OT Gateway Protocol Conversion With Application-Layer Security Filtering

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The integration of operational technology (OT) systems into IT networks poses security challenges due to incompatibilities, vulnerabilities, and increased cyber attack risks, with existing solutions like firewalls and converters providing insufficient security and flexibility for secure data exchange.

Innovation Solution

A method and apparatus that decodes and examines data at the application layer to ensure secure communication between OT and IT networks by extracting and generating messages based on examination results, using protocol stacks to handle different protocols and protocols stacks, ensuring asynchronous communication and access control.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If OT systems are integrated into IT networks to enable remote monitoring and control, then automation and connectivity are improved, but security vulnerabilities and cyber attack risks increase

Engineering Contradiction:
ImproveconnectivityVSAvoidsecurity risks
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a gateway as an intermediary device between IT and OT networks. The gateway performs protocol conversion and message examination, acting as a secure mediator that enables communication while filtering malicious content. The gateway extracts information pieces from messages, examines them against security rules, and only forwards legitimate messages, thus resolving the contradiction between connectivity and security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the network infrastructure into separate IT and OT network zones with a gateway in between. This segmentation isolates vulnerable OT systems from direct Internet exposure while maintaining controlled connectivity. The gateway creates a boundary that allows necessary communication while blocking security threats.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If protocol converters are used to enable communication between different OT and IT systems, then interoperability is improved, but security protection against cyber attacks remains insufficient

Engineering Contradiction:
ImproveinteroperabilityVSAvoidsecurity protection
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent merges protocol conversion functionality with security examination functionality into a single gateway device. Instead of using separate converters that only translate protocols, the gateway simultaneously performs protocol conversion and security filtering by examining message content at the application layer, thus achieving both interoperability and security protection.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The gateway serves as a secure intermediary that not only translates between different protocols but also actively examines message content for security threats. It mediates communication by filtering malicious content while allowing legitimate data exchange, thereby improving both interoperability and security reliability.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If firewalls are used to restrict communication to necessary protocols, then security is improved, but communication flexibility and adaptability to different protocols deteriorate

Engineering Contradiction:
ImprovesecurityVSAvoidcommunication flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The gateway dynamically changes communication parameters by adapting to different protocols while maintaining security. Instead of restricting communication to fixed protocols like traditional firewalls, the gateway examines message content and adapts its filtering rules based on the specific protocol and message type, thus providing both security and communication flexibility.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The security examination mechanism is dynamic rather than static. The gateway adapts its security rules and examination criteria based on the specific protocol being used and the content of each message. This dynamic approach allows the system to maintain high security while accommodating diverse communication protocols and formats.

Inventive Principle:
Principle #15Dynamics

4Reliability

If safety-related software is installed on manufacturer hardware, then system security is improved, but hardware performance becomes sluggish and control software malfunctions

Engineering Contradiction:
Improvesystem securityVSAvoidhardware performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The gateway acts as an intermediary security layer that protects OT systems without requiring installation of security software on the hardware itself. By performing security examination externally at the gateway, the system achieves security protection while maintaining the original hardware performance and control software functionality.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12580889B2Specific use of a gateway in operational technology networks
Publication Date: 2026.03.17 TRIOVEGA GMBH
  • US12580889B2 patent drawing
  • US12580889B2 patent drawing
  • US12580889B2 patent drawing

AI summary

The invention relates to an apparatus configured to receive an input message via the first interface. The input message having a first layer structure and containing an information piece associated with the top layer of the first layer structure, extracting the information piece from the input message by passing the input message through a protocol stack associated with the first layer structure from bottom to top, examining the extracted information piece to obtain an examination result, generating an output message by passing the extracted information piece or an information piece generated on the basis of the extracted information piece through a protocol stack associated with a second layer structure from top to bottom, and sending the output message via the second interface. The generating and/or the sending of the output message are performed as a function of the examination result.