Physical Isolator for Industrial Data Communication Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing industrial data communication systems face challenges in securely uploading real-time data to the internet, are costly to maintain, and have limitations in scalability and performance due to hierarchical network topology, making it difficult for small enterprises to implement and maintain.
Innovation Solution
A method and system for industrial data communication using dedicated physical isolation, where data collectors transmit data through specific communication media to a physical isolator, which encrypts and uploads it to a cloud platform, bypassing general internet protocols and Ethernet, allowing for secure, efficient, and cost-effective data management with a flat hierarchy control system.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If hierarchical network topology is used for industrial data communication, then data security can be maintained through multiple isolation layers, but system complexity and maintenance costs increase significantly
Solution Approach 1:
The patent extracts the security isolation function from the complex hierarchical network structure and concentrates it in a single physical isolator device. This isolator is placed at the boundary between the industrial control network and external networks, removing the need for multiple isolation layers while maintaining security. The isolator acts as a dedicated gateway that provides security without requiring the entire hierarchical structure.
Solution Approach 2:
The patent implements asymmetric communication where the industrial control network initiates connections to the external network, but the external network cannot initiate connections back to the industrial network. This asymmetric access control provides security while simplifying the network topology, as it eliminates the need for symmetric firewall protection in both directions while maintaining data security.
2Reliability
If hierarchical network topology with multiple isolation layers is implemented, then data security is improved, but maintenance costs and system upgrade bottlenecks increase
Solution Approach 1:
The patent merges multiple security isolation functions into a single physical isolator device. Instead of maintaining separate isolation layers at different hierarchical levels, the system uses one consolidated isolator that provides the same security functionality. This reduction in the number of security devices directly lowers maintenance costs and eliminates upgrade bottlenecks associated with managing multiple isolation layers.
Solution Approach 2:
The physical isolator is designed as a universal device that performs multiple functions: data security isolation, protocol conversion, and network gateway functionality. By making the isolator multi-functional, the system eliminates the need for separate devices for each function, thereby reducing overall maintenance costs and simplifying system upgrades while maintaining robust data security.
3Reliability
If traditional hierarchical control system with dedicated controlling center is used, then monitoring and control functions are achieved, but initial investment and daily maintenance costs are high
Solution Approach 1:
The patent replaces the physical controlling center with a virtualized control system that runs on standard computing hardware. Instead of investing in expensive dedicated controlling center equipment, the system uses software-based control functions that can be deployed on ordinary servers or even cloud infrastructure. This virtualization approach maintains monitoring and control functionality while dramatically reducing initial investment costs.
Solution Approach 2:
The patent changes the fundamental parameter of control system hardware from specialized expensive equipment to standard off-the-shelf computing devices. By transitioning from dedicated hardware to general-purpose computing platforms, the system maintains full monitoring and control capabilities while reducing both initial investment and daily maintenance costs through standardized, commercially available components.
4Adaptability or versatility
If Ethernet and general internet protocols are used for industrial data transmission, then communication versatility is improved, but network security risks increase due to port scanning, invalid accessing, and network attacks
Solution Approach 1:
The patent introduces the physical isolator as an intermediary device between the industrial control network and external networks. This isolator acts as a mediator that allows controlled data transmission while blocking malicious traffic. It provides communication versatility by enabling authorized data exchange while simultaneously protecting against network attacks, port scanning, and invalid accessing through its isolation mechanism.
Solution Approach 2:
The patent applies different communication characteristics to different parts of the network. Inside the industrial control network, full Ethernet and internet protocol versatility is maintained for communication needs. At the network boundary, the physical isolator implements restricted communication rules that block harmful traffic. This local differentiation allows the system to maintain communication versatility where needed while applying security restrictions only at the vulnerable boundary points.
Data Source
AI summary
A method and a system of industrial data communication with dedicated physical isolation are provided that, the data collector and the physical isolator cooperate with each other. The data collector collects the data of each nodes of an enterprise by the intranet or by the wired and wireless communication module. The data is converted into encrypted messages under a protocol. The physical isolator secondarily encrypts the data and uploads the standardized data to a cloud platform via the internet. The data is exchanged between the data collector and the physical isolator by a dedicated data channel. The data transmitted in the dedicated data channel is encrypted by an algorithm, and is transmitted in a form of encrypted messages. Two ports of the dedicated data channel can only transmit the data in the form of encrypted messages. The dedicated data channel uses specific communication media, and forms physical isolation directly.


