Storage Area Network Platform for Secure Industrial Data Exchange

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Industrial networks, particularly in mission-critical sectors like energy and utilities, face significant cybersecurity threats due to inadequate protection against external attacks, especially when connected to less secure corporate or internet networks, leading to potential losses of control and data integrity.

Innovation Solution

The implementation of a storage area network internetworking platform that enables secure data exchange between secured and less secured zones by breaking IP connections, using Data Staging Modules and Storage Area Network Inter-networking Modules to facilitate non-IP communication at the storage drive level, thereby preventing the transfer of vulnerable files and eliminating the need for firewalls and DMZs.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If full IP communication end-to-end is implemented between SZ and LSZ, then data exchange capability is improved, but security vulnerability increases due to potential malware and worm transmission

Engineering Contradiction:
Improvedata exchange capabilityVSAvoidsecurity vulnerability
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the end-to-end IP communication path into separate zones (SZ and LSZ) with a storage area network platform in between. Data is broken down into blocks that are independently processed, stored, and transmitted through the segmented architecture, preventing direct communication paths that could transmit malware while maintaining data exchange functionality.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The storage area network platform acts as an intermediary between SZ and LSZ. Instead of direct IP communication, data flows through this intermediate storage system that can validate, filter, and control data transmission, blocking malicious content while allowing legitimate data exchange between the two zones.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If Firewall and DMZ are deployed between SZ and LSZ, then security protection is improved, but system complexity and communication overhead increase

Engineering Contradiction:
Improvesecurity protectionVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the security function from traditional network firewalls and DMZ architectures and relocates it to the storage area network platform. Security validation is performed at the storage layer rather than the network layer, simplifying the network architecture while maintaining robust security protection through a different architectural approach.

Inventive Principle:
Principle #2Taking out (Extraction)

3Adaptability or versatility

If active files with executable code are allowed to transfer between zones, then data utility is improved, but risk of computer worms and viruses increases

Engineering Contradiction:
Improvedata utilityVSAvoidcomputer worms and viruses
Core Design Contradiction:
Adaptability or versatilityVSObject-generated harmful factors

Solution Approach 1:

The patent performs preliminary actions by validating and processing data blocks at the storage layer before they are transmitted between zones. Executable content is identified and handled specially during the storage processing stage, allowing legitimate data utility while preventing malicious code execution through pre-validation and controlled processing of potentially harmful content.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP3140976B1Apparatus, systems, platforms, and methods for securing communication data exchanges between multiple networks for industrial and non-industrial applications
Publication Date: 2020.09.09 SAUDI ARABIAN OIL CO
  • EP3140976B1 patent drawingFigure 1~2
  • EP3140976B1 patent drawingFigure 3
  • EP3140976B1 patent drawingFigure 4

AI summary

Apparatus, systems, network platforms, and methods of providing secure communication between multiple networks, and program product for managing heat exchanger energy efficiency and retrofit for an industrial facility, are provided. According to an exemplary apparatus, the apparatus can include provisions for preventing uninterrupted application-to-application layer communications between the one or more secured networked members and the one or more networked enterprise members to thereby eliminate active files from being communicated, preventing communication of active files or other vulnerable files, and preventing establishment of active links or sessions, between the one or more secured networked members and the one or more networked enterprise members.