Secure Data Transfer via One-Way Gateway for SCADA Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Industrial control systems (ICS) like SCADA networks are vulnerable to cyber-attacks due to the lack of security in packet control protocols, making it difficult to transfer information securely from high-integrity MODBUS networks to non-secure remote networks without compromising the secure environment.
Innovation Solution
A system utilizing a send server within the secure domain to act as a proxy for MODBUS devices, collecting and transmitting data via a one-way data link to a receive server outside the secure domain, ensuring that communication can only flow from the send server to the receive server, thus preventing unauthorized access and maintaining network integrity.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If a two-way interface is provided to transfer information from secure SCADA network to non-secure remote network, then information transfer capability is improved, but security vulnerability increases due to potential unauthorized access and cyber-attacks
Solution Approach 1:
The patent introduces a gateway as an intermediary device positioned between the secure SCADA network and the non-secure remote network. This gateway acts as a mediator that enables information transfer from the secure network to external systems while blocking reverse connections and unauthorized access attempts, thus resolving the contradiction between information transfer capability and security vulnerability
Solution Approach 2:
The patent segments the network architecture into distinct secure and non-secure zones separated by a gateway. This segmentation isolates the critical SCADA network from potential cyber-attacks while allowing controlled information exchange, thereby maintaining both information transfer capability and network security
2Object-affected harmful factors
If physical access control is implemented to prevent unauthorized access to SCADA network jacks and switches, then security is improved, but operational flexibility deteriorates due to restricted access for maintenance and monitoring
Solution Approach 1:
The gateway serves as an intermediary that provides a secure interface for authorized operations. It allows maintenance and monitoring activities to be performed remotely through the gateway without requiring physical access to network jacks or switches, thus preventing unauthorized access while maintaining operational flexibility
Solution Approach 2:
The patent replaces physical access control mechanisms with a logical access control system implemented through the gateway. Instead of requiring physical access to network hardware, authorized operations are performed through software-based authentication and communication protocols, thereby eliminating the need for physical access while maintaining operational flexibility
Data Source
AI summary
A system for securely transferring information from an industrial control system network, including, within the secure domain, one or more remote terminal units coupled by a first network, one or more client computers coupled by a second network, and a send server coupled to the first and second networks. The send server acts as a proxy for communications between the client computers and the remote terminals and transmits first information from such communications on an output. The send server also transmits a poll request to a remote terminal unit via the first network and transmits second information received in response to the poll on the output. The system also includes, outside the secure domain, a receive server having an input coupled to the output of the send server via a one-way data link. The receive server receives and stores the first and second information provided via the input.


