Industrial Network Domain Control for Secure and Fast Communication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing industrial communication networks lack effective mechanisms to differentiate between secure and normal communication domains, leading to inadequate response to network abnormalities and potential security vulnerabilities.
Innovation Solution
Implementing a control system with multiple communication domains, where secure domains perform security processing to detect and respond to network abnormalities, while normal domains prioritize speed and reduced processing load, using error detection codes, data multiplexing, and fail-safe protocols.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If security processing is performed in all communication domains, then network security and reliability are improved, but processing load and communication time increase
Solution Approach 1:
The communication network is segmented into multiple communication domains (secure domain and normal domain) based on security requirements. By dividing the network into distinct domains, security processing is only applied where necessary (secure domain), while normal domain communication maintains high speed without security overhead, thus resolving the contradiction between security and communication time.
Solution Approach 2:
Different security qualities are applied to different parts of the network based on local requirements. The secure domain implements comprehensive security processing for critical communications, while the normal domain uses simplified or no security processing for non-critical communications. This localized approach ensures security where needed without compromising overall network performance.
2Reliability
If security processing is performed in all communication domains, then network security is improved, but processing load increases
Solution Approach 1:
The network is segmented into secure and normal domains, allowing security processing to be concentrated only in the secure domain. This segmentation reduces the overall processing load on the network by eliminating redundant security operations in the normal domain, while maintaining adequate security through targeted protection in critical areas.
Solution Approach 2:
Instead of applying full security processing universally, the system applies security processing partially - only in the secure domain where it is truly necessary. This partial action approach reduces processing load while still providing adequate security protection for critical communications, avoiding the excessive processing that would result from universal security application.
3Reliability
If communication domains are differentiated by security levels, then network resilience is improved, but system complexity increases
Solution Approach 1:
The network is segmented into distinct communication domains with different security characteristics. This segmentation improves resilience by containing security issues to specific domains and preventing them from affecting the entire network. The complexity increase is managed through clear domain definitions and standardized protocols for domain identification and selection.
Solution Approach 2:
The communication system is designed with multi-functionality to handle both secure and normal domain communications through a unified framework. Industrial devices can operate in multiple domains and adapt their behavior based on the current domain context. This universal design approach manages complexity by providing a single system that can function in different security modes rather than requiring separate systems for each domain type.
Data Source
AI summary
A control system includes multiple industrial devices each belonging to one or more communication domains of multiple communication domains set in the same industrial communication network such that industrial devices belonging to the same communication domain communicate with each other. One or more industrial devices of the industrial devices include processing circuitry that stores domain information indicating whether or not the one or more communication domains to which the one or more industrial devices belong is a secure domain in which secure communication is performed, performs security processing related to the secure communication when the domain information indicates the secure domain, and performs the secure communication based on the security processing.


