Gateway Server Tunnel for Secure Industrial Data
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing communication systems for remote access and management of industrial devices lack flexibility in alternative configurations and effective security control, particularly in maintaining secure communication through firewalls and VPN-like structures.
Innovation Solution
A method involving a gateway and server system where a one-time secret is transmitted to establish a communication tunnel, allowing only trusted gateways to send data, with data categorization and encryption, and location-based security measures to ensure secure communication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a VPN-like structure with encrypted channels is established between gateway and client to increase security, then security level is improved, but system flexibility and coordinated security management become cumbersome
Solution Approach 1:
The patent introduces a server as an intermediary component that mediates between the gateway and client. The server establishes and manages the encrypted communication tunnel, handling security protocols centrally rather than requiring direct VPN configuration between gateway and client. This intermediary approach maintains high security through encrypted channels while improving system flexibility and ease of security management through centralized control.
2Productivity
If direct communication between client and gateway is established through firewall tunnel, then communication efficiency is improved, but security control and firewall protection become more complex
Solution Approach 1:
The server acts as a mediator that simplifies firewall configuration. Instead of requiring direct peer-to-peer tunnel configuration through firewalls, the server handles the tunnel establishment and management, reducing the complexity of firewall rules while maintaining efficient encrypted communication between gateway and client.
3Reliability
If multiple security checkpoints (gateway, client, server) are implemented to ensure security, then security level is improved, but coordination of security management becomes cumbersome
Solution Approach 1:
The server is designed with multi-functional capabilities, handling authentication, tunnel establishment, encryption management, and communication coordination in a single centralized component. This universal approach maintains multiple security checkpoints (gateway security, client security, server security) while simplifying security management coordination through a single point of control rather than requiring separate coordination of multiple distributed security components.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
This invention relates to a method in a communication system comprising a gateway and a server. The method comprises: sending a request for establishment of a communication tunnel from the gateway to the server; transmitting a secret from the server to the gateway in response to receiving the request in the server; establishing a communication tunnel by connecting a tunnel client in the gateway to a tunnel server in the server using the received secret; receiving data from a device connected to the gateway and transmitting at least a portion of the data to the tunnel server via the communication tunnel.