One-Way Data Link for Secure OPC Transfer

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing technologies do not provide a secure method for transferring OPC data from a secure process control network to a corporate business network, as direct connections can lead to significant security risks, and conventional protocols like DCOM and TCP/IP are not suitable for one-way data transfer systems.

Innovation Solution

A system utilizing a one-way data link with a send server, a receive server, and stand-alone servers configured to use DCOM and TCP/IP protocols to securely transfer OPC information from a highly secure domain to a less secure domain, ensuring unidirectional data flow and preventing unauthorized data leakage.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If direct connection is used between process control network and corporate business network, then data transfer capability is improved, but network security deteriorates

Engineering Contradiction:
Improvedata transfer capabilityVSAvoidnetwork security
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a one-way data link as an intermediary device between the process control network and corporate business network. This mediator allows data to flow only in one direction (from process control network to corporate network), enabling data transfer while preventing reverse connections that could compromise security. The one-way link acts as a buffer that decouples the two networks physically while maintaining data flow.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If firewall is used to couple two networks, then network security is improved, but security can still be compromised

Engineering Contradiction:
Improvenetwork securityVSAvoidsecurity reliability
Core Design Contradiction:
Object-affected harmful factorsVSReliability

Solution Approach 1:

The patent replaces the software-based firewall mechanism with a hardware-based one-way data link. Instead of relying on software protocols and rules that can be compromised or misconfigured, the solution uses physical hardware that enforces unidirectional data flow at the electrical/optical level. This substitution of mechanical/hardware enforcement for software-based security improves reliability.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Object-affected harmful factors

If one-way data link is implemented, then network security is improved, but data transfer protocols like DCOM and TCP/IP become unsuitable

Engineering Contradiction:
Improvenetwork securityVSAvoidprotocol compatibility
Core Design Contradiction:
Object-affected harmful factorsVSAdaptability or versatility

Solution Approach 1:

The patent segments the data transfer system into three distinct parts: (1) the process control network with OPC servers, (2) the one-way data link for secure transfer, and (3) the corporate network with OPC clients. Each segment uses appropriate protocols for its function - DCOM/TCP/IP on the corporate network side, and a simplified unidirectional protocol on the one-way link. This segmentation allows protocol compatibility where needed while maintaining security where critical.

Inventive Principle:
Principle #1Segmentation

4Adaptability or versatility

If conventional OPC protocols are used for data transfer, then protocol compatibility is improved, but security against unauthorized data leakage deteriorates

Engineering Contradiction:
Improveprotocol compatibilityVSAvoidunauthorized data leakage
Core Design Contradiction:
Adaptability or versatilityVSObject-generated harmful factors

Solution Approach 1:

The patent applies asymmetry by implementing unidirectional data flow where data can only travel from the process control network to the corporate network, never in reverse. This asymmetric communication pattern prevents unauthorized data leakage because the corporate network cannot send commands or data back to the process control system. The asymmetry is enforced physically by the one-way data link hardware.

Inventive Principle:
Principle #4Asymmetry

Data Source

PatentUS9088558B2Secure one-way interface for OPC data transfer
Publication Date: 2015.07.21 OWL CYBER DEFENSE SOLUTIONS LLC
  • US9088558B2 patent drawing
  • US9088558B2 patent drawing
  • US9088558B2 patent drawing

AI summary

A system for transmitting OPC information from a first network in a first security domain to a second network in a second security domain. A first stand-alone server within the first security domain retrieves information via the first network from a first OPC server in the first security domain and forwards the retrieved information to a send server coupled to the first network. The send server forwards the received information received to a receive server via a one-way data link. The receive server receives the information from the send server and forwards the received information to a second stand-alone server via the second network. The second stand-alone server receives the information from the receive server and forwards the information to one or more OPC clients in the second security domain.