Firewall Verification Assembly for Safety-Critical Data Receivers
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional firewall devices are inadequate for safety-critical systems as they fail to effectively differentiate and block non-permissible data traffic, posing a risk to systems like railroad signaling networks and nuclear power stations, where remote access is increasingly needed while maintaining high security standards.
Innovation Solution
An assembly comprising an acquisition device to monitor data traffic, an evaluation device to check for non-permissible data based on predetermined rules, a shutdown device to interrupt traffic if malfunctions are detected, and a monitoring device to ensure operational readiness, along with a test data generator to verify proper functioning, all working together to protect safety-critical systems from unauthorized data access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional firewall devices are used to block non-permissible data traffic, then basic filtering capability is provided, but reliability and security for safety-critical systems are insufficient
Solution Approach 1:
An acquisition device is introduced as an intermediary component that captures data traffic allowed through the firewall device and transfers it to an evaluation device for independent verification. This mediator enables safety-critical monitoring without altering the firewall's primary function, thereby improving reliability while maintaining manageable system complexity through modular architecture.
Solution Approach 2:
The evaluation device continuously monitors the firewall's performance by comparing actual data traffic against expected behavior based on predetermined rules. When deviations are detected indicating potential malfunctions or attacks, the system provides feedback through alarm signals and automated shutdown actions, creating a closed-loop control system that enhances firewall reliability for safety-critical applications.
2Ease of operation
If firewall devices allow remote access to safety-critical systems, then operational flexibility is improved, but security risks increase
Solution Approach 1:
The system performs preliminary verification by capturing and evaluating data traffic before it reaches the safety-critical system. The acquisition device records traffic patterns and the evaluation device checks them against predetermined rules in advance, enabling the system to identify and block potential security threats before they can cause harm, thus allowing safe remote access.
Solution Approach 2:
The evaluation device is configured with predetermined rules that define permissible traffic patterns. By comparing actual traffic against these pre-established criteria, the system proactively identifies and counteracts potential security threats before they can compromise the safety-critical system, enabling secure remote operation.
3Reliability
If the firewall device blocks all non-permissible traffic, then security is improved, but false positives may interrupt legitimate traffic
Solution Approach 1:
The evaluation device provides continuous feedback by monitoring firewall decisions and comparing them against expected behavior. When the firewall blocks traffic, the evaluation device verifies whether this action was appropriate based on predetermined rules. This feedback mechanism reduces false positives by distinguishing between legitimate security blocks and erroneous rejections of permissible traffic, thereby maintaining both security assurance and productive data flow.
Solution Approach 2:
The system replaces reliance on the firewall device's internal decision-making mechanisms with an independent evaluation device that uses predetermined rules and statistical analysis to verify blocking decisions. This substitution reduces false positives by providing an external verification layer that can distinguish between genuine security threats and legitimate traffic, maintaining productivity while ensuring security.
Data Source
AI summary
An assembly checks at least one firewall device and a method protects at least one data receiver. In the method, permissible and non-permissible data traffic is differentiated in data traffic in the direction of the data receiver using specific rules. Non-permissible data traffic is blocked, and permissible data traffic is allowed through. In order to check the function of the firewall device, the data traffic which has been allowed through is interrupted if the data traffic which has been allowed through has non-permissible data traffic.
