Smart Network Switching for Industrial Control Traffic Authorization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional technologies for protecting industrial control systems from cyber-attacks are difficult to scale and manage, especially in larger systems, and often assume endpoints are secure, which is a flawed assumption, limiting their effectiveness in preventing unauthorized access and attacks.

Innovation Solution

A smart network switching system utilizing software-defined networking that monitors and controls industrial control system traffic at the application layer, enabling real-time creation and modification of rules, out-of-band monitoring and control, and scalable management of endpoints to prevent unauthorized access and attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional monitoring technologies are used, then basic traffic monitoring is achieved, but scalability and remote management capability are poor

Engineering Contradiction:
Improvesecurity monitoring capabilityVSAvoidsystem scalability
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a software-defined networking (SDN) controller as an intermediary between the network switches and the monitoring system. This controller abstracts the complex switching operations and provides centralized management, enabling scalable deployment across large networks while maintaining comprehensive security monitoring. The SDN architecture separates the control plane from the data plane, allowing complex security policies to be managed remotely without complicating the underlying network infrastructure.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Device complexity

If endpoint security assumptions are made, then system complexity is reduced, but security effectiveness deteriorates due to compromised endpoints

Engineering Contradiction:
Improvesystem simplicityVSAvoidsecurity effectiveness
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent places an intermediary monitoring system at the network layer between endpoints and their destinations. This intermediary can inspect, filter, and control traffic without requiring trust in the endpoint systems. By operating at the network level rather than relying on endpoint security, the system maintains simplicity while achieving robust security that is independent of endpoint integrity.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If bump-in-the-wire devices are deployed for equipment protection, then individual equipment security is improved, but scalability to larger systems is poor

Engineering Contradiction:
Improveequipment securityVSAvoiddeployment scalability
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements a universal network switch architecture that can serve multiple functions simultaneously: data forwarding, security monitoring, access control, and traffic management. This multi-functional switch replaces the need for multiple specialized devices like bump-in-the-wire protectors, providing comprehensive equipment security while enabling scalable deployment across entire networks through a single standardized platform.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Reliability

If span port monitoring is used, then traffic monitoring capability is achieved, but remote management and control capability are limited

Engineering Contradiction:
Improvetraffic monitoring capabilityVSAvoidremote management capability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent replaces the mechanical/physical approach of span port configuration with software-defined networking control. Instead of manually configuring span ports on physical switches, the system uses an SDN controller to programmatically manage traffic monitoring and access control policies. This substitution enables remote management and dynamic policy changes without physical access to the switches, while maintaining comprehensive traffic monitoring capability.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS12028318B2Smart network switching systems and related methods
Publication Date: 2024.07.02 BATTELLE ENERGY ALLIANCE LLC
  • US12028318B2 patent drawing
  • US12028318B2 patent drawing
  • US12028318B2 patent drawing

AI summary

A method of monitoring and controlling network traffic within an industrial control system including receiving one or more data packets at a smart network switching system operating software-defined networking, analyzing the one or more data packets at a protocol level within a control plane of the software-defined networking, based on the analysis, determining whether the one or more data packets are authorized data packets, and forwarding a data packet of the one or more data packets to a destination device within a data plane of the software-defined networking upon determining that the data packet is an authorized data packet. The method further includes providing information related to the analysis of the one or more data packets to an out-of-band monitoring and control system for display to a user, and receiving a response communication from the out-of-band monitoring and control system indicating whether the one or more data packets are authorized data packets.