Edge Honeypot Using Virtual Field Devices for Secure Cloud Links

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing data transmission methods between edge devices and cloud-based service platforms in industrial automation systems lack sufficient security, making it vulnerable to unauthorized access and data breaches.

Innovation Solution

An automation system that employs an edge device to simulate virtual field devices, generating and transmitting simulated data to a cloud-based service platform, thereby confusing attackers and ensuring only actual field device data is presented to authorized users, while using encryption and AI algorithms to enhance plausibility and security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If data transmission between edge device and cloud-based service platform is performed using standard encryption methods, then data security is improved, but the system remains vulnerable to unauthorized access and data breaches

Engineering Contradiction:
Improvedata securityVSAvoidunauthorized access vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a honeypot system as an intermediary component between the edge device and cloud platform. This honeypot contains simulated field devices that act as a decoy layer, intercepting and absorbing unauthorized access attempts before they can reach the actual production data, thereby enhancing security without affecting normal operations

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system combines real field device data with simulated honeypot data to create a composite data structure. This composite approach allows the system to present a mixed dataset where genuine production data is protected by being embedded within and protected by the decoy honeypot data layer

Inventive Principle:
Principle #40Composite materials

2Measurement precision

If the edge device transmits only actual field device data to the cloud platform, then data accuracy is improved, but security against attackers is worsened

Engineering Contradiction:
Improvedata accuracyVSAvoidsecurity against attackers
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The patent segments the data transmission into two distinct channels: one for actual production data and another for honeypot decoy data. The segmentation allows the system to maintain accurate production data transmission while simultaneously deploying security decoys that confuse and deter attackers

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system changes the parameter of data composition by introducing simulated data with realistic characteristics into the transmission stream. This parameter change creates a mixed dataset that maintains accuracy for legitimate users while providing security obfuscation against attackers

Inventive Principle:
Principle #35Parameter changes

3Reliability

If the system implements honeypot with simulated field devices, then security is improved, but device complexity is worsened

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent creates simplified copies of field devices (honeypots) that replicate only the essential characteristics needed for deception. These copied entities provide security functionality without requiring full complexity of actual production devices, thereby limiting the increase in system complexity

Inventive Principle:
Principle #26Copying

4Reliability

If the edge device generates and transmits simulated data for virtual field devices, then attacker confusion is improved, but data processing complexity is worsened

Engineering Contradiction:
Improveattacker confusionVSAvoiddata processing complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system creates disposable simulated data objects that are inexpensive to generate and can be easily replaced. These short-living simulated data entities provide effective confusion for attackers without requiring complex, long-term data management structures

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Data Source

PatentUS20240036557A1Honeypot for a connection between an edge device and a cloud-based service platform
Publication Date: 2024.02.01 ENDRESS & HAUSER GMBH & CO KG
  • US20240036557A1 patent drawing

AI summary

A first plant part includes a multitude of field devices and an edge device, which is part of a communication network. The edge device monitors data transmitted by the field devices and a higher-level unit or requests further data. The edge device generates a live list, which contains an identifier of each field device or the higher-level unit and the requested or monitored data. The edge device simulates a multitude of virtual field devices, generates data, and enters identifiers of the virtual field devices and the generated data into the live list. The live list is made available via a first interface. The edge device transmits the live list containing the current requested or monitored data to a cloud-based service platform at regular intervals, and the cloud-based service platform is designed to prepare or present the live list, with the data of the virtual field devices being disregarded.