Proactive Internet Connectivity Probe Generator for Industrial Asset Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Industrial equipment connected to the public Internet is susceptible to cyber-attacks due to lack of isolation, leading to data theft and asset malfunctions, which can occur due to system errors, human errors, or sabotage.

Innovation Solution

A system that generates and transmits a secure message with asset-identifying information using a specified security protocol through designated network interfaces, ensuring secure communication within a demilitarized computing network to protect hardware assets from unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If industrial equipment is connected to the public Internet for remote control and data collection, then connectivity and functionality are improved, but susceptibility to cyber-attacks increases

Engineering Contradiction:
ImproveInternet connectivityVSAvoidcyber-attack susceptibility
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a DMZ (demilitarized zone) network as an intermediary layer between industrial equipment and the public Internet. This DMZ contains probe generators and security monitoring systems that can safely interact with both the internal network and external Internet, preventing direct exposure of critical assets while maintaining connectivity capabilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The network architecture is segmented into multiple isolated zones: the industrial equipment network, the DMZ network, and the public Internet. This segmentation allows controlled communication through specific pathways while preventing direct access to equipment, thereby maintaining functionality while reducing attack surface.

Inventive Principle:
Principle #1Segmentation

2Object-affected harmful factors

If network isolation is implemented to protect assets from cyber-attacks, then security is improved, but remote control and data collection capabilities are reduced

Engineering Contradiction:
Improvesecurity protectionVSAvoidremote control capability
Core Design Contradiction:
Object-affected harmful factorsVSAdaptability or versatility

Solution Approach 1:

The DMZ acts as an intermediary that enables remote control and data collection functions while maintaining security isolation. Security probes and monitoring systems in the DMZ can communicate with equipment through controlled channels, allowing functionality without direct Internet exposure.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements active probing and monitoring that provides feedback about network connectivity status and security conditions. This feedback mechanism allows the system to maintain isolation while dynamically adjusting communication pathways to preserve necessary remote access capabilities.

Inventive Principle:
Principle #23Feedback

3Measurement precision

If active probing is used to detect Internet connectivity, then detection accuracy is improved, but network traffic and system resource usage increase

Engineering Contradiction:
Improveconnectivity detection accuracyVSAvoidsystem resource consumption
Core Design Contradiction:
Measurement precisionVSLoss of energy

Solution Approach 1:

The probe generator implements periodic connectivity probing rather than continuous monitoring. Probes are sent at scheduled intervals to detect Internet connectivity status, achieving adequate detection accuracy while significantly reducing network traffic and system resource consumption compared to continuous monitoring.

Inventive Principle:
Principle #19Periodic action

Data Source

PatentUS9756078B2Proactive internet connectivity probe generator
Publication Date: 2017.09.05 INNOVATEPRO MANAGEMENT USA LLC
  • US9756078B2 patent drawing
  • US9756078B2 patent drawing
  • US9756078B2 patent drawing

AI summary

Described herein are reception of first processor-executable program code and a configuration file specifying a target internet protocol address, an asset-identifying information type, and a security protocol, and execution of the received first processor-executable program code to identify a first one or more network communication interfaces of the first computing system, generate a message including information conforming to the asset-identifying information type, the information identifying a first asset, secure the message based on the security protocol, and transmit the secure message to the target internet protocol address via each of the first one or more network communication interfaces.