Ethernet Switch Security for Factory Automation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Factory automation networks using Ethernet lack effective security measures to protect against non-malicious or unsophisticated attacks, which can lead to downtime due to traffic storms caused by viruses or worms, unlike proprietary networks that relied on obscurity for security.
Innovation Solution
An Ethernet switching platform is implemented to secure the network by limiting connected nodes to specific traffic types, defining protected ports, and controlling traffic rates between them, using features like ingress policing, Access Control Lists, and protected ports to prevent broadcast storms and unauthorized access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If proprietary protocols and specialized NICs are used, then network security is maintained through obscurity, but network cost remains high
Solution Approach 1:
The patent changes the security approach from relying on proprietary protocol parameters to using standard Ethernet parameters with added security features. The switch implements security policies that filter and rate-limit traffic based on Ethernet frame characteristics, allowing standard NICs to be used while maintaining security through configurable parameters rather than proprietary protocols
Solution Approach 2:
The patent introduces an intermediary security mechanism at the Ethernet switch level that mediates between standard Ethernet traffic and manufacturing devices. The switch acts as a security gateway that inspects, filters, and rate-limits traffic before it reaches end devices, eliminating the need for specialized proprietary NICs while maintaining security
2Ease of manufacture
If standard Ethernet NICs are used throughout the network, then network cost decreases, but network security against attacks deteriorates
Solution Approach 1:
The patent implements preliminary security actions at the Ethernet switch by pre-configuring security policies, access control lists, and rate-limiting rules before attacks occur. The switch proactively filters malicious traffic and prevents broadcast storms before they can overwhelm manufacturing devices, allowing standard NICs to be used without compromising security
Solution Approach 2:
The patent enables the Ethernet switch to perform self-service security functions by automatically detecting abnormal traffic patterns, applying rate-limiting policies, and blocking malicious sources without requiring specialized hardware. The switch's built-in security features provide protection against viruses, worms, and traffic storms using standard Ethernet infrastructure
3Device complexity
If no specific security features are implemented, then device complexity is reduced, but vulnerability to traffic storms increases
Solution Approach 1:
The patent segments security functions into modular policies that can be independently configured and applied at the Ethernet switch. Security policies are divided into separate rules for filtering, rate-limiting, and access control, allowing the system to maintain low device complexity while providing comprehensive protection against traffic storms and attacks
Data Source
AI summary
A method and apparatus for providing security to factory automation devices in a switched Ethernet network. Traffic between factory automation devices and an Ethernet switch is limited to packets including approved TCP/UDP port numbers and to selected data rates.


