Industrial Security Gateway for Legacy Automation Protocols

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Industrial automation devices, particularly legacy devices, lack sufficient security features for monitoring data traffic, making them vulnerable to malicious attacks and compromising the entire system.

Innovation Solution

A security device that automatically detects capabilities and attributes of industrial automation devices, implementing security techniques such as data packet filtering, cryptographically signing, and generating alerts based on communication protocols, and updates itself to handle new protocols.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If legacy industrial automation devices are used without native security features, then device compatibility and ease of operation are maintained, but system security and reliability deteriorate

Engineering Contradiction:
Improvesystem securityVSAvoidsecurity feature implementation
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary security device that positions itself between legacy industrial automation devices and the network/external systems. This intermediary device provides security functions (packet filtering, encryption, authentication) without requiring modifications to the legacy devices themselves, thus maintaining compatibility while improving system security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The security device is designed to work with multiple types of legacy industrial automation devices across different protocols and manufacturers. It provides universal security enforcement capabilities that can be applied to various device types without requiring device-specific security implementations.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If security monitoring is implemented for all data traffic, then security detection capability is improved, but processing time and energy consumption increase

Engineering Contradiction:
Improvesecurity detection capabilityVSAvoiddata processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The security device implements selective monitoring rather than examining every single data packet in depth. It uses partial inspection methods such as examining only packet headers, metadata, or specific fields that indicate potential security threats, rather than fully analyzing the content of all packets, thus reducing processing time while maintaining detection capability.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The device performs preliminary security checks on incoming data packets before they reach the industrial automation devices. It pre-filters and pre-validates data based on security rules and patterns, so that only packets requiring detailed analysis are subjected to more intensive scrutiny, reducing overall processing time.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If comprehensive security techniques are applied to all devices, then security enforcement is improved, but device compatibility and ease of operation worsen

Engineering Contradiction:
Improvesecurity enforcementVSAvoiddevice compatibility
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The security device acts as a transparent intermediary that enforces security policies without requiring configuration changes or software updates on legacy industrial automation devices. It intercepts and processes data packets, applying security rules centrally while leaving individual devices unchanged and easy to operate.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The security device automatically discovers and adapts to the communication protocols and data formats used by connected industrial automation devices. It performs self-configuration by monitoring traffic patterns and learning device-specific protocols, eliminating the need for manual configuration and maintaining ease of operation.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP4307146B1Systems and methods for automatic security enforcement for industrial automation devices
Publication Date: 2026.04.22 ROCKWELL AUTOMATION TECH INC
  • EP4307146B1 patent drawingFigure 1
  • EP4307146B1 patent drawingFigure 2
  • EP4307146B1 patent drawingFigure 3

AI summary

A security device includes one or more processors and a memory that includes instructions, that when executed by the processors, cause the processors to perform operations. The operations include monitoring data traffic between industrial automation devices in an industrial system and one or more devices in an external network, determining that a first industrial automation device does not include native security features for receiving secure data from the devices in the external network or transmitting secure data to the devices in the external network, and implementing one or more security techniques in response to determining that the first industrial automation device does not include the native security features.