Single Link Connector for Plant Network Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current access management systems for plant networks face inefficiencies due to numerous security rules, increased virus spread probability, and compatibility issues, as each computer on the corporate network requires individual configuration and interaction with multiple plant applications, leading to processing overload and incompatibilities.

Innovation Solution

A Single Link Connector (SLC) computer is introduced to consolidate all network connections from the corporate network into a single point, allowing only the SLC to communicate with the plant network, thereby reducing firewall rules and minimizing virus spread by funneling all traffic through a secured and protected single access point.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If individual security rules are configured on the firewall for each computer in the corporate network to access plant applications, then authorized access control is improved, but device complexity and processing load increase significantly

Engineering Contradiction:
Improveauthorized access controlVSAvoidfirewall configuration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges multiple individual computer connections into a single gateway server connection. The gateway server consolidates access requests from multiple corporate network computers into unified connections to plant applications, reducing the number of firewall rules from hundreds to just a few rules governing the gateway server's access.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The gateway server acts as an intermediary between the corporate network and the plant network. It receives requests from multiple corporate computers, processes them centrally, and forwards authenticated requests to plant applications through the firewall, eliminating the need for individual firewall rules for each corporate computer.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If multiple direct connections are allowed from corporate network computers to plant applications, then access flexibility is improved, but the probability of virus spread increases

Engineering Contradiction:
Improveaccess flexibilityVSAvoidvirus spread probability
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The gateway server serves as a security intermediary that all corporate network access must pass through. It implements security scanning, authentication, and request filtering before forwarding to plant applications, maintaining access flexibility while blocking viruses and malicious content at the gateway layer.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system segments the network access path into distinct security zones: the corporate network side, the gateway server security layer, and the plant network side. This segmentation isolates the plant network from direct exposure to corporate network threats while maintaining controlled access through the security gateway.

Inventive Principle:
Principle #1Segmentation

3Measurement precision

If numerous security rules are configured on the firewall for each computer, then access control precision is improved, but processing load and maintenance difficulty increase

Engineering Contradiction:
Improveaccess control precisionVSAvoidconfiguration and maintenance time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The gateway server consolidates access control logic for multiple computers into a single centralized system. Instead of maintaining separate firewall rules for each computer, the gateway implements unified authentication and authorization, reducing configuration time from hours to minutes while maintaining precise access control through centralized policy management.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS10038670B2System and method for controlling access to a plant network
Publication Date: 2018.07.31 SAUDI ARABIAN OIL CO
  • US10038670B2 patent drawing
  • US10038670B2 patent drawing
  • US10038670B2 patent drawing

AI summary

A system for centrally controlling access by computers in a corporate network to a plant network that runs plant applications. The system includes an access control computer in communication with the corporate network and includes a memory, a processor coupled to the memory and a multi-user application stored in the memory and executable by the processor. The multi-user application communicates with a plurality of computers in the corporate network concurrently and communicates with at least one plant application running in the plant network to retrieve data from and pass data to the plant application on behalf of the plurality of computers in the corporate network concurrently. Since all communication from the plurality of computers is tunneled through the access control computer, the likelihood of any virus or worm spreading into the plant network is minimized.