Secure Data Pool for OT-IT Integration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The convergence of IT and OT systems poses challenges due to security concerns and the lack of trust in data sharing, particularly in OT environments, where there is no scalable data catalog, inability to run analytics, lack of data provenance, and inability to simulate IT access, leading to risks of industrial espionage and sabotage.

Innovation Solution

Implementing a secure data pool with blockchain-based registration and decentralized identifiers to manage and store OT data, providing secure access to IT clients while maintaining data ownership and provenance, and enabling monetization through a data marketplace.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If OT systems are made accessible to IT processes, then data sharing and integration capabilities are improved, but security risks and vulnerability to industrial espionage increase

Engineering Contradiction:
Improvedata sharing capabilityVSAvoidsecurity risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a gateway as an intermediary component between OT and IT systems. The gateway collects data from OT sensors, performs security validation, and exposes data through standardized IT interfaces. This mediator enables data sharing while isolating OT systems from direct IT access, thereby reducing security risks.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent extracts critical security functions from the OT system core and places them in the gateway layer. Security validation, authentication, and data filtering are performed at the gateway before data enters the IT environment, separating security responsibilities from OT operational systems.

Inventive Principle:
Principle #2Taking out (Extraction)

2Productivity

If remote accessibility is enabled for IT personnel, then operational efficiency and monitoring capabilities are improved, but vulnerability to industrial espionage and sabotage increases

Engineering Contradiction:
Improveoperational efficiencyVSAvoidvulnerability to espionage
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The gateway serves as a secure intermediary that allows IT personnel to access OT data remotely through standardized interfaces without direct access to OT systems. All remote access requests must pass through the gateway's security validation layer, enabling operational efficiency while maintaining security.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If data integration between IT and OT is implemented, then business-critical control and data sharing are improved, but system complexity and integration challenges increase

Engineering Contradiction:
Improvedata sharing capabilityVSAvoidintegration complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the integrated system into distinct functional layers: OT sensor layer, gateway layer for security and data collection, and IT application layer. This segmentation isolates complexity to specific layers while maintaining clean interfaces between them, simplifying overall integration.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The gateway provides multiple functions including data collection, security validation, data formatting, and interface provisioning through a single universal component. This multi-functionality reduces the need for multiple specialized integration components, simplifying the overall system architecture.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11012426B2Secure data pools
Publication Date: 2021.05.18 EMC IP HLDG CO LLC
  • US11012426B2 patent drawing
  • US11012426B2 patent drawing
  • US11012426B2 patent drawing

AI summary

Techniques for secure data management in a sensor data environment are provided. For example, a method obtains sensor data, at a gateway, generated by at least one sensor associated with a set of one or more sensors operatively coupled to the gateway. The method generates at least one data object comprising the sensor data and metadata corresponding to the sensor data, and sends the data object to a secure data pool for storage and for secure access by one or more clients.