Industrial Internet Firewall Segmentation for Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security protection measures for industrial Internet platforms are inadequate, failing to consider the network use requirements and security protection capabilities of these platforms, leading to potential security risks.

Innovation Solution

A security protection method and device based on industrial Internet, which includes deploying exit and regional firewalls to isolate the Internet from the industrial Internet platform intranet, implementing access policies to control communication, and utilizing intrusion prevention systems, vulnerability scanning systems, and data security systems to enhance security measures.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If simple security protection measures are implemented, then device complexity is reduced, but security reliability deteriorates

Engineering Contradiction:
Improvesecurity protection measures complexityVSAvoidsecurity protection capability
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent segments the network into multiple security zones (Internet access zone, DMZ zone, intranet core zone, etc.) and implements firewalls at each zone boundary. This segmentation allows security measures to be applied locally at each boundary rather than requiring a single complex centralized system, thereby improving security reliability while managing complexity through modular deployment.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements preliminary security actions by pre-configuring access control policies, port forwarding rules, and security parameters before actual communication occurs. The exit firewall pre-establishes which ports and protocols are allowed, and the regional firewall pre-defines access permissions for different network zones, ensuring security is in place before threats can exploit gaps.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If strict access control policies are implemented, then security reliability is improved, but network usability deteriorates

Engineering Contradiction:
Improvesecurity protection capabilityVSAvoidnetwork usability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent applies different access control policies to different network zones and devices based on their specific security requirements and functionality. For example, the exit firewall applies specific rules for Internet access, while regional firewalls apply different rules for intranet communication. This localized policy application ensures security without uniformly restricting all network traffic, thereby maintaining usability.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent introduces DMZ (Demilitarized Zone) as an intermediary layer between the Internet and the intranet core. This intermediary zone allows controlled access to specific services (such as web servers, mail servers) while preventing direct access to the internal network. The intermediary firewall mediates traffic between zones, enabling security policies to be enforced without completely blocking legitimate network operations.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If multiple firewalls and security systems are deployed, then security reliability is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity protection capabilityVSAvoidsecurity system structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent divides the security system into multiple independent firewall units deployed at different network boundaries (exit firewall at Internet boundary, regional firewalls at zone boundaries). Each firewall is relatively simple in structure but collectively they provide comprehensive security coverage. This segmentation transforms a single complex security system into multiple simpler, manageable components.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent designs the firewall system to perform multiple functions including access control, port forwarding, protocol filtering, and security monitoring. By making each firewall unit multi-functional, the system reduces the need for separate specialized devices, thereby managing overall complexity while maintaining comprehensive security capabilities.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12238145B2Security protection method and device based on industrial internet
Publication Date: 2025.02.25 HUANENG INFORMATION TECH CO LTD
  • US12238145B2 patent drawing
  • US12238145B2 patent drawing
  • US12238145B2 patent drawing

AI summary

A security protection method and device based on industrial Internet is provided. The disclosure relates to the technical field of network security and realize the isolation between the Internet and the industrial Internet platform intranet by deploying the exit firewall, and there is no restriction from the industrial Internet platform intranet to the Internet, and only necessary ports are opened from the Internet to the industrial Internet platform intranet. By deploying a regional firewall, isolation between the intranet core server and each of the secondary nodes is realized. The regional firewall is deployed on the wide area network router, and the second access policy of secondary nodes and intranet core servers is preset. After the second access policy is formulated, only the IP and service ports of specific hosts are opened, and all other accesses are prohibited.