Industrial Security Gateway for Legacy Automation Protocols
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Industrial automation devices, particularly legacy devices, lack sufficient security features for monitoring data traffic, making them vulnerable to malicious attacks and compromising the entire system.
Innovation Solution
A security device that automatically detects capabilities and attributes of industrial automation devices, implementing security techniques such as data packet filtering, cryptographically signing, and generating alerts based on communication protocols, and updates itself to handle new protocols.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If legacy industrial automation devices are used without native security features, then device compatibility and ease of operation are maintained, but system security and reliability deteriorate
Solution Approach 1:
The patent introduces an intermediary security device that positions itself between legacy industrial automation devices and the network/external systems. This intermediary device provides security functions (packet filtering, encryption, authentication) without requiring modifications to the legacy devices themselves, thus maintaining compatibility while improving system security.
Solution Approach 2:
The security device is designed to work with multiple types of legacy industrial automation devices across different protocols and manufacturers. It provides universal security enforcement capabilities that can be applied to various device types without requiring device-specific security implementations.
2Reliability
If security monitoring is implemented for all data traffic, then security detection capability is improved, but processing time and energy consumption increase
Solution Approach 1:
The security device implements selective monitoring rather than examining every single data packet in depth. It uses partial inspection methods such as examining only packet headers, metadata, or specific fields that indicate potential security threats, rather than fully analyzing the content of all packets, thus reducing processing time while maintaining detection capability.
Solution Approach 2:
The device performs preliminary security checks on incoming data packets before they reach the industrial automation devices. It pre-filters and pre-validates data based on security rules and patterns, so that only packets requiring detailed analysis are subjected to more intensive scrutiny, reducing overall processing time.
3Reliability
If comprehensive security techniques are applied to all devices, then security enforcement is improved, but device compatibility and ease of operation worsen
Solution Approach 1:
The security device acts as a transparent intermediary that enforces security policies without requiring configuration changes or software updates on legacy industrial automation devices. It intercepts and processes data packets, applying security rules centrally while leaving individual devices unchanged and easy to operate.
Solution Approach 2:
The security device automatically discovers and adapts to the communication protocols and data formats used by connected industrial automation devices. It performs self-configuration by monitoring traffic patterns and learning device-specific protocols, eliminating the need for manual configuration and maintaining ease of operation.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A security device includes one or more processors and a memory that includes instructions, that when executed by the processors, cause the processors to perform operations. The operations include monitoring data traffic between industrial automation devices in an industrial system and one or more devices in an external network, determining that a first industrial automation device does not include native security features for receiving secure data from the devices in the external network or transmitting secure data to the devices in the external network, and implementing one or more security techniques in response to determining that the first industrial automation device does not include the native security features.