Post-Quantum Encryption for Air-Gapped OT Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Operational Technology (OT) environments lack secure networked communications, relying on air-gapped isolation and legacy protocols, which limits visibility into conditional deviations and exposes systems to security risks, especially with the threat of quantum computing compromising modern encryption methodologies.
Innovation Solution
Implementing a Post-Quantum Encryption (PQE) module within OT and IT equipment for end-to-end secure communications, using a hardware-agnostic solution that encrypts and decrypts data, performs local analysis, and routes it through a cloud-based demilitarized zone (DMZ) for further analysis and filtering, ensuring resistance to quantum attacks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If air-gapped isolation is used in OT environments, then security against network attacks is improved, but networked communications and visibility into conditional deviations are lost
Solution Approach 1:
The patent introduces a DMZ environment as an intermediary between OT and IT networks. The DMZ contains gateway servers that act as mediators, allowing secure data exchange without direct network connections. This enables visibility into OT system conditions while maintaining air-gapped security through the buffered intermediary zone.
2Reliability
If legacy encryption protocols are used, then current security standards are met, but vulnerability to quantum computing attacks increases
Solution Approach 1:
The patent implements Post-Quantum Encryption (PQE) algorithms that change the cryptographic parameters from traditional RSA/ECC to quantum-resistant algorithms such as lattice-based cryptography, code-based cryptography, or hash-based signatures. This parameter change maintains current security compliance while providing future-proof protection against quantum computing threats.
3Loss of information
If direct networked communications are implemented in OT environments, then visibility and data exchange are improved, but security risks and exposure to attacks increase
Solution Approach 1:
The patent segments the network architecture into distinct zones: OT network, DMZ environment, and IT network. This segmentation allows visibility and data exchange between OT and IT systems while isolating security risks to specific segments. The DMZ acts as a buffer zone that prevents direct exposure of OT systems to IT network threats.
4Reliability
If encryption is applied to all communications, then security is improved, but bandwidth requirements and processing overhead increase
Solution Approach 1:
The patent applies encryption selectively to specific data streams and communication channels based on their sensitivity and security requirements. Not all OT communications are encrypted with full PQE overhead - only those requiring enhanced security. This partial application reduces bandwidth consumption and processing overhead while maintaining security for critical data exchanges.
Data Source
AI summary
Systems, methods, and computer-readable storage media for secure communications, and more specifically to securing communications on previously air-gapped equipment using post-quantum encryption. A system can include: a first technology environment comprising at least one first technology component, the at least one first technology component comprising a first Post-Quantum Encryption (PQE) module; a second technology environment comprising at least one second technology component, the at least one second technology component comprising a second PQE module; a demilitarized zone (DMZ) environment having at least one DMZ processor; and a communications network, where the first technology environment, the second technology environment, and the DMZ environment are networked together across the communications network such that communications between the first technology environment and the second technology environment pass through the DMZ environment, the communications being encrypted using PQE.


