Security Function Execution Device for Legacy OT Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Enabling security measures in legacy Operational Technology (OT) systems is challenging due to the need for system updates and partial replacements, which are costly. Additionally, network mediation techniques, such as Man-in-the-Middle (MitM), cause communication delays and resource depletion, making them difficult to apply effectively in legacy IP-based network systems.
Innovation Solution
The method involves identifying the attributions of nodes in a network, determining the criticality of each node, and mediating communications between non-critical nodes while executing security functions on these mediated communications. This approach allows for efficient security measures without altering the system configuration or requiring additional updates.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If network mediation (MitM) is used to secure communications in legacy OT systems, then security function is improved, but communication delay increases and resource depletion occurs
Solution Approach 1:
The patent applies different security mediation strategies to different communication scenarios. Critical communications (e.g., control commands) bypass mediation to avoid delays, while non-critical communications (e.g., monitoring data) undergo full security checking. This localized application of security functions resolves the contradiction by ensuring security where needed without compromising time-critical operations.
Solution Approach 2:
The patent segments communications into critical and non-critical categories based on their importance and timing requirements. By dividing the communication stream and applying different mediation levels to each segment, the system achieves both security for non-critical traffic and real-time performance for critical traffic, resolving the contradiction between security and communication delay.
2Reliability
If proxy server mediates all communications between nodes, then security coverage is improved, but resource availability decreases and communication efficiency deteriorates
Solution Approach 1:
The patent implements selective security mediation where only communications involving vulnerable nodes or non-critical traffic are mediated through the proxy server. Critical communications between trusted nodes bypass the proxy entirely. This localized security approach maintains comprehensive security coverage for vulnerable areas while preserving communication efficiency for critical operations.
Solution Approach 2:
Instead of applying full security mediation to all communications, the patent applies partial mediation only where necessary based on node vulnerability assessment and communication criticality. This partial action approach achieves adequate security coverage without the performance penalty of universal mediation, resolving the contradiction between security coverage and communication efficiency.
3Reliability
If system updates and partial replacements are implemented to enable security measures, then security capability is improved, but engineering cost increases
Solution Approach 1:
The patent introduces a proxy server as an intermediary security device that operates between the legacy OT systems and the network. This mediator provides modern security capabilities (authentication, encryption, monitoring) without requiring modifications to the legacy OT equipment itself. The solution achieves improved security capability while avoiding the high engineering costs of system updates and replacements.
Solution Approach 2:
Instead of investing in expensive, long-term system updates and hardware replacements, the patent employs a software-based proxy server that can be deployed quickly and modified easily. This approach provides adequate security capability at lower engineering cost by using software intermediaries rather than hardware modifications to legacy systems.
Data Source
AI summary
A security function execution device in communication with a network. The device may include a processor, the processor is configured to: identify attributions of a plurality of nodes in communications with the network; determine criticality of each node of the plurality of nodes based on the attributions; and mediate communications between nodes of the plurality of nodes that are determined as being non-critical and execute security functions on the mediated communications.


