Virtual Firewall Port Configuration for Industrial Automation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Industrial automation networks face inefficiencies in configuring firewalls due to their rigid structure and predictable traffic patterns, which traditional firewall solutions struggle to adapt to, leading to suboptimal security and segmentation.

Innovation Solution

Implementing a virtual firewall on each port of devices communicating across zone boundaries within an industrial network, configured based on the network's operation and specific industrial protocols, enabling fine-grained, software-defined network (SDN) control for deterministic and secure communication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional firewall solutions are used in industrial automation networks, then basic security protection is provided, but the firewall cannot adapt to the rigid structure and predictable traffic patterns, leading to suboptimal security and segmentation

Engineering Contradiction:
Improvesecurity enforcementVSAvoidadaptability to network structure
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent applies dynamics by making the firewall configuration adaptive and changeable based on network conditions. The system dynamically adjusts firewall rules to match the actual traffic patterns and network structure, transforming the static firewall into a dynamic security mechanism that evolves with the network environment.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the parameters of firewall configuration from fixed to variable. By monitoring traffic patterns and network topology, the system automatically adjusts firewall parameters such as rule sets, zone definitions, and conduit configurations to optimize security enforcement for the specific industrial automation network characteristics.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If virtual firewalls are implemented on each port with fine-grained control, then security enforcement and validation are enhanced, but device complexity and configuration difficulty increase

Engineering Contradiction:
Improvesecurity enforcementVSAvoidfirewall configuration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements self-service by enabling the firewall system to automatically configure itself based on observed network behavior. The virtual firewalls monitor traffic patterns, identify legitimate communication flows, and automatically generate appropriate security rules, eliminating the need for manual configuration and reducing complexity despite the fine-grained control capability.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system employs feedback mechanisms where the firewall continuously monitors network traffic and uses this information to refine its security rules. The feedback loop allows the system to learn from actual network operations and automatically adjust configurations, reducing the burden on administrators while maintaining high security standards.

Inventive Principle:
Principle #23Feedback

3Reliability

If firewalls are synchronized with traffic flows and conduit locations, then granular control and compliance with security standards are achieved, but loss of time for configuration and setup increases

Engineering Contradiction:
Improvecompliance with security standardsVSAvoidconfiguration time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies preliminary action by pre-configuring virtual firewalls on all ports before network operations begin. The system proactively establishes security zones and conduits based on expected network topology, allowing firewalls to be ready immediately upon network deployment rather than requiring time-consuming configuration after the fact.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system automatically synchronizes firewall rules with traffic flows and conduit locations through self-configuration. By monitoring network operations and automatically adapting rules, the system achieves compliance with security standards without requiring manual intervention or time-consuming configuration processes.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10243926B2Configuring firewalls for an industrial automation network
Publication Date: 2019.03.26 CISCO TECHNOLOGY INC
  • US10243926B2 patent drawing
  • US10243926B2 patent drawing
  • US10243926B2 patent drawing

AI summary

In one embodiment, a virtual firewall is installed on a port of a device that communicates across a zone boundary within an industrial network. The virtual firewall is then configured based on operation of the industrial network, such that the port may then communicate via the firewall to a remote virtual firewall of a remote port of a remote device across the zone boundary.