Industrial Edge Data Flow Control for Secure PLC-Cloud Separation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Industrial edge devices face challenges in managing data security while allowing access to both industrial automation networks and data clouds, as existing security measures like firewalls struggle to provide unrestricted access for applications that require it, while preventing unauthorized access and direct connections between public and private networks.

Innovation Solution

Implementing an edge device with at least two separate physical network connections, one for the automation network and one for the data cloud, and using a data flow control device to manage data exchange, ensuring that applications do not communicate directly with both networks simultaneously, and employing a control device with firewall and content filtering functionality to regulate data access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a firewall is installed to protect the edge device and restrict access between cloud and automation network, then data security is improved, but application functionality deteriorates because applications require free access to both networks

Engineering Contradiction:
Improvedata securityVSAvoidapplication functionality
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces a control device as an intermediary between applications and network connections. This control device monitors and manages data flow between the cloud connection and automation network connection, allowing secure communication while maintaining application functionality. The control device acts as a mediator that enables controlled access without requiring direct unfiltered connections.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the network architecture by separating cloud communication and automation network communication into distinct connections. The edge device maintains at least two separate network connections, one to the cloud and one to the automation network, with a control device managing the segmentation and controlled data exchange between them.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If direct connection between cloud and automation network is allowed for application access, then application functionality is improved, but data security deteriorates due to risk of unauthorized access and cyber attacks

Engineering Contradiction:
Improveapplication functionalityVSAvoidcyber attack risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The control device serves as a mandatory intermediary between the cloud connection and automation network connection. All data exchanges between cloud services and automation network components must pass through this control device, which monitors and filters traffic to prevent unauthorized access and cyber attacks while still enabling legitimate application functionality.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The control device implements preliminary security measures by monitoring and controlling data flows before they can reach the automation network. It proactively prevents potentially harmful data exchanges by establishing control rules that block unauthorized access attempts before they can compromise the system.

Inventive Principle:
Principle #9Preliminary anti-action

3Reliability

If firewall restrictions are applied to control data flow, then data security is improved, but ease of operation deteriorates due to complex configuration and management

Engineering Contradiction:
Improvedata securityVSAvoidconfiguration complexity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The control device is designed to autonomously manage data flow control between network connections. It automatically monitors application requirements and adjusts data exchange permissions without requiring manual configuration for each application, reducing operational complexity while maintaining security.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP3798767B1Method and arrangement for controlling the data exchange of an industrial edge device
Publication Date: 2022.03.02 SIEMENS AG
  • EP3798767B1 patent drawingFigure 1

AI summary

The invention relates to a method and an edge device for controlling the data exchange of an industrial edge device (ED) with an industrial automation arrangement (PLC) and with a data cloud (CL), wherein the edge device (ED) has a first communication port (KA1) to the industrial automation arrangement (PLC) and a second communication port (KA2) to a network of the data cloud (CL), wherein the edge device (ED) is provided with a number of data-exchanging applications (AW1, AW2), and wherein the edge device (ED) is equipped with at least one control device (KE) for controlling the data to be exchanged in the manner of a firewall or in the manner of a content filter.For each application (AW1, AW2), it is configured whether the data exchange of the respective application is controlled via the first communication port (KA1) using the control unit (KE) and the data exchange via the second communication port (KA2) occurs directly, or vice versa. A data flow control unit (DKE) on the edge device (ED) ensures that an application does not simultaneously exchange data directly via both communication ports. This method eliminates the need for intensive data security testing of the applications or containers (Docker containers) containing the applications, as protection against attacks is implemented in the centrally and separately managed control unit using firewall functionality and content filters.