Relay Unit Address Mapping for Secure PLC Network Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In control systems with multiple connected units, users face difficulties in accessing target function units without knowing their IP addresses, especially as the number of connected units increases, leading to a need for a technology that enables access without revealing or requiring the IP address of the destination unit.
Innovation Solution
A relay unit connected to a Programmable Logic Controller (PLC) that acquires address information of other units, generates setting information associating this information with an identifier, and creates link information for external devices to access these units, concealing the IP address and preventing direct communication between external devices and internal network units.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If users directly access function units using IP addresses, then communication between external devices and internal units is established, but security risks increase and system complexity increases as the number of units grows
Solution Approach 1:
The patent introduces a relay unit as an intermediary between external devices and internal function units. The relay unit receives access requests from external devices, translates them into internal network requests using address information, and forwards them to the target function units. This mediator approach allows external access without exposing internal IP addresses, thereby improving security while managing system complexity through centralized address management.
Solution Approach 2:
The patent segments the network into distinct zones: an external network where devices use identifiers instead of IP addresses, and an internal network where function units have their own IP addresses. The relay unit acts as the boundary between these segments, translating requests between the two address systems. This segmentation isolates the internal network from external access risks while maintaining functionality.
2Adaptability or versatility
If the number of connected function units increases, then system functionality improves, but the difficulty of grasping IP addresses increases
Solution Approach 1:
The patent creates a simplified copy of the internal network structure in the external network through the relay unit. Instead of requiring external devices to know complex internal IP addressing, the relay unit presents a simplified address space using identifiers. This copying approach maintains the functional structure while simplifying the access interface for external devices.
Solution Approach 2:
The relay unit serves as an intermediary that manages the mapping between external identifiers and internal IP addresses. As the number of function units increases, the relay unit automatically handles the complexity of address management, translation, and routing, allowing users to access any function unit using simple identifiers without needing to understand or memorize IP address schemes.
3Reliability
If IP addresses are concealed from external devices, then security is improved, but direct communication capability is reduced
Solution Approach 1:
The relay unit acts as a necessary intermediary that enables communication while maintaining security. It receives requests from external devices using identifiers, translates them to internal IP address-based requests, and forwards them to the appropriate function units. This intermediary approach preserves full communication capability while ensuring that internal IP addresses remain concealed and secure.
Solution Approach 2:
The patent adds an additional dimension to the communication architecture by introducing the relay unit as a translation layer between two different address spaces. External devices communicate in one dimension using identifiers, while internal function units operate in another dimension using IP addresses. The relay unit bridges these dimensions, enabling communication without direct exposure between the two systems.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Provided is a technology with which it is possible to access a function unit to be accessed without ascertaining an IP address of the function unit. Provided is a unit (200) comprising: a communication unit for relaying a communication between an external device (500) connected to a first network and another unit (300) connected to a second network; a setting unit (252) for acquiring address information of the other unit (300) in the second network from the other unit (300) and generating setting information (230) in which the address information is associated with an identifier which substitutes for the address information; and a link information generation unit (254) for generating, on the basis of the identifier, link information used to access information on the other unit (300) from the external device (500).