Zero-Trust Remote Access Tunnels for Dynamic OT Device Support

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current VPN technologies are inefficient for dynamic access configuration and require significant manual effort to set up on-demand access for external clients to devices in an OT network, lacking the ability to consider user roles and device context for access decisions.

Innovation Solution

An automated method using a software solution that creates an overlay network with policy enforcement points and connectors, allowing external clients to access devices through a demilitarized zone, where access requests are validated by a digital twin and policy decision points, enabling dynamic and context-aware access without requiring OT-specific configuration information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Extent of automation

If VPN technology is used for remote access, then connectivity is established, but manual configuration effort is significant and dynamic access setup is not possible

Engineering Contradiction:
Improveaccess configurationVSAvoidsetup time
Core Design Contradiction:
Extent of automationVSLoss of time

Solution Approach 1:

The system enables self-service automated access configuration where external clients can request access to OT devices without manual administrative intervention. The access request is processed automatically by matching client context (user role, application) with device context (device type, communication service) and provisioning the appropriate tunnel connection dynamically.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The access configuration transitions from static VPN setup to dynamic on-demand provisioning. Tunnels are created temporarily when access is requested and validated, allowing external clients to connect to specific OT devices based on current context requirements, and are automatically removed when no longer needed.

Inventive Principle:
Principle #15Dynamics

2Reliability

If static VPN configuration is used, then access is established, but it is not secure for zero-trust model and does not consider user roles or device context

Engineering Contradiction:
ImprovesecurityVSAvoidaccess control mechanism
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Access permissions are customized locally for each client-device pair based on specific context attributes. Instead of a blanket VPN configuration, each tunnel is provisioned with permissions tailored to the external client's user role, application requirements, and the target OT device's characteristics, ensuring minimal necessary access.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The network access is segmented into isolated tunnels for different external clients and target devices. Each tunnel represents a separate access path with its own authentication and authorization policies, preventing lateral movement and limiting attack surface compared to a shared VPN configuration.

Inventive Principle:
Principle #1Segmentation

3Ease of operation

If direct connectivity is provided to OT devices, then access is simplified, but security is compromised and OT configuration parameters are exposed

Engineering Contradiction:
Improveaccess simplicityVSAvoidsecurity risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system introduces tunnel endpoints and policy decision points as intermediaries between external clients and OT devices. These intermediaries handle authentication, authorization, and traffic filtering, allowing external clients to access OT devices without direct connectivity. The intermediaries also prevent exposure of internal OT network configuration parameters.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

OT-specific configuration parameters (IP addresses, device identifiers) are extracted and hidden from external clients. Access is provided through abstracted tunnel endpoints that forward traffic to the actual OT devices, keeping sensitive configuration information isolated within the OT network boundary.

Inventive Principle:
Principle #2Taking out (Extraction)

4Duration of action of stationary object

If long-duration access is provided, then connectivity is maintained, but attack surface is increased and device context may change

Engineering Contradiction:
Improveaccess durationVSAvoidattack surface
Core Design Contradiction:
Duration of action of stationary objectVSObject-affected harmful factors

Solution Approach 1:

Access tunnels are provisioned for limited durations based on the specific access request and device context requirements. Instead of permanent or long-lived connections, the system creates temporary tunnels that are automatically removed after a predetermined time period or when the access session completes, periodically refreshing access rights based on current device state.

Inventive Principle:
Principle #19Periodic action

Data Source

PatentEP4089974B1Software defined remote access for zero-trust support
Publication Date: 2023.08.23 SIEMENS AG
  • EP4089974B1 patent drawingFigure 1
  • EP4089974B1 patent drawingFigure 2

AI summary

The invention discloses an automated method for data access to a device (D) of an internal network (IN) by an external client (EC) of an external network (EN), comprising the steps of: - by the external client sending a communication access request for the device to a software implemented application access point (AAP), which is set up to authorize access requests, - by the application access point configuring a corresponding software implemented connector, acting as an endpoint for a communication tunnel (NT) to the device, - by the AAP configuring a corresponding software implemented policy decision point (PDP) as an interface to the external network for arriving of application data traffic of the external client, whereby the PDP is set up to validated accept and forward the access request of the external client to the connector, and - accessing the device via the communication tunnel by the external client.