Industrial Security Agent Platform for Legacy Controllers
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Industrial control systems face security risks due to the connection of operational technology networks with information technology networks and the Internet, as some controller devices lack cybersecurity features and are vulnerable to unauthorized access and attacks.
Innovation Solution
An industrial security agent platform is implemented, which creates virtual security entities for each controller device, using device emulators to handle network communications and provide secure representations, enabling cybersecurity controls like authentication and encryption without interrupting system operations or requiring software installations on the devices.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If controller devices are connected to enterprise networks and the Internet, then network accessibility and information sharing are improved, but vulnerability to unauthorized access and attacks increases
Solution Approach 1:
The patent introduces a security gateway as an intermediary device between controller devices and enterprise networks/Internet. The gateway performs authentication, encryption, and protocol translation, allowing network connectivity while filtering and securing communications. This mediator protects vulnerable controllers from direct exposure to network threats while maintaining accessibility.
Solution Approach 2:
The system segments the network architecture into isolated zones: a control zone containing controller devices, a demilitarized zone (DMZ) with the security gateway, and an enterprise network zone. This segmentation limits attack propagation and contains vulnerabilities to specific segments, allowing network connectivity without exposing all devices to the same risk level.
2Reliability
If cybersecurity controls like authentication and encryption are implemented, then security is improved, but device complexity and operational overhead increase
Solution Approach 1:
The patent combines multiple security functions (authentication, encryption, decryption, protocol translation) into a single security gateway device. This consolidation reduces the complexity burden on individual controller devices while maintaining comprehensive security controls. The gateway handles all cryptographic operations and security policies centrally.
Solution Approach 2:
The security gateway automatically performs authentication, key management, and encryption/decryption operations without requiring manual intervention or complex configuration on controller devices. The system self-manages security credentials and cryptographic keys, reducing operational overhead for users while maintaining strong security controls.
3Reliability
If software installations or updates are required on controller devices, then security capabilities are improved, but system operations are interrupted
Solution Approach 1:
The security gateway serves as an external intermediary that provides security capabilities without requiring software installation on controller devices. By placing security functionality in the gateway, the system avoids interrupting controller operations while still enhancing security capabilities through external security services.
Solution Approach 2:
The gateway creates virtual representations or proxies of controller devices and handles security communications on their behalf. This copying approach allows security controls to be applied without modifying or installing software on the actual controller devices, maintaining operational continuity while providing security enhancements.
Data Source
AI summary
Systems, methods, and apparatus, including computer programs encoded on computer storage media, for facilitating communication in an industrial control network. A system includes an industrial control network, one or more controller devices, one or more emulators, and an encryption relay processor. Each controller device can be operable to control one or more operational devices connected to the industrial control network. Each emulator can be configured to communicate with a respective controller device, and each emulator can be configured to reference a respective profile that includes information about security capabilities of the respective controller device. The encryption relay processor can be operable to facilitate communication to and from each emulator over the industrial control network. The encryption relay processor can execute a cryptographic function for a communication between the emulator and a node on the industrial control network when the respective controller device is incapable of performing the cryptographic function.


