Intermediary Security Enforcement for Legacy Industrial Automation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Industrial automation systems with legacy devices lacking modern security features are vulnerable to attacks from malicious entities due to unmonitored data traffic, leading to potential security issues such as unauthorized access, loss of control, and system shutdown.

Innovation Solution

A security device that automatically discovers capabilities and attributes of industrial automation devices, implementing security techniques like data packet filtering, cryptographically signing, and generating alerts based on communication protocols, and updates itself to handle new protocols.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If legacy industrial automation devices are used without native security features, then device compatibility and system legacy support are maintained, but security vulnerability increases

Engineering Contradiction:
Improvelegacy device compatibilityVSAvoidsecurity vulnerability
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an intermediary security device that positions itself between legacy industrial automation devices and the network/external entities. This security device monitors, filters, and secures data traffic without requiring modifications to the legacy devices themselves, thus maintaining compatibility while eliminating security vulnerabilities through external security enforcement

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If security monitoring is implemented for all data traffic, then security detection capability improves, but system complexity increases

Engineering Contradiction:
Improvesecurity detection capabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the security monitoring function into a dedicated security device separate from the operational automation devices. This segmentation allows comprehensive security monitoring to be implemented without complicating the operational devices, as the security functions are isolated in a specialized component that handles only security-related tasks

Inventive Principle:
Principle #1Segmentation

3Productivity

If automatic security enforcement is implemented, then security response time improves, but device complexity increases

Engineering Contradiction:
Improvesecurity response timeVSAvoidsecurity device complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The security device is designed with automatic detection and enforcement capabilities that operate without human intervention. It automatically monitors data traffic, detects security threats, and enforces security policies in real-time, providing rapid security response while the automation of these functions manages the complexity within the security device itself

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12399478B2Systems and methods for automatic security enforcement for industrial automation devices
Publication Date: 2025.08.26 ROCKWELL AUTOMATION TECH INC
  • US12399478B2 patent drawing
  • US12399478B2 patent drawing
  • US12399478B2 patent drawing

AI summary

A security device includes one or more processors and a memory that includes instructions, that when executed by the processors, cause the processors to perform operations. The operations include monitoring data traffic between industrial automation devices in an industrial system and one or more devices in an external network, determining that a first industrial automation device does not include native security features for receiving secure data from the devices in the external network or transmitting secure data to the devices in the external network, and implementing one or more security techniques in response to determining that the first industrial automation device does not include the native security features.