Storage Area Network Platform for Secure Industrial Data Exchange
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Industrial networks, particularly in mission-critical sectors like energy and utilities, face significant cybersecurity threats due to inadequate protection against external attacks, especially when connected to less secure corporate or internet networks, leading to potential losses of control and data integrity.
Innovation Solution
The implementation of a storage area network internetworking platform that enables secure data exchange between secured and less secured zones by breaking IP connections, using Data Staging Modules and Storage Area Network Inter-networking Modules to facilitate non-IP communication at the storage drive level, thereby preventing the transfer of vulnerable files and eliminating the need for firewalls and DMZs.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If full IP communication end-to-end is implemented between SZ and LSZ, then data exchange capability is improved, but security vulnerability increases due to potential malware and worm transmission
Solution Approach 1:
The patent segments the end-to-end IP communication path into separate zones (SZ and LSZ) with a storage area network platform in between. Data is broken down into blocks that are independently processed, stored, and transmitted through the segmented architecture, preventing direct communication paths that could transmit malware while maintaining data exchange functionality.
Solution Approach 2:
The storage area network platform acts as an intermediary between SZ and LSZ. Instead of direct IP communication, data flows through this intermediate storage system that can validate, filter, and control data transmission, blocking malicious content while allowing legitimate data exchange between the two zones.
2Reliability
If Firewall and DMZ are deployed between SZ and LSZ, then security protection is improved, but system complexity and communication overhead increase
Solution Approach 1:
The patent extracts the security function from traditional network firewalls and DMZ architectures and relocates it to the storage area network platform. Security validation is performed at the storage layer rather than the network layer, simplifying the network architecture while maintaining robust security protection through a different architectural approach.
3Adaptability or versatility
If active files with executable code are allowed to transfer between zones, then data utility is improved, but risk of computer worms and viruses increases
Solution Approach 1:
The patent performs preliminary actions by validating and processing data blocks at the storage layer before they are transmitted between zones. Executable content is identified and handled specially during the storage processing stage, allowing legitimate data utility while preventing malicious code execution through pre-validation and controlled processing of potentially harmful content.
Data Source
Figure 1~2
Figure 3
Figure 4
AI summary
Apparatus, systems, network platforms, and methods of providing secure communication between multiple networks, and program product for managing heat exchanger energy efficiency and retrofit for an industrial facility, are provided. According to an exemplary apparatus, the apparatus can include provisions for preventing uninterrupted application-to-application layer communications between the one or more secured networked members and the one or more networked enterprise members to thereby eliminate active files from being communicated, preventing communication of active files or other vulnerable files, and preventing establishment of active links or sessions, between the one or more secured networked members and the one or more networked enterprise members.