×

Remote control of secure installations

  • US 9,635,037 B2
  • Filed: 09/06/2012
  • Issued: 04/25/2017
  • Est. Priority Date: 09/06/2012
  • Status: Active Grant
First Claim
Patent Images

1. Communication apparatus, comprising:

  • a transmission station, which comprises;

    a processor running software which generates commands in a predetermined command format, responsive to input from a user;

    hardware encoding logic configured to receive commands in the predetermined command format from the software running on the processor, to convert the received commands into a predefined converted data format of permitted commands including only a limited subset of the commands in the predetermined command format and to cryptographically sign the converted commands in the predefined converted data format; and

    a communications processor configured to transmit the cryptographically signed converted commands over a communications network, and an uplink controller, comprising;

    a first hardware interface configured to receive commands from the transmission station over the communications network;

    a second hardware interface configured to convey the received commands to a protected destination;

    hardware logic, which is coupled between the first and second interfaces so as to receive commands from the first interface, to authenticate that the received commands were cryptographically signed by the transmission station, to compare the received commands to a set of hardware masks corresponding to the permitted commands to check the commands are in the predefined converted data format, and to pass to the second interface only received commands that were authenticated as received from the transmission station and match one of the masks, while rejecting commands in the predetermined command format;

    a first one-way link connecting the first hardware interface to the hardware logic, allowing data from the first hardware interface to the hardware logic, but incapable of carrying data from the hardware logic to the first hardware interface; and

    a second one-way link separate from and independent of the hardware logic, connecting the protected destination to the communication network in a manner allowing information to flow freely out of the protected destination to the communication network, without passing through the hardware logic, wherein the one-way link is incapable of carrying data from the communication network to the protected destination,wherein the hardware encoding logic comprises dedicated hardware logic not containing a CPU and is designed to perform a task which cannot be changed remotely,wherein the hardware logic of the uplink controller comprises dedicated hardware logic not containing a CPU and is designed to perform a task which cannot be changed remotely,wherein the protected destination is an industrial control system, and wherein the permitted commands are configured to control an operating configuration of the industrial control system, andwherein the hardware encoding logic of the transmission station is configured to encrypt the commands it receives and the hardware logic of the uplink controller is configured to decrypt the received commands.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×