Folder-Based Data Exchange for Secure OT-IT Communication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing communication methods between operational technology (OT) networks and information technology (IT) networks are insecure, leading to potential cyber threats and operational challenges due to the use of data diodes, which restrict bidirectional communication.
Innovation Solution
A folder-based data exchange module is introduced to facilitate secure bi-directional communication between OT and IT networks using a data diode for unidirectional data flow, allowing data exchange through files stored in designated folders.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a data diode is used to secure communication between OT and IT networks, then security is improved, but bidirectional communication capability deteriorates
Solution Approach 1:
The system segments the communication process into multiple unidirectional data diode channels, each handling specific data flows in different directions. By dividing the bidirectional communication requirement into separate unidirectional segments, the system maintains security through data diodes while achieving functional bidirectional communication capability.
Solution Approach 2:
The patent introduces intermediary components including a demilitarized zone (DMZ) network and gateway devices that mediate between the OT and IT networks. These intermediaries enable bidirectional communication by receiving, processing, and forwarding data through multiple secured unidirectional data diode connections, thus preserving security while enabling versatility.
2Reliability
If traditional security measures are implemented between OT and IT networks, then security is improved, but implementation complexity increases
Solution Approach 1:
The gateway devices and folder-based data exchange modules are designed to perform multiple functions including data routing, format conversion, protocol translation, and security enforcement. By consolidating these functions into universal components, the system reduces the number of separate devices needed and simplifies implementation while maintaining robust security.
Solution Approach 2:
The system uses folder-based data exchange where data is copied between designated folders in the DMZ network rather than establishing complex direct connections. This copying mechanism simplifies the data exchange process and reduces implementation complexity while maintaining security through the intermediary DMZ environment.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Techniques for secure communication between an operational technology (OT) network and an information technology (IT) network are described. In one aspect, for secure communication, a data diode comprising a transmitting end and a receiving end to facilitate unidirectional communication between a source network and a destination network is provided. The source and destination network are any one of the OT network and the IT network. Further, a folder-based data exchange module communicatively coupled to the receiving end of the data diode is provided to facilitate exchange of data between the source network and the destination network through one or more files, where the one or more files include data to be communicated between the OT network and the IT network. Further, the folder-based data exchange module comprises a first folder to store files designated for the destination network and a second folder to store files designated for the source network.