Decapsulating Firewall for Industrial Control Network Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Industrial control systems face security issues due to the transparency of Ethernet routing mechanisms, which allow unauthorized access to non-IP network devices, even when conventional IT firewalls are in place, as embedded non-IP protocols can bypass these firewalls.
Innovation Solution
Implementing decapsulating firewalls that intercept and analyze data packets to identify the ultimate destination device and apply access control rules, ensuring that only authorized devices can access restricted resources by decapsulating embedded routing information and comparing it with access control information stored in a database.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional IT firewalls are used to protect industrial control systems, then basic network security is provided, but embedded non-IP protocols can bypass these firewalls and access non-IP network devices unauthorized
Solution Approach 1:
The patent introduces a decapsulating firewall as an intermediary device positioned between the IP network and non-IP network devices. This firewall intercepts IP packets, decapsulates embedded non-IP protocols, and applies access control rules to the extracted non-IP packets before forwarding them to destination devices. This intermediary mechanism prevents unauthorized access by blocking malicious packets that would otherwise bypass conventional firewalls through embedded protocol encapsulation.
2Ease of operation
If Ethernet routing mechanisms are made transparent to facilitate communication, then network connectivity is improved, but security control over non-IP network devices is compromised
Solution Approach 1:
The patent implements preliminary action by establishing access control rules in advance for each non-IP network device. The decapsulating firewall maintains an access control database that pre-defines which IP sources are authorized to communicate with which non-IP devices. When packets are intercepted, the firewall checks these pre-established rules before allowing communication, thus maintaining security control while enabling transparent Ethernet routing for authorized devices.
3Speed
If embedded routing information is allowed to bypass firewalls for efficient routing, then packet transmission speed is improved, but unauthorized access to destination devices occurs
Solution Approach 1:
The patent applies the extraction principle by removing embedded non-IP packets from their IP packet encapsulation at the decapsulating firewall. The firewall extracts the inner non-IP protocol packets, examines their destination addresses and routing information, and applies access control rules to these extracted packets independently of the outer IP packet. This allows efficient routing to be maintained for authorized communications while blocking unauthorized access attempts through protocol encapsulation.
Data Source
AI summary
Method and apparatus for use with systems including networked resources where communication between resources is via dual packet protocols wherein a first protocol includes a frame that specifies a destination device/resource and a data field and the second protocol specifies a final destination device/resource and includes a data field, where the second packets are encapsulated in the first protocol packet frames, the method including specifying access control information for resources, for each first protocol packet transmitted on the network, intercepting the first protocol packet prior to the first protocol destination resource, examining a subset of the additional embedded packet information to identify one of the intermediate path resources and the final destination resource, identifying the access control information associated with the identified at least one of the intermediate path resources and the final destination resource and restricting transmission of the first protocol packet as a function of the identified access control information.


