Proactive Internet Connectivity Probe Generator for Industrial Asset Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Industrial equipment connected to the public Internet is susceptible to cyber-attacks due to lack of isolation, leading to data theft and asset malfunctions, which can occur due to system errors, human errors, or sabotage.
Innovation Solution
A system that generates and transmits a secure message with asset-identifying information using a specified security protocol through designated network interfaces, ensuring secure communication within a demilitarized computing network to protect hardware assets from unauthorized access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If industrial equipment is connected to the public Internet for remote control and data collection, then connectivity and functionality are improved, but susceptibility to cyber-attacks increases
Solution Approach 1:
The patent introduces a DMZ (demilitarized zone) network as an intermediary layer between industrial equipment and the public Internet. This DMZ contains probe generators and security monitoring systems that can safely interact with both the internal network and external Internet, preventing direct exposure of critical assets while maintaining connectivity capabilities.
Solution Approach 2:
The network architecture is segmented into multiple isolated zones: the industrial equipment network, the DMZ network, and the public Internet. This segmentation allows controlled communication through specific pathways while preventing direct access to equipment, thereby maintaining functionality while reducing attack surface.
2Object-affected harmful factors
If network isolation is implemented to protect assets from cyber-attacks, then security is improved, but remote control and data collection capabilities are reduced
Solution Approach 1:
The DMZ acts as an intermediary that enables remote control and data collection functions while maintaining security isolation. Security probes and monitoring systems in the DMZ can communicate with equipment through controlled channels, allowing functionality without direct Internet exposure.
Solution Approach 2:
The system implements active probing and monitoring that provides feedback about network connectivity status and security conditions. This feedback mechanism allows the system to maintain isolation while dynamically adjusting communication pathways to preserve necessary remote access capabilities.
3Measurement precision
If active probing is used to detect Internet connectivity, then detection accuracy is improved, but network traffic and system resource usage increase
Solution Approach 1:
The probe generator implements periodic connectivity probing rather than continuous monitoring. Probes are sent at scheduled intervals to detect Internet connectivity status, achieving adequate detection accuracy while significantly reducing network traffic and system resource consumption compared to continuous monitoring.
Data Source
AI summary
Described herein are reception of first processor-executable program code and a configuration file specifying a target internet protocol address, an asset-identifying information type, and a security protocol, and execution of the received first processor-executable program code to identify a first one or more network communication interfaces of the first computing system, generate a message including information conforming to the asset-identifying information type, the information identifying a first asset, secure the message based on the security protocol, and transmit the secure message to the target internet protocol address via each of the first one or more network communication interfaces.


