Edge Gateway Data Diode for Secure Process Plant Knowledge Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Process control systems in industrial plants face significant security risks due to interconnections with external networks, which can lead to cyber intrusions and potential hazards such as equipment damage, product loss, and even loss of human life, necessitating robust security measures for data delivery.

Innovation Solution

An edge gateway system is implemented, featuring a field-facing component connected to the process plant and an edge-facing component via a unidirectional data diode, which securely delivers process plant data to external systems by storing and processing data in a data lake, discovering relationships, and providing contextualized knowledge repositories accessible to external systems while preventing reverse data flow.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If process control systems are interconnected with external networks to enable data delivery and utilization, then data accessibility and productivity are improved, but security risks and vulnerability to cyber intrusions increase

Engineering Contradiction:
Improvedata delivery efficiencyVSAvoidcyber security risks
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

A data diode is introduced as an intermediary device between the process control network and external networks. The data diode enables unidirectional data flow from the control network to external systems while physically blocking any reverse data flow or cyber intrusions, thus resolving the contradiction between data accessibility and security

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system is segmented into isolated network zones: the process control network, the data diode interface, and external networks. This segmentation allows data to be delivered to external systems while maintaining security boundaries that prevent cyber threats from propagating into the control environment

Inventive Principle:
Principle #1Segmentation

2Reliability

If robust security measures such as data diodes are implemented to prevent cyber intrusions, then security and reliability are improved, but system complexity and data delivery overhead increase

Engineering Contradiction:
Improvesystem securityVSAvoidsecurity infrastructure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The data diode provides automatic, hardware-enforced security without requiring complex software configurations or manual intervention. The unidirectional data flow is enforced by the physical design of the diode itself, eliminating the need for complex access control lists, firewall rules, or authentication mechanisms that would increase system complexity

Inventive Principle:
Principle #25Self-service

3Productivity

If data is delivered securely to external systems, then data accessibility is improved, but the risk of reverse data flow and potential plant compromise increases

Engineering Contradiction:
Improveexternal data utilizationVSAvoidreverse data flow threats
Core Design Contradiction:
ProductivityVSObject-generated harmful factors

Solution Approach 1:

The data diode creates an asymmetric communication channel where data flow is permitted in only one direction (from process control network to external systems). This asymmetry is physically embedded in the diode's design, making reverse data flow inherently impossible and eliminating the threat of external systems compromising the plant through reverse communication

Inventive Principle:
Principle #4Asymmetry

Data Source

PatentUS11436242B2Edge gateway system with contextualized process plant knowledge repository
Publication Date: 2022.09.06 FISHER ROSEMOUNT SYST INC
  • US11436242B2 patent drawing
  • US11436242B2 patent drawing
  • US11436242B2 patent drawing

AI summary

An edge gateway system securely delivers and exposes data generated by and/or related to a process plant for consumption by external systems, and includes an edge-facing component that receives process plant-related data from a process plant via a field-facing component of the system. The received data may comport with an exposable data type system utilizing a syntax known to the external systems. The edge-facing component stores the received data in a data lake, and mines the data lake to thereby discover relationships between stored data points. Indications of the received data and the discovered interrelationships are stored in a contextualized process plant knowledge repository, such as a graph database, that is accessible to the external systems and other systems and applications via one or more access mechanisms, which may include utilities, services, servers, and/or applications. Some of the access mechanisms allow external applications to be installed at the edge-facing component.