Secure Container Lockout for Critical Infrastructure Network Breaches

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security systems for critical infrastructure, such as wind turbines and electric power grids, fail to effectively prevent unauthorized access and subsequent network infiltration, as they lack robust mechanisms to immediately disable outgoing communications upon unauthorized portal breaches.

Innovation Solution

A secure container system equipped with a security checkpoint and a logical lock module that switches to a breach mode upon unauthorized access, triggering the network switch to disable outgoing communications, thereby preventing unauthorized network access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a secure container with access control is used to protect critical infrastructure, then security against unauthorized access is improved, but the system complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines multiple security functions (access control monitoring, breach detection, and network communication disabling) into an integrated system where the logical lock module coordinates between the physical lock and network switch, reducing overall system complexity while maintaining high security

Inventive Principle:
Principle #5Merging (Combining)

2Reliability

If a logical lock module is added to monitor access portal state and trigger breach mode, then security response capability is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity response capabilityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The logical lock module serves multiple functions: it monitors the access portal state, determines breach conditions, triggers breach mode, and coordinates with both the physical lock and network switch, thereby improving security response capability without requiring separate dedicated components for each function

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If the network switch disables outgoing communications upon breach detection, then prevention of network infiltration is improved, but loss of legitimate communications increases

Engineering Contradiction:
Improveprevention of network infiltrationVSAvoidloss of legitimate communications
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The system preemptively disables outgoing network communications upon detecting a breach condition, before unauthorized infiltration can occur. This preliminary protective action blocks potential threats while the breach is being addressed, accepting temporary communication loss as necessary for security

Inventive Principle:
Principle #9Preliminary anti-action

Applied Scientific Principles

This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.

Function Achieved in This Case

The system effectively impedes unauthorized network infiltration by immediately disabling outgoing communications upon unauthorized access, thereby protecting critical infrastructure from potential threats.

Implementation Method 1

A magnetic reed switch (or simply a reed switch) is an electrical switch operated by an applied magnetic field

Methodology Applied
Scientific EffectMagnetic field sensing: Magnetic Field

Implementation Method 2

When the electromagnet is energized, a current passing through the electromagnet creates a magnetic flux that causes the armature plate to attract to the electromagnet, creating a locking action

Methodology Applied
Scientific EffectElectromagnetic attraction: Electromagnet

Data Source

PatentUS11551544B2Impeding unauthorized network infiltration at remote critical infrastructure facilities
Publication Date: 2023.01.10 INVENTUS HOLDINGS LLC
  • US11551544B2 patent drawing
  • US11551544B2 patent drawing
  • US11551544B2 patent drawing

AI summary

A system for preventing unauthorized access to a network can include a secure container having an access portal for controlling access to contents of the secure container and a security checkpoint configured to determine a state of the access portal and to receive an authorization code for opening the access portal. The security checkpoint can also include a logical lock module that switches to a breach mode of operation in response to a signal from the security checkpoint indicating that the access portal has been opened without receipt of the authorization code within a predetermined amount of time. The system can also include a network switch disposed within the secure container. The network switch is configured to communicate on a network and disable outgoing network communications to the network in response to a breach signal indicating that the logical lock module has switched to the breach mode.