for optimized operation with complex optimization algorithms, then the operational efficiency and financial returns are improved, but the system becomes vulnerable to malware entering from the cloud which can cause failures in essential functions
Solution Approach 1:
The interface system is divided into two separate fault containment units (FCU_1 and FCU_2) that are connected via a communication channel. FCU_1 interfaces with the technical system while FCU_2 interfaces with the cloud. This segmentation isolates the technical system from direct cloud connections, allowing optimized operation algorithms to run in the cloud while preventing malware from directly accessing the technical system's command registers.
Solution Approach 2:
The fault containment units act as intermediary components between the cloud and the technical system. The communication channel between FCU_1 and FCU_2 serves as a restricted data connection that allows necessary data flow for optimized operation while blocking malicious code. This intermediary structure enables the system to benefit from cloud-based optimization without direct exposure to cloud-based threats.
2Reliability
If malware detection programs are implemented to protect against cloud-based threats, then system security is improved, but the device complexity and computational overhead increase
Solution Approach 1:
The system implements preliminary protective measures by configuring FCU_1 with restricted write access to its command registers before any potential malware can enter the system. The fault containment structure and communication channel restrictions are established in advance, creating a preemptive barrier that blocks malware execution before detection is even needed. This preliminary action eliminates the need for complex runtime malware detection programs.
3Reliability
If a restrictive data connection is implemented between FCU_1 and FCU_2 to prevent malware transmission, then system security is improved, but the data flow capability and operational flexibility are reduced
Solution Approach 1:
The communication channel between FCU_1 and FCU2 implements local quality restrictions specifically targeted at preventing malware transmission. The restriction applies selectively to write operations to command registers while allowing necessary data flow for optimized operation. This localized restriction maintains data flow capability for legitimate operations while blocking malicious code transmission.
Data Source
Figure 1
Figure 2
AI summary
The invention relates to an interface system arranged between a technical system and the cloud, which prevents malware originating from the cloud or errors in the data supplied by the cloud from leading to a failure of essential functions of the technical system. The interface system comprises two Fault Containment Units (FCUs), FCU_1 and FCU_2, and a restrictive data connection between these two FCUs. A well-defined periodic data flow between the two FCUs is realized via this restrictive data connection. The strict restrictions in the data flow from FCU_2 to FCU_1 make it technically impossible for an intruder to transmit malware from FCU_2 to FCU_1, even if they have taken complete control of FCU_2. This protects FCU_1 and thus the technical system from attacks from the cloud.