Transparent Field Device Firewall for Whitelisted HART Communications

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Field devices in industrial networks, particularly those using HART protocol, are vulnerable to cyber-attacks due to lack of inherent security measures, leading to potential tampering of device configurations and disruption of critical processes or safety operations.

Innovation Solution

A field device firewall with a cyber-protection algorithm and memory storing device types and commands, implementing whitelisting to allow only authorized communications, positioned between the field network and process controller, ensuring secure communication without impacting existing network configurations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If field devices are connected to industrial networks with Internet access, then connectivity and accessibility are improved, but vulnerability to cyber-attacks increases

Engineering Contradiction:
Improvenetwork connectivityVSAvoidcyber-attack vulnerability
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a transparent firewall as an intermediary device positioned between the industrial field device and the network. This firewall mediates all communications, inspecting and filtering packets to block malicious traffic while allowing legitimate communications to pass through unchanged, thus resolving the contradiction between network connectivity and cyber-security

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If firewalls are deployed to protect field devices, then security is improved, but network configuration complexity increases

Engineering Contradiction:
Improvecyber-protectionVSAvoidnetwork configuration
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the firewall functionality from traditional complex network security systems and implements it as a standalone transparent device with built-in whitelisting capabilities. The firewall maintains a simplified whitelist of authorized commands and devices, automatically comparing incoming packets against this whitelist without requiring complex configuration rules, thus achieving security with reduced complexity

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If traditional firewalls with IP addresses are used, then network security is improved, but compatibility with existing field devices is reduced

Engineering Contradiction:
Improvesecurity protectionVSAvoidprotocol compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The transparent firewall acts as an intermediary that operates at the packet level without requiring IP addressing or native wireless protocol support. It inspects packets transparently as they pass through the network, allowing it to protect field devices using various protocols (HART, Fieldbus, wireless standards) without needing to understand or configure device-specific address schemes

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The firewall separates security functionality from network layer protocols by operating independently at the packet inspection level. This segmentation allows it to provide security protection without being tied to specific IP addressing schemes or device protocols, maintaining compatibility across different field device types

Inventive Principle:
Principle #1Segmentation

Data Source

PatentEP3586491B1Transparent firewall for protecting field devices
Publication Date: 2025.07.09 HONEYWELL INTERNATIONAL INC
  • EP3586491B1 patent drawingFigure 1
  • EP3586491B1 patent drawingFigure 2
  • EP3586491B1 patent drawingFigure 3

AI summary

A field device firewall (200) includes a processor that runs a cyber-protection algorithm, and a memory (200g) storing a list of device types, requests and commands. The field device firewall is adapted for use in a communications network between a field network communication interface (215) coupled to a field device (225) and a process controller. The field device firewall does not support any native communications with the field device and also lacks an IP address. The cyber-protection algorithm implements comparing information in a received packet to the stored list, allowing transmission of the received packet to the field device if the comparing determines the information is on the stored list, and blocking transmission of the received packet to the field device if the comparing determines the information is not on the stored list.