Industrial Internet Firewall Segmentation for Network Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing security protection measures for industrial Internet platforms are inadequate, failing to consider the network use requirements and security protection capabilities of these platforms, leading to potential security risks.
Innovation Solution
A security protection method and device based on industrial Internet, which includes deploying exit and regional firewalls to isolate the Internet from the industrial Internet platform intranet, implementing access policies to control communication, and utilizing intrusion prevention systems, vulnerability scanning systems, and data security systems to enhance security measures.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If simple security protection measures are implemented, then device complexity is reduced, but security reliability deteriorates
Solution Approach 1:
The patent segments the network into multiple security zones (Internet access zone, DMZ zone, intranet core zone, etc.) and implements firewalls at each zone boundary. This segmentation allows security measures to be applied locally at each boundary rather than requiring a single complex centralized system, thereby improving security reliability while managing complexity through modular deployment.
Solution Approach 2:
The patent implements preliminary security actions by pre-configuring access control policies, port forwarding rules, and security parameters before actual communication occurs. The exit firewall pre-establishes which ports and protocols are allowed, and the regional firewall pre-defines access permissions for different network zones, ensuring security is in place before threats can exploit gaps.
2Reliability
If strict access control policies are implemented, then security reliability is improved, but network usability deteriorates
Solution Approach 1:
The patent applies different access control policies to different network zones and devices based on their specific security requirements and functionality. For example, the exit firewall applies specific rules for Internet access, while regional firewalls apply different rules for intranet communication. This localized policy application ensures security without uniformly restricting all network traffic, thereby maintaining usability.
Solution Approach 2:
The patent introduces DMZ (Demilitarized Zone) as an intermediary layer between the Internet and the intranet core. This intermediary zone allows controlled access to specific services (such as web servers, mail servers) while preventing direct access to the internal network. The intermediary firewall mediates traffic between zones, enabling security policies to be enforced without completely blocking legitimate network operations.
3Reliability
If multiple firewalls and security systems are deployed, then security reliability is improved, but device complexity increases
Solution Approach 1:
The patent divides the security system into multiple independent firewall units deployed at different network boundaries (exit firewall at Internet boundary, regional firewalls at zone boundaries). Each firewall is relatively simple in structure but collectively they provide comprehensive security coverage. This segmentation transforms a single complex security system into multiple simpler, manageable components.
Solution Approach 2:
The patent designs the firewall system to perform multiple functions including access control, port forwarding, protocol filtering, and security monitoring. By making each firewall unit multi-functional, the system reduces the need for separate specialized devices, thereby managing overall complexity while maintaining comprehensive security capabilities.
Data Source
AI summary
A security protection method and device based on industrial Internet is provided. The disclosure relates to the technical field of network security and realize the isolation between the Internet and the industrial Internet platform intranet by deploying the exit firewall, and there is no restriction from the industrial Internet platform intranet to the Internet, and only necessary ports are opened from the Internet to the industrial Internet platform intranet. By deploying a regional firewall, isolation between the intranet core server and each of the secondary nodes is realized. The regional firewall is deployed on the wide area network router, and the second access policy of secondary nodes and intranet core servers is preset. After the second access policy is formulated, only the IP and service ports of specific hosts are opened, and all other accesses are prohibited.


