Zero-Trust Remote Access for OT Devices
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing VPN technologies are inefficient for dynamic access configuration and require significant administrative effort, making it difficult to set up on-demand access for external clients to devices in an OT network, especially in shopfloor environments, and fail to consider user roles and device context for access decisions.
Innovation Solution
Implementing a zero-trust remote access system using software components like application access points, connectors, policy decision points, and digital twins to automate and validate access requests, creating on-demand communication tunnels within a demilitarized zone, separating device and application traffic, and ensuring context-based access without revealing OT-specific configuration parameters.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Extent of automation
If VPN technology is used for remote access, then access to devices is established, but dynamic access configuration and on-demand setup require significant manual administrative effort
Solution Approach 1:
The system enables self-service access configuration where external clients can request access to OT devices automatically. The access point validates requests against predefined policies and digital twins, automatically establishing communication tunnels without requiring manual IT administration. This transforms the process from manual configuration to automated self-service access.
Solution Approach 2:
The invention changes the configuration parameters from static VPN settings to dynamic, context-based parameters. Access decisions are made based on real-time evaluation of user roles, device context, and digital twin data, allowing parameters like access duration, permissions, and communication channels to be dynamically adjusted rather than fixed in advance.
2Adaptability or versatility
If static VPN configuration is used, then access is established for a specified duration, but dynamic access configuration from external clients to devices in shopfloor is not efficiently possible
Solution Approach 1:
The system replaces static VPN configurations with dynamic access control. The access point continuously evaluates current context (user roles, device state, digital twin data) to make real-time access decisions. Communication tunnels can be established, modified, or terminated dynamically based on changing conditions, enabling flexible adaptation to different access scenarios without manual reconfiguration.
Solution Approach 2:
The system performs preliminary validation by evaluating access requests against predefined policies and digital twin data before establishing communication. This pre-checking mechanism ensures that only authorized access is permitted, while the actual tunnel establishment occurs automatically and rapidly once validation passes, reducing overall setup time.
3Ease of operation
If direct connectivity of devices from shopfloor to Internet is implemented, then access is simplified, but security risks increase and OT-specific configuration parameters become exposed
Solution Approach 1:
The invention introduces an intermediary access point between external clients and OT devices. This access point acts as a secure gateway that receives access requests, validates them against policies and digital twins, and establishes encrypted communication tunnels. It prevents direct exposure of OT devices to the internet while maintaining simplified access for authorized users, thereby reducing security risks and hiding sensitive configuration parameters.
Solution Approach 2:
The system segments the network architecture by separating OT devices in the shopfloor from the external internet through a dedicated access point and demilitarized zone. This segmentation creates a secure boundary that allows controlled access while preventing direct connectivity, thus protecting OT-specific configuration parameters and reducing the attack surface.
4Reliability
If access decisions are made without considering user roles and device context, then access control is simplified, but security and adaptability are compromised
Solution Approach 1:
The system implements feedback mechanisms where the access point continuously monitors and evaluates user roles, device context, and digital twin data to make informed access decisions. This feedback loop ensures that access control is both secure and adaptive, adjusting permissions based on real-time context while maintaining reliable security through automated validation.
Solution Approach 2:
The access point serves multiple functions: it validates access requests, evaluates user roles, checks device context, compares digital twin data, and establishes secure tunnels. By consolidating these functions into a single multi-functional component, the system achieves reliable security without proportionally increasing overall system complexity.
Data Source
AI summary
Various embodiments of the teachings herein include an automated method for data access to a device by an external client, allowing the device to communicate with an internal communication network while the external client communicates with an external communication network. An example method includes: sending a communication access request from the external client for the device to a software implemented application access point; configuring a corresponding software implemented connector using the application access point, so the connector acts as an endpoint for a communication tunnel to the device; configuring a corresponding software implemented policy decision point using the application access point as an interface to the external network for arriving of application data traffic of the external client, so the policy decision point is set up to validate, accept, and forward the access request of the external client to the connector; and accessing the device via the communication tunnel.

