Response Filter for Automation Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Industrial automation networks face increased security risks due to unauthorized external interventions, and existing security monitoring systems struggle to reliably detect and react to potential attacks in a timely manner, especially when using firewalls for communication filtering.

Innovation Solution

Implementing a bidirectional data processing system with a response filter in the first data processing means to check and accept only specific response packets, ensuring reaction-free transmission of security events, and generating a warning signal for impermissible responses, thus preventing unauthorized access and maintaining system availability.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Object-affected harmful factors

If firewalls are used for communication filtering in automation networks, then security protection is improved, but system reliability and availability deteriorate due to potential manipulation and false alarms

Engineering Contradiction:
Improvesecurity protectionVSAvoidsystem reliability
Core Design Contradiction:
Object-affected harmful factorsVSReliability

Solution Approach 1:

The patent introduces a response filter as an intermediary component between the data processing means and the external network. This filter acts as a mediator that selectively permits or blocks response packets based on predefined criteria, providing security without the reliability issues associated with traditional firewalls. The response filter is integrated into the TCP stack, ensuring it operates at the protocol level and cannot be easily manipulated by external attacks.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The response filter implements self-service by automatically verifying response packets against expected parameters and blocking suspicious traffic without requiring external intervention. The system monitors its own communication patterns and autonomously defends against unauthorized access attempts, eliminating the need for manual firewall configuration and reducing false alarms.

Inventive Principle:
Principle #25Self-service

2Difficulty of detecting and measuring

If traditional firewall-based security monitoring is implemented, then detection capability is improved, but system complexity and susceptibility to manipulation increase

Engineering Contradiction:
Improvedetection capabilityVSAvoidsystem complexity
Core Design Contradiction:
Difficulty of detecting and measuringVSDevice complexity

Solution Approach 1:

The patent merges the security monitoring function directly into the TCP communication stack by integrating the response filter at the protocol level. This consolidation eliminates the need for separate firewall systems and complex security infrastructure, reducing overall system complexity while maintaining strong detection capabilities. The response filter operates as an inherent part of the communication mechanism rather than an external add-on.

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If bidirectional communication is enabled for security event transmission, then data transmission reliability is improved, but vulnerability to unauthorized access increases

Engineering Contradiction:
Improvedata transmission reliabilityVSAvoidvulnerability to unauthorized access
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements feedback mechanisms where the response filter continuously monitors incoming response packets and compares them against expected communication patterns. This feedback loop enables the system to distinguish between legitimate bidirectional communication and unauthorized access attempts, maintaining reliable data transmission while blocking malicious traffic. The filter uses acknowledgment packets and sequence numbers to verify the authenticity of responses.

Inventive Principle:
Principle #23Feedback

Data Source

PatentEP3122016B1Automation network and method of surveillance for security of the transmission of data packets
Publication Date: 2020.01.08 SIEMENS AG
  • EP3122016B1 patent drawingFigure 1~2

AI summary

The invention relates to an automation network for monitoring the security of data packet transmission, comprising at least a first data processing means (1) for transmitting data packets from and to a plant component, and a second data processing means, wherein at least the first data processing means (1) is bidirectionally connected to the second data processing means for transmitting the data packets, wherein when a data packet is transmitted from the first data processing means (1) to the second data processing means, it is detected by the second data processing means and response packets (5) are generated, which are sent back from the second data processing means to the first data processing means (1), wherein the first data processing means (1) comprises a response filter (6).with which an examination and subsequent rejection/acceptance of the response packages (5) can be carried out.