One-Way Gateway Architecture for Secure Industrial IoT Data Transfer
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing data networks in industrial plants face challenges in securely and cost-effectively transmitting data from multiple automation network zones to an IoT backend system without allowing external influence or feedback, especially in complex setups with legacy devices and real-time requirements.
Innovation Solution
A hierarchical one-way gateway solution using multiple first data acquisition units (satellite DCUs) to collect and transmit data to a second data acquisition unit (master DCU) for preprocessing and aggregation, ensuring unidirectional communication and cryptographic protection, with centralized management to maintain security and scalability.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a one-way gateway is installed at each cell to enable intrusion detection, then security monitoring capability is improved, but device complexity and cost increase significantly
Solution Approach 1:
The patent combines multiple gateway functions (data acquisition, unidirectional transmission, intrusion detection) into a single integrated gateway device. This allows one gateway to serve multiple cells through the factory network, reducing the total number of gateways needed while maintaining security monitoring capability across all cells.
Solution Approach 2:
The gateway is designed with multi-functionality to perform data acquisition from multiple automation network zones, unidirectional transmission to the factory network, and intrusion detection simultaneously. This universal design allows a single gateway to replace multiple dedicated gateways, reducing complexity and cost.
2Reliability
If multiple separate gateways are deployed for each automation network zone, then intrusion detection coverage is improved, but installation and operation cost increase
Solution Approach 1:
The patent merges multiple gateway instances into a single gateway that can acquire data from multiple automation network zones simultaneously. This consolidation maintains comprehensive intrusion detection coverage while significantly reducing the number of devices to install and operate.
Solution Approach 2:
The gateway acts as an intermediary that collects data from multiple automation network zones through the factory network and transmits it unidirectionally to the IoT backend. This intermediary approach allows centralized monitoring of multiple zones without requiring separate gateways at each zone.
3Adaptability or versatility
If traditional bidirectional communication is used, then communication flexibility is improved, but security against external attacks worsens
Solution Approach 1:
The patent segments the communication into two separate unidirectional channels: one from the automation network zones to the gateway, and another from the gateway to the IoT backend. This segmentation ensures that data flows only in the intended direction, preventing external attacks while maintaining communication flexibility through proper protocol design.
Solution Approach 2:
The gateway serves as a unidirectional intermediary that receives data from automation network zones and forwards it to the IoT backend without allowing reverse communication. This intermediary architecture maintains communication flexibility for data transmission while eliminating the security vulnerabilities associated with bidirectional communication.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
The invention relates to a data network (1) for industrial systems. The data network (1) is characterised by: - at least one first data capture unit (S-DCU) which is designed to capture first data generated by at least one automation network zone (2) assigned thereto and to transmit said data as second data over a network connection (4); and - a second data capture unit (M-DCU) which is designed to collect second data, the automation network zone (2) comprising at least one automation component (5) and the first data capture unit (S-DCU) and the second data capture unit (M-DCU) together forming a one-way gateway. The invention also relates to a method for operating a data network (1).