Decapsulating Firewall for Industrial Control Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Industrial control systems face security issues due to the transparency of Ethernet routing mechanisms, which allow unauthorized access to non-IP network devices, even when conventional IT firewalls are in place, as embedded non-IP protocols can bypass these firewalls.

Innovation Solution

Implementing decapsulating firewalls that intercept and analyze data packets to identify the ultimate destination device and apply access control rules, ensuring that only authorized devices can access restricted resources by decapsulating embedded routing information and comparing it with access control information stored in a database.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional IT firewalls are used to protect industrial control systems, then basic network security is provided, but embedded non-IP protocols can bypass these firewalls and access non-IP network devices unauthorized

Engineering Contradiction:
Improvenetwork securityVSAvoidunauthorized access
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a decapsulating firewall as an intermediary device positioned between the IP network and non-IP network devices. This firewall intercepts IP packets, decapsulates embedded non-IP protocols, and applies access control rules to the extracted non-IP packets before forwarding them to destination devices. This intermediary mechanism prevents unauthorized access by blocking malicious packets that would otherwise bypass conventional firewalls through embedded protocol encapsulation.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If Ethernet routing mechanisms are made transparent to facilitate communication, then network connectivity is improved, but security control over non-IP network devices is compromised

Engineering Contradiction:
Improvenetwork connectivityVSAvoidaccess control
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements preliminary action by establishing access control rules in advance for each non-IP network device. The decapsulating firewall maintains an access control database that pre-defines which IP sources are authorized to communicate with which non-IP devices. When packets are intercepted, the firewall checks these pre-established rules before allowing communication, thus maintaining security control while enabling transparent Ethernet routing for authorized devices.

Inventive Principle:
Principle #10Preliminary action

3Speed

If embedded routing information is allowed to bypass firewalls for efficient routing, then packet transmission speed is improved, but unauthorized access to destination devices occurs

Engineering Contradiction:
Improvepacket transmission speedVSAvoidunauthorized access
Core Design Contradiction:
SpeedVSObject-affected harmful factors

Solution Approach 1:

The patent applies the extraction principle by removing embedded non-IP packets from their IP packet encapsulation at the decapsulating firewall. The firewall extracts the inner non-IP protocol packets, examines their destination addresses and routing information, and applies access control rules to these extracted packets independently of the outer IP packet. This allows efficient routing to be maintained for authorized communications while blocking unauthorized access attempts through protocol encapsulation.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS8774186B2Firewall method and apparatus for industrial systems
Publication Date: 2014.07.08 ROCKWELL AUTOMATION TECH INC
  • US8774186B2 patent drawing
  • US8774186B2 patent drawing
  • US8774186B2 patent drawing

AI summary

Method and apparatus for use with systems including networked resources where communication between resources is via dual packet protocols wherein a first protocol includes a frame that specifies a destination device/resource and a data field and the second protocol specifies a final destination device/resource and includes a data field, where the second packets are encapsulated in the first protocol packet frames, the method including specifying access control information for resources, for each first protocol packet transmitted on the network, intercepting the first protocol packet prior to the first protocol destination resource, examining a subset of the additional embedded packet information to identify one of the intermediate path resources and the final destination resource, identifying the access control information associated with the identified at least one of the intermediate path resources and the final destination resource and restricting transmission of the first protocol packet as a function of the identified access control information.