DMZ Proxy Server Whitelist Automation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Industrial control systems face challenges in securely updating configurations of secure proxies in DMZs to access cloud-based systems like AVEVA Wonderware Online Cloud, balancing security with the need for information flow without exposing systems to new attack vectors.

Innovation Solution

A server system with a demilitarized zone proxy server system that digitally signs configurations using specific certificates, allowing secure data transfer connections and automatically updating a whitelist of necessary sites to prevent unauthorized access and tampering, thereby reducing manual updates and system downtime.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a DMZ proxy server is used to allow information flow from control systems to cloud-based systems, then access to valuable business information is enabled, but security protection is reduced due to increased exposure to attack vectors

Engineering Contradiction:
Improveaccess to business informationVSAvoidexposure to attack vectors
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent employs a DMZ proxy server as an intermediary component positioned between the internal control system network and external cloud-based systems. This proxy server mediates all communications, allowing authorized information flow while maintaining a security buffer that prevents direct exposure of internal systems to external attack vectors. The intermediary enables the beneficial access function while isolating the harmful security risks.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If manual configuration updates are performed on proxy servers, then configuration accuracy is maintained, but system downtime increases and productivity decreases

Engineering Contradiction:
Improveconfiguration accuracyVSAvoidsystem downtime
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements a configuration management system that prepares and stages configuration updates in advance. The system maintains an updated configuration database and can push changes to proxy servers during scheduled maintenance windows or low-activity periods. This preliminary preparation of configuration data allows for rapid deployment without requiring lengthy manual update processes, thereby maintaining accuracy while minimizing downtime.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system enables automated self-service configuration updates where the configuration management server automatically pushes updated configurations to proxy servers without requiring manual intervention on the proxy systems themselves. The proxy servers automatically apply the pushed configurations, eliminating the need for operators to manually log in and update each server individually, thus reducing downtime and increasing productivity while maintaining reliability.

Inventive Principle:
Principle #25Self-service

3Object-affected harmful factors

If security measures are strengthened to prevent unauthorized access, then protection against malware and viruses is improved, but ease of operation for legitimate access is reduced

Engineering Contradiction:
Improveprotection against malwareVSAvoidease of access
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The patent implements a feedback mechanism where the configuration management system continuously monitors proxy server configurations and communication patterns. The system receives feedback about legitimate access requirements and automatically adjusts configuration policies to maintain security while enabling authorized operations. This feedback loop allows the system to distinguish between legitimate access attempts and malicious activity, strengthening protection against malware while preserving ease of operation for authorized users.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11671427B2Server and system for secure configuration push for DMZ proxy clients
Publication Date: 2023.06.06 AVEVA SOFTWARE LLC
  • US11671427B2 patent drawing
  • US11671427B2 patent drawing
  • US11671427B2 patent drawing

AI summary

A server system can include an internal computer network including at least one client server configured to establish a data transfer connection to an external computer network, and at least one proxy server system positioned between the internal computer network and the external computer network. The proxy server system can include a proxy server positioned between a first firewall and a second firewall, where the first firewall is positioned between the first proxy server and the internal computer network, and the second firewall is positioned between the proxy server and the external computer network. The server system can develop and maintain a proxy server system that includes a whitelist of sites deemed necessary and/or desirable for system operation. The whitelist can be updated as a user works with and uses the system. Such updates can take place continuously in real or near-real time or periodically as frequently as desired. A single party can be the only entity that can update the whitelist, ensuring the whitelist contains all required sites. Whitelist updates can be automatically delivered to all proxy instances as the whitelist changes over time.