Virtual Firewall Tunneling for Industrial Datagrams in Automation Cells

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Industrial automation systems face challenges in efficiently checking and securing datagrams within a network of automation cells, particularly due to the need for real-time transmission and protection against unauthorized access across IP-based communication networks, which leads to scalability and configuration complexities.

Innovation Solution

A virtualized and distributed firewall system is implemented, with each automation cell having a firewall interface that transmits datagrams to a virtual machine-based firewall system for rule-based checking, using data link layer tunnels and encapsulating them with network and transport layer headers, ensuring secure and scalable communication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a centralized firewall system is used to check datagrams in industrial automation systems, then security checking capability is improved, but device complexity and scalability are worsened

Engineering Contradiction:
Improvesecurity checking capabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent divides the centralized firewall system into distributed firewall functions implemented across multiple automation cells. Each automation cell becomes an independent node with firewall capabilities, eliminating the single-point complexity of centralized firewalls while maintaining security checking across the entire system.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces virtualization as a new dimension, implementing firewall functions as virtual machines or containers within the automation control system. This allows security checking to be deployed flexibly across hardware resources without increasing physical device complexity.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Reliability

If firewall checking is implemented for all datagrams in real-time, then security protection is improved, but data transmission speed is worsened

Engineering Contradiction:
Improvesecurity protectionVSAvoiddata transmission speed
Core Design Contradiction:
ReliabilityVSSpeed

Solution Approach 1:

The patent implements selective firewall checking where not all datagrams undergo full security verification. Critical time-sensitive automation data may use expedited paths with reduced checking, while non-critical management traffic receives full security scrutiny. This partial action approach maintains security protection while preserving real-time transmission speeds for critical operations.

Inventive Principle:
Principle #16Partial or excessive action

3Adaptability or versatility

If automation cells are connected via IP communication network for cross-factory networking, then adaptability and scalability are improved, but vulnerability to unauthorized access is worsened

Engineering Contradiction:
Improvecross-factory networking capabilityVSAvoidunauthorized access risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces encrypted communication channels and authentication mechanisms as intermediaries between automation cells on the IP network. These intermediaries verify the legitimacy of datagrams and establish secure tunnels, allowing scalable cross-factory networking while blocking unauthorized access attempts at the communication layer.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If multiple firewall interfaces are deployed in each automation cell, then security coverage is improved, but device complexity and configuration difficulty are worsened

Engineering Contradiction:
Improvesecurity coverageVSAvoidconfiguration ease
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements a universal firewall interface design that can handle multiple security functions through a single standardized component. This multi-functional interface provides comprehensive security coverage (inspection, filtering, encryption) while maintaining uniform configuration procedures across all automation cells, reducing overall system complexity despite enhanced security capabilities.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP3646559B1Method for inspecting datagrams transmitted within an industrial automation system and automation and/or communication device
Publication Date: 2021.06.09 SIEMENS AG
  • EP3646559B1 patent drawingFigure 1

AI summary

In order to check datagrams transmitted in an industrial automation system containing a plurality of automation cells, datagrams to be checked are transmitted out of the automation cells via a respective firewall interface in order to check the firewall system and said datagrams are then checked in a rule-based manner. The firewall system is formed by at least one virtual machine provided in a data processing system comprising a plurality of computer units. For the transmission of the datagrams to be checked, a data link layer tunnel is respectively built between each firewall interface and the firewall system. Both datagrams to be checked and at least successfully checked datagrams are transmitted inside the respective data link layer tunnel.