Cloud Interface Segmentation for Malware-Safe Technical Systems
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing systems are vulnerable to malware entering a technical system from the cloud, which can cause malfunction or failure of essential functions.
Innovation Solution
An interface system with two fault containment units (FCU_1 and FCU_2) is implemented, where FCU_1 prevents data from FCU_2 or the cloud from being written to its command registers, and a restrictive data flow is established using a periodic sequence of message instances with verified formats to ensure secure communication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If a direct data connection is established between the cloud and the technical system to enable optimized operation with complex algorithms, then the system can achieve better operational optimization and financial return, but the system becomes vulnerable to malware entering from the cloud and causing malfunction or failure of essential functions
Solution Approach 1:
The interface system is divided into two separate fault containment units (FCU_1 and FCU_2) that are connected via a communication channel. FCU_1 interfaces with the technical system while FCU_2 interfaces with the cloud. This segmentation allows data flow from the cloud to be restricted and prevents malware from directly reaching the technical system, while still enabling optimized operation through controlled data exchange.
Solution Approach 2:
FCU_1 acts as an intermediary between the cloud (via FCU_2) and the technical system. It receives data from FCU2 through a communication channel and processes this data without allowing direct writing to command registers that could execute malware. This intermediary structure enables the system to benefit from cloud-based optimization algorithms while maintaining security against malicious code.
2Reliability
If malware detection programs are implemented on FCU1 to protect against malware from the cloud, then system security can be improved, but the complexity of the system increases and performance overhead is introduced
Solution Approach 1:
Instead of implementing malware detection programs that react to threats, the system applies preliminary anti-action by configuring FCU1 with a restrictive data connection that prevents malware from being written to command registers in the first place. The configuration inherently blocks malicious code execution pathways, eliminating the need for additional detection software and reducing system complexity.
Solution Approach 2:
FCU1 provides self-protection through its inherent configuration restrictions. The unit is designed to not write received data to its command registers, making it inherently resistant to malware execution without requiring external protection mechanisms. This self-service approach to security simplifies the overall system architecture.
Data Source
AI summary
The invention relates to an interface system, which is arranged between a technical system and the cloud and which prevents malware originating from the cloud or errors in the data delivered by the cloud from causing essential functions of the technical system to fail. The interface system comprises two fault containment units (FCUs), FCU_1 and FCU_2, and a restrictive data connection between these two FCUs. Using this restrictive data connection, a well-defined periodic data flow is realized between the two FCUs. The stringent restrictions in the data flow from FCU_2 to FCU_1 make it technically impossible for an intruder to transmit malware from FCU_2 to FCU_1 even if they have assumed complete control over FCU_2. This provides protection of the FCU_1 and, therefore, the technical system from attacks from the cloud.

