Security Protocol Proxy for Legacy OT Device Protection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing OT systems face vulnerabilities due to the presence of legacy devices that do not support secure protocols, making them susceptible to malware attacks, and current protection methods are costly and complex.
Innovation Solution
A firewall and/or security appliance is deployed between external and internal networks, capable of translating secure protocols to non-secure protocols for legacy devices, ensuring secure communication by adding or removing encryption and security aspects as needed based on device capabilities.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If protection devices (bump-in-the-wire) are deployed for each insecure OT device, then security protection is improved, but device complexity and cost increase
Solution Approach 1:
The patent combines multiple protection device functions into a single network firewall/security appliance. Instead of deploying individual bump-in-the-wire devices for each OT device, the firewall consolidates protocol translation, encryption/decryption, and security monitoring capabilities into one centralized system that protects multiple insecure OT devices simultaneously, thereby reducing overall system complexity while maintaining security protection.
Solution Approach 2:
The firewall is designed as a universal protection platform that can handle multiple secure protocols (Modbus TCP Security, BACnet/SCT, etc.) and serve multiple different insecure OT devices through a single interface. This multi-functional approach eliminates the need for device-specific protection appliances, reducing both complexity and cost while providing broad security coverage.
2Reliability
If protection devices are deployed for each insecure OT device, then security protection is improved, but cost increases
Solution Approach 1:
The patent combines multiple protection device functions into a single network firewall/security appliance. Instead of deploying individual bump-in-the-wire devices for each OT device, the firewall consolidates protocol translation, encryption/decryption, and security monitoring capabilities into one centralized system that protects multiple insecure OT devices simultaneously, thereby reducing overall system complexity while maintaining security protection.
Solution Approach 2:
The firewall is designed as a universal protection platform that can handle multiple secure protocols (Modbus TCP Security, BACnet/SCT, etc.) and serve multiple different insecure OT devices through a single interface. This multi-functional approach eliminates the need for device-specific protection appliances, reducing both complexity and cost while providing broad security coverage.
3Adaptability or versatility
If protocol translation is implemented at device level, then legacy device compatibility is improved, but installation complexity increases
Solution Approach 1:
The firewall acts as an intermediary between secure and insecure protocols. Rather than modifying each legacy OT device to support secure protocols, the firewall translates secure protocol traffic into incompatible legacy protocols that legacy devices can understand, maintaining protocol compatibility while simplifying installation since no changes are needed at the legacy device level.
Solution Approach 2:
The firewall creates virtual copies of protocol communication patterns, translating secure protocol messages into legacy protocol formats. This copying approach allows legacy devices to communicate securely without actual hardware modifications, reducing installation complexity while maintaining full protocol compatibility.
Data Source
AI summary
A firewall and/or security appliance is provided between an external network or zone (network/zone) and an internal network/zone having a processing device configured to perform operations including receiving or transmitting inbound and outbound messages of network traffic between the external network/zone, an external port connected to the external network/zone supporting at least one secure protocol, and an internal port connected to the internal network/zone not supporting the at least one secure protocol, and providing firewall and/or security protection for filtering and/or monitoring the network traffic, including adding or removing encryption and/or first applicable security aspects of the at least one secure protocol before transmitting a message depending on whether the message is an inbound or outbound message.


