Network Guard Unit for Industrial Embedded Systems

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional industrial control system firewalls lack identity authentication, deep protocol parsing, and effective security measures for dynamic port communications, leading to vulnerabilities and inadequate protection against malicious data packets.

Innovation Solution

A network guard unit (NGU) with access control, identity authentication, key negotiation, and data encryption modules, utilizing dual-network card and PCIE communication modes to create a secure, virtual communication link for industrial embedded systems, ensuring secure data exchange and threat management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If traditional IP address based authentication is used in firewalls, then packet filtering can be implemented, but identity authentication capability is lost

Engineering Contradiction:
Improvepacket filteringVSAvoididentity authentication
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a certificate-based authentication mechanism as an intermediary layer between IP address filtering and application-layer security. Each device obtains a digital certificate from a trusted certification authority, and the firewall verifies these certificates to establish identity authentication. This intermediary certificate system enables both packet filtering and reliable identity verification simultaneously.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If packet filtering based on header information is used, then access control is achieved, but deep protocol parsing capability is lost

Engineering Contradiction:
Improveaccess control speedVSAvoidprotocol detection accuracy
Core Design Contradiction:
ProductivityVSMeasurement precision

Solution Approach 1:

The patent segments the packet processing into multiple stages: first performing rapid IP address and port filtering at the network layer, then conducting deep protocol parsing at the application layer for authenticated connections. This segmentation allows the system to maintain high-speed access control for unauthenticated packets while performing thorough protocol analysis only for authenticated traffic, resolving the contradiction between speed and accuracy.

Inventive Principle:
Principle #1Segmentation

3Ease of manufacture

If firewall filtering rules are manually configured, then access control policy is established, but rule correctness and conflict detection become difficult

Engineering Contradiction:
Improvefiltering rule configurationVSAvoidrule correctness
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The patent implements a feedback mechanism where the system automatically detects and reports rule conflicts and incorrect configurations. The firewall monitors packet flow patterns and compares them against configured rules, providing feedback when contradictions are detected. This automated feedback loop enables manual configuration flexibility while maintaining high reliability through continuous validation.

Inventive Principle:
Principle #23Feedback

4Reliability

If traditional firewall architecture is used, then network security is provided, but adaptability to dynamic port assignments is insufficient

Engineering Contradiction:
Improvenetwork securityVSAvoiddynamic port authentication
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces dynamic port authentication mechanisms that work alongside traditional IP-based filtering. The system maintains state information about authenticated connections and dynamically updates filtering rules based on observed communication patterns. This dynamic adaptation allows the firewall to recognize legitimate dynamic port assignments while maintaining security, resolving the contradiction between static security rules and dynamic communication needs.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS11134064B2Network guard unit for industrial embedded system and guard method
Publication Date: 2021.09.28 SHENYANG INST OF AUTOMATION - CHINESE ACAD OF SCI
  • US11134064B2 patent drawing
  • US11134064B2 patent drawing
  • US11134064B2 patent drawing

AI summary

The present invention relates to a network guard unit for an industrial embedded system and a guard method. The specific method is to form the network guard unit (NGU) through security technologies, such as integrated access control, identity authentication and communication data encryption, to provide active guard for a site control device. The NGU comprises an access control module, an identity authentication module, a data encryption module, a key negotiation module and a PCIE communication module, and supports the communication modes of dual network cards and PCIE bus. The present invention builds a secure and trusted operating environment for industrial control systems in combination with an active guard technical means in the field of information security on the basis of ensuring the correctness and the feasibility of security of various terminal devices in the industrial control systems.