Encrypted Traffic Firewall for Secure Unlock Message Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional process control systems face challenges in protecting against unauthorized access, especially when encrypted messages are involved, as deep packet inspection is required to identify unlock messages, which can expose the system to network intrusion.
Innovation Solution
The solution involves repurposing a specific field in the message header, such as the Ethertype field, to indicate unlock messages, allowing intrusion protection devices to identify unlock messages without decrypting the payload, thereby reducing the risk of network intrusion.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If deep packet inspection is used to identify unlock messages in encrypted traffic, then unauthorized access protection is improved, but system exposure to network intrusion increases
Solution Approach 1:
The patent extracts the unlock message identification function from the encrypted payload and relocates it to the unencrypted message header. By placing the unlock indicator in a specific field of the header (which remains unencrypted), the system can identify unlock messages without decrypting the payload, thus avoiding network intrusion exposure while maintaining unauthorized access protection.
Solution Approach 2:
The message structure is segmented into two parts: an unencrypted header containing the unlock indicator, and an encrypted payload containing the actual data. This segmentation allows the firewall to inspect only the header for unlock messages without needing to decrypt the entire message, resolving the contradiction between security and intrusion exposure.
2Object-affected harmful factors
If message headers are used to identify unlock messages, then network intrusion risk is reduced, but compatibility with existing protocols may worsen
Solution Approach 1:
The patent makes the message header serve multiple functions: it maintains its original protocol-specific functions while also carrying the unlock indicator. The header structure is designed to be protocol-agnostic, allowing it to work with different message protocols while providing the security function of unlock message identification.
Solution Approach 2:
The patent changes the parameter location for unlock indication from the payload (encrypted) to the header (unencrypted). This parameter change allows the system to maintain protocol compatibility while reducing network intrusion risk, as the header structure can be extended without affecting the core protocol functionality.
Data Source
AI summary
A method for decreasing the risk of unauthorized access to an embedded node in a secure subsystem of a process control system includes receiving a message comprising a message header and a message payload, and determining that the message is an unlock message configured to access one or more protected functions of the embedded node, at least by analyzing a bit sequence of one or more bits in the message header. The method also includes determining whether a manual control mechanism has been placed in a particular state by a human operator, and, based upon those determinations, either causing or not causing the embedded node to enter an unlocked state in which one or more of the protected functions are accessible.


