Zero-Trust OT Access With Multi-Layer Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Operational technology (OT) and industrial control systems (ICS) environments lack effective security controls, particularly in multi-layer network architectures, leading to vulnerabilities that can result in data exfiltration, identity theft, and operational disruptions due to complex management and insufficient identity verification.

Innovation Solution

Implementing a zero-trust cybersecurity model with a defense-in-depth strategy, involving multi-layer authentication and continuous verification of user identities and devices, to enhance security by restricting access and preventing lateral movements within the network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional security controls are implemented in OT and ICS environments, then security coverage is improved, but device complexity and management complexity increase significantly

Engineering Contradiction:
Improvesecurity coverageVSAvoidmanagement complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the network into multiple security zones (OT zone, DMZ, IT zone) with dedicated security appliances for each zone. This segmentation allows security controls to be implemented in a structured manner, improving security coverage while making management more organized and less complex through clear zone boundaries and dedicated security functions for each segment.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a DMZ (demilitarized zone) as an intermediary layer between OT and IT systems. This DMZ contains dedicated security appliances that mediate communications and security enforcement, reducing direct management complexity between OT and IT teams while maintaining comprehensive security coverage through the intermediary security layer.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If firewalls are deployed across multiple layers to secure the network, then security enforcement is improved, but the complexity of managing interactions between zones increases

Engineering Contradiction:
Improvesecurity enforcementVSAvoidzone interaction complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent deploys firewalls and security appliances in a segmented architecture where each zone (OT, DMZ, IT) has its own dedicated security enforcement points. This segmentation simplifies zone interaction management by establishing clear security boundaries and policies for each segment, reducing the complexity of managing cross-zone interactions while maintaining strong security enforcement at each boundary.

Inventive Principle:
Principle #1Segmentation

3Adaptability or versatility

If multiple user identities are created for the same user across multiple Active Directory servers, then access control to different security zones is improved, but account management complexity increases

Engineering Contradiction:
Improveaccess control flexibilityVSAvoidaccount management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces a centralized identity management system as an intermediary that bridges multiple Active Directory servers. This intermediary maintains a unified view of user identities and their mappings to different security zones, allowing flexible access control across zones while simplifying account management by providing a central coordination point that reduces the complexity of managing identities across multiple AD servers.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Ease of operation

If static accounts are used on jump boxes for remote access, then ease of access is improved, but security vulnerability increases due to potential compromise

Engineering Contradiction:
Improveremote access easeVSAvoidsecurity vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent replaces static jump box accounts with dynamic, ephemeral credentials that are created on-demand and automatically invalidated after use. This dynamic approach maintains ease of remote access operation while significantly reducing security vulnerabilities, as compromised credentials have limited lifetime and scope, and new credentials are generated as needed rather than relying on long-lived static accounts.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS12432218B1Zero-trust cybersecurity enforcement in operational technology systems
Publication Date: 2025.09.30 XAGE SECURITY INC
  • US12432218B1 patent drawing
  • US12432218B1 patent drawing
  • US12432218B1 patent drawing

AI summary

In one embodiment, a method may implement a multi-layer cybersecurity model for a multi-layer distributed computer system which comprises a sensitive data resource, such as a computing environment with an operational technology (OT) layer with multiple zones, an information technology (IT) layer, a DMZ, and a cloud layer. The method can assess a policy based on a zero-trust model for the sensitive data resource. The method can receive one or more requests, at any layer of a multi-layer distributed computing system, to access the sensitive data resource and acquire identity information for a user account specified in the first request. The method can perform a multi-layer multi-factor authentication of the user account using the identity information and the multi-layer cybersecurity model. In response to authenticating the identity information, the method can acquire sensitive access data corresponding to the identity information. The method can determine a sensitive resource access value using the sensitive access data and the zero trust model. In response to determining the sensitive resource access value is above a predetermined threshold, the method can authenticate the user account.