IP Library › Granted Patent US 12,335,167
Granted Patent B2
US 12,335,167 · App. 18/223,872 · Granted Jun 17, 2025

Security function execution device

Inventors: Junya Fujita (San Jose, CA); Noritaka Matsumoto (Tokyo, JP)
Assignee: HITACHI, Ltd.
H04L47/821H04L47/781
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,335,167
App. No.
18/223,872
Granted
Jun 17, 2025
Kind
B2
Abstract

A security function execution device in communication with a network. The device may include a processor, the processor is configured to: identify attributions of a plurality of nodes in communications with the network; determine criticality of each node of the plurality of nodes based on the attributions; and mediate communications between nodes of the plurality of nodes that are determined as being non-critical and execute security functions on the mediated communications.

Claims (46)

1. A security function execution device in communication with a network, the device comprising:

a memory storing instructions; and

a processor executing the instructions stored in the memory, the processor is configured to:

identify attributions of a plurality of nodes in communications with the network;

determine criticality of each node of the plurality of nodes based on the attributions; and

mediate communications between nodes of the plurality of nodes that are determined as being non-critical and execute security functions on the mediated communications.

2. The device of claim 1 , wherein determine criticality of each node of the plurality of nodes based on the attributions comprises:

for a node of the plurality of nodes being connected to an external network, determine criticality of the node as non-critical;

for a node of the plurality of nodes having application of field control, determine criticality of the node as critical; and

for a node of the plurality of nodes having application other than field control, determine criticality of the node as non-critical.

3. The device of claim 2 , further comprising:

for a node of the plurality of nodes being determined as being critical, exclude the node from communication mediation.

4. The device of claim 1 , wherein determine criticality of each node of the plurality of nodes based on the attributions comprises:

for a node of the plurality of nodes being associated with a critical process of business operations, determine criticality of the node as critical;

for a node of the plurality of nodes being determined as having computing resources less than a resource threshold, determine criticality of the node as critical;

for a node of the plurality of nodes not being associated with a critical process of business operations, determine criticality of the node as non-critical; and

for a node of the plurality of nodes being determined as having computing resources equal to or more than the resource threshold, determine criticality of the node as non-critical.

5. The device of claim 1 , wherein identify attributions of the plurality of nodes in communications with the network comprises automatically retrieving the attributions of the plurality of nodes from the network.

6. The device of claim 1 , wherein the plurality of nodes comprises software components, hardware components, or a combination of software and hardware components,

wherein software components comprise supervisory control and data acquisition (SCADA) systems, manufacturing execution systems (MES), manufacturing operation management (MoM) systems, and enterprise resource planning (ERP) systems, and

wherein hardware components comprise field devices, controllers, and servers.

7. The device of claim 1 , wherein the attributions comprise network structure, device type, application, resource, and processing state associated with the plurality of nodes.

8. The device of claim 1 , wherein the network is a wireless network, and the plurality of nodes communicate with the wireless network through an access point that manages the wireless network; and

wherein identify attributions of the plurality of nodes in communications with the network comprises identifying the attributions of the plurality of nodes by scanning the access point.

9. A method for security function execution, the method comprising:

identifying, by a processor, attributions of a plurality of nodes in communications with a network;

determining, by the processor, criticality of each node of the plurality of nodes based on the attributions; and

mediating, by the processor, communications between nodes of the plurality of nodes that are determined as being non-critical and executing security functions on the mediated communications.

10. The method of claim 9 , wherein determining criticality of each node of the plurality of nodes based on the attributions comprises:

for a node of the plurality of nodes being connected to an external network, determining criticality of the node as non-critical;

for a node of the plurality of nodes having application of field control, determining criticality of the node as critical; and

for a node of the plurality of nodes having application other than field control, determining criticality of the node as non-critical.

11. The method of claim 10 , further comprising:

for a node of the plurality of nodes being determined as being critical, excluding the node from communication mediation.

12. The method of claim 9 , wherein determining criticality of each node of the plurality of nodes based on the attributions comprises:

for a node of the plurality of nodes being associated with a critical process of business operations, determining criticality of the node as critical;

for a node of the plurality of nodes being determined as having computing resources less than a resource threshold, determining criticality of the node as critical;

for a node of the plurality of nodes not being associated with a critical process of business operations, determining criticality of the node as non-critical; and

for a node of the plurality of nodes being determined as having computing resources equal to or more than the resource threshold, determining criticality of the node as non-critical.

13. The method of claim 9 , wherein identifying attributions of the plurality of nodes in communications with the network comprises automatically retrieving the attributions of the plurality of nodes from the network.

14. The method of claim 9 , wherein the plurality of nodes comprises software components, hardware components, or a combination of software and hardware components,

wherein software components comprise supervisory control and data acquisition (SCADA) systems, manufacturing execution systems (MES), manufacturing operation management (MoM) systems, and enterprise resource planning (ERP) systems, and

wherein hardware components comprise field devices, controllers, and servers.

15. The method of claim 9 , wherein the attributions comprise network structure, device type, application, resource, and processing state associated with the plurality of nodes.

16. The method of claim 9 , wherein the network is a wireless network, and the plurality of nodes communicate with the wireless network through an access point that manages the wireless network; and

wherein identifying attributions of the plurality of nodes in communications with the network comprises identifying the attributions of the plurality of nodes by scanning the access point.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 19, 2023
From: FUJITA, JUNYA; MATSUMOTO, NORITAKA
To: HITACHI, LTD.
Reel/Frame 064316/0755 →
Continuity (1)
Related Publication 20250039108A1 · Jan 30, 2025
References Cited (9)
US 10516689B2 · Christian · 2019 [cited by applicant]
US 11374689B2 · James · 2022 [cited by examiner]
US 20140173336A1 · Bennah · 2014 [cited by examiner]
US 20180359612A1 · Buckley · 2018 [cited by examiner]
US 20210320944A1 · Ogle · 2021 [cited by examiner]
CN 105376156B · 2018 [cited by examiner]
JP 4339004B2 · 2009 [cited by examiner]
WO WO2018000197A1 · 2018 [cited by examiner]
S. Whalen, “An Introduction to ARP Spoofing,” Apr. 2001 https://priv.gg/e/arp_spoofing_intro.pdf. [cited by applicant]