Industrial Plant Network Security via Protocol Translation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Industrial automation and control systems, increasingly interconnected with enterprise networks, face heightened security threats due to their exposure to malware and other cyber risks, which can lead to significant downtime and liability in modern automated industrial plants.

Innovation Solution

A multi-service packet switch with an embedded application-aware engine (AWE) that recognizes and processes data packets across various industrial protocols, converting them into a common format for security inspection at any OSI layer, and optionally blocking or transmitting packets based on threat assessment, supported by a distributed firewall configuration across the plant network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If industrial plants adopt standard network software and protocols (Ethernet, TCP/IP, HTTP, Windows) to increase flexibility and responsiveness, then adaptability and productivity are improved, but exposure to security threats (malware, viruses, worms, unauthorized access) increases

Engineering Contradiction:
Improveflexibility and responsiveness to market conditionsVSAvoidsecurity threats
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an intermediary security system that sits between the industrial control systems and the enterprise network. This intermediary monitors, filters, and controls data packets flowing through the network, blocking malicious traffic while allowing legitimate communication. The system acts as a buffer that protects the industrial plant from external threats while maintaining network connectivity and standard protocols.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If firewalls and security devices are deployed to protect against malware, then security is improved, but device complexity and potential downtime increase

Engineering Contradiction:
Improvesecurity protectionVSAvoidsecurity system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the security system into multiple functional components distributed across the network infrastructure. Rather than a single complex firewall, the security functionality is divided into packet inspection engines, protocol translators, and filtering mechanisms that operate at different network layers. This segmentation reduces the complexity of any single device while maintaining comprehensive security coverage.

Inventive Principle:
Principle #1Segmentation

3Measurement precision

If comprehensive security inspection at all OSI layers is performed, then measurement precision of security threats is improved, but processing time and productivity are reduced

Engineering Contradiction:
Improvesecurity threat detection accuracyVSAvoiddata packet processing speed
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The patent implements a layered inspection approach where not all packets undergo full multi-layer inspection. Instead, the system performs basic filtering at lower layers (L2-L3) for all packets, and only subjects suspicious or specific types of traffic to deeper application-layer inspection (L7). This partial action approach maintains high detection accuracy for threats while preserving overall network throughput and minimizing processing delays for legitimate traffic.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS9191367B2Plant communication network
Publication Date: 2015.11.17 RADIFLOW
  • US9191367B2 patent drawing
  • US9191367B2 patent drawing
  • US9191367B2 patent drawing

AI summary

An embodiment of the disclosure provides a communication network having a plurality of end devices protected by multilayer switches that receive data packets in different formats for transmission to the end devices, translate received data packets to a common data format for inspection to determine if they pose a security threat, and if they do not pose a threat, forward the data packets to their end device destinations.