Security Function Execution Device for Legacy OT Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Enabling security measures in legacy Operational Technology (OT) systems is challenging due to the need for system updates and partial replacements, which are costly. Additionally, network mediation techniques, such as Man-in-the-Middle (MitM), cause communication delays and resource depletion, making them difficult to apply effectively in legacy IP-based network systems.

Innovation Solution

The method involves identifying the attributions of nodes in a network, determining the criticality of each node, and mediating communications between non-critical nodes while executing security functions on these mediated communications. This approach allows for efficient security measures without altering the system configuration or requiring additional updates.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If network mediation (MitM) is used to secure communications in legacy OT systems, then security function is improved, but communication delay increases and resource depletion occurs

Engineering Contradiction:
Improvesecurity functionVSAvoidcommunication delay
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies different security mediation strategies to different communication scenarios. Critical communications (e.g., control commands) bypass mediation to avoid delays, while non-critical communications (e.g., monitoring data) undergo full security checking. This localized application of security functions resolves the contradiction by ensuring security where needed without compromising time-critical operations.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent segments communications into critical and non-critical categories based on their importance and timing requirements. By dividing the communication stream and applying different mediation levels to each segment, the system achieves both security for non-critical traffic and real-time performance for critical traffic, resolving the contradiction between security and communication delay.

Inventive Principle:
Principle #1Segmentation

2Reliability

If proxy server mediates all communications between nodes, then security coverage is improved, but resource availability decreases and communication efficiency deteriorates

Engineering Contradiction:
Improvesecurity coverageVSAvoidcommunication efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements selective security mediation where only communications involving vulnerable nodes or non-critical traffic are mediated through the proxy server. Critical communications between trusted nodes bypass the proxy entirely. This localized security approach maintains comprehensive security coverage for vulnerable areas while preserving communication efficiency for critical operations.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

Instead of applying full security mediation to all communications, the patent applies partial mediation only where necessary based on node vulnerability assessment and communication criticality. This partial action approach achieves adequate security coverage without the performance penalty of universal mediation, resolving the contradiction between security coverage and communication efficiency.

Inventive Principle:
Principle #16Partial or excessive action

3Reliability

If system updates and partial replacements are implemented to enable security measures, then security capability is improved, but engineering cost increases

Engineering Contradiction:
Improvesecurity capabilityVSAvoidengineering cost
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent introduces a proxy server as an intermediary security device that operates between the legacy OT systems and the network. This mediator provides modern security capabilities (authentication, encryption, monitoring) without requiring modifications to the legacy OT equipment itself. The solution achieves improved security capability while avoiding the high engineering costs of system updates and replacements.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

Instead of investing in expensive, long-term system updates and hardware replacements, the patent employs a software-based proxy server that can be deployed quickly and modified easily. This approach provides adequate security capability at lower engineering cost by using software intermediaries rather than hardware modifications to legacy systems.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Data Source

PatentUS12335167B2Security function execution device
Publication Date: 2025.06.17 HITACHI LTD
  • US12335167B2 patent drawing
  • US12335167B2 patent drawing
  • US12335167B2 patent drawing

AI summary

A security function execution device in communication with a network. The device may include a processor, the processor is configured to: identify attributions of a plurality of nodes in communications with the network; determine criticality of each node of the plurality of nodes based on the attributions; and mediate communications between nodes of the plurality of nodes that are determined as being non-critical and execute security functions on the mediated communications.