OT Security Device Intercepting Control Commands

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Operational technology (OT) and Internet of Things (IoT) networks lack effective cybersecurity protections, making them vulnerable to cyber threats that can disrupt operations, cause safety issues, and degrade production processes, as traditional IT security solutions are inadequate for these environments due to resource constraints and different security objectives.

Innovation Solution

A security device is introduced to monitor and intercept communications within OT and IoT networks, using artificial intelligence to detect and block undesirable control commands, authenticate sources, and log forensic data, while providing data validation and anomaly detection to ensure system integrity and reliability.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Object-affected harmful factors

If traditional IT security solutions (firewalls, virus protection, network segmentation) are applied to OT networks, then attack apertures are reduced, but the specific vulnerabilities of OT networks designed for process efficiency and safety remain unaddressed

Engineering Contradiction:
Improvecyber security threatsVSAvoidadaptability to OT network specific vulnerabilities
Core Design Contradiction:
Object-affected harmful factorsVSAdaptability or versatility

Solution Approach 1:

The patent introduces a security device as an intermediary component that sits between the HMI and ICD in the control system architecture. This intermediary monitors and analyzes control commands before they reach the ICD, detecting anomalies and potential cyber threats without disrupting the core control functionality. The security device mediates between the HMI operator interface and the ICD control logic, providing specialized OT-aware security protection that traditional IT firewalls cannot provide.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If conventional control systems are interconnected to communication networks for automation and efficiency, then process control capability is enhanced, but vulnerability to cyber security threats increases

Engineering Contradiction:
Improveprocess efficiencyVSAvoidcyber security threats
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The security device serves as a mediator that enables safe network connectivity for process efficiency while protecting against cyber threats. It allows control commands to flow through the network for automation purposes while simultaneously monitoring for malicious activity, thus maintaining productivity without exposing the system to unchecked cyber risks.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The security device implements continuous feedback by monitoring control commands in real-time, analyzing them for anomalies, and providing immediate responses to detected threats. This feedback mechanism allows the system to maintain efficient operation while dynamically adjusting security responses to emerging threats, ensuring both productivity and security.

Inventive Principle:
Principle #23Feedback

3Ease of operation

If ICDs reside on wired or wireless networks for control functions, then system connectivity is improved, but the control devices are inherently not secured against cyber threats

Engineering Contradiction:
Improvenetwork connectivityVSAvoidsecurity against cyber threats
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The security device acts as a protective intermediary between the networked HMI and ICD, enabling the ICD to maintain network connectivity for ease of operation while the security device filters and secures the communication. This allows control devices to remain connected for operational efficiency without being directly exposed to network-based cyber threats.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11818098B2Security system, device, and method for protecting control systems
Publication Date: 2023.11.14 SERVICENOW INC
  • US11818098B2 patent drawing
  • US11818098B2 patent drawing
  • US11818098B2 patent drawing

AI summary

A protection system, method, and a security device can protect an operational technology (OT) system having connected hardware equipment, including at least an interface that can receive a control communication and an industrial control device (ICD) for controlling at least one industrial device. They feature tasks/steps that receive control communication from the communication interface, determine whether the received control communication contains an undesirable control command, and either pass or block the received control communication to the ICD depending on whether the received control communication contains an undesirable control command. The security device can be disposed between a source of communication in an OT network and the ICD for protection.