Automated System Gateway Security Configuration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing automated system network protection methods are complex to configure and do not easily allow for secure remote access, making it difficult to set up and manage security configurations for devices within the network.

Innovation Solution

A method and system that collect architecture data of automated systems, build a security configuration based on this data, and install a data transmission application on a gateway to ensure secure data exchange with external devices, while defining actions within the security configuration to prevent malicious access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a gateway is used to function as a data diode for protecting AS devices, then security level is improved, but device complexity increases due to multiple gateways and complex security configuration

Engineering Contradiction:
Improvesecurity levelVSAvoidgateway configuration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines multiple gateway functions into a single integrated gateway device that performs data diode functionality, security configuration management, and application deployment. This merging eliminates the need for multiple separate gateways and simplifies the overall system architecture while maintaining security levels.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The gateway is equipped with automated security configuration capabilities that allow it to self-configure and self-manage security parameters. The system can automatically generate and update security configurations without requiring complex manual setup, reducing configuration complexity while maintaining security.

Inventive Principle:
Principle #25Self-service

2Reliability

If security configuration is made restrictive to ensure security level, then security level is improved, but ease of operation deteriorates due to difficulty in setting up and managing access rules

Engineering Contradiction:
Improvesecurity levelVSAvoidsecurity configuration management
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces an intermediary component that acts as a security configuration manager, facilitating easier setup and management of security rules. This intermediary layer provides user-friendly interfaces and automated tools that simplify the configuration process while maintaining the restrictive security measures needed for protection.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system enables dynamic adjustment of security configuration parameters through automated processes. Security parameters can be modified and updated without requiring complex manual reconfiguration, allowing the system to adapt to changing requirements while maintaining security levels through parameter optimization.

Inventive Principle:
Principle #35Parameter changes

3Ease of operation

If remote access to data streams is enabled for operational needs, then ease of operation is improved, but security level deteriorates due to potential unauthorized access

Engineering Contradiction:
Improveremote access capabilityVSAvoidsecurity level
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the network architecture into isolated zones with controlled access points. Remote access is enabled through segmented communication channels that allow data stream access while maintaining security boundaries. This segmentation prevents unauthorized access to the core AS devices while permitting operational remote monitoring and control through controlled interfaces.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentEP3694174B1Systems and methods for protecting automated systems using a gateway
Publication Date: 2021.09.01 AO KASPERSKY LAB
  • EP3694174B1 patent drawingFigure 1
  • EP3694174B1 patent drawingFigure 2
  • EP3694174B1 patent drawingFigure 3

AI summary

Systems and methods for protecting an automated system (AS) including building a security configuration based on architecture data of the AS such that compliance with the security configuration ensures a security level for AS devices, installing a data transmission application on a gateway of an AS network using the security configuration, and transmitting data from one of the AS devices through the data transmission application such that the actions of the data transmission application are defined by the security configuration.