PLC Communication Module Network Isolation Filter
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Industrial Ethernet networks in critical automation environments are vulnerable to cyber-attacks and non-intentional disruptions, leading to potential safety hazards and significant losses, as traditional security solutions fail to provide adequate authentication, integrity, and confidentiality mechanisms, and are not easily patchable.
Innovation Solution
An Ethernet communication interface module for programmable logic controllers (PLCs) with integrated Ethernet switch and processor configuration to filter packets at OSI layers 2 and 3, extracting and verifying MAC and IP addresses, and applying predetermined criteria to control packet flow, ensuring only intended communication is allowed between plant and control/office networks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional firewalls or security measures are used to separate industrial network from other networks, then external cyber-attacks are partially prevented, but the industrial network remains vulnerable to attacks by viruses, worms, Trojans, and other malicious code
Solution Approach 1:
The patent segments the network filtering function into multiple layers (Layer 2 MAC address filtering, Layer 3 IP address filtering, and Layer 7 application protocol filtering). Each layer independently filters packets based on different criteria, creating a multi-layered security architecture that addresses the limitations of traditional single-layer firewalls.
Solution Approach 2:
The communication module acts as an intermediary device between the control network and the plant network. It intercepts and filters all packets passing between these networks, applying multiple filtering criteria before allowing packets to reach their destination, thereby preventing malicious code from directly accessing the industrial network.
2Productivity
If a device is legitimately connected to the control system, then information flows and efficiency are improved, but the device may inundate the network with messages to another device, adversely affecting time-critical communication requirements
Solution Approach 1:
The patent implements dynamic packet filtering that adapts to network conditions. The Layer 7 application protocol filter dynamically identifies and prioritizes time-critical communication protocols while blocking or rate-limiting non-critical traffic, allowing the system to maintain high productivity for essential communications while preventing network inundation.
Solution Approach 2:
The communication module monitors network traffic patterns and provides feedback control by adjusting packet filtering decisions based on real-time network conditions. When detecting excessive message rates or communication failures, the module dynamically adjusts filtering rules to maintain reliable time-critical communications.
3Adaptability or versatility
If Ethernet technology is used to connect PLCs and industrial instruments, then communication capability is improved, but traditional off-the-shelf Ethernet equipment cannot meet high reliability requirements of industrial applications
Solution Approach 1:
The patent applies specialized quality control at each layer of the communication module tailored to industrial requirements. Layer 2 filtering uses MAC address validation, Layer 3 filtering uses IP address and protocol validation, and Layer 7 filtering uses application-specific protocol validation. Each layer provides localized quality assurance appropriate to its function, ensuring high reliability for industrial applications.
4Reliability
If security measures are implemented to protect industrial networks, then external attacks are reduced, but security measures are not foolproof and may be bypassed by modems, direct connections, or VPNs
Solution Approach 1:
The communication module performs preliminary action by filtering packets at multiple layers before they can reach the industrial network. By validating MAC addresses, IP addresses, and application protocols in advance, the module prevents bypass attempts through modems, direct connections, or VPNs from successfully compromising the network.
Solution Approach 2:
The patent adds another dimension to security by implementing filtering at Layer 7 (application protocol level) in addition to traditional Layer 2 and Layer 3 filtering. This additional dimensional layer of security makes it significantly harder for attackers to bypass security measures, as they would need to successfully circumvent multiple independent filtering mechanisms operating at different protocol layers.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Aspects of the invention provide apparatuses, systems, and computer readable media for protecting a programmable logic controller (PLC) 201 and plant network 203 against unauthorized access and for providing robust intended communication. A communication module 211 provides only intended communication and blocks all unintended communication between the plant network and a control network/office network 205 without using external infrastructure network devices. The communication module includes an Ethernet switch 303 and ports that electrically couple the CPU module 209, a plant network, and control/office network and controls communication to the PLC and the plant network from the control/office network by forwarding packets based on configuration information 406 and 504, where the packets are received through the ports. The communication module passes packets only when the associated source address and destination address are in accordance with the configuration information. The communication module may further pass packets based on packet traffic limits.