NAT System Security Policy Enforcement for Internal Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Industrial automation systems face challenges in securing communications between internal networks and external networks, as components behind a Network Address Translation (NAT) system may not be provisioned for security updates, making them vulnerable to threats and unable to send data using appropriate protocols.

Innovation Solution

A method and system that allow internal components to discover and communicate with servers on external networks through a NAT boundary, using a processor to transmit requests for security policies and adjust communication operations based on received policies, ensuring secure communication protocols are enforced.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If internal components communicate directly with external servers, then security policy updates can be delivered, but the internal network becomes vulnerable to external threats

Engineering Contradiction:
Improvesecurity policy deliveryVSAvoidexternal network threats
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The NAT system acts as an intermediary between internal components and external servers. Internal components send discovery requests through the NAT system, which forwards them to external servers. The NAT system then relays security policy responses back to internal components, enabling secure policy delivery without direct external access to the internal network.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The network is segmented into internal and external portions with the NAT system forming a boundary. This segmentation allows internal components to obtain security policies while maintaining network isolation, as the NAT system controls and filters all communications between the two network segments.

Inventive Principle:
Principle #1Segmentation

2Object-affected harmful factors

If internal components remain isolated behind NAT boundary, then network security is maintained, but components cannot receive security updates or communicate with external servers

Engineering Contradiction:
Improvenetwork securityVSAvoidsecurity update delivery
Core Design Contradiction:
Object-affected harmful factorsVSReliability

Solution Approach 1:

The NAT system serves as a mediator that enables controlled communication between isolated internal components and external servers. Internal components can discover servers and request security policies through the NAT system, which facilitates these communications while maintaining the protective boundary.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

Internal components autonomously initiate discovery requests and security policy updates through the NAT boundary. The components themselves perform the actions of finding servers and requesting policies, eliminating the need for external systems to actively push updates through the NAT boundary.

Inventive Principle:
Principle #25Self-service

3Loss of information

If internal components initiate discovery requests through NAT system, then server location can be obtained, but communication protocols must be properly enforced

Engineering Contradiction:
Improveserver location dataVSAvoidcommunication protocol enforcement
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The NAT system enforces communication protocols by requiring internal components to follow specific procedures: initiating discovery requests, receiving server location data, and subsequently requesting security policies. This feedback loop ensures protocols are properly enforced while obtaining necessary server information.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11271974B2Securely deploying security policy and configuration through network address translation systems
Publication Date: 2022.03.08 ROCKWELL AUTOMATION TECH INC
  • US11271974B2 patent drawing
  • US11271974B2 patent drawing
  • US11271974B2 patent drawing

AI summary

A device may include a communication component that may communicatively couple to a first network. The device may also include a processor that may transmit a first signal via the communication component to a network address translation (NAT) system, the first signal including a first request to discover a server device. The NAT system may communicatively couple to the first network and a second network, such that the first network is inaccessible to the second network. The processor may then receive location data associated with the server device and transmit a second signal addressed to the server device based on the location data. The second signal is transmitted to the NAT system, such that the second signal may include a second request for a security policy from the server device. The processor may then receive the security policy via the NAT system and adjust one or more communication operations based on the security policy.