Publishing data across a data diode for secured process control communications

US11700232B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-11700232-B2
Application numberUS-202117528825-A
CountryUS
Kind codeB2
Filing dateNov 17, 2021
Priority dateOct 24, 2016
Publication dateJul 11, 2023
Grant dateJul 11, 2023

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

To secure communications from a process plant across a unidirectional data diode to a remote system, a sending device at the plant end publishes data across the diode to a receiving device at the remote end. The publication of various data is respectively in accordance with context information (e.g., identification of data sources, respective expected rate of data generation/arrival, etc.) that is descriptive of data sources of the plant and that is recurrently provided by the sending device across the diode. A recurrence interval may be based on a tolerance for lost data or another characteristic of an application, service, or consumer of data at the remote system. The publishing may leverage an industrial communication protocol (e.g., HART-IP) and/or a suitable general-purpose communication protocol (e.g., JSON).

First claim

Opening claim text (preview).

What is claimed: 1. A method of securely transporting communications, the method comprising: at a sending device disposed between a process plant network of a process plant and a data diode configured to prevent communications from ingressing into the process plant network: providing, by the sending device across the data diode to a receiving device, information indicative of an identity of process plant data, the information indicative of the identity of the process plant data mapped from a configuration that corresponds to the process plant data and that is stored in the process plant; converting, by the sending device, the process plant data from a first format into a second format; and publishing, by the sending device across the data diode to the receiving device, the process plant data in the second format using a second label different than a first label utilized by the configuration corresponding to the process plant data. 2. The method of claim 1 , wherein providing the information indicative of the identity of the process plant data includes providing information indicative of an identity of process data generated by and/or corresponding to at least one of: a process parameter, a process variable, a function block, a module, an event, historized data, a piece of equipment, a display view, a device, or one or more other components of the process plant. 3. The method of claim 1 , further comprising providing a context of the process plant data in conjunction with providing the information indicative of the identity of the process plant data, the context of the process plant data including at least one of: an indication of a rate of arrival of the process plant data, data indicative of respective gateways or other devices to which the one or more devices are communicatively connected, respective statuses of the respective gateways or other devices, respective statuses of the one or more devices, or other information corresponding to the one or more devices generating the process plant data. 4. The method of claim 1 , further comprising obtaining, by the sending device, the process plant data in the first format via the process plant network; and wherein converting the process plant data into the second format comprises converting the process plant data into an IP format or another type of packet format. 5. The method of claim 1 , wherein publishing the process plant data in the second format comprises publishing, in the second format, at least one of: run-time process data, continuous process data, batch process data, historized data, event data, alarms data, analytics data, diagnostic data, user interface data, performance data, or another type of data corresponding to the one or more devices of the process plant operating to control an industrial process. 6. The method of claim 1 , further comprising selecting, by the sending device, a subset of a set of process plant data generated by devices of the process plant while the process plant operates to control an industrial process to be the process plant data that is to be published across the data diode to the receiving device. 7. The method of claim 6 , further comprising not publishing, across the data diode to the receiving device, another subset of the set of process plant data generated by the devices of the process plant, the selected subset and the another subset being mutually exclusive subsets. 8. The method of claim 1 , wherein the sending device is a field gateway of the process plant, and publishing, by the field gateway, the process plant data in the second format across the data diode to the receiving device comprises publishing, by the field gateway, the process plant data in the second format across the data diode to an edge gateway of the process plant. 9. The method of claim 1 , wherein publishing the process plant data in the second format across the data diode to the receiving device comprises publishing the process plant data in the second format across the data diode to a remote system or a remote device. 10. The method of claim 1 , wherein providing, by the sending device across the data diode, the information indicative of the identity of the process plant data includes providing, by a gateway, a data source device, or another component of the process plant across the data diode, the information indicative of the identity of the process plant data. 11. A system for securely transporting communications from a process plant, the system comprising: a sending device communicatively coupled to a network of the process plant and to a data diode configured to prevent communications from ingressing into the network of the process plant, the sending device including one or more processors and one or more non-transitory memories, the one or more non-transitory memories storing computer-executable instructions thereon that, when executed by the one or more processors, cause the sending device to: provide, across the data diode to a receiving device, information indicative of an identity of process plant data, the information indicative of the identity of the process plant data mapped from a configuration that corresponds to the process plant data and that is stored in the process plant; convert the process plant data from a first format into a second format; and publish, across the data diode to the receiving device, the process plant data in the second format using a second label different than a first label utilized by the configuration corresponding to the process plant data. 12. The system of claim 11 , wherein: the information indicative of the identity of the process plant data includes information indicative of an identity of process data generated by and/or corresponding to at least one of: a process parameter, a process variable, a function block, a module, an event, historized data, a piece of equipment, a display view, a device, or one or more other components of the process plant; and the process plant data includes at least one of: run-time process data, continuous process data, batch process data, historized data, event data, alarms data, analytics data, diagnostic data, user interface data, performance data, or another type of data corresponding to the one or more devices of the process plant operating to control an industrial process. 13. The system of claim 11 , wherein the computer-executable instructions are further executable to cause the sending device to provide, to the receiving device, a context of the process plant data in conjunction with providing the information indicative of the identity of the process plant data, the context of the process plant data including information corresponding to the one or more devices generating the process plant data. 14. The system of claim 13 , wherein the context of the process plant data includes at least one of: an indication of a rate of arrival of the process plant data, data indicative of respective gateways to which the one or more devices are communicatively connected, respective statuses of the respective gateways, or respective statuses of the one or more devices. 15. The system of claim 11 , wherein the conversion of the process plant data into the second format comprises a conversion of the process plant data into an IP format or another type of packet format. 16. The system of claim 11 , wherein the process plant data that is published across the data diode to the receiving device is a selected subset of a set of process plant data generated by devices of the process plant while the process plant operates to control an industrial process.

Assignees

Inventors

Classifications

  • Architectural arrangements, e.g. perimeter networks or demilitarized zones · CPC title

  • for controlling access to devices or network resources · CPC title

  • characterised by the network communication · CPC title

  • Design of industrial communication system with expert system · CPC title

  • Multiple levels of security · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US11700232B2 cover?
To secure communications from a process plant across a unidirectional data diode to a remote system, a sending device at the plant end publishes data across the diode to a receiving device at the remote end. The publication of various data is respectively in accordance with context information (e.g., identification of data sources, respective expected rate of data generation/arrival, etc.) that…
Who is the assignee on this patent?
Fisher Rosemount Systems Inc
What technology area does this patent fall under?
Primary CPC classification H04L63/0209. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Jul 11 2023 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 12 related publications on this page (citations in our corpus or others sharing the same primary CPC).