Security Appliance Protocol Conversion IEC 61131-3

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Integrating subsystem devices that communicate using various legacy protocols into a modern secure Ethernet network is complex due to the need for multiple devices from different vendors, each serving a single function and using different configuration tools, leading to high engineering complexity and security exposure, with existing security appliances lacking user-customizable programming environments.

Innovation Solution

A security appliance with processing circuitry that receives data from one network using a first secure protocol, determines its intended destination on a second network with a different secure protocol, authenticates and transmits the data, and collects additional data, utilizing an embedded IEC 61131 environment for protocol conversion and manipulation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If multiple devices from different vendors are used to integrate legacy protocols into a secure Ethernet network, then protocol compatibility is improved, but device complexity and engineering complexity increase

Engineering Contradiction:
Improveprotocol compatibilityVSAvoidengineering complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent combines multiple previously separate devices (protocol converter, gateway, firewall, and security appliance) into a single integrated security appliance. This consolidation maintains support for multiple legacy protocols and secure Ethernet network integration while reducing the number of individual components, simplifying engineering complexity, and eliminating the need for multiple vendor-specific configuration tools.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The security appliance is designed with multi-functional capabilities to perform protocol conversion, data authentication, and security enforcement across multiple legacy protocols (such as Modbus, Profibus, and EtherNet/IP) and secure Ethernet networks simultaneously. This universal design allows a single device to replace multiple specialized devices, reducing overall system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If multiple devices from different vendors are used, then protocol support is improved, but security exposure increases

Engineering Contradiction:
Improveprotocol supportVSAvoidsecurity exposure
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

By consolidating security functions into a single appliance, the attack surface is reduced compared to having multiple separate devices. The integrated architecture allows for centralized security policy enforcement and consistent authentication mechanisms across all protocol conversions, reducing security gaps that could exist between multiple vendor-specific devices.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The security appliance acts as an intermediary between legacy protocol devices and the secure Ethernet network. It performs authentication and validation of data packets before allowing communication, effectively mediating security between incompatible systems with different security postures. This intermediary role centralizes security control and prevents direct exposure of the secure network to potentially insecure legacy devices.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If existing security appliances are used, then security enforcement is improved, but adaptability and user customization are reduced

Engineering Contradiction:
Improvesecurity enforcementVSAvoiduser customization
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The security appliance incorporates a programmable environment that allows users to dynamically configure security policies, authentication methods, and protocol conversion rules according to specific application requirements. This dynamic configurability enables customization while maintaining strong security enforcement, as the system can adapt its behavior based on user-defined parameters rather than being fixed in functionality.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS10637841B2Apparatus and method for using a security appliance with IEC 61131-3
Publication Date: 2020.04.28 HONEYWELL INTERNATIONAL INC
  • US10637841B2 patent drawing
  • US10637841B2 patent drawing
  • US10637841B2 patent drawing

AI summary

A security appliance to perform a method that includes receiving a first set of data from a first device using a first secure protocol of a first network, the first secure protocol comprises a first level of security, and determining, by the security appliance, that the received first set of data is intended for a second device on a second network using a second secure protocol, the second secure protocol comprises a second level of security different from the first. The method includes authenticating, by the security appliance, the received first set of data from the first network using the first secure protocol for transmission through the second network using the second secure protocol while collecting and concentrating additional data from the first network and transmitting, by the security appliance, the received first set of data to the second device via the second network comprising the second secure protocol.