Folder-Based Data Exchange for Secure OT-IT Communication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing communication methods between operational technology (OT) networks and information technology (IT) networks are insecure, leading to potential cyber threats and operational challenges due to the use of data diodes, which restrict bidirectional communication.

Innovation Solution

A folder-based data exchange module is introduced to facilitate secure bi-directional communication between OT and IT networks using a data diode for unidirectional data flow, allowing data exchange through files stored in designated folders.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a data diode is used to secure communication between OT and IT networks, then security is improved, but bidirectional communication capability deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidbidirectional communication capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system segments the communication process into multiple unidirectional data diode channels, each handling specific data flows in different directions. By dividing the bidirectional communication requirement into separate unidirectional segments, the system maintains security through data diodes while achieving functional bidirectional communication capability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces intermediary components including a demilitarized zone (DMZ) network and gateway devices that mediate between the OT and IT networks. These intermediaries enable bidirectional communication by receiving, processing, and forwarding data through multiple secured unidirectional data diode connections, thus preserving security while enabling versatility.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If traditional security measures are implemented between OT and IT networks, then security is improved, but implementation complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidimplementation complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The gateway devices and folder-based data exchange modules are designed to perform multiple functions including data routing, format conversion, protocol translation, and security enforcement. By consolidating these functions into universal components, the system reduces the number of separate devices needed and simplifies implementation while maintaining robust security.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system uses folder-based data exchange where data is copied between designated folders in the DMZ network rather than establishing complex direct connections. This copying mechanism simplifies the data exchange process and reduces implementation complexity while maintaining security through the intermediary DMZ environment.

Inventive Principle:
Principle #26Copying

Data Source

PatentEP4571553A1Secure communication between information technology network and operational technology network
Publication Date: 2025.06.18 HONEYWELL INTERNATIONAL INC
  • EP4571553A1 patent drawingFigure 1
  • EP4571553A1 patent drawingFigure 2
  • EP4571553A1 patent drawingFigure 3

AI summary

Techniques for secure communication between an operational technology (OT) network and an information technology (IT) network are described. In one aspect, for secure communication, a data diode comprising a transmitting end and a receiving end to facilitate unidirectional communication between a source network and a destination network is provided. The source and destination network are any one of the OT network and the IT network. Further, a folder-based data exchange module communicatively coupled to the receiving end of the data diode is provided to facilitate exchange of data between the source network and the destination network through one or more files, where the one or more files include data to be communicated between the OT network and the IT network. Further, the folder-based data exchange module comprises a first folder to store files designated for the destination network and a second folder to store files designated for the source network.