Industrial Firewall Mediation for Encrypted Automation Connections

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Industrial automation systems face challenges in establishing secured communication connections that prevent eavesdropping while ensuring the integrity and verification of transmitted data, particularly in real-time message traffic and remote maintenance scenarios.

Innovation Solution

A firewall system and method that utilize a connection management device, such as a rendezvous server, to perform authorization verification based on access control lists and apply defined security rules for encrypted communication connections, ensuring secure data transmission and verification through decryption and re-encryption of data packets.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If end-to-end encryption is used for VPN communication connections, then data transmission is secured against eavesdropping, but control over exchanged data and verification of protocol compliance is lost

Engineering Contradiction:
Improvedata transmission securityVSAvoidcontrol capability
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a firewall system as an intermediary component positioned between the VPN encryption layer and the industrial automation system. This firewall decrypts incoming data packets, verifies them against security rules and protocol specifications, and only forwards compliant packets to the target system. This mediator approach resolves the contradiction by maintaining encryption security while regaining control capability through active inspection and filtering of data traffic.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Device complexity

If a firewall system decrypts and verifies data packets, then control and verification capability is restored, but processing time and system complexity increase

Engineering Contradiction:
Improvecontrol capabilityVSAvoiddata packet processing time
Core Design Contradiction:
Device complexityVSLoss of time

Solution Approach 1:

The patent implements preliminary action by establishing security rules and access control lists before communication sessions begin. The firewall system pre-configures verification criteria, protocol requirements, and authorized user permissions in advance. When data packets arrive during active communication, the firewall can quickly match them against pre-established rules rather than performing complex analysis in real-time, thereby reducing processing time while maintaining control capability.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If access control lists are implemented for authorization verification, then unauthorized interventions are prevented, but authentication overhead and connection establishment time increase

Engineering Contradiction:
Improvesystem securityVSAvoidconnection establishment time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies preliminary action by performing authorization verification against access control lists during the connection establishment phase rather than for every subsequent data packet. The firewall system authenticates users and verifies their permissions upfront, caching the authorization results for the duration of the communication session. This approach prevents unauthorized interventions while minimizing authentication overhead to the initial connection setup rather than continuous processing.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11209803B2Firewall system and method for establishing secured communications connections to an industrial automation system
Publication Date: 2021.12.28 SIEMENS AG
  • US11209803B2 patent drawing
  • US11209803B2 patent drawing

AI summary

A connection management device for establishing secured communications connections to an industrial automation system, wherein the device provides, in cases of a positive authorization verification outcome, access control information for establishing an encrypted communication connection between a first communication unit of a requesting user and a selected second communication unit, where the connection management device is formed by a server instance running on a firewall system, where data packets transmitted via an encrypted communications connection between the first communication unit of the requesting user and the selected second communication unit are encrypted for verification by the firewall system, based on specified security rules and, in cases of a successful verification, the data packets are forwarded encrypted to the first communication unit of the requesting user or to the selected second communication unit.