DMZ Gateway Architecture for Secure Process Plant Data Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Process control systems in industrial settings face security challenges due to vulnerabilities in external data access, where malware can exploit authorized connections to compromise the control network, and existing security features like firewalls and antivirus software are insufficient against zero-day attacks, potentially leading to destructive consequences.
Innovation Solution
Implementing a secure mechanism within the process control network that includes an external data server connected to a DMZ gateway device, where a configuration engine configures the external data server to provide controlled data access, blocking browse, read, write, and configuration calls from external sources, thereby preventing unauthorized access and reducing the risk of malware exploitation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If external data access is allowed through authorized connections, then data accessibility is improved, but security vulnerability increases allowing malware exploitation
Solution Approach 1:
The patent introduces a gateway device as an intermediary between the process control network and external networks. This gateway acts as a mediator that receives data requests from external sources and forwards them to the process control network, while also serving as a containment point for malware. The gateway's data store holds copies of process data that can be accessed externally without direct network connection, thus enabling data accessibility while preventing direct malware access to the control network.
Solution Approach 2:
The patent segments the system into distinct components: the process control network, the gateway device with its own data store, and external networks. By creating this segmentation, the patent isolates the control network from direct external access while maintaining data accessibility through the gateway's data store. This segmentation ensures that even if malware compromises the gateway, it cannot directly access the process control network.
2Reliability
If firewalls and antivirus software are used, then security protection is improved, but they are insufficient against zero-day attacks
Solution Approach 1:
The patent implements preliminary action by pre-fetching process data and storing it in the gateway's data store before external requests arrive. This pre-positioning of data eliminates the need for the gateway to execute code or establish direct connections to the process control network when handling external requests. Since the data is already available locally, even zero-day malware cannot exploit the gateway to access the control network, as no dynamic code execution or network communication is required.
3Ease of operation
If DMZ gateway is compromised by malware, then external access is maintained, but control system access becomes vulnerable
Solution Approach 1:
The gateway device serves as an intermediary that decouples external access from control system access. Even when compromised, the gateway can only access its own data store containing process data copies, not the control system itself. The intermediary architecture ensures that malware in the gateway cannot pivot to the control network because no direct communication channels exist between them.
Solution Approach 2:
The patent extracts the data access function from the control system and places it in the gateway's data store. By taking out the data and storing it separately in the gateway, the patent removes the vulnerability pathway that would allow malware in the gateway to access the control system. The control system remains isolated while external entities can access the extracted data through the gateway.
Data Source
AI summary
A process control system having an external data server that provides process control data to external networks via one or more firewalls implements a cost-effective security mechanism that reduces or eliminates the ability of the external data server to be compromised by viruses or other security attacks. The security mechanism includes a DMZ gateway disposed outside of the process control network that connects to an external data server located within the process control network. A configuration engine is located within the process control network and configures the external data server to publish one or more preset or pre-established data views to the DMZ gateway, which then receives the data/events/alarms as defined by the data views from the control system automatically, without performing read and write requests to the external data server. The DMZ gateway then republishes the data within the data views on an external network to make the process control data within the published data views available to one or more client applications connected to the external network. Because this security mechanism does not support client read, write, or configuration access to the external data server within the control system, this security mechanism limits the opportunity of viruses to use the structure in the DMZ gateway device to access the process control network.

