Post-Quantum Encryption for Air-Gapped OT Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Operational Technology (OT) environments lack secure networked communications, relying on air-gapped isolation and legacy protocols, which limits visibility into conditional deviations and exposes systems to security risks, especially with the threat of quantum computing compromising modern encryption methodologies.

Innovation Solution

Implementing a Post-Quantum Encryption (PQE) module within OT and IT equipment for end-to-end secure communications, using a hardware-agnostic solution that encrypts and decrypts data, performs local analysis, and routes it through a cloud-based demilitarized zone (DMZ) for further analysis and filtering, ensuring resistance to quantum attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If air-gapped isolation is used in OT environments, then security against network attacks is improved, but networked communications and visibility into conditional deviations are lost

Engineering Contradiction:
ImprovesecurityVSAvoidvisibility into conditional deviations
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent introduces a DMZ environment as an intermediary between OT and IT networks. The DMZ contains gateway servers that act as mediators, allowing secure data exchange without direct network connections. This enables visibility into OT system conditions while maintaining air-gapped security through the buffered intermediary zone.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If legacy encryption protocols are used, then current security standards are met, but vulnerability to quantum computing attacks increases

Engineering Contradiction:
Improvecurrent security complianceVSAvoidquantum attack vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements Post-Quantum Encryption (PQE) algorithms that change the cryptographic parameters from traditional RSA/ECC to quantum-resistant algorithms such as lattice-based cryptography, code-based cryptography, or hash-based signatures. This parameter change maintains current security compliance while providing future-proof protection against quantum computing threats.

Inventive Principle:
Principle #35Parameter changes

3Loss of information

If direct networked communications are implemented in OT environments, then visibility and data exchange are improved, but security risks and exposure to attacks increase

Engineering Contradiction:
ImprovevisibilityVSAvoidsecurity risks
Core Design Contradiction:
Loss of informationVSObject-affected harmful factors

Solution Approach 1:

The patent segments the network architecture into distinct zones: OT network, DMZ environment, and IT network. This segmentation allows visibility and data exchange between OT and IT systems while isolating security risks to specific segments. The DMZ acts as a buffer zone that prevents direct exposure of OT systems to IT network threats.

Inventive Principle:
Principle #1Segmentation

4Reliability

If encryption is applied to all communications, then security is improved, but bandwidth requirements and processing overhead increase

Engineering Contradiction:
ImprovesecurityVSAvoidbandwidth and processing overhead
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent applies encryption selectively to specific data streams and communication channels based on their sensitivity and security requirements. Not all OT communications are encrypted with full PQE overhead - only those requiring enhanced security. This partial application reduces bandwidth consumption and processing overhead while maintaining security for critical data exchanges.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS20240323163A1Systems and methods for secure communications
Publication Date: 2024.09.26 CROWLEY GOVERNMENT SERVICES INC
  • US20240323163A1 patent drawing
  • US20240323163A1 patent drawing
  • US20240323163A1 patent drawing

AI summary

Systems, methods, and computer-readable storage media for secure communications, and more specifically to securing communications on previously air-gapped equipment using post-quantum encryption. A system can include: a first technology environment comprising at least one first technology component, the at least one first technology component comprising a first Post-Quantum Encryption (PQE) module; a second technology environment comprising at least one second technology component, the at least one second technology component comprising a second PQE module; a demilitarized zone (DMZ) environment having at least one DMZ processor; and a communications network, where the first technology environment, the second technology environment, and the DMZ environment are networked together across the communications network such that communications between the first technology environment and the second technology environment pass through the DMZ environment, the communications being encrypted using PQE.