Remote Access Server for Automation Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing automation networks face issues with high data transmission rates, potential damage from unauthorized changes to operating data, access conflicts, and security vulnerabilities due to direct access by remote computers to automation devices via the Internet.

Innovation Solution

Implementing a remote access server that intermediates communication between remote computers and automation devices, allowing only authorized changes to be validated and applied, with software objects providing secure, session-oriented access and utilizing unused computing power for efficient data processing.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If remote computers access automation devices directly via the Internet, then ease of operation is improved, but security is worsened due to unauthorized access and hacker attacks

Engineering Contradiction:
Improveremote accessVSAvoidunauthorized access
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

A remote access server is introduced as an intermediary component between remote computers and automation devices. The server manages all communication requests, validates authentication credentials, and controls access permissions. This mediator architecture allows remote access functionality while preventing direct unauthorized access to automation devices, as all requests must pass through the server's security checks.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system is segmented into distinct functional components: the remote access server handles authentication and communication management, while automation devices focus on control functions. This segmentation separates security-critical functions from control functions, allowing the server to implement security measures without affecting the operational integrity of automation devices.

Inventive Principle:
Principle #1Segmentation

2Ease of operation

If automation devices process communication tasks directly, then ease of operation is improved, but productivity is worsened due to insufficient computing power for control tasks

Engineering Contradiction:
Improveremote accessVSAvoidcontrol task execution
Core Design Contradiction:
Ease of operationVSProductivity

Solution Approach 1:

Communication processing functions are extracted from automation devices and relocated to a dedicated remote access server. This extraction allows automation devices to concentrate their computing resources on control tasks without the overhead of handling communication protocols, authentication, and data transmission management, thereby improving their productivity and responsiveness.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The remote access server is designed as a multi-functional component that handles authentication, communication management, data buffering, and protocol conversion for multiple automation devices. This universal server consolidates communication tasks that would otherwise burden individual automation devices, freeing them to focus on their primary control functions.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Ease of operation

If multiple remote computers access the same automation device simultaneously, then ease of operation is improved, but reliability is worsened due to access conflicts

Engineering Contradiction:
Improvemulti-user accessVSAvoidaccess conflict
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The remote access server acts as a mediator that manages simultaneous access requests from multiple remote computers. It implements request queuing, user authentication, and session management to coordinate access to automation devices, preventing conflicts that would arise from direct peer-to-peer communication between multiple remote computers and the same device.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements feedback mechanisms where the remote access server monitors the state of automation devices and adjusts access permissions accordingly. When an automation device is busy or in a critical state, the server can temporarily block or queue access requests, providing feedback control that prevents access conflicts and ensures reliable operation.

Inventive Principle:
Principle #23Feedback

4Ease of operation

If changes to operating data are allowed from remote computers, then ease of operation is improved, but safety is worsened due to potential damage to the controlling process

Engineering Contradiction:
Improveremote modificationVSAvoidprocess damage
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The remote access server serves as a security intermediary that intercepts and validates all modification requests before they reach automation devices. It checks user permissions, validates parameter ranges, and ensures that proposed changes comply with safety constraints defined in the system configuration, thereby preventing harmful modifications while allowing legitimate operational adjustments.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary validation of modification requests at the remote access server before applying changes to automation devices. This preliminary action includes checking user authorization, validating parameter values against predefined safe ranges, and verifying that changes will not create unsafe process conditions, thus preventing potential damage before it occurs.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP2005262B1Automation network, remote access server for an automation network and a method for transmitting operating data between an automation system and a remote computer
Publication Date: 2014.07.16 SIEMENS AG
  • EP2005262B1 patent drawingFigure 1
  • EP2005262B1 patent drawingFigure 2

AI summary

The invention relates to an automation network, a remote access server (7) for an automation network and a method for transmission of operating data between an automation system with one or more automation devices (1..3) and a remote computer (4 6) with the operating data of the automation device (1..3) being transmitted via the Internet or an intranet and displayed and/or changed on the remote computer (4 6) by an Internet browser (8 10). The remote access server (7) provides the operating data for the remote computer (4 6) and, for a session-oriented access, creates a software object (17, 21, 22, 26 28) as an image of the automation device (1 3) and, if changes are to be made to the operating data by the access, a software object (18, 23 25, 30, 31) for simulation of the automation device (1 3) and/or of the process to be controlled by the automation device, so that any changes can be checked for permissibility and/or validity before being forwarded to the automation device (1 3).