Industrial Firewall for Automation Control Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Industrial automation networks face security threats from unauthorized access and malicious attacks, such as viruses and hacking, due to increased networking, which can lead to denial of service and safety hazards, and existing IT path filtering is not suited to regulate access effectively.

Innovation Solution

Implementing an electronic communication firewall that monitors and filters communications within the automation control network using deep packet inspection and a filtering component to deny unauthorized access, and acting as a communication proxy to manage routing and addressing information, thereby securing the network from unauthorized communication and denial of service attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If automation control networks are connected to office networks and external entities, then data transfer and communication capability are improved, but security risks from unauthorized access and malicious attacks increase

Engineering Contradiction:
Improvecommunication capabilityVSAvoidsecurity risks
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an industrial firewall as an intermediary device positioned between the automation control network and external networks/office networks. This firewall monitors, filters, and controls all data packets passing through it, allowing legitimate communication while blocking unauthorized access and malicious attacks. The firewall acts as a mediator that enables safe interaction between previously isolated networks.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If IT path filtering is used to regulate access between networks, then some security control is achieved, but it is not suited to effectively regulate access to automation control networks

Engineering Contradiction:
Improvesecurity controlVSAvoidaccess regulation effectiveness
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent changes the filtering parameters from standard IT network addressing (IP addresses, ports) to automation-specific parameters including device names, device types, process control functions, and automation protocol identifiers. This parameter transformation enables the firewall to understand and control access based on the semantic meaning of automation network communications rather than just network topology.

Inventive Principle:
Principle #35Parameter changes

3Measurement precision

If deep packet inspection is implemented to inspect communication instances, then security monitoring capability is improved, but processing complexity and time increase

Engineering Contradiction:
Improvesecurity inspection capabilityVSAvoidprocessing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent implements preliminary action by pre-configuring security rules, device profiles, and access policies in the firewall before actual communication occurs. The firewall is pre-loaded with knowledge of authorized devices, their functions, and permitted communication patterns. This allows the firewall to make rapid decisions based on pre-evaluated criteria rather than analyzing every packet from scratch.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8782771B2Real-time industrial firewall
Publication Date: 2014.07.15 ROCKWELL AUTOMATION TECH INC
  • US8782771B2 patent drawing
  • US8782771B2 patent drawing
  • US8782771B2 patent drawing

AI summary

Providing for employing a real time firewall to secure components of an automation control network from unauthorized communication to or from such components is disclosed herein. A monitoring component can inspect at least a portion of an instance of communication directed toward or originating from a component of the automation control network. Such inspection can, e.g., be a deep packet inspection based on information received from a communication request and/or response protocol. A filtering component can selectively admit or deny propagation of the instance of communication based on the inspection and a predetermined security criterion. In such a manner, the subject innovation can provide for limited access to network components from office network machines and for securing components of an automation control network from influence by unauthorized entities.