One-Way Gateway Architecture for Secure Industrial IoT Data Transfer

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data networks in industrial plants face challenges in securely and cost-effectively transmitting data from multiple automation network zones to an IoT backend system without allowing external influence or feedback, especially in complex setups with legacy devices and real-time requirements.

Innovation Solution

A hierarchical one-way gateway solution using multiple first data acquisition units (satellite DCUs) to collect and transmit data to a second data acquisition unit (master DCU) for preprocessing and aggregation, ensuring unidirectional communication and cryptographic protection, with centralized management to maintain security and scalability.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a one-way gateway is installed at each cell to enable intrusion detection, then security monitoring capability is improved, but device complexity and cost increase significantly

Engineering Contradiction:
Improvesecurity monitoring capabilityVSAvoidgateway installation complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines multiple gateway functions (data acquisition, unidirectional transmission, intrusion detection) into a single integrated gateway device. This allows one gateway to serve multiple cells through the factory network, reducing the total number of gateways needed while maintaining security monitoring capability across all cells.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The gateway is designed with multi-functionality to perform data acquisition from multiple automation network zones, unidirectional transmission to the factory network, and intrusion detection simultaneously. This universal design allows a single gateway to replace multiple dedicated gateways, reducing complexity and cost.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If multiple separate gateways are deployed for each automation network zone, then intrusion detection coverage is improved, but installation and operation cost increase

Engineering Contradiction:
Improveintrusion detection coverageVSAvoidinstallation and operation cost
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent merges multiple gateway instances into a single gateway that can acquire data from multiple automation network zones simultaneously. This consolidation maintains comprehensive intrusion detection coverage while significantly reducing the number of devices to install and operate.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The gateway acts as an intermediary that collects data from multiple automation network zones through the factory network and transmits it unidirectionally to the IoT backend. This intermediary approach allows centralized monitoring of multiple zones without requiring separate gateways at each zone.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If traditional bidirectional communication is used, then communication flexibility is improved, but security against external attacks worsens

Engineering Contradiction:
Improvecommunication flexibilityVSAvoidvulnerability to external attacks
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the communication into two separate unidirectional channels: one from the automation network zones to the gateway, and another from the gateway to the IoT backend. This segmentation ensures that data flows only in the intended direction, preventing external attacks while maintaining communication flexibility through proper protocol design.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The gateway serves as a unidirectional intermediary that receives data from automation network zones and forwards it to the IoT backend without allowing reverse communication. This intermediary architecture maintains communication flexibility for data transmission while eliminating the security vulnerabilities associated with bidirectional communication.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP4014467B1Data network having a one-way gateway
Publication Date: 2024.04.10 SIEMENS MOBILITY GMBH DE
  • EP4014467B1 patent drawingFigure 1
  • EP4014467B1 patent drawingFigure 2
  • EP4014467B1 patent drawingFigure 3

AI summary

The invention relates to a data network (1) for industrial systems. The data network (1) is characterised by: - at least one first data capture unit (S-DCU) which is designed to capture first data generated by at least one automation network zone (2) assigned thereto and to transmit said data as second data over a network connection (4); and - a second data capture unit (M-DCU) which is designed to collect second data, the automation network zone (2) comprising at least one automation component (5) and the first data capture unit (S-DCU) and the second data capture unit (M-DCU) together forming a one-way gateway. The invention also relates to a method for operating a data network (1).