Secure remote access to historical data
Systems and methods for providing access to historical data over a real-time tunnel are disclosed. The method provides a mechanism for secure communication between one or more historians. In an example, attack surfaces on historians in an industrial control system operational technology (OT) network and in an information technology (IT) networks are reduced and possibly entirely eliminated by tunneling through a DMZ (de-militarized zone) or “secured network”.
1. A method for providing access to historical data over a real-time tunnel, the method comprising:
establishing, by a first connector, a first tunnel connection between the first connector and a second connector, the first tunnel connection being established by using an outbound connection request from the first connector;
establishing, by a third connector, a second tunnel connection between the third connector and a fourth connector, the second tunnel connection being established by using an outbound connection request from the third connector;
obtaining by the first connector, data;
propagating the data from the first connector to the second connector through the first tunnel connection;
receiving, by the second connector, the data via the first tunnel connection;
propagating the data, by the second connector to the third connector via the fourth connector and the second tunnel connection; and
wherein the data includes historical data.
2. The method of claim 1 , wherein the first connector, the second connector, the third connector and the fourth connector are in a same network.
3. The method of claim 1 , further comprising:
configuring a first network to include the first connector;
configuring a second network to include the second connector;
configuring a third network to include the third connector;
configuring a fourth network to include the fourth connector; and
separating each of the first network, the second network, the third network, and the fourth network by a respective firewall.
4. The method according to claim 3 , further comprising:
receiving, by the second network, an inbound connection.
5. The method according to claim 3 , further comprising:
making, by the first network, an outbound connection.
6. The method according to claim 1 , further comprising:
initiating, by any one of (i) the first connector, (ii) the second connector, (iii) the third connector or (iv) the fourth connector, a connection; and
storing, by the connector initiating the connection, security information.
7. The method according to claim 1 , further comprising:
retrieving, by the first connector, historical data from a first historian;
transmitting, by the first connector, the historical data over the first tunnel connection to the second connector;
propagating, by the second connector, the historical data to a second historian; and
retrieving, by the second connector the historical data from the second historian.
8. A system for providing access to historical data over a real-time tunnel, the method comprising:
a first device that operates as a first connector configured to establish, by using an outbound connection request from the first connector, a first tunnel connection with a second device that operates as a second connector and to receive data from a data source;
a third device that operates as a third connector configured to establish, by using an outbound connection request from the third connector, a second tunnel connection with a fourth connector;
the first connector configured to propagate the data to the third connector through the first tunnel connection and the second tunnel connection;
the second connector configured to:
receive the data via the first tunnel connection, and
propagate the data to the third connector via the fourth connector and the second tunnel connection; and
wherein the data includes historical data.
9. The system of claim 8 , wherein the first connector, the second connector, the third connector and the fourth connector are in a same network.
10. The system of claim 8 , wherein:
the first connector is configured to be included in a first network;
the second connector is configured to be included in a second network;
the third connector is configured to be included in a third network;
the fourth connector is configured to be included in a fourth network; and
each of the first network, the second network, the third network, and the fourth network is configured to be separated by a respective firewall.
11. The system according to claim 10 , wherein the second network is configured to receive an inbound connection.
12. The system according to claim 8 , wherein:
at least one of (i) the first connector, (ii) the second connector, (iii) the third connector and (iv) the fourth connector further configured to:
initiate a connection; and
store, by the connector initiating the connection, security information.
13. The system of claim 8 , further comprising:
the first connector further configured to:
retrieve historical data from a first historian;
transmit the historical data over the first tunnel connection to the second connector;
propagate, by the second connector, the historical data to a second historian; and
retrieve, by the second connector the historical data from the second historian.
14. The system of claim 10 , wherein the first network is configured to make an outbound connection.
15. A non-transitory computer-readable medium having stored thereon one or more sequences of instructions for causing one or more processors to perform:
establishing, by a first connector, a first tunnel connection from the first connector to a second connector, the first tunnel connection being established by using an outbound connection request from the first connector;
establishing, by a third connector, a second tunnel connection from the third connector to the second connector, the second tunnel connection being established by using an outbound connection request from the third connector;
obtaining by the first connector, data;
propagating the data from the first connector to the third connector through the first tunnel connection and the second tunnel connection;
receiving, by the second connector, the data via the first tunnel connection;
propagating the data, by the second connector to the third connector via the fourth connector and the second tunnel connection; and
wherein the data includes historical data.
16. The non-transitory computer-readable medium of claim 15 , further having stored thereon a sequence of instructions for causing the one or more processors to perform:
retrieving, by the first connector, historical data from a first historian;
transmitting, by the first connector, the historical data over the first tunnel connection to the second connector;
propagating, by the second connector, the historical data to a second historian; and
retrieving, by the second connector the historical data from the second historian.
17. The non-transitory computer-readable medium of claim 15 , further having stored thereon a sequence of instructions for causing the one or more processors to perform:
establishing, by the third connector a second tunnel connection with the second connector;
receiving, by the third connector the data; and
sending, by the third connector the data to a third historian.
18. The non-transitory computer-readable medium of claim 15 , wherein the first connector, the second connector, the third connector and the fourth connector are in a same network.
19. The non-transitory computer-readable medium of claim 15 , further having stored thereon a sequence of instructions for causing the one or more processors to perform:
configuring a first network to include the first connector;
configuring a second network to include the second connector;
configuring a third network to include the third connector;
configuring a fourth network to include the fourth connector; and
separating each of the first network, the second network, the third network, and the fourth network by a respective firewall.
20. The non-transitory computer-readable medium of claim 19 , further having stored thereon a sequence of instructions for causing the one or more processors to perform:
receiving, by the second network, an inbound connection.