Edge Gateway Data Diode for Secure Process Plant Data Streaming

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Process control systems in industrial plants face significant security risks due to interconnections with external networks, which can lead to cyber intrusions and potential hazards such as equipment damage, product loss, and even loss of human life, necessitating secure data delivery mechanisms.

Innovation Solution

An edge gateway system is introduced, featuring a field-facing component connected to process plant networks and an edge-facing component, with a unidirectional data diode for secure data transmission. This system uses interest lists to determine exposable data and employs encryption, ensuring only authorized data is shared with external systems, thus preventing unauthorized access and maintaining system integrity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If process control systems are interconnected with external networks to enable data sharing and remote access, then data accessibility and operational flexibility are improved, but security risks and vulnerability to cyber intrusions increase

Engineering Contradiction:
Improvedata accessibilityVSAvoidsecurity risks
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

A data diode is introduced as an intermediary device between the process control system and external networks. This unidirectional communication device allows data to flow only from the control system to external systems, blocking any reverse communication that could introduce cyber threats. The data diode acts as a physical mediator that enables data sharing while inherently preventing bidirectional communication attacks.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system is segmented into isolated zones: the process control network, the data diode interface, and external network systems. This segmentation creates security boundaries that prevent direct connection between control systems and external networks, allowing data exchange while maintaining isolation to protect against cyber intrusions.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If all process plant data is exposed to external systems for comprehensive data utilization, then external system functionality is improved, but system security and data protection are worsened

Engineering Contradiction:
Improveexternal system functionalityVSAvoidsystem security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

Different data exposure permissions are assigned to different data streams based on their sensitivity and external system requirements. The system selectively exposes only necessary data elements to external systems while keeping critical control data protected, creating localized security policies for different data types rather than a blanket approach.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The data diode serves as a mediator that filters and controls which process plant data reaches external systems. It enables comprehensive data utilization for permitted data types while physically blocking exposure of sensitive control data, thus balancing external functionality with security protection.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If a unidirectional data diode is used for secure data transmission, then security against cyber intrusions is improved, but data transmission flexibility and bidirectional communication are reduced

Engineering Contradiction:
Improvesecurity against cyber intrusionsVSAvoiddata transmission flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system dynamically adapts to unidirectional communication constraints by implementing data caching and buffering mechanisms. When external systems need to send requests or updates, the system uses stored data copies and asynchronous communication patterns to maintain functionality despite the physical unidirectional nature of the data diode connection.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS10915081B1Edge gateway system for secured, exposable process plant data delivery
Publication Date: 2021.02.09 FISHER ROSEMOUNT SYST INC
  • US10915081B1 patent drawing
  • US10915081B1 patent drawing
  • US10915081B1 patent drawing

AI summary

An edge gateway system securely delivers and exposes data generated by and/or related to a process plant for consumption by external systems, and includes a field-facing component that stores interest lists indicating the particular data that is allowed to be exposed by the field-facing component. Each interest list is defined (e.g., manually and/or automatically) in accordance with an exposable data type system extracted from (in some cases, multiple different) configurations of the process plant, and may include multiple types of data (e.g., control, I/O, diagnostic, device, historical, etc.) that collectively represent a particular named entity of the plant. The field-facing component obtains the process plant-related data indicated by the interest lists, and provides the obtained field content data to an edge-facing component of the edge gateway system for exposure to external systems, for example, by streaming and/or publishing the obtained data to the edge-facing component.