Industrial Firewall Mediation for Encrypted Automation Connections
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Industrial automation systems face challenges in establishing secured communication connections that prevent eavesdropping while ensuring the integrity and verification of transmitted data, particularly in real-time message traffic and remote maintenance scenarios.
Innovation Solution
A firewall system and method that utilize a connection management device, such as a rendezvous server, to perform authorization verification based on access control lists and apply defined security rules for encrypted communication connections, ensuring secure data transmission and verification through decryption and re-encryption of data packets.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If end-to-end encryption is used for VPN communication connections, then data transmission is secured against eavesdropping, but control over exchanged data and verification of protocol compliance is lost
Solution Approach 1:
The patent introduces a firewall system as an intermediary component positioned between the VPN encryption layer and the industrial automation system. This firewall decrypts incoming data packets, verifies them against security rules and protocol specifications, and only forwards compliant packets to the target system. This mediator approach resolves the contradiction by maintaining encryption security while regaining control capability through active inspection and filtering of data traffic.
2Device complexity
If a firewall system decrypts and verifies data packets, then control and verification capability is restored, but processing time and system complexity increase
Solution Approach 1:
The patent implements preliminary action by establishing security rules and access control lists before communication sessions begin. The firewall system pre-configures verification criteria, protocol requirements, and authorized user permissions in advance. When data packets arrive during active communication, the firewall can quickly match them against pre-established rules rather than performing complex analysis in real-time, thereby reducing processing time while maintaining control capability.
3Reliability
If access control lists are implemented for authorization verification, then unauthorized interventions are prevented, but authentication overhead and connection establishment time increase
Solution Approach 1:
The patent applies preliminary action by performing authorization verification against access control lists during the connection establishment phase rather than for every subsequent data packet. The firewall system authenticates users and verifies their permissions upfront, caching the authorization results for the duration of the communication session. This approach prevents unauthorized interventions while minimizing authentication overhead to the initial connection setup rather than continuous processing.
Data Source
AI summary
A connection management device for establishing secured communications connections to an industrial automation system, wherein the device provides, in cases of a positive authorization verification outcome, access control information for establishing an encrypted communication connection between a first communication unit of a requesting user and a selected second communication unit, where the connection management device is formed by a server instance running on a firewall system, where data packets transmitted via an encrypted communications connection between the first communication unit of the requesting user and the selected second communication unit are encrypted for verification by the firewall system, based on specified security rules and, in cases of a successful verification, the data packets are forwarded encrypted to the first communication unit of the requesting user or to the selected second communication unit.

