Cloud Interface Isolation Using Dual FCUs Against Malware

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems are vulnerable to malware entering from the cloud, which can cause failures in essential functions of technical systems, necessitating malware detection programs and risking system integrity.

Innovation Solution

An interface system with two fault containment units (FCU_1 and FCU_2) is implemented, where FCU_1 prevents data from FCU_2, including malware, from being written into its command registers, and enforces a restrictive data flow using periodic message instances with predefined formats, ensuring only valid data is processed.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If the technical system is connected to the cloud for optimized operation with complex optimization algorithms, then the operational efficiency and financial returns are improved, but the system becomes vulnerable to malware entering from the cloud which can cause failures in essential functions

Engineering Contradiction:
Improveoperational efficiencyVSAvoidsystem integrity
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The interface system is divided into two separate fault containment units (FCU_1 and FCU_2) that are connected via a communication channel. FCU_1 interfaces with the technical system while FCU_2 interfaces with the cloud. This segmentation isolates the technical system from direct cloud connections, allowing optimized operation algorithms to run in the cloud while preventing malware from directly accessing the technical system's command registers.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The fault containment units act as intermediary components between the cloud and the technical system. The communication channel between FCU_1 and FCU_2 serves as a restricted data connection that allows necessary data flow for optimized operation while blocking malicious code. This intermediary structure enables the system to benefit from cloud-based optimization without direct exposure to cloud-based threats.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If malware detection programs are implemented to protect against cloud-based threats, then system security is improved, but the device complexity and computational overhead increase

Engineering Contradiction:
Improvesystem securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system implements preliminary protective measures by configuring FCU_1 with restricted write access to its command registers before any potential malware can enter the system. The fault containment structure and communication channel restrictions are established in advance, creating a preemptive barrier that blocks malware execution before detection is even needed. This preliminary action eliminates the need for complex runtime malware detection programs.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If a restrictive data connection is implemented between FCU_1 and FCU_2 to prevent malware transmission, then system security is improved, but the data flow capability and operational flexibility are reduced

Engineering Contradiction:
Improvesystem securityVSAvoiddata flow capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The communication channel between FCU_1 and FCU2 implements local quality restrictions specifically targeted at preventing malware transmission. The restriction applies selectively to write operations to command registers while allowing necessary data flow for optimized operation. This localized restriction maintains data flow capability for legitimate operations while blocking malicious code transmission.

Inventive Principle:
Principle #3Local quality

Data Source

PatentEP4586586A1Interface system for the execution and control of data flow between a cloud and a technical installation
Publication Date: 2025.07.16 TTTECH COMPUTERTECHNIK AG
  • EP4586586A1 patent drawingFigure 1
  • EP4586586A1 patent drawingFigure 2
  • EP4586586A1 patent drawing

AI summary

The invention relates to an interface system arranged between a technical system and the cloud, which prevents malware originating from the cloud or errors in the data supplied by the cloud from leading to a failure of essential functions of the technical system. The interface system comprises two Fault Containment Units (FCUs), FCU_1 and FCU_2, and a restrictive data connection between these two FCUs. A well-defined periodic data flow between the two FCUs is realized via this restrictive data connection. The strict restrictions in the data flow from FCU_2 to FCU_1 make it technically impossible for an intruder to transmit malware from FCU_2 to FCU_1, even if they have taken complete control of FCU_2. This protects FCU_1 and thus the technical system from attacks from the cloud.