Location-Specific Gateway for Secure OT-IT Integration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current industrial control systems face challenges in achieving desired security levels due to complex infrastructure requirements and compatibility issues between operational technology (OT) and information technology (IT) networks, leading to insecure data transfer practices and increased latency when integrating cloud-based components.

Innovation Solution

A new process control and automation system architecture that implements a shared, virtualized compute fabric, allowing for robust and secure communication between physical devices and IT infrastructure, bypassing traditional Purdue model constraints by using containerized components and virtual private networks for secure data transmission.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional Purdue model architecture is used for industrial control systems, then security infrastructure is established, but device complexity and integration difficulty increase

Engineering Contradiction:
ImprovesecurityVSAvoidinfrastructure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a gateway device as an intermediary component that bridges the OT network (process control network) and IT network (enterprise network). This gateway handles protocol translation, data formatting, and secure communication protocols, allowing secure integration without requiring complex infrastructure changes throughout the entire system. The gateway acts as a mediator that resolves compatibility issues between OT and IT networks while maintaining security boundaries.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the network architecture into distinct zones (OT zone, DMZ, IT zone) with controlled communication pathways. By dividing the system into modular segments with defined interfaces and communication protocols, the complexity of securing the entire system is reduced to managing security at specific boundary points rather than throughout the entire infrastructure.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If cloud-based components are integrated into industrial control systems, then system functionality and flexibility improve, but latency increases due to network transmission

Engineering Contradiction:
Improvesystem flexibilityVSAvoidcommunication latency
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The patent implements edge computing capabilities at the gateway and local control levels, allowing critical control functions to execute locally rather than requiring constant cloud communication. Time-sensitive control operations are performed at the edge with minimal network latency, while non-critical data processing and analytics are offloaded to cloud-based components. This creates different quality levels of computation based on location and function.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system dynamically routes communication paths based on data priority and timing requirements. Critical control commands and real-time data follow low-latency local pathways, while non-critical monitoring and historical data can traverse cloud-based pathways. The architecture adapts communication routes in real-time to optimize for either speed or functionality based on operational needs.

Inventive Principle:
Principle #15Dynamics

3Adaptability or versatility

If OT and IT networks are integrated for data transfer, then system interoperability improves, but security vulnerabilities increase due to protocol incompatibilities

Engineering Contradiction:
Improvenetwork interoperabilityVSAvoidsecurity vulnerabilities
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The gateway serves as a security intermediary that validates, translates, and sanitizes data between OT and IT networks. It implements protocol translation while enforcing security policies, filtering malicious content, and ensuring data integrity. The gateway mediates all communications between the two networks, preventing direct exposure of vulnerable OT devices to IT network threats while maintaining interoperability.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent converts the potential harm of protocol incompatibilities and network exposure into a benefit by using the gateway to enforce strict communication protocols and validation rules. The very act of translation and adaptation required for interoperability creates additional security checkpoints where data can be validated, authenticated, and sanitized, turning the complexity of integration into a security advantage.

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

Data Source

PatentUS20240039870A1Location specific communications gateway for multi-site enterprise
Publication Date: 2024.02.01 FISHER ROSEMOUNT SYST INC
  • US20240039870A1 patent drawing
  • US20240039870A1 patent drawing
  • US20240039870A1 patent drawing

AI summary

A process plant and industrial control system architecture includes a generalized compute fabric that is agnostic or indifferent to the physical location at which the compute fabric is implemented, includes one or more physical control or field devices located at one or more specific plant sites at which a product or process is being manufactured and further includes a transport network that securely provides communications between the compute fabric and the pool of physical devices using a communications gateway device at each plant site that provides secured communications between the compute fabric and the one or more physical control or field devices at each plant site. The communications gateway at each plant site implements one or more secured point-to-point or peer-to-peer communication networks between the compute fabric and the plant site using one or more virtual private networks.