Zero-Trust Remote Access Tunnels for Dynamic OT Device Support
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current VPN technologies are inefficient for dynamic access configuration and require significant manual effort to set up on-demand access for external clients to devices in an OT network, lacking the ability to consider user roles and device context for access decisions.
Innovation Solution
An automated method using a software solution that creates an overlay network with policy enforcement points and connectors, allowing external clients to access devices through a demilitarized zone, where access requests are validated by a digital twin and policy decision points, enabling dynamic and context-aware access without requiring OT-specific configuration information.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Extent of automation
If VPN technology is used for remote access, then connectivity is established, but manual configuration effort is significant and dynamic access setup is not possible
Solution Approach 1:
The system enables self-service automated access configuration where external clients can request access to OT devices without manual administrative intervention. The access request is processed automatically by matching client context (user role, application) with device context (device type, communication service) and provisioning the appropriate tunnel connection dynamically.
Solution Approach 2:
The access configuration transitions from static VPN setup to dynamic on-demand provisioning. Tunnels are created temporarily when access is requested and validated, allowing external clients to connect to specific OT devices based on current context requirements, and are automatically removed when no longer needed.
2Reliability
If static VPN configuration is used, then access is established, but it is not secure for zero-trust model and does not consider user roles or device context
Solution Approach 1:
Access permissions are customized locally for each client-device pair based on specific context attributes. Instead of a blanket VPN configuration, each tunnel is provisioned with permissions tailored to the external client's user role, application requirements, and the target OT device's characteristics, ensuring minimal necessary access.
Solution Approach 2:
The network access is segmented into isolated tunnels for different external clients and target devices. Each tunnel represents a separate access path with its own authentication and authorization policies, preventing lateral movement and limiting attack surface compared to a shared VPN configuration.
3Ease of operation
If direct connectivity is provided to OT devices, then access is simplified, but security is compromised and OT configuration parameters are exposed
Solution Approach 1:
The system introduces tunnel endpoints and policy decision points as intermediaries between external clients and OT devices. These intermediaries handle authentication, authorization, and traffic filtering, allowing external clients to access OT devices without direct connectivity. The intermediaries also prevent exposure of internal OT network configuration parameters.
Solution Approach 2:
OT-specific configuration parameters (IP addresses, device identifiers) are extracted and hidden from external clients. Access is provided through abstracted tunnel endpoints that forward traffic to the actual OT devices, keeping sensitive configuration information isolated within the OT network boundary.
4Duration of action of stationary object
If long-duration access is provided, then connectivity is maintained, but attack surface is increased and device context may change
Solution Approach 1:
Access tunnels are provisioned for limited durations based on the specific access request and device context requirements. Instead of permanent or long-lived connections, the system creates temporary tunnels that are automatically removed after a predetermined time period or when the access session completes, periodically refreshing access rights based on current device state.
Data Source
Figure 1
Figure 2
AI summary
The invention discloses an automated method for data access to a device (D) of an internal network (IN) by an external client (EC) of an external network (EN), comprising the steps of: - by the external client sending a communication access request for the device to a software implemented application access point (AAP), which is set up to authorize access requests, - by the application access point configuring a corresponding software implemented connector, acting as an endpoint for a communication tunnel (NT) to the device, - by the AAP configuring a corresponding software implemented policy decision point (PDP) as an interface to the external network for arriving of application data traffic of the external client, whereby the PDP is set up to validated accept and forward the access request of the external client to the connector, and - accessing the device via the communication tunnel by the external client.