Whitelist Storage Segmentation for Critical Infrastructure Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing communication systems in critical infrastructure networks, such as power plants, face challenges in preventing unauthorized access and maintaining a high security level due to limited memory capacity in packet relay devices, which restricts the number of entries in whitelists, leading to potential breaches even if authorized terminals are compromised.
Innovation Solution
A communication apparatus that generates a whitelist by adding control information indicating data receiver groups and prioritizing entries based on storage conditions, integrating multiple entries to optimize storage capacity while maintaining security levels, and masking parameters to reduce the number of entries required, ensuring high security even when terminals are infected or compromised.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If multiple types of information (sender, destination, protocol) are included in each whitelist entry to prevent attacks from compromised terminals, then security level is improved, but the number of entries increases beyond storage capacity
Solution Approach 1:
The patent segments the whitelist into multiple storage areas (first whitelist storage for control information, second whitelist storage for header information) to separate the storage of identification data from detailed communication parameters. This allows the system to maintain security through comprehensive entry information while managing storage capacity efficiently by dividing the whitelist structure.
Solution Approach 2:
The patent introduces a new dimension by adding control information that identifies data receiver groups, transforming the traditional flat whitelist structure into a hierarchical one. This dimensional change allows the system to manage entries more efficiently by grouping related communications under common receiver identifiers, reducing the effective number of unique entries needed.
2Reliability
If the number of whitelist entries is increased to maintain security when terminals are compromised, then security level is improved, but memory capacity is exceeded
Solution Approach 1:
The patent merges related whitelist entries by introducing control information that groups multiple header information entries under a single control information record. When the same data receiver group receives packets with different header information, the system stores them as one consolidated entry rather than separate entries, reducing total storage requirements while maintaining security coverage.
Solution Approach 2:
The control information in the whitelist serves multiple functions: it identifies the data receiver group, enables packet filtering, and provides the basis for security decisions. This multi-functionality allows a single control information entry to replace what would otherwise require multiple separate entries, optimizing memory usage while maintaining comprehensive security coverage.
Data Source
AI summary
A communication apparatus receives control information of first data and a plurality of types of header information of first data, the first data being received by a first data receiver; selects a parameter from the plurality of types of header information of the first data based on a priority of a first data receiver group to which the first data receiver belongs and a storage condition, the priority being indicated by priority information, the storage condition indicating the number of entries of a whitelist that can be stored in a whitelist storage first memory; and add, to the whitelist, an entry that includes control information of the first data and at least one parameter selected above.


