Ethernet Switch Security for Factory Automation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Factory automation networks using Ethernet lack effective security measures to protect against non-malicious or unsophisticated attacks, which can lead to downtime due to traffic storms caused by viruses or worms, unlike proprietary networks that relied on obscurity for security.

Innovation Solution

An Ethernet switching platform is implemented to secure the network by limiting connected nodes to specific traffic types, defining protected ports, and controlling traffic rates between them, using features like ingress policing, Access Control Lists, and protected ports to prevent broadcast storms and unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If proprietary protocols and specialized NICs are used, then network security is maintained through obscurity, but network cost remains high

Engineering Contradiction:
Improvenetwork securityVSAvoidnetwork cost
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent changes the security approach from relying on proprietary protocol parameters to using standard Ethernet parameters with added security features. The switch implements security policies that filter and rate-limit traffic based on Ethernet frame characteristics, allowing standard NICs to be used while maintaining security through configurable parameters rather than proprietary protocols

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent introduces an intermediary security mechanism at the Ethernet switch level that mediates between standard Ethernet traffic and manufacturing devices. The switch acts as a security gateway that inspects, filters, and rate-limits traffic before it reaches end devices, eliminating the need for specialized proprietary NICs while maintaining security

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of manufacture

If standard Ethernet NICs are used throughout the network, then network cost decreases, but network security against attacks deteriorates

Engineering Contradiction:
Improvenetwork costVSAvoidnetwork security
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The patent implements preliminary security actions at the Ethernet switch by pre-configuring security policies, access control lists, and rate-limiting rules before attacks occur. The switch proactively filters malicious traffic and prevents broadcast storms before they can overwhelm manufacturing devices, allowing standard NICs to be used without compromising security

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent enables the Ethernet switch to perform self-service security functions by automatically detecting abnormal traffic patterns, applying rate-limiting policies, and blocking malicious sources without requiring specialized hardware. The switch's built-in security features provide protection against viruses, worms, and traffic storms using standard Ethernet infrastructure

Inventive Principle:
Principle #25Self-service

3Device complexity

If no specific security features are implemented, then device complexity is reduced, but vulnerability to traffic storms increases

Engineering Contradiction:
Improvesecurity featuresVSAvoidvulnerability to attacks
Core Design Contradiction:
Device complexityVSObject-affected harmful factors

Solution Approach 1:

The patent segments security functions into modular policies that can be independently configured and applied at the Ethernet switch. Security policies are divided into separate rules for filtering, rate-limiting, and access control, allowing the system to maintain low device complexity while providing comprehensive protection against traffic storms and attacks

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS7607166B2Secure manufacturing devices in a switched Ethernet network
Publication Date: 2009.10.20 CISCO TECHNOLOGY INC
  • US7607166B2 patent drawing
  • US7607166B2 patent drawing
  • US7607166B2 patent drawing

AI summary

A method and apparatus for providing security to factory automation devices in a switched Ethernet network. Traffic between factory automation devices and an Ethernet switch is limited to packets including approved TCP/UDP port numbers and to selected data rates.