Secure Production Network Modeling via Test Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In automated IC fabrication facilities, accessing real-time production data for testing purposes often interferes with daily manufacturing operations, leading to downtime and degradation of manufacturing execution system availability.

Innovation Solution

A method and system for modeling a secure production network by generating a test network, capturing and analyzing data traffic, determining data flow requirements, and applying business logic to firewalls to isolate secure and non-secure networks, allowing selective data transmission to the test network while preventing incoming transmissions to the secure production network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If test systems access the MES and interact with production activities to enable testing of real-time data, then testing capability is improved, but production system availability and manufacturing quota are degraded

Engineering Contradiction:
Improvetesting capabilityVSAvoidproduction system availability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system is divided into three distinct network segments: secure production network, non-secure production network, and test network. This segmentation allows testing operations to occur in isolation from production systems, enabling testing capability while preserving production system availability and reliability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A non-secure production network acts as an intermediary layer between the secure production network and the test network. This intermediary enables data flow requirements to be established and enforced through firewalls, allowing test systems to access real-time production data indirectly without directly interacting with the secure production MES, thus maintaining production system availability while enabling testing.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If test networks directly access secure production networks to obtain real-time data, then data access for testing is improved, but security and system integrity are compromised

Engineering Contradiction:
Improvedata access for testingVSAvoidsecurity risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The non-secure production network serves as a secure intermediary that mediates data access between the test network and secure production network. Firewalls are configured to establish data flow requirements that permit necessary data transmission while blocking unauthorized access, thus enabling ease of operation for data access while maintaining security and preventing harmful factors.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

Different network segments are assigned different security qualities: the secure production network maintains high security with restricted access, the non-secure production network provides controlled access with firewall protection, and the test network allows open access for testing purposes. This local quality differentiation enables appropriate data access for testing while maintaining security where needed.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS8291473B2Methods, systems, and computer program products for modeling a secure production network
Publication Date: 2012.10.16 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US8291473B2 patent drawing
  • US8291473B2 patent drawing
  • US8291473B2 patent drawing

AI summary

Methods, systems, and computer program products for modeling a secure production network are provided. A method includes generating a test network for emulating production operations, capturing and analyzing data traffic occurring over the secure production network and a non-secure production network, and determining data flow requirements for isolating the secure production network and the non-secure production network from the test network. The data flow requirements are determined from results of data traffic capture and analysis. The method also includes generating business log from the data flow requirements and applying the business logic to a firewall associated with the test network. The business logic permits transmission of a subset of secure production data to the test network and prevents receipt of incoming transmission at the secure production network.