Tunnel Device Bypassing Gateway for Secure Layer Communication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing communication systems face challenges in enabling direct communication between equipment connected to different layers, particularly when using International Society for Automation (ISA) 100.11a standards, and struggle to secure end-to-end security in such communications.
Innovation Solution
The introduction of a tunnel device that bypasses the gateway device to establish a virtual tunnel for direct communication between lower-layer equipment and higher-layer applications, enabling end-to-end security through encryption and authentication processes, while also performing priority and access control, and synchronizing settings with other tunnel devices.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If communication is performed via the gateway device between lower-layer equipment and higher-layer application, then protocol conversion can be performed, but end-to-end security cannot be secured and direct communication is impossible
Solution Approach 1:
The patent introduces a tunnel device as an intermediary that establishes a direct communication path between lower-layer equipment and higher-layer applications. This tunnel device acts as a mediator that enables secure end-to-end communication while bypassing the gateway device, thus resolving the contradiction between security requirements and communication path complexity
Solution Approach 2:
The patent segments the communication system into two distinct paths: the existing gateway-based path for general communication and a new tunnel-based path for secure direct communication. This segmentation allows different communication requirements to be met through different paths, enabling both protocol conversion through the gateway and end-to-end security through the tunnel
2Adaptability or versatility
If the gateway device detects and performs protocol conversion on all communications, then communication between different layers is enabled, but the gateway device cannot handle new communications efficiently and end-to-end security is compromised
Solution Approach 1:
The tunnel device serves as a specialized intermediary that handles secure direct communications between lower-layer equipment and higher-layer applications. By offloading these specific communication tasks from the gateway device, the system improves overall communication handling efficiency while maintaining the gateway's protocol conversion capabilities for other communications
Solution Approach 2:
The patent segments communication handling between the gateway device and tunnel device based on communication type. The gateway handles general protocol conversion tasks, while the tunnel device handles secure direct communications. This segmentation improves productivity by distributing communication handling responsibilities appropriately
3Reliability
If direct communication is established between lower-layer equipment and higher-layer application, then end-to-end security is secured, but the gateway device cannot perform protocol conversion for this communication
Solution Approach 1:
The patent creates two separate communication channels: one through the gateway device for communications requiring protocol conversion, and another through the tunnel device for communications requiring end-to-end security. This segmentation allows each channel to be optimized for its specific purpose without compromising the other
Solution Approach 2:
The system maintains multi-functionality by allowing communications to be routed through either the gateway device or the tunnel device depending on requirements. The gateway device retains its protocol conversion function, while the tunnel device provides secure direct communication, making the overall system adaptable to different communication needs
Data Source
AI summary
A communication system may include a first network connected to lower-layer equipment, a second network connected to a higher-layer application, a gateway device connected to the first network and the second network, and a tunnel device connected to the first network and the second network, the tunnel device bypassing the gateway device.


