Gateway Subsystem Isolating Control Systems from Network Attacks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing computer security systems are vulnerable to denial-of-service attacks, stack buffer overrun attacks, and impersonation attacks, particularly due to direct communication between control systems and networks, which can lead to unauthorized access and disruption of critical operations.
Innovation Solution
A computer security system is designed with three semi-independent subsystems: a communications subsystem, a control subsystem, and a gateway subsystem, where the gateway selectively blocks or allows communications between the other two, using a logic element that operates in 'safe' and 'sensitive' modes based on user input, preventing malicious changes to the control subsystem.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If direct communication between control systems and networks is allowed, then system functionality and ease of operation are improved, but security and resistance to malicious attacks deteriorate
Solution Approach 1:
The patent introduces a gateway subsystem as an intermediary component between the control subsystem and network. This gateway selectively blocks or allows communications based on predetermined criteria, preventing direct access to the control subsystem while maintaining necessary communication functionality. The gateway acts as a mediator that filters malicious traffic while permitting legitimate operations.
Solution Approach 2:
The control system is divided into semi-independent subsystems including a control subsystem, communications subsystem, and gateway subsystem. This segmentation isolates the critical control functions from direct network exposure, allowing the control subsystem to maintain security while the communications subsystem handles network interactions through the gateway.
2Object-affected harmful factors
If communication blocking is implemented to prevent attacks, then security is improved, but system functionality and ease of operation worsen
Solution Approach 1:
The gateway subsystem dynamically adjusts its communication blocking behavior based on operational conditions. It selectively blocks predetermined types of communications while allowing other communications to pass through, creating a dynamic security posture that adapts to different operational states rather than implementing static blocking rules.
Solution Approach 2:
The system changes the parameters of communication filtering based on operational mode. In different operational configurations, the gateway applies different blocking rules and criteria, allowing legitimate communications while preventing malicious ones. The blocking parameters are adjusted according to the specific operational context and security requirements.
Data Source
AI summary
The subject matter of this specification can be embodied in, among other things, a computer system that includes a first processor system configured to communicate with a network, a second processor system configured to control a process, and a third processor system configured to selectively operate in a first configuration and a second configuration, wherein the third processor system is configured to selectively block predetermined types of communications from the first processor system to the second processor system in the first configuration, and the third processor system is configured to permit the predetermined types of communications from the first processor system to the second processor system in the second configuration.


