Methods and systems for providing data from an internal data processing system of an industrial plant to an external data processing system
Data are sent from an internal data processing system of an Industrial plant to an external data processing system of the industrial plant by generating with an industrial edge device data packets from data related to an industrial machine, and generating therefrom signed data packets signed with a first digital signature. While the signed data packet are read, a user-defined data filter is applied, which either passes or rejects the signed data packets. The data packets that passed the user-defined data filter are then sent to the external data processing system. In addition, double-signed data packets are produced by signing the signed data packets that pass the user-defined data filter with a second digital signature.
1 . A method for providing data from an internal data processing system of an industrial plant to an external data processing system external to the industrial plant, wherein the internal data processing system comprises a plurality of industrial edge devices each having at least one data processing module and a user-defined data filter, and a plurality of industrial machines, wherein each single industrial edge device is associated with a different single industrial machine, the method comprising:
with each of the industrial edge devices, generating a plurality of data packets from data related to each of the associated industrial machines, and
with each of the industrial edge devices, signing each data packet of the plurality of data packets with a first digital signature, thus producing a plurality of signed data packets;
with each of the data processing modules and user-defined data filters,
reading each signed data packet of the plurality of the signed data packets and, while reading, applying the user-defined data filter to each signed data packet to determine if each of the signed data packets contains sensitive data and/or confidential information,
letting through those signed data packets that contain no sensitive data and/or confidential information and pass the user-defined data filter and sending all those data packets that have passed the user-defined data filter towards the external data processing system;
rejecting those signed data packets that contain sensitive data and/or confidential information and fail to pass the user-defined data filter and not forwarding further the rejected signed data packets so that the rejected signed data packets remain within the internal data processing system; and
producing double-signed data packets by signing the signed data packets that pass the user-defined data filter with a second digital signature.
2 . The method of claim 1 , further comprising sending the data packets that have passed the user-defined data filter towards the external data processing system through at least one gateway component of the internal data processing system.
3 . The method of claim 1 , further comprising sending the double-signed data packets towards the external data processing system through at least one gateway component of the internal data processing system by
sending the double-signed data packets to the at least one gateway component;
validating the second digital signature of each of the double-signed data packets by a second key that corresponds to the second digital signature; and
sending the validated double-signed data packets to the external data processing system.
4 . The method of claim 3 , wherein sending the double-signed data packets further comprises encrypting each of the double-signed data packets.
5 . The method of claim 1 , further comprising, with the external data processing system, validating the first digital signature of each data packet or noting a packet's absence.
6 . The method of claim 5 , further comprising storing a first key that corresponds to the first signature at the external data processing system, and is using first key to validate the first signature.
7 . The method of claim 1 , further comprising encrypting each signed data packet by using each industrial edge device.
8 . The method of claim 1 , wherein the internal data processing system further comprises at least one gateway component, the method further comprising sending all those data packets that have passed the user-defined data filter towards the external data processing system through the at least one gateway component.
9 . The method of claim 1 , wherein each user-defined data filter is implemented as a whitelist that contains allowed terms detectable in the content of the data packets, in particular by finding the terms by searching for at least one of the term's text, applying image classification, object detection and mapping objects detected in images to one or multiple terms.
10 . The method of claim 1 , wherein the user-defined data filter is implemented as a whitelist that contains matchmaking patterns, in particular regular expressions, particularly those that can be applied to the content of the data packets.
11 . An industrial network comprising an internal data processing system of an industrial plant and an external data processing system external to the industrial plant, wherein the internal data processing system comprises a plurality of industrial edge devices each having at least one data processing module and a user-defined data filter, and a plurality of industrial machines, wherein each single industrial edge device is associated with a different single industrial machine, wherein each one of the industrial edge devices is adapted to
generate a plurality of data packets from data related to each of the associated industrial machines, and
with each of the industrial edge devices, sign each data packet of the plurality of data packets with a first digital signature, thus producing a plurality of signed data packets,
with each of the data processing modules and user-defined data filters,
read each signed data packet of the plurality of the signed data packets and, while reading, apply the at least one user-defined data filter to each signed data packet to determine if each of the signed data packets contains sensitive data and/or confidential information;
let through those signed data packets that contain no sensitive data and/or confidential information and pass the user-defined data filter and send all those data packets that have passed the user-defined data filter towards the external data processing system;
reject those signed data packets that contain sensitive data and/or confidential information and fall to pass the user-defined data filter and not forward further the rejected signed data packets so that the rejected signed data packets remain within the internal data processing system; and
produce double-signed data packets by signing the signed data packets that pass the user-defined data filter with a second digital signature.
12 . The industrial network of claim 11 , wherein each industrial edge device is adapted to generate a plurality of unencrypted data packets from data related to the at least one industrial machine.
13 . The industrial network of claim 11 , wherein each user-defined data filter is certified.
14 . The industrial network of claim 11 , wherein each user-defined data filter is certified by a third trusted party.
15 . The industrial network of claim 11 , wherein each industrial edge device comprises at least one hardware controller configured to encrypt the data packets.
16 . The industrial network of claim 15 , wherein the at least one hardware controller is a Field Programmable Gate Array controller.
17 . A computer program stored on a non-transitory computer-readable medium and comprising instructions which when stored in a memory of an internal data processing system of an industrial plant comprising a plurality of industrial edge devices each having at least one data processing module and a user-defined data filter, a plurality of industrial machines, wherein each single industrial edge device is associated with a different single industrial machine, and executed by a processor of the internal industrial data processing system, causes the internal industrial data processing system to
provide data from the internal data processing system to an external data processing system external to the industrial plant,
with each of the industrial edge devices, generate a plurality of data packets from data related to each of the associated industrial machines,
with each of the industrial edge devices, sign each data packet of the plurality of data packets with a first digital signature, thus producing a plurality of signed data packets;
with each of the data processing modules and user-defined data filters,
read each signed data packet of the plurality of the signed data packets and, while reading, apply the user-defined data filter to each signed data packet to determine if each of the signed data packets contains sensitive data and/or confidential information,
let through those signed data packets that contain no sensitive data and/or confidential information and pass the user-defined data filter and send all those data packets that have passed the user-defined data filter towards the external data processing system;
reject those signed data packets that contain sensitive data and/or confidential information and fail to pass the user-defined data filter and not forward further the rejected signed data packets so that the rejected signed data packets remain within the internal data processing system; and
produce double-signed data packets by signing the signed data packets that pass the user-defined data filter with a second digital signature.
18 . The industrial network of claim 11 , further comprising sending the double-signed data packets towards the external data processing system through at least one gateway component of the internal data processing system by
sending the double-signed data packets to the at least one gateway component;
validating the second digital signature of each of the double-signed data packets by a second key that corresponds to the second digital signature; and
sending the validated double-signed data packets to the external data processing system.
19 . The Industrial network of claim 18 , wherein sending the double-signed data packets further comprises encrypting each of the double-signed data packets.
20 . The computer program stored on a non-transitory computer-readable medium of claim 17 , further comprising sending the double-signed data packets towards the external data processing system through at least one gateway component of the internal data processing system by
sending the double-signed data packets to the at least one gateway component;
validating the second digital signature of each of the double-signed data packets by a second key that corresponds to the second digital signature; and
sending the validated double-signed data packets to the external data processing system.
21 . The computer program stored on a non-transitory computer-readable medium of claim 20 , wherein sending the double-signed data packets further comprises encrypting each of the double-signed data packets.