Process Plant Gateway With Data Diode for Secure External Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Process control systems in industrial plants face significant security challenges due to increased connectivity with external networks, making them vulnerable to cyber intrusions that can lead to equipment damage, product loss, and even human safety risks, as existing security measures are insufficient to prevent unauthorized data access and malicious attacks.

Innovation Solution

An edge gateway system is introduced, featuring a field-facing component connected to the process plant and an edge-facing component via a unidirectional data diode, which securely delivers process plant data to external systems by storing and mining data in a contextualized knowledge repository, providing mechanisms for external access while preventing reverse data flow and ensuring high-security data transmission.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If process control systems are connected to external networks for data access, then external systems can utilize process plant data, but the system becomes vulnerable to cyber intrusions and unauthorized access

Engineering Contradiction:
Improveexternal data access capabilityVSAvoidcyber intrusion vulnerability
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an edge gateway system as an intermediary component between the process control system and external networks. This gateway includes a field-facing component that connects to the process control system and an edge-facing component that interfaces with external systems, with a unidirectional data diode between them. The gateway mines process data to generate contextualized knowledge and delivers it to external systems without allowing direct access to the process control system, thus enabling external data utilization while preventing cyber intrusions.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Loss of information

If data is made accessible to external systems, then external systems can consume process plant knowledge, but unauthorized access and malicious attacks increase

Engineering Contradiction:
Improvedata availability to external systemsVSAvoidsystem security
Core Design Contradiction:
Loss of informationVSReliability

Solution Approach 1:

The patent segments the data delivery architecture into multiple isolated components: the process control system, the edge gateway system with field-facing and edge-facing components, and external systems. The unidirectional data diode creates a one-way data flow that allows information to be delivered to external systems while preventing any reverse access or control signals from reaching the process control system, thus maintaining security while enabling data availability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The edge gateway system acts as a mediator that transforms raw process data into contextualized knowledge through data mining and relationships discovery, then delivers this processed information to external systems. This intermediary processing layer ensures that external systems receive useful information without gaining direct access to the underlying process control system, maintaining both data availability and system reliability.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If existing security measures are used to protect process control systems, then some level of protection is provided, but they are insufficient to prevent unauthorized data access and malicious attacks

Engineering Contradiction:
Improvesecurity protection levelVSAvoidunauthorized access and malicious attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements an edge gateway system as a security intermediary that sits between the process control system and external networks. This gateway performs data mining on process data to create contextualized knowledge, then delivers this knowledge to external systems through a unidirectional data diode. This architecture provides robust security by allowing external systems to consume processed information while completely isolating them from the process control system, preventing unauthorized access and malicious attacks that would otherwise penetrate through existing security measures.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20220405278A1Gateway system with contextualized process plant knowledge repository
Publication Date: 2022.12.22 FISHER ROSEMOUNT SYST INC
  • US20220405278A1 patent drawing
  • US20220405278A1 patent drawing
  • US20220405278A1 patent drawing

AI summary

A gateway system securely delivers and exposes data generated by and/or related to a process plant for consumption by external systems, and includes an edge-facing component that receives process plant-related data from a process plant via a field-facing component of the system. The received data may comport with an exposable data type system utilizing a syntax known to the external systems. The edge-facing component stores the received data in a data lake, and mines the data lake to thereby discover relationships between stored data points. Indications of the received data and the discovered interrelationships are stored in a contextualized process plant knowledge repository, such as a graph database, that is accessible to the external systems and other systems and applications via one or more access mechanisms, which may include utilities, services, servers, and/or applications. Some of the access mechanisms allow external applications to be installed at the edge-facing component.