Zero Trust Adapters for Secure Deterministic Industrial Data
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing industrial automation systems face challenges in integrating zero trust concepts due to economic constraints on cryptographic functionality and hardware limitations, which hinder data security and deterministic data transmission.
Innovation Solution
A communication system with a control network separate from local networks, utilizing zero trust adapters to capture and preprocess status information, determine trust scores, and apply rules for secure communication, ensuring compatibility with existing infrastructure.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If zero trust concepts are integrated into industrial automation systems, then data security is improved, but device complexity and cost increase due to additional cryptographic functionality and hardware requirements
Solution Approach 1:
The patent introduces a firewall system as an intermediary component that mediates between the existing industrial communication network and the zero trust security requirements. The firewall system performs authentication and authorization functions without requiring cryptographic functionality in every terminal device, thus achieving data security while avoiding the complexity of distributed cryptographic implementations.
Solution Approach 2:
The patent creates a virtualized firewall system using virtual machines that replicate security functions. Instead of embedding complex cryptographic hardware in each terminal, the system uses virtual machine instances that can be deployed on existing servers, providing the necessary security functionality through software-based copies rather than hardware-intensive implementations.
2Reliability
If mutual authentication of communication partners is implemented, then data security is improved, but deterministic data transmission and processing become more difficult
Solution Approach 1:
The patent performs authentication actions preliminarily before data transmission begins. The firewall system authenticates communication partners in advance and establishes secure connections, allowing subsequent data transmission to proceed deterministically without repeated authentication interruptions. This preliminary authentication approach separates the security function from the data transmission function, preserving determinism.
Solution Approach 2:
The patent segments the communication system into distinct functional layers: authentication layer handled by the firewall system, and data transmission layer handled by the industrial communication network. This segmentation allows authentication to occur independently and deterministically, while data transmission follows predictable paths once authentication is complete, maintaining deterministic behavior.
3Reliability
If existing security protocols are adapted to implement zero trust concepts, then data security is improved, but integration difficulty increases due to incompatibility with existing infrastructure
Solution Approach 1:
The patent designs the firewall system to perform multiple functions: authentication, authorization, and data transmission filtering. This multi-functional approach allows the system to work with existing industrial communication protocols while implementing zero trust security, avoiding the need to replace or adapt complex existing infrastructure.
Solution Approach 2:
The firewall system acts as an intermediary that translates between existing industrial communication protocols and zero trust security requirements. It intercepts communications, performs authentication according to zero trust principles, and allows or blocks transmissions based on authentication results, thereby integrating security without requiring changes to existing terminal devices or communication protocols.
Data Source
AI summary
A method for securely transmitting time-critical data within a communication system that includes local networks each having a switch and a plurality of terminals, a controller that controls functions of switches and terminals, and having a control network assigned to the controller and separate from the local networks, where communication within the local networks is implicitly authorized based on an assignment of respective terminals to the same local network, each terminal is assigned a zero trust adapter that captures status information, transfers the status information via the control network to the controller for evaluation and authenticates the terminal to the controller to communication partners, and where the controller determines a trust index for each of the terminals based on the status information and applies rules dependent on the trust index for configuration or permissible communication relationships of the terminals.


