An FPGA-based Unidirectional Gateway Proposal for OT-IT Network Separation to Secure Industrial Automation Systems

Song Son Ha, Henry Beuster, T. Doebbert, G. Scholl
{"title":"An FPGA-based Unidirectional Gateway Proposal for OT-IT Network Separation to Secure Industrial Automation Systems","authors":"Song Son Ha, Henry Beuster, T. Doebbert, G. Scholl","doi":"10.1109/INDIN51400.2023.10218126","DOIUrl":null,"url":null,"abstract":"A new FPGA-based approach for a data diode transmitting data unidirectionally from a high security zone to a lower security zone is evaluated and implemented. With the FPGA implementation, the need of additional hardware could be minimized compared to most state-of-the-art data diode realizations. The proposed data diode is designed to use the available backplane bus communication protocol between the programmable logic controller (PLC) and its connected peripherals. To demonstrate the universal approach an open-source platform based on the Revolution Pi (RevPi) and its backplane bus is used. Principally the data diode behaves as a mirror presenting the complete protected system behind the high security zone including the RevPi controller and its devices to the information technology (IT) network. Another controller within the lower security zone is used to imitate the operational technology (OT) process. Our approach is not limited to the above controller and can be applied to any type of PLC. The only requirement is that the communication protocol on the backplane bus is known and can be modified for this purpose.","PeriodicalId":174443,"journal":{"name":"2023 IEEE 21st International Conference on Industrial Informatics (INDIN)","volume":"1 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2023-07-18","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2023 IEEE 21st International Conference on Industrial Informatics (INDIN)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/INDIN51400.2023.10218126","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0

Abstract

A new FPGA-based approach for a data diode transmitting data unidirectionally from a high security zone to a lower security zone is evaluated and implemented. With the FPGA implementation, the need of additional hardware could be minimized compared to most state-of-the-art data diode realizations. The proposed data diode is designed to use the available backplane bus communication protocol between the programmable logic controller (PLC) and its connected peripherals. To demonstrate the universal approach an open-source platform based on the Revolution Pi (RevPi) and its backplane bus is used. Principally the data diode behaves as a mirror presenting the complete protected system behind the high security zone including the RevPi controller and its devices to the information technology (IT) network. Another controller within the lower security zone is used to imitate the operational technology (OT) process. Our approach is not limited to the above controller and can be applied to any type of PLC. The only requirement is that the communication protocol on the backplane bus is known and can be modified for this purpose.
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
基于fpga的iot - it网络分离单向网关方案以保护工业自动化系统
提出并实现了一种基于fpga的数据二极管从高安全区域向低安全区域单向传输数据的新方法。与大多数最先进的数据二极管实现相比,FPGA实现可以最大限度地减少对额外硬件的需求。所提出的数据二极管被设计为在可编程逻辑控制器(PLC)与其连接的外设之间使用可用的背板总线通信协议。为了演示通用方法,使用了基于Revolution Pi (RevPi)及其背板总线的开源平台。数据二极管主要作为一面镜子,将包括RevPi控制器及其设备在内的高安全区后面的完整受保护系统呈现给信息技术(IT)网络。低安全区域内的另一个控制器用于模拟操作技术(OT)过程。我们的方法不局限于上述控制器,可以应用于任何类型的PLC。唯一的要求是背板总线上的通信协议是已知的,并且可以为此目的进行修改。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 去求助
来源期刊
自引率
0.00%
发文量
0
期刊最新文献
Technical Debt Management in Industrial ML - State of Practice and Management Model Proposal Measuring the Robustness of ML Models Against Data Quality Issues in Industrial Time Series Data 5G packet delay considerations for different 5G-TSN communication scenarios Non-Interventional Precise TC Assessment for Enhancing Consumer Energy Flexibility Model-based Automation of TSN Configuration for Industrial Distributed Systems
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1