Data Diode Publishing for Secure Process Control Communications

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Securing communications between process control systems and remote systems is challenging due to the risk of cyber intrusions and malicious attacks, especially when process plants are connected to external networks, which can lead to equipment damage, product loss, and even human safety risks.

Innovation Solution

Implementing a data diode that prevents two-way communications between the field gateway and the edge gateway, allowing only unidirectional data flow from the process plant to the remote system, while using encryption and secure protocols like HART-IP and JSON formats to secure data transmission across the diode.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If two-way communications are implemented between process control systems and remote systems, then data accessibility and system functionality are improved, but security risks and vulnerability to cyber attacks increase

Engineering Contradiction:
Improvedata accessibilityVSAvoidsecurity risks
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The communication system is segmented into unidirectional data diodes that separate the process control network from external networks, allowing data to flow only in one direction (from process control to external systems) thereby maintaining accessibility while eliminating the risk of external attacks penetrating into the control system

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A data diode acts as an intermediary device between the process control system and external systems, enabling secure data transmission by physically preventing any data flow from external systems back into the control network, thus resolving the contradiction between accessibility and security

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If data is transmitted unidirectionally through a data diode, then security and data integrity are improved, but communication flexibility and system responsiveness deteriorate

Engineering Contradiction:
Improvedata integrityVSAvoidcommunication flexibility
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

All necessary data is collected, processed, and transmitted through the data diode before any external system needs it, eliminating the need for bidirectional communication while maintaining system responsiveness through advance data preparation and buffering

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The data diode creates accurate copies of process control data for external systems without allowing external systems to access or modify the original data, maintaining data integrity while providing flexible access to data copies for multiple external consumers

Inventive Principle:
Principle #26Copying

3Reliability

If encryption and secure protocols are implemented for data transmission, then security and confidentiality are improved, but system complexity and processing overhead increase

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Security functions including encryption, authentication, and protocol handling are extracted from the process control system and implemented in dedicated security devices and gateways, reducing complexity within the control system while maintaining robust security through specialized security infrastructure

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS11700232B2Publishing data across a data diode for secured process control communications
Publication Date: 2023.07.11 FISHER ROSEMOUNT SYST INC
  • US11700232B2 patent drawing
  • US11700232B2 patent drawing
  • US11700232B2 patent drawing

AI summary

To secure communications from a process plant across a unidirectional data diode to a remote system, a sending device at the plant end publishes data across the diode to a receiving device at the remote end. The publication of various data is respectively in accordance with context information (e.g., identification of data sources, respective expected rate of data generation/arrival, etc.) that is descriptive of data sources of the plant and that is recurrently provided by the sending device across the diode. A recurrence interval may be based on a tolerance for lost data or another characteristic of an application, service, or consumer of data at the remote system. The publishing may leverage an industrial communication protocol (e.g., HART-IP) and/or a suitable general-purpose communication protocol (e.g., JSON).