Protocol-Based Network Access Control for Critical OT Systems

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods fail to effectively prevent IoT devices from inadvertently or intentionally connecting to operationally and security-critical networks during diagnostics, maintenance, or configuration, posing a risk to network security and operation.

Innovation Solution

A control unit that observes and evaluates network communication protocols to distinguish between critical and non-critical networks, generating a warning and automatically blocking access to critical networks, using a program module that compares observed protocols with reference protocols stored in a protocol data memory to prevent unauthorized connectivity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If IoT devices are allowed to access networks for diagnostics and maintenance, then device functionality and diagnostic capability are improved, but network security and operational integrity deteriorate due to risk of unauthorized connectivity to critical networks

Engineering Contradiction:
Improvediagnostic capabilityVSAvoidnetwork security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a protocol observer as an intermediary component that monitors network traffic between IoT devices and networks. This observer evaluates communication protocols to determine whether a device is attempting to access a critical network, thereby mediating between the need for diagnostic access and the requirement for network security without requiring direct trust between the IoT device and the critical network

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If physical hardware restrictions are implemented to prevent network access, then network security is improved, but device versatility and diagnostic functionality deteriorate

Engineering Contradiction:
Improvenetwork securityVSAvoidnetwork access flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic access control where the protocol observer continuously monitors and evaluates network communication protocols in real-time. The system adapts its behavior based on the evaluated protocol type, dynamically permitting or blocking access without requiring fixed physical hardware restrictions, thereby maintaining both security and flexibility

Inventive Principle:
Principle #15Dynamics

3Measurement precision

If manual network configuration and monitoring are performed, then access control precision is improved, but operational complexity and time consumption deteriorate

Engineering Contradiction:
Improveaccess control precisionVSAvoidconfiguration time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent implements a self-service mechanism where the protocol observer automatically evaluates communication protocols and determines network access permissions without requiring manual configuration or intervention. The system autonomously identifies critical network protocols and blocks access accordingly, eliminating the need for manual network configuration while maintaining precise access control

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP3382478B1Method, computer program product and control unit for controlling access to it system based networks, in particular automation networks, management networks or control networks comprising embedded systems or distributed systems
Publication Date: 2021.09.08 SIEMENS AG
  • EP3382478B1 patent drawingFigure 1
  • EP3382478B1 patent drawingFigure 2

AI summary

To control access to IT systems (ITS) based networks (NW, NWUKR, NWKR), in particular embedded systems (EBS) or distributed systems (VS) comprehensive automation networks (ANW), control networks (SNW) or control networks (KNW), to improve access control in terms of security and protection of network operation and network data, it is proposed by observing and evaluating (detecting) the communication in a network (performing a network communication protocol comparison of the observed protocol with a variety of commonly used in operational and/ or security-critical networks used, preferably stored in a list) to independently recognize whether, in the course of network access, in particular the establishment of network connectivity, at least one of at least one non-critical in terms of operation and/or security, in particular referred to as the default network, network (NWUKR) and at least one operationally and/or security critical network (NWKR) is a non-critical or critical network. Depending on the detection result, a warning, preferably a "critical network signal <cns>", provided.</cns>