Protocol-Based Network Access Control for Critical OT Systems
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods fail to effectively prevent IoT devices from inadvertently or intentionally connecting to operationally and security-critical networks during diagnostics, maintenance, or configuration, posing a risk to network security and operation.
Innovation Solution
A control unit that observes and evaluates network communication protocols to distinguish between critical and non-critical networks, generating a warning and automatically blocking access to critical networks, using a program module that compares observed protocols with reference protocols stored in a protocol data memory to prevent unauthorized connectivity.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If IoT devices are allowed to access networks for diagnostics and maintenance, then device functionality and diagnostic capability are improved, but network security and operational integrity deteriorate due to risk of unauthorized connectivity to critical networks
Solution Approach 1:
The patent introduces a protocol observer as an intermediary component that monitors network traffic between IoT devices and networks. This observer evaluates communication protocols to determine whether a device is attempting to access a critical network, thereby mediating between the need for diagnostic access and the requirement for network security without requiring direct trust between the IoT device and the critical network
2Reliability
If physical hardware restrictions are implemented to prevent network access, then network security is improved, but device versatility and diagnostic functionality deteriorate
Solution Approach 1:
The patent implements dynamic access control where the protocol observer continuously monitors and evaluates network communication protocols in real-time. The system adapts its behavior based on the evaluated protocol type, dynamically permitting or blocking access without requiring fixed physical hardware restrictions, thereby maintaining both security and flexibility
3Measurement precision
If manual network configuration and monitoring are performed, then access control precision is improved, but operational complexity and time consumption deteriorate
Solution Approach 1:
The patent implements a self-service mechanism where the protocol observer automatically evaluates communication protocols and determines network access permissions without requiring manual configuration or intervention. The system autonomously identifies critical network protocols and blocks access accordingly, eliminating the need for manual network configuration while maintaining precise access control
Data Source
Figure 1
Figure 2
AI summary
To control access to IT systems (ITS) based networks (NW, NWUKR, NWKR), in particular embedded systems (EBS) or distributed systems (VS) comprehensive automation networks (ANW), control networks (SNW) or control networks (KNW), to improve access control in terms of security and protection of network operation and network data, it is proposed by observing and evaluating (detecting) the communication in a network (performing a network communication protocol comparison of the observed protocol with a variety of commonly used in operational and/ or security-critical networks used, preferably stored in a list) to independently recognize whether, in the course of network access, in particular the establishment of network connectivity, at least one of at least one non-critical in terms of operation and/or security, in particular referred to as the default network, network (NWUKR) and at least one operationally and/or security critical network (NWKR) is a non-critical or critical network. Depending on the detection result, a warning, preferably a "critical network signal <cns>", provided.</cns>