Hybrid Hardware-Software Security Module for Ethernet Industrial Controls
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Industrial control systems using Ethernet networks face security challenges due to malicious traffic, and existing firewalls or security protocols may introduce communication delays and resource constraints, making them impractical for legacy devices or high-speed control environments.
Innovation Solution
A high-speed network security module divides security tasks between a hardware component and a software component, where the hardware quickly evaluates packets against an allow list and passes known packets, while the software performs sophisticated state analysis and updates the list, allowing for fast and secure processing of high-speed control data.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a standard firewall or security protocol is used to block malicious traffic, then security is improved, but communication delay and processing time increase
Solution Approach 1:
The security module is divided into two distinct components: a hardware component for rapid packet evaluation and a software component for sophisticated analysis. This segmentation allows time-critical packets to be processed quickly in hardware while less time-sensitive analysis is performed in software, resolving the contradiction between security and communication delay.
Solution Approach 2:
The hardware security module acts as an intermediary between the network and the control device, performing initial packet filtering and evaluation before packets reach the control device. This intermediary approach blocks malicious traffic early (improving security) while allowing legitimate traffic to pass through quickly (reducing delay).
2Reliability
If a sophisticated firewall with state analysis is used, then security is improved, but device complexity and resource requirements increase
Solution Approach 1:
The security functionality is segmented between hardware and software components. The hardware component handles rapid packet evaluation using simplified logic, while the software component performs sophisticated state analysis. This segmentation reduces the processing resource requirements of individual components while maintaining overall security effectiveness.
Solution Approach 2:
The patent replaces software-based security processing with a hardware-based security module that uses dedicated circuitry (FPGA or ASIC) for packet evaluation. This substitution of mechanical/hardware systems for software systems reduces processing time and resource requirements while maintaining security functionality.
Data Source
AI summary
A high-speed security device for network connected industrial controls provides hybrid processing in tandem hardware and software security components. The software security component establishes state-less data identifying each packet that requires high-speed processing and loads a data table in the hardware component. The hardware component may then allow packets matching data of the data table to bypass the software component while passing other non-matching packets to the software component for more sophisticated state analysis.


