Industrial Edge Data Flow Control for Secure PLC-Cloud Separation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Industrial edge devices face challenges in managing data security while allowing access to both industrial automation networks and data clouds, as existing security measures like firewalls struggle to provide unrestricted access for applications that require it, while preventing unauthorized access and direct connections between public and private networks.
Innovation Solution
Implementing an edge device with at least two separate physical network connections, one for the automation network and one for the data cloud, and using a data flow control device to manage data exchange, ensuring that applications do not communicate directly with both networks simultaneously, and employing a control device with firewall and content filtering functionality to regulate data access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a firewall is installed to protect the edge device and restrict access between cloud and automation network, then data security is improved, but application functionality deteriorates because applications require free access to both networks
Solution Approach 1:
The patent introduces a control device as an intermediary between applications and network connections. This control device monitors and manages data flow between the cloud connection and automation network connection, allowing secure communication while maintaining application functionality. The control device acts as a mediator that enables controlled access without requiring direct unfiltered connections.
Solution Approach 2:
The patent segments the network architecture by separating cloud communication and automation network communication into distinct connections. The edge device maintains at least two separate network connections, one to the cloud and one to the automation network, with a control device managing the segmentation and controlled data exchange between them.
2Adaptability or versatility
If direct connection between cloud and automation network is allowed for application access, then application functionality is improved, but data security deteriorates due to risk of unauthorized access and cyber attacks
Solution Approach 1:
The control device serves as a mandatory intermediary between the cloud connection and automation network connection. All data exchanges between cloud services and automation network components must pass through this control device, which monitors and filters traffic to prevent unauthorized access and cyber attacks while still enabling legitimate application functionality.
Solution Approach 2:
The control device implements preliminary security measures by monitoring and controlling data flows before they can reach the automation network. It proactively prevents potentially harmful data exchanges by establishing control rules that block unauthorized access attempts before they can compromise the system.
3Reliability
If firewall restrictions are applied to control data flow, then data security is improved, but ease of operation deteriorates due to complex configuration and management
Solution Approach 1:
The control device is designed to autonomously manage data flow control between network connections. It automatically monitors application requirements and adjusts data exchange permissions without requiring manual configuration for each application, reducing operational complexity while maintaining security.
Data Source
Figure 1
AI summary
The invention relates to a method and an edge device for controlling the data exchange of an industrial edge device (ED) with an industrial automation arrangement (PLC) and with a data cloud (CL), wherein the edge device (ED) has a first communication port (KA1) to the industrial automation arrangement (PLC) and a second communication port (KA2) to a network of the data cloud (CL), wherein the edge device (ED) is provided with a number of data-exchanging applications (AW1, AW2), and wherein the edge device (ED) is equipped with at least one control device (KE) for controlling the data to be exchanged in the manner of a firewall or in the manner of a content filter.For each application (AW1, AW2), it is configured whether the data exchange of the respective application is controlled via the first communication port (KA1) using the control unit (KE) and the data exchange via the second communication port (KA2) occurs directly, or vice versa. A data flow control unit (DKE) on the edge device (ED) ensures that an application does not simultaneously exchange data directly via both communication ports. This method eliminates the need for intensive data security testing of the applications or containers (Docker containers) containing the applications, as protection against attacks is implemented in the centrally and separately managed control unit using firewall functionality and content filters.