Edge Gateway Data Typing for Secure Process Plant Delivery
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Process control systems in industrial plants face significant security risks due to interconnection with external networks, which can lead to cyber intrusions and attacks, potentially causing equipment damage, product loss, and even human safety threats, necessitating a secure method for data delivery.
Innovation Solution
An edge gateway system with a field-facing component and an edge-facing component interconnected by a unidirectional data diode, allowing secure, one-way data flow from the field-facing component to the edge-facing component, enabling the secure delivery of process plant data to external systems while preventing reverse data flow and using exposable data types to facilitate consumption by external systems.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If process control systems are interconnected with external networks to enable data delivery and consumption, then data accessibility and utility are improved, but security risks and vulnerability to cyber intrusions increase
Solution Approach 1:
The patent introduces an edge gateway system as an intermediary component between the process control system and external networks. This gateway includes a field-facing component that interfaces with the control system and an edge-facing component that interfaces with external systems, with data flowing only from field-facing to edge-facing through a unidirectional data diode. The gateway performs data typing, validation, and contextualization, acting as a security buffer that enables external data consumption while preventing direct access to the control system, thus resolving the contradiction between data accessibility and security risks
Solution Approach 2:
The patent segments the data delivery architecture into distinct functional components: the process control system, the edge gateway system (with field-facing and edge-facing components), and external systems. This segmentation isolates the control system from direct external network exposure while allowing controlled data flow through the gateway. The unidirectional data diode further segments bidirectional communication into one-way flow, enabling external systems to consume data without the ability to send commands back to the control system, thus maintaining security while improving data accessibility
2Reliability
If a unidirectional data diode is used to prevent reverse data flow and ensure security, then system security and integrity are improved, but communication flexibility and bidirectional interaction are reduced
Solution Approach 1:
The patent resolves the contradiction by adding a temporal and functional dimension to the communication architecture. While the data diode enforces unidirectional flow at the network layer (preventing reverse data flow), the edge gateway system implements bidirectional communication at the application layer through multiple mechanisms: the field-facing component receives configuration updates and interest list modifications from the edge-facing component, and the gateway caches and manages data locally. This multi-dimensional approach maintains system integrity through unidirectional data flow while preserving communication flexibility through alternative bidirectional pathways for control and configuration
3Measurement precision
If data typing and validation are implemented to ensure secure data delivery, then data security and precision are improved, but processing complexity and system complexity increase
Solution Approach 1:
The patent applies preliminary action by implementing data typing, validation, and contextualization rules in advance within the edge gateway system's configuration. Data types are defined beforehand with specific schemas, validation rules are pre-configured, and contextualization logic is established prior to data flow. This preliminary setup enables automated, consistent data processing without requiring complex real-time decision-making, reducing operational complexity while maintaining high data precision and security standards
Data Source
AI summary
An edge gateway system securely delivers and exposes data generated by and/or related to a process plant for consumption by external systems, and includes a field-facing component that sends, to an edge-facing component of the system, a collection of data types defined based on configurations of the process plant and represented using a syntax that is native to the one or more external systems. The field-facing component streams process plant-related content data indicated by one or more interest lists to the edge-facing component, where the streamed data is expressed using the collection of data types. Each interest list may include multiple types of data (e.g., control, I/O, diagnostic, device, historical, etc.) that collectively represent a particular named entity of the plant. Accordingly, the streamed data is securely delivered and exposed, via the edge-facing component, to the external systems.


