Hybrid Hardware-Software Security Module for Ethernet Industrial Controls

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Industrial control systems using Ethernet networks face security challenges due to malicious traffic, and existing firewalls or security protocols may introduce communication delays and resource constraints, making them impractical for legacy devices or high-speed control environments.

Innovation Solution

A high-speed network security module divides security tasks between a hardware component and a software component, where the hardware quickly evaluates packets against an allow list and passes known packets, while the software performs sophisticated state analysis and updates the list, allowing for fast and secure processing of high-speed control data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a standard firewall or security protocol is used to block malicious traffic, then security is improved, but communication delay and processing time increase

Engineering Contradiction:
ImprovesecurityVSAvoidcommunication delay
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The security module is divided into two distinct components: a hardware component for rapid packet evaluation and a software component for sophisticated analysis. This segmentation allows time-critical packets to be processed quickly in hardware while less time-sensitive analysis is performed in software, resolving the contradiction between security and communication delay.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The hardware security module acts as an intermediary between the network and the control device, performing initial packet filtering and evaluation before packets reach the control device. This intermediary approach blocks malicious traffic early (improving security) while allowing legitimate traffic to pass through quickly (reducing delay).

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If a sophisticated firewall with state analysis is used, then security is improved, but device complexity and resource requirements increase

Engineering Contradiction:
ImprovesecurityVSAvoidprocessing resources
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The security functionality is segmented between hardware and software components. The hardware component handles rapid packet evaluation using simplified logic, while the software component performs sophisticated state analysis. This segmentation reduces the processing resource requirements of individual components while maintaining overall security effectiveness.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent replaces software-based security processing with a hardware-based security module that uses dedicated circuitry (FPGA or ASIC) for packet evaluation. This substitution of mechanical/hardware systems for software systems reduces processing time and resource requirements while maintaining security functionality.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS9674146B2Network security module for Ethernet-receiving industrial control devices
Publication Date: 2017.06.06 ROCKWELL AUTOMATION TECH INC
  • US9674146B2 patent drawing
  • US9674146B2 patent drawing
  • US9674146B2 patent drawing

AI summary

A high-speed security device for network connected industrial controls provides hybrid processing in tandem hardware and software security components. The software security component establishes state-less data identifying each packet that requires high-speed processing and loads a data table in the hardware component. The hardware component may then allow packets matching data of the data table to bypass the software component while passing other non-matching packets to the software component for more sophisticated state analysis.