Deterministic Network Switch Packet Classification for ICS Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Industrial control systems face challenges in securing communications within deterministic networks, where malicious or invalid communication packets can disrupt the precise delivery of control commands, potentially leading to adverse consequences such as system damage or inefficiencies.

Innovation Solution

A network switch is configured to enforce protocol constraints and use process behavioral models to classify communication packets, selectively routing them and generating control actions based on classifications to ensure valid and secure communication, thereby preventing malicious packets from causing harm.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If network switches route all communication packets without classification, then network throughput and speed are maintained, but malicious or invalid packets can disrupt system operation and cause adverse consequences

Engineering Contradiction:
Improvesystem operation securityVSAvoidpacket classification system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by classifying communication packets into different priority levels before routing them. The network switch examines packet headers and assigns priority classifications (e.g., high, medium, low) based on predetermined criteria such as protocol type, source/destination addresses, or application requirements. This pre-classification enables deterministic routing where high-priority packets are forwarded first, ensuring critical control commands receive bounded delivery time while maintaining overall network throughput without requiring complex real-time analysis of every packet.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent segments the network traffic flow into multiple priority queues based on packet classification. Instead of treating all packets uniformly, the switch divides the communication stream into distinct segments (priority levels) that are handled separately through different routing paths or scheduling mechanisms. This segmentation allows the system to provide deterministic service to time-critical packets while still processing best-effort traffic, thereby improving reliability without requiring complete reconfiguration of the entire network infrastructure.

Inventive Principle:
Principle #1Segmentation

2Loss of time

If network switches enforce strict deterministic routing for all packets, then delivery time is bounded and predictable, but network flexibility and adaptability to different traffic types are reduced

Engineering Contradiction:
Improvepacket delivery time variabilityVSAvoidnetwork protocol support
Core Design Contradiction:
Loss of timeVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamics by making the routing behavior adaptive based on packet characteristics. The network switch dynamically selects routing paths and priority levels according to the specific requirements of each packet or packet class. For example, time-sensitive control commands receive deterministic low-latency paths, while less critical data traffic uses more flexible routing options. This dynamic approach allows the same network infrastructure to provide bounded delivery time for critical packets while maintaining adaptability to support diverse industrial protocols and traffic types simultaneously.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent applies local quality by providing different quality of service characteristics to different packets based on their specific requirements. Instead of enforcing uniform deterministic routing on all traffic, the switch applies deterministic guarantees only to packets that require them (identified through classification), while allowing more flexible handling for packets that can tolerate variable latency. This localized application of strict routing rules maintains time predictability for critical communications while preserving network versatility for supporting multiple protocol types and traffic patterns.

Inventive Principle:
Principle #3Local quality

3Measurement precision

If network switches perform deep packet inspection and classification, then packet routing accuracy and security are improved, but processing speed and network throughput are reduced

Engineering Contradiction:
Improvepacket classification accuracyVSAvoidnetwork throughput
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The patent extracts only the essential classification information needed for deterministic routing from the full packet data. Instead of performing deep inspection of entire packets, the switch focuses on examining specific header fields and key characteristics that determine packet priority and routing requirements. This extraction approach achieves sufficient classification accuracy for industrial control applications by identifying packet type, source, and destination information without analyzing the complete packet payload, thereby maintaining high processing speed and network throughput while still enabling accurate routing decisions.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent applies partial action by performing classification and inspection only to the extent necessary for deterministic routing decisions. The network switch implements selective deep packet inspection that focuses on critical fields required for protocol compliance and priority determination, rather than examining every byte of every packet. This partial inspection approach provides sufficient accuracy for routing precision while minimizing the processing overhead that would otherwise reduce network throughput, allowing the system to maintain both high-speed operation and accurate packet classification for time-critical communications.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentEP3518478B1Configurable network switch for industrial control systems including deterministic networks
Publication Date: 2022.12.14 GE AVIATION SYST LTD
  • EP3518478B1 patent drawingFigure 1
  • EP3518478B1 patent drawingFigure 2
  • EP3518478B1 patent drawingFigure 3

AI summary

A network switch 350 includes a first port 352 configured for communication with a first electric device and a second port 353 configured for communication with a second electric device in a deterministic network. The network switch includes one or more processors configured to receive at the first port a communication packet 355 associated with the first electric device and the second electric device, determine if the communication packet 355 satisfies a plurality of protocol constraints 364, and in response to the communication packet satisfying the plurality of protocol constraints 364, input one or more message characteristics from the communication packet 355 into a model 368 associated with a first industrial process. The model 368 is configured to output a process behavioral classification based on the one or more message characteristics. The one or more processors receive a process behavioral classification for the communication packet, and selectively generate a control action 372 for the ICS based on the process behavioral classification.