PLC Proxy Security Module for Patchless Network Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Industrial control systems face vulnerabilities due to existing security patch solutions that often require shutting down the entire control network for installation, are incompatible with existing software, and fail to effectively combat security threats, leading to prolonged exposure and user dissatisfaction.

Innovation Solution

A network security module acts as a PLC proxy to implement security patches and monitor traffic, providing real-time protection by cloning MAC and IP addresses, filtering threats, and receiving automatic updates from the cloud, thereby minimizing downtime and latency.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If software patches are installed to secure industrial control systems, then security protection is improved, but system downtime increases due to required shutdowns for patch installation

Engineering Contradiction:
Improvesecurity protectionVSAvoidsystem downtime
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

A network security module is introduced as an intermediary component between the PLC and the network. This module handles security patching and threat filtering independently, allowing the PLC to remain operational during security updates. The security module acts as a proxy that can be updated without shutting down the control network, thus resolving the contradiction between maintaining security protection and avoiding system downtime.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If traditional security patches are applied to PLCs, then security vulnerabilities are addressed, but compatibility issues arise with existing control system software

Engineering Contradiction:
Improvesecurity vulnerability protectionVSAvoidsoftware compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The security functionality is segmented from the PLC's core control software. The network security module operates as a separate, independent component that handles security functions. This segmentation allows the PLC's existing control software to continue running without modification while the security module provides updated protection, eliminating compatibility issues between security patches and legacy control system software.

Inventive Principle:
Principle #1Segmentation

3Manufacturing precision

If there is a large time gap between security tag identification and patch installation, then thorough testing is possible, but the control system remains vulnerable to threats during this period

Engineering Contradiction:
Improvepatch testing qualityVSAvoidsystem vulnerability exposure
Core Design Contradiction:
Manufacturing precisionVSObject-affected harmful factors

Solution Approach 1:

The network security module continuously monitors for security threats and automatically receives and applies patches in real-time without waiting for scheduled maintenance windows. This preliminary and continuous action ensures that security updates are applied immediately when threats are identified, eliminating the vulnerable time gap while maintaining system operational integrity through the intermediary security module.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP3175304B1Apparatus and method for security of industrial control networks
Publication Date: 2022.05.11 INTELLIGENT PLATFORMS LLC
  • EP3175304B1 patent drawingFigure 1
  • EP3175304B1 patent drawingFigure 2
  • EP3175304B1 patent drawingFigure 3~4

AI summary

Approaches for providing security for a programmable logic controller (PLC) are provided and include cloning a security module as a PLC proxy by copying at least one of a media access control (MAC) address and an internet protocol (IP) address of the PLC and determining, based on a predetermined security criteria, whether to route the message to the PLC. Based on the determination, the message is selectively routed to the PLC. So configured, by clonmg the security module as the PLC proxy is effective to route network traffic intended for the PLC to the security module.