Policy Evaluation System for Control Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing control systems for social infrastructure face challenges in evaluating the validity of new filtering policies without affecting normal operations, especially when configurations change post-delivery, and are vulnerable to malware and unauthorized access due to increased connectivity.

Innovation Solution

A system comprising a network device, a gateway device, and a policy evaluation device that copies and filters packets, allowing evaluation of new filtering policies in a real environment without disrupting operations by using a test server for rare packets and evaluating filtering processing time.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a simulation environment is used to evaluate filtering policies, then policy evaluation can be performed without affecting real operations, but it becomes difficult to rebuild the local environment when configurations change post-delivery

Engineering Contradiction:
Improveoperational reliabilityVSAvoidenvironment adaptability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent creates a copy of the actual communication packets flowing through the control system and routes them to a policy evaluation device. This copying approach allows the evaluation device to analyze filtering policies using real packet data without interfering with the original system operations, thereby maintaining both operational reliability and environmental adaptability

Inventive Principle:
Principle #26Copying

Solution Approach 2:

A network device acts as an intermediary to capture and copy packets from the control system, then forward copies to both the gateway device (for actual filtering) and the policy evaluation device (for policy assessment). This intermediary mechanism enables parallel evaluation without disrupting normal operations or requiring environment reconstruction

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If the actual environment is used for policy evaluation, then real operational data can be utilized, but the usual operation of the control system may be affected

Engineering Contradiction:
Improveevaluation accuracyVSAvoidsystem throughput
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The patent segments the packet flow into multiple copies: one copy continues through the normal gateway device for actual filtering and system operation, while another copy is diverted to the policy evaluation device for policy assessment. This segmentation allows both accurate evaluation using real data and maintenance of normal system throughput without interference

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The network device creates a duplicate copy of each packet received from the control system. The original packet proceeds to the gateway device for normal filtering operations, while the copied packet is sent to the policy evaluation device. This copying mechanism enables simultaneous evaluation and operation without performance degradation

Inventive Principle:
Principle #26Copying

3Ease of manufacture

If general-purpose OS and protocol are used for cost reduction, then system cost decreases, but vulnerability to malware and unauthorized access increases

Engineering Contradiction:
Improvesystem costVSAvoidsecurity vulnerability
Core Design Contradiction:
Ease of manufactureVSObject-affected harmful factors

Solution Approach 1:

The patent implements a policy evaluation device that assesses filtering policies before they are applied to the control system. This preliminary evaluation identifies potential security vulnerabilities and ineffective policies, allowing administrators to correct issues before deployment, thereby reducing security risks associated with using general-purpose OS and protocols

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The policy evaluation device provides feedback on the effectiveness and security implications of proposed filtering policies. This feedback mechanism allows administrators to refine and improve policies iteratively, enhancing security posture even when using cost-effective general-purpose operating systems and protocols

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10051004B2Evaluation system
Publication Date: 2018.08.14 HITACHI LTD
  • US10051004B2 patent drawing
  • US10051004B2 patent drawing
  • US10051004B2 patent drawing

AI summary

An evaluation system includes a network device, a gateway device, a policy evaluation device, and first and second control devices. The network device copies a packet received from the first control device and transmits to the gateway device and the policy evaluation device. The gateway device receives the copied packet, performs a first filtering based on the policy stored in a first policy storage unit, transmits the packet to the second control device while storing the result of the first filtering, and transmits the result of the stored first filtering to the policy evaluation device. The policy evaluation device receives the copied packet, performs a second filtering based on the policy stored in a second policy storage unit, stores the result of the second filtering, and evaluates the policy stored in the second policy storage unit based on the results of the two filterings.