Edge-to-Cloud Honeypot Using Virtual Field Devices for Data Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data transmission systems between edge devices and cloud-based service platforms in industrial automation are vulnerable to unauthorized access and data interception, risking the exposure of sensitive information.

Innovation Solution

An automation system that simulates additional virtual field devices and generates plausible data for these devices, encrypts their identifications, and uses separate communication channels for monitoring and reporting unauthorized access, thereby confusing attackers and protecting actual system data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If data is transmitted between edge device and cloud-based service platform via secure connection, then data security is improved, but vulnerability to interception and unauthorized access still exists

Engineering Contradiction:
Improvedata securityVSAvoidunauthorized access and data interception
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a honeypot system as an intermediary component between the edge device and cloud platform. This honeypot contains simulated field devices that act as a mediator to intercept and analyze unauthorized access attempts, allowing security monitoring without exposing actual field device data to attackers

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system creates a composite data environment by combining real field device data with simulated honeypot data in the live list transmitted to the cloud platform. This composite structure makes it difficult for attackers to distinguish between real and fake data, thereby protecting sensitive information

Inventive Principle:
Principle #40Composite materials

2Loss of information

If edge device transmits all field device data to cloud platform, then comprehensive data analysis is improved, but attack surface and risk exposure increase

Engineering Contradiction:
Improvecomprehensive data analysisVSAvoidattack surface and risk exposure
Core Design Contradiction:
Loss of informationVSObject-affected harmful factors

Solution Approach 1:

The patent segments the data transmission by creating separate channels: one for real field device data and another for simulated honeypot data. The honeypot data is transmitted through the same live list mechanism but can be independently monitored and analyzed, allowing comprehensive data collection while isolating sensitive information from direct attack risks

Inventive Principle:
Principle #1Segmentation

3Reliability

If system monitors and detects unauthorized access in real-time, then security response time is improved, but system complexity and resource consumption increase

Engineering Contradiction:
Improvesecurity response timeVSAvoidsystem complexity and resource consumption
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The honeypot system operates autonomously by automatically generating simulated field device data and independently monitoring access attempts to honeypot components. This self-service capability allows real-time security detection without requiring additional manual intervention or complex centralized monitoring infrastructure

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP4264382B1Honeypot for a connection between an edge device and a cloud-based service platform
Publication Date: 2025.07.23 ENDRESS & HAUSER GMBH & CO KG
  • EP4264382B1 patent drawingFigure 1

AI summary

The invention relates to an automation system, comprising: - a first plant part (AT1), consisting of a plurality of field devices (FG); - an edge device (ED), which is part of the communications network, wherein the edge device (ED) is designed to monitor at least some of the data transmitted by the field devices (FG) and by the higher-level unit (ÜE) and/or to request further data from the field devices (FG) and/or from the higher-level unit (ÜE), wherein the edge device (ED) is designed to generate a live list, which contains an identifier of each of the field devices (FG) and/or of the control unit and the currently requested and/or monitored data, wherein the edge device (ED) is designed to simulate a plurality of virtual field devices (FG'), to generate data for the virtual field devices (FG'), to input the identifiers of the virtual field devices (FG') and the generated data into the live list, and to make the live list available via a first interface (API1), in particular an interface for application programming; - a cloud-based service platform (SP), wherein the edge device (ED) is designed to transmit the live list containing the current requested and/or monitored data to the cloud-based service platform (SP) at regular intervals, and wherein the cloud-based service platform (SP) is designed to prepare and/or present the live list, wherein the data of the virtual field devices (FG') is disregarded.