Edge Gateway Data Typing With Data Diode for Secure Plant Data Delivery

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Process control systems in industrial plants face significant security risks due to interconnections with external networks, which can lead to cyber intrusions and attacks, potentially causing equipment damage, product loss, and even human safety threats, necessitating robust security measures for data communication.

Innovation Solution

An edge gateway system is implemented, featuring a field-facing component and an edge-facing component connected by a unidirectional data diode, allowing secure one-way data flow from the field-facing component to the edge-facing component, with data types defined and represented in a syntax native to external systems, enabling secure delivery of process plant data to external systems while preventing reverse data flow.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If process control systems are interconnected with external networks to enable data sharing and remote access, then productivity and adaptability are improved, but security risks and vulnerability to cyber threats increase

Engineering Contradiction:
Improvedata sharing efficiencyVSAvoidcyber security risks
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an edge gateway system as an intermediary component between process control systems and external networks. This gateway includes a field-facing component that interfaces with the control system and an edge-facing component that interfaces with external systems, with a data diode between them. The intermediary enables controlled data sharing while maintaining security isolation, allowing productivity benefits without direct exposure to cyber threats.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The edge gateway system is segmented into distinct functional components: a field-facing component for receiving process data, a unidirectional data diode for controlled transmission, and an edge-facing component for external communication. This segmentation isolates the critical process control system from external networks while enabling necessary data exchange, thus improving productivity without compromising security.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If bidirectional communication is implemented between process control systems and external networks to enable real-time data exchange, then adaptability is improved, but security vulnerabilities and risk of unauthorized access increase

Engineering Contradiction:
Improvedata exchange capabilityVSAvoidsystem security integrity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent implements asymmetric communication by using a unidirectional data diode that allows data flow only from the field-facing component to the edge-facing component. This asymmetric design enables external systems to receive and process process data (improving adaptability) while preventing any reverse data flow that could introduce malware or unauthorized commands (maintaining security integrity).

Inventive Principle:
Principle #4Asymmetry

Solution Approach 2:

The edge gateway acts as a security intermediary that mediates all communications between the process control system and external networks. The data diode within this intermediary enforces unidirectional data flow, allowing versatile data exchange capabilities while maintaining reliable security boundaries that prevent unauthorized access.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Productivity

If data is exposed to external systems for consumption and processing, then productivity is improved, but risk of data breaches and unauthorized access increases

Engineering Contradiction:
Improveexternal data utilizationVSAvoiddata breach risk
Core Design Contradiction:
ProductivityVSObject-generated harmful factors

Solution Approach 1:

The edge gateway system serves as a security intermediary that enables external systems to consume and process process data for productivity improvements. The unidirectional data diode ensures that while data flows freely to external consumers, any attempt at unauthorized reverse communication or data breach is physically prevented, thus enabling external data utilization without exposing the control system to breach risks.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent extracts the security risk from the data exchange process by removing the ability for external systems to directly access or communicate back to the process control system. The data diode extracts only the necessary data flow in one direction, allowing external systems to utilize process data for productivity while the control system remains isolated from external threats.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS11165839B2Edge gateway system with data typing for secured process plant data delivery
Publication Date: 2021.11.02 FISHER ROSEMOUNT SYST INC
  • US11165839B2 patent drawing
  • US11165839B2 patent drawing
  • US11165839B2 patent drawing

AI summary

An edge gateway system securely delivers and exposes data generated by and/or related to a process plant for consumption by external systems, and includes a field-facing component that sends, to an edge-facing component of the system, a collection of data types defined based on configurations of the process plant and represented using a syntax that is native to the one or more external systems. The field-facing component streams process plant-related content data indicated by one or more interest lists to the edge-facing component, where the streamed data is expressed using the collection of data types. Each interest list may include multiple types of data (e.g., control, I/O, diagnostic, device, historical, etc.) that collectively represent a particular named entity of the plant. Accordingly, the streamed data is securely delivered and exposed, via the edge-facing component, to the external systems.