Uni-Directional Equipment Data Transfer With Secure Rule Updates
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Industrial systems face risks such as unauthorized data transmission, system malfunction, and misuse due to the separation of data collection and processing, particularly in cloud-driven analytics, where data pre-processing can lose efficiency if data is missing and modifying filtering or addressing rules is complicated.
Innovation Solution
Implementing a system with uni-directional interfaces and data diodes to securely transmit data from industrial systems to analytics systems, allowing pre-defined rule modifications through a separate control channel with limited instruction size to prevent unauthorized changes and ensure secure data flow.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If data is transmitted from industrial system to analytics systems through uni-directional interfaces, then data security and system stability are improved, but data pre-processing efficiency deteriorates due to missing data and inability to modify filtering rules
Solution Approach 1:
The system segments data transmission into two separate uni-directional channels: one for data flow (industrial system to analytics system) and another for control instructions (analytics system to industrial system). This segmentation allows secure data transmission while enabling rule modifications through the control channel, resolving the contradiction between security and efficiency.
Solution Approach 2:
The patent introduces an intermediary control mechanism that allows the analytics system to send instruction packets to modify filtering rules in the data collection server. This intermediary control channel enables dynamic rule adjustment without compromising the security of the main data transmission path, thus maintaining both security and processing efficiency.
2Reliability
If data is transmitted partially to different analytics systems according to particular purposes, then data security risks are mitigated, but system complexity increases due to multiple filtering and addressing rules
Solution Approach 1:
The system employs dynamic filtering rules that can be modified at runtime through instruction packets sent from the analytics system. Instead of static complex rule sets, the rules adapt dynamically based on instructional commands, reducing the inherent complexity while maintaining security through purpose-specific data transmission.
Solution Approach 2:
The patent changes the parameters of data transmission by using configurable filtering criteria that can be adjusted through control instructions. By modifying transmission parameters (which data to send, where to send it) dynamically, the system achieves secure purpose-specific transmission without permanent complex rule configurations.
3Productivity
If control instructions are received to modify filtering rules, then data pre-processing efficiency is improved, but unauthorized access risks increase
Solution Approach 1:
The system implements preliminary authentication and validation mechanisms for control instructions before applying rule modifications. By预先 verifying the legitimacy of instruction packets, the system enables efficient rule modifications while preventing unauthorized access, thus resolving the contradiction between productivity improvement and security risk.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A computer system (110) provides a rule-based communication of equipment data (105) from an industrial system (101) to an analysis system (120). The computer system (110) transmits equipment data (105) through a first uni-directional interface (150) in a first data direction, but receives rule modifications (115) through a second uni-directional interface (136). The first interface (150) can be implemented with a data diode (151), and the second interface (136) can be implemented by an air-gap for interaction with a mobile data carrier (132). The mobile data carrier (132) provides instructions that allow the modification of the rules.