IP Library Granted Patent US 9,088,558
Granted Patent B2
US 9,088,558 · App. 13/972,130 · Granted Jul 21, 2015

Secure one-way interface for OPC data transfer

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,088,558
App. No.
13/972,130
Granted
Jul 21, 2015
Kind
B2
Abstract

A system for transmitting OPC information from a first network in a first security domain to a second network in a second security domain. A first stand-alone server within the first security domain retrieves information via the first network from a first OPC server in the first security domain and forwards the retrieved information to a send server coupled to the first network. The send server forwards the received information received to a receive server via a one-way data link. The receive server receives the information from the send server and forwards the received information to a second stand-alone server via the second network. The second stand-alone server receives the information from the receive server and forwards the information to one or more OPC clients in the second security domain.

Claims (32)

1. A system for transmitting OPC information from a first network in a first security domain to a second network in a second security domain, comprising:

a send server having an input coupled to the first network and an output, the send server configured to forward OPC information received via the input on the output;

a one-way data link having an input coupled to the output of the send server and an output, the one-way data link configured to transfer data only from the input to the output and to prevent any data or signal from passing from the output to the input;

a receive server having an input coupled to the output of the one-way data link and an output coupled to the second network;

a first stand-alone server within the first security domain coupled to the first network and configured to retrieve OPC information via the first network from at least one OPC server in the first security domain and to forward the retrieved OPC information to the send server via the first network;

a second stand-alone server within the second security domain coupled to the second network;

wherein the receive server is configured to receive the OPC information from the send server via the one-way data link and to forward the received OPC information to the second stand-alone server via the second network;

wherein the second stand-alone server is configured to receive the OPC information from the receive server and forward the OPC information to one or more OPC clients in the second security domain; and

wherein the send server is coupled to the receive server only via the one-way data link.

2. The system of claim 1 , wherein the first stand-alone server is configured to communicate with each of the at least one OPC servers using Distributed Component Object Mode (DCOM) protocol.

3. The system of claim 1 , wherein the first stand-alone server is configured to communicate with the send server using Transmission Control Protocol/Internet Protocol (TCP/IP) protocol.

4. The system of claim 1 , wherein the first stand-alone server is configured to communicate with each of the at least one OPC servers using Distributed Component Object Mode (DCOM) protocol and to communicate with the send server using Transmission Control Protocol/Internet Protocol (TCP/IP) protocol.

5. The system of claim 1 , wherein the second stand-alone server is configured to communicate with each of the at least one OPC clients using Distributed Component Object Mode (DCOM) protocol.

6. The system of claim 1 , wherein the second stand-alone server is configured to communicate with the receive server using Transmission Control Protocol/Internet Protocol (TCP/IP) protocol.

7. The system of claim 1 , wherein the second stand-alone server is configured to communicate with each of the at least one OPC clients using Distributed Component Object Mode (DCOM) protocol and to communicate with the receive server using Transmission Control Protocol/Internet Protocol (TCP/IP) protocol.

8. A system for transmitting OPC information from a first network in a first security domain to a second network in a second security domain, comprising:

a send server having an input coupled to the first network and an output, the send server configured to forward OPC information received via the input on the output;

a one-way data link having an input coupled to the output of the send server and an output, the one-way data link configured to transfer data only from the input to the output and to prevent any data or signal from passing from the output to the input;

a receive server having an input coupled to the output of the one-way data link and an output coupled to the second network;

a first stand-alone server within the first security domain coupled to the first network and configured to receive OPC information via the first network from at least one OPC server in the first security domain and to forward the received OPC information to the send server via the first network, wherein each of the OPC servers is configured to collect predefined OPC information and forward the predefined OPC information to the first stand-alone server using Transmission Control Protocol/Internet Protocol (TCP/IP) protocol;

a second stand-alone server within the second security domain coupled to the second network;

wherein the receive server is configured to receive the OPC information from the send server via the one-way data link and to forward the received OPC information to the second stand-alone server via the second network;

wherein the second stand-alone server is configured to receive the OPC information from the receive server and forward the OPC information to one or more OPC clients in the second security domain using TCP/IP protocol, and wherein each of the one or more OPC clients in the second security domain is configured to receive the OPC information in TCP/IP protocol; and

wherein the send server is coupled to the receive server only via the one-way data link.

