Industrial Edge Data Flow Control for Secure Dual-Network Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Industrial edge devices face challenges in implementing robust data security when requiring access to both automation networks and data clouds, as conventional firewalls struggle to manage unrestricted access for certain applications while preventing unauthorized connections between public and private networks.
Innovation Solution
The method ensures edge devices have separate physical network connections for automation and cloud access, with a data flow control device managing data exchange and implementing firewall functionality to prevent simultaneous direct access by applications, allowing controlled indirect connections and content filtering.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional firewalls are used to restrict access to specific services, then data security is improved, but application functionality deteriorates because some applications require free access to the automation network
Solution Approach 1:
The network connection is segmented into two separate physical connections: one dedicated to the automation network and another to the cloud/public network. The data flow control device segments data traffic by application, directing each application's traffic through the appropriate connection based on security requirements and application needs.
Solution Approach 2:
The data flow control device acts as an intermediary between applications and network connections. It controls and directs data traffic from multiple applications to appropriate network connections, implementing security policies without requiring changes to the applications themselves.
2Adaptability or versatility
If applications are granted uncontrolled access to the automation network, then application functionality is improved, but data security deteriorates because unauthorized access cannot be prevented
Solution Approach 1:
The system segments network access by creating separate physical connections for different network zones (automation network and cloud network). Applications require explicit configuration to access the automation network, preventing unauthorized access while allowing necessary functionality.
Solution Approach 2:
The data flow control device implements preliminary security controls by configuring which applications can access the automation network and under what conditions. This preemptive approach prevents unauthorized access attempts before they can compromise security.
3Reliability
If applications are prevented from accessing the automation network, then data security is improved, but application functionality deteriorates because necessary data exchange cannot occur
Solution Approach 1:
The system dynamically configures network access on a per-application basis. The data flow control device can enable or disable access to the automation network for specific applications based on security requirements, allowing necessary data exchange while preventing unauthorized access.
Solution Approach 2:
Different security policies are applied to different applications. The data flow control device configures individual access rules for each application, allowing those that need automation network access to function properly while restricting access for applications that don't require it.
4Reliability
If edge devices have separate physical network connections for automation and cloud access, then data security is improved, but device complexity increases due to the need for multiple network cards and routing configurations
Solution Approach 1:
The data flow control device combines multiple network connection management functions into a single integrated component. It manages traffic from multiple applications across multiple network connections, implementing security policies and routing decisions in one centralized location rather than requiring complex configurations across multiple devices.
Solution Approach 2:
The data flow control device performs multiple functions: it acts as a firewall, router, and traffic manager for multiple applications simultaneously. This multi-functional approach consolidates what would otherwise require multiple separate network devices and configurations.
Data Source
AI summary
A method and edge device for controlling data exchange of an industrial edge device with an industrial automation arrangement and a data cloud, wherein the edge device includes a first communication connection to the industrial automation arrangement and a second communication connection to a network of the data cloud, where the edge device includes applications exchanging data, and where the edge device includes a control device to control the data to be exchanged, wherein whether data exchange of an application is controlled via the first communication connection and the data exchange is implemented directly via the second communication connection or vice versa is defined for each application, where a data flow control device ensures simultaneous direct data exchange by an application via both communication connections does not occur, such that rigorous checking of applications or containers within the applications with respect to data security is not required.

