Virtual Firewall Tunneling for Industrial Datagrams in Automation Cells
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Industrial automation systems face challenges in efficiently checking and securing datagrams within a network of automation cells, particularly due to the need for real-time transmission and protection against unauthorized access across IP-based communication networks, which leads to scalability and configuration complexities.
Innovation Solution
A virtualized and distributed firewall system is implemented, with each automation cell having a firewall interface that transmits datagrams to a virtual machine-based firewall system for rule-based checking, using data link layer tunnels and encapsulating them with network and transport layer headers, ensuring secure and scalable communication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a centralized firewall system is used to check datagrams in industrial automation systems, then security checking capability is improved, but device complexity and scalability are worsened
Solution Approach 1:
The patent divides the centralized firewall system into distributed firewall functions implemented across multiple automation cells. Each automation cell becomes an independent node with firewall capabilities, eliminating the single-point complexity of centralized firewalls while maintaining security checking across the entire system.
Solution Approach 2:
The patent introduces virtualization as a new dimension, implementing firewall functions as virtual machines or containers within the automation control system. This allows security checking to be deployed flexibly across hardware resources without increasing physical device complexity.
2Reliability
If firewall checking is implemented for all datagrams in real-time, then security protection is improved, but data transmission speed is worsened
Solution Approach 1:
The patent implements selective firewall checking where not all datagrams undergo full security verification. Critical time-sensitive automation data may use expedited paths with reduced checking, while non-critical management traffic receives full security scrutiny. This partial action approach maintains security protection while preserving real-time transmission speeds for critical operations.
3Adaptability or versatility
If automation cells are connected via IP communication network for cross-factory networking, then adaptability and scalability are improved, but vulnerability to unauthorized access is worsened
Solution Approach 1:
The patent introduces encrypted communication channels and authentication mechanisms as intermediaries between automation cells on the IP network. These intermediaries verify the legitimacy of datagrams and establish secure tunnels, allowing scalable cross-factory networking while blocking unauthorized access attempts at the communication layer.
4Reliability
If multiple firewall interfaces are deployed in each automation cell, then security coverage is improved, but device complexity and configuration difficulty are worsened
Solution Approach 1:
The patent implements a universal firewall interface design that can handle multiple security functions through a single standardized component. This multi-functional interface provides comprehensive security coverage (inspection, filtering, encryption) while maintaining uniform configuration procedures across all automation cells, reducing overall system complexity despite enhanced security capabilities.
Data Source
Figure 1
AI summary
In order to check datagrams transmitted in an industrial automation system containing a plurality of automation cells, datagrams to be checked are transmitted out of the automation cells via a respective firewall interface in order to check the firewall system and said datagrams are then checked in a rule-based manner. The firewall system is formed by at least one virtual machine provided in a data processing system comprising a plurality of computer units. For the transmission of the datagrams to be checked, a data link layer tunnel is respectively built between each firewall interface and the firewall system. Both datagrams to be checked and at least successfully checked datagrams are transmitted inside the respective data link layer tunnel.