9. A system for transmitting OPC information from a first network in a first security domain to a second network in a second security domain, comprising:

a first server having an input coupled to the first network and an output, the first server configured to retrieve OPC information via the first network from a at least one OPC server in the first security domain and to forward the retrieved OPC information on the output;

a one-way data link having an input coupled to the output of the first server and an output, the one-way data link configured to transfer data only from the input to the output and to prevent any data or signal from passim from the output to the input;

a second server having an input coupled to the output of the one-way data link and an output coupled to the second network, the second server configured to receive the OPC information from the first server via the one-way data link and to forward the received OPC information to one or more OPC clients in the second security domain via the second network; and

wherein the first server is coupled to the second server only via the one-way data link.

10. The system of claim 9 , wherein the OPC information received by the first server via the first network is received using Transmission Control Protocol/Internet Protocol (TCP/IP) protocol.

11. The system of claim 9 , wherein the OPC information forwarded by the second server to one or more OPC clients in the second security domain via the second network is forwarded using Transmission Control Protocol/Internet Protocol (TCP/IP) protocol.

12. The system of claim 9 , wherein the OPC information received by the first server via the first network is received using Transmission Control Protocol/Internet Protocol (TCP/IP) protocol, and wherein the OPC information forwarded by the second server to one or more OPC clients in the second security domain via the second network is forwarded using TCP/IP protocol.

Assignments (8)
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS RECORDED AT REEL 041136, FRAME 0223 Recorded Sep 11, 2024
From: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
To: OWL CYBER DEFENSE SOLUTIONS, LLC
Reel/Frame 068945/0922 →
SECURITY INTEREST Recorded Sep 11, 2024
From: OWL CYBER DEFENSE SOLUTIONS, LLC
To: RGA REINSURANCE COMPANY
Reel/Frame 068938/0313 →
MERGER AND CHANGE OF NAME Recorded Sep 2, 2022
From: OWL CYBER DEFENSE SOLUTIONS, LLC; TRESYS TECHNOLOGY, LLC
To: OWL CYBER DEFENSE SOLUTIONS, LLC
Reel/Frame 060978/0964 →
CHANGE OF NAME Recorded Jun 20, 2017
From: OWL COMPUTING TECHNOLOGIES, LLC
To: OWL CYBER DEFENSE SOLUTIONS, LLC
Reel/Frame 042902/0582 →
CORRECTIVE ASSIGNMENT TO CORRECT TO REMOVE THIS DOCUMENT SERVES AS AN OATH/DECLARATION (37 CFR 1.63) FROM THE COVER SHEET PREVIOUSLY RECORDED AT REEL: 041765 FRAME: 0034. ASSIGNOR(S) HEREBY CONFIRMS THE MERGER EFFECTIVE DATE 02/03/2017. Recorded Apr 21, 2017
From: OWL COMPUTING TECHNOLOGIES, INC.
To: OWL COMPUTING TECHNOLOGIES, LLC
Reel/Frame 042344/0033 →
MERGER Recorded Mar 28, 2017
From: OWL COMPUTING TECHNOLOGIES, INC.
To: OWL COMPUTING TECHNOLOGIES, LLC
Reel/Frame 041765/0034 →
SECURITY INTEREST Recorded Jan 31, 2017
From: OWL COMPUTING TECHNOLOGIES, INC.
To: BANK OF AMERICA, N.A.
Reel/Frame 041136/0223 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 21, 2013
From: CURRY, JOHN; MRAZ, RONALD
To: OWL COMPUTING TECHNOLOGIES, INC.
Reel/Frame 031052/0061 →