Physical Isolator for Industrial Data Communication Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing industrial data communication systems face challenges in securely uploading real-time data to the internet, are costly to maintain, and have limitations in scalability and performance due to hierarchical network topology, making it difficult for small enterprises to implement and maintain.

Innovation Solution

A method and system for industrial data communication using dedicated physical isolation, where data collectors transmit data through specific communication media to a physical isolator, which encrypts and uploads it to a cloud platform, bypassing general internet protocols and Ethernet, allowing for secure, efficient, and cost-effective data management with a flat hierarchy control system.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If hierarchical network topology is used for industrial data communication, then data security can be maintained through multiple isolation layers, but system complexity and maintenance costs increase significantly

Engineering Contradiction:
Improvedata securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the security isolation function from the complex hierarchical network structure and concentrates it in a single physical isolator device. This isolator is placed at the boundary between the industrial control network and external networks, removing the need for multiple isolation layers while maintaining security. The isolator acts as a dedicated gateway that provides security without requiring the entire hierarchical structure.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent implements asymmetric communication where the industrial control network initiates connections to the external network, but the external network cannot initiate connections back to the industrial network. This asymmetric access control provides security while simplifying the network topology, as it eliminates the need for symmetric firewall protection in both directions while maintaining data security.

Inventive Principle:
Principle #4Asymmetry

2Reliability

If hierarchical network topology with multiple isolation layers is implemented, then data security is improved, but maintenance costs and system upgrade bottlenecks increase

Engineering Contradiction:
Improvedata securityVSAvoidmaintenance cost
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent merges multiple security isolation functions into a single physical isolator device. Instead of maintaining separate isolation layers at different hierarchical levels, the system uses one consolidated isolator that provides the same security functionality. This reduction in the number of security devices directly lowers maintenance costs and eliminates upgrade bottlenecks associated with managing multiple isolation layers.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The physical isolator is designed as a universal device that performs multiple functions: data security isolation, protocol conversion, and network gateway functionality. By making the isolator multi-functional, the system eliminates the need for separate devices for each function, thereby reducing overall maintenance costs and simplifying system upgrades while maintaining robust data security.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If traditional hierarchical control system with dedicated controlling center is used, then monitoring and control functions are achieved, but initial investment and daily maintenance costs are high

Engineering Contradiction:
Improvemonitoring and control functionVSAvoidinitial investment cost
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent replaces the physical controlling center with a virtualized control system that runs on standard computing hardware. Instead of investing in expensive dedicated controlling center equipment, the system uses software-based control functions that can be deployed on ordinary servers or even cloud infrastructure. This virtualization approach maintains monitoring and control functionality while dramatically reducing initial investment costs.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent changes the fundamental parameter of control system hardware from specialized expensive equipment to standard off-the-shelf computing devices. By transitioning from dedicated hardware to general-purpose computing platforms, the system maintains full monitoring and control capabilities while reducing both initial investment and daily maintenance costs through standardized, commercially available components.

Inventive Principle:
Principle #35Parameter changes

4Adaptability or versatility

If Ethernet and general internet protocols are used for industrial data transmission, then communication versatility is improved, but network security risks increase due to port scanning, invalid accessing, and network attacks

Engineering Contradiction:
Improvecommunication versatilityVSAvoidnetwork security risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces the physical isolator as an intermediary device between the industrial control network and external networks. This isolator acts as a mediator that allows controlled data transmission while blocking malicious traffic. It provides communication versatility by enabling authorized data exchange while simultaneously protecting against network attacks, port scanning, and invalid accessing through its isolation mechanism.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent applies different communication characteristics to different parts of the network. Inside the industrial control network, full Ethernet and internet protocol versatility is maintained for communication needs. At the network boundary, the physical isolator implements restricted communication rules that block harmful traffic. This local differentiation allows the system to maintain communication versatility where needed while applying security restrictions only at the vulnerable boundary points.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS10742680B2Method of industrial data communication with dedicated physical channel isolation and a system applying the method
Publication Date: 2020.08.11 XIAMEN OPTIKOM AUTOMATIC CONTROL TECH CO LTD
  • US10742680B2 patent drawing
  • US10742680B2 patent drawing
  • US10742680B2 patent drawing

AI summary

A method and a system of industrial data communication with dedicated physical isolation are provided that, the data collector and the physical isolator cooperate with each other. The data collector collects the data of each nodes of an enterprise by the intranet or by the wired and wireless communication module. The data is converted into encrypted messages under a protocol. The physical isolator secondarily encrypts the data and uploads the standardized data to a cloud platform via the internet. The data is exchanged between the data collector and the physical isolator by a dedicated data channel. The data transmitted in the dedicated data channel is encrypted by an algorithm, and is transmitted in a form of encrypted messages. Two ports of the dedicated data channel can only transmit the data in the form of encrypted messages. The dedicated data channel uses specific communication media, and forms physical isolation directly.