Gateway Security Configuration for Automated Systems

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Automated system networks face vulnerabilities due to complex security configurations and the need for remote access, making it difficult to protect devices while ensuring security levels and easily setting up access rules.

Innovation Solution

A method and system for protecting automated systems by building a security configuration based on architecture data, installing a data transmission application on a gateway, and transmitting data through the application, with actions defined by the security configuration to ensure compliance and security levels for multiple AS devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a gateway is used to protect AS devices with unidirectional data transmission, then security level is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity levelVSAvoidgateway configuration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by pre-configuring security rules and access policies in the gateway before data transmission occurs. The gateway is pre-loaded with security configurations that automatically evaluate and enforce access requests, eliminating the need for complex real-time configuration changes and reducing operational complexity while maintaining high security levels.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The gateway serves as an intermediary component between AS devices and external networks. It mediates all data transmission requests by evaluating them against predefined security rules, thereby simplifying the security architecture while maintaining robust protection. The intermediary nature of the gateway allows centralized security management without increasing overall system complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If remote access to AS devices is enabled, then ease of operation is improved, but security level deteriorates

Engineering Contradiction:
Improveremote access capabilityVSAvoidsecurity level
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent applies local quality by implementing different access control policies for different data sources and destinations within the gateway. Each data transmission request is evaluated against location-specific security rules that define what data can be accessed remotely, from where, and under what conditions. This granular approach enables remote access functionality while maintaining security by applying appropriate restrictions to each access attempt.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The gateway implements dynamic security rule evaluation that adapts to each data transmission request in real-time. Access permissions are not static but dynamically determined based on the specific characteristics of each request, the source of data, and predefined security policies. This dynamic approach allows flexible remote access while maintaining security through context-aware decision-making.

Inventive Principle:
Principle #15Dynamics

3Reliability

If security configuration rules are strictly enforced, then security level is improved, but ease of operation deteriorates

Engineering Contradiction:
Improvesecurity complianceVSAvoidconfiguration setup ease
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The gateway applies self-service by automatically evaluating incoming data transmission requests against stored security rules without requiring manual intervention. The system autonomously determines whether each request complies with security policies and enforces decisions automatically. This self-service capability maintains strict security compliance while simplifying operations by eliminating the need for manual security verification and reducing configuration complexity.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11546367B2Systems and methods for protecting automated systems using a gateway
Publication Date: 2023.01.03 AO KASPERSKY LAB
  • US11546367B2 patent drawing
  • US11546367B2 patent drawing
  • US11546367B2 patent drawing

AI summary

Systems and methods for protecting an automated system (AS) including building a security configuration based on architecture data of the AS such that compliance with the security configuration ensures a security level for AS devices, installing a data transmission application on a gateway of an AS network using the security configuration, and transmitting data from one of the AS devices through the data transmission application such that the actions of the data transmission application are defined by the security configuration.