Process Control Network Lockdown Mechanism

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In complex process control systems, managing and securing network access becomes impractical due to the increasing number of network devices and access points, leading to potential security vulnerabilities and management difficulties, as existing methods struggle to effectively monitor and control access on a device-by-device and port-by-port basis.

Innovation Solution

Implementing a 'lockdown' mechanism that uses Private Management Information Bases (MIBs) and command line interfaces to monitor and disable unused or invalid ports network-wide, restricting future re-configuration and preventing unwanted communication, while ensuring only authorized devices can connect by freezing the network configuration and denying power to unused access points.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If network devices and access points are increased to support system growth, then system functionality and connectivity are improved, but security management complexity and difficulty increase

Engineering Contradiction:
Improvesystem connectivityVSAvoidsecurity management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent merges security management functions into a centralized system that can manage multiple network devices through a single interface. The lockdown mechanism consolidates port security, access control, and configuration management into one unified approach, allowing administrators to manage security across the entire network rather than individually at each device level.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The lockdown mechanism is designed as a universal solution that can be applied across different types of network devices and access points throughout the process control network. A single lockdown command can secure multiple devices simultaneously, making the security management system versatile and adaptable to various network configurations without requiring device-specific management procedures.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If device-by-device and port-by-port monitoring is implemented, then security control precision is improved, but management time and operational complexity increase

Engineering Contradiction:
Improvesecurity control precisionVSAvoidmanagement time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary security actions by pre-configuring and pre-securing network ports before they are potentially compromised. The lockdown mechanism proactively disables unused ports and configures security parameters in advance, eliminating the need for time-consuming reactive security measures and reducing the time required for security management operations.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent segments security management into distinct functional components: port status monitoring, lockdown execution, and configuration management. This segmentation allows each function to operate independently and efficiently, with the ability to execute security actions on specific ports or devices without affecting the entire network, thereby reducing overall management time while maintaining precise control.

Inventive Principle:
Principle #1Segmentation

3Adaptability or versatility

If unused ports are left open for potential network expansion, then system adaptability is improved, but security vulnerabilities increase

Engineering Contradiction:
Improvenetwork expandabilityVSAvoidsecurity vulnerabilities
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system implements dynamic port management where port states can change from locked to unlocked and vice versa based on authorized actions. Unused ports are dynamically locked to prevent unauthorized access, while authorized expansion activities can dynamically unlock specific ports when needed. This dynamic approach maintains security by default while preserving adaptability when required, eliminating the need to leave ports permanently open.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentEP2611108B1One Button Security Lockdown of a Process Control Network
Publication Date: 2018.12.05 FISHER ROSEMOUNT SYST INC
  • EP2611108B1 patent drawingFigure 1a~1b
  • EP2611108B1 patent drawingFigure 1c
  • EP2611108B1 patent drawingFigure 2

AI summary

The present invention discloses a method for locking down one or more access points in a process control network and comprises identifying a network device of the process control network, wherein the network device includes one or more of a valid access point or an invalid access point. Further the valid access point includes one or more of an active link to a node of the process control network and a wired connection to the process control network. The method further includes disabling any remaining invalid access points of the network device by one or more of: freezing a current configuration of the valid access point, and removing an ability of the invalid access point to receive electrical power.