IP Library › Granted Patent US 11,770,363
Granted Patent B2
US 11,770,363 · App. 17/239,172 · Granted Sep 26, 2023

Systems and methods for secure access smart hub for cyber-physical systems

Inventors: Ly Vessels (Chandler, AZ); Daniel Tyler (Gilbert, AZ); William Neumann (Robbinsdale, MN)
Assignee: Honeywell International Inc.
H04L63/0263H04L63/166H04W76/15
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,770,363
App. No.
17/239,172
Granted
Sep 26, 2023
Kind
B2
Abstract

Systems and methods are disclosed for providing a secure communication between a first network and a second network. The method may include receiving, at a Secure Access Smart Hub (SASH), a signal from the first network requesting a communication connection; establishing a first connection between the first network and the SASH; establishing a second connection between the SASH and the second network; receiving, at the SASH, data from the first network having a first protocol; translating the data having the first protocol into data having a second protocol; and transmitting the data from the SASH to the second network.

Claims (38)

1. A computer-implemented method for providing a secure communication between a first network and a second network, the method comprising:

receiving, at a Secure Access Smart Hub (SASH), a signal from the first network requesting a communication connection;

establishing a first connection between the first network and the SASH;

establishing a second connection between the SASH and the second network by creating and hosting a secure virtual private network (VPN) and requesting a connection from a cyber-physical system (CPS) device, wherein the SASH securely connects the CPS device to the first network through the second network;

receiving, at the SASH, data from the first network having a first protocol;

translating the data having the first protocol into data having a second protocol; and

transmitting the data having the second protocol from the SASH to the second network, wherein the second network is a CPS network running fieldbus network protocol supporting real-time and performance constraints, and the second network is restricted to a point to point connection with a master system.

2. The computer-implemented method of claim 1 , wherein establishing the first connection comprises establishing a secure enterprise network protocol between the first network and the SASH.

3. The computer-implemented method of claim 1 , wherein translating and/or bridging the data having the first protocol comprises decrypting the data from the first network, and re-encrypting the decrypted data into the data having the second protocol.

4. The computer-implemented method of claim 1 , wherein the first protocol is a secure TCP/IP protocol.

5. The computer-implemented method of claim 1 , wherein the SASH comprises an integrated SASH that includes software components and hardware components, the integrated SASH connecting to the CPS device through the second network.

6. The computer-implemented method of claim 5 , wherein the hardware components include a computing platform, an Ethernet interface, and a second network interface.

7. The computer-implemented method of claim 5 , wherein the software components include a user domain, a security domain, and a network domain that enables for complete isolation of various types of data.

8. The computer-implemented method of claim 1 , wherein the SASH routes network packets from a first device of a first network subgroup to a second device in a second network subgroup.

9. The computer-implemented method of claim 1 , the SASH comprises one or more security filters enabling a user to configure policies that control a type of data sent to a specific CPS device.

10. A system for providing a secure communication between a first network and a second network, the system comprising:

a memory storing instructions; and

a processor executing the instructions to perform a process including:

receiving, at a Secure Access Smart Hub (SASH), a signal from the first network requesting a communication connection;

establishing a first connection between the first network and the SASH;

establishing a second connection between the SASH and the second network by creating and hosting a secure virtual private network (VPN) and requesting a connection from a cyber-physical system (CPS) device, wherein the SASH securely connects the CPS device to the first network through the second network;

receiving, at the SASH, data from the first network having a first protocol;

translating the data having the first protocol into data having a second protocol; and

transmitting the data having the second protocol from the SASH to the second network, wherein the second network is a CPS network running fieldbus network protocol supporting real-time and performance constraints, and the second network is restricted to a point to point connection with a master system.

11. The system of claim 10 , wherein establishing the first connection comprises establishing a secure enterprise network protocol between the first network and the SASH.

12. The system of claim 10 , wherein translating and/or bridging the data having the first protocol comprises decrypting the data from the first network, and re-encrypting the decrypted data into the data having the second protocol.

13. The system of claim 10 , wherein the first protocol is a secure TCP/IP protocol.

14. The system of claim 10 , wherein the SASH comprises an integrated SASH that includes software components and hardware components, the integrated SASH connecting to the CPS device through the second network.

15. The system of claim 14 , wherein the software components include a user domain, a security domain, and a network domain that enables for complete isolation of various types of data.

16. The system of claim 10 , wherein the SASH routes network packets from a first device of a first network subgroup to a second device in a second network subgroup.

17. The system of claim 10 , the SASH comprises one or more security filters enabling a user to configure policies that control a type of data sent to a specific CPS device.

18. A non-transitory computer-readable medium storing instructions that, when executed by a processor, cause the processor to perform an operation for providing a secure communication between a first network and a second network, the operation comprising:

receiving, at a Secure Access Smart Hub (SASH), a signal from the first network requesting a communication connection;

establishing a first connection between the first network and the SASH;

establishing a second connection between the SASH and the second network by creating and hosting a secure virtual private network (VPN) and requesting a connection from a cyber-physical system (CPS) device, wherein the SASH securely connects the CPS device to the first network through the second network;

receiving, at the SASH, data from the first network having a first protocol;

translating the data having the first protocol into data having a second protocol; and

transmitting the data having the second protocol from the SASH to the second network, wherein the second network is a CPS network running fieldbus network protocol supporting real-time and performance constraints, and the second network is restricted to a point to point connection with a master system.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 26, 2021
From: VESSELS, LY; TYLER, DANIEL; NEUMANN, WILLIAM
To: HONEYWELL INTERNATIONAL INC.
Reel/Frame 056038/0347 →
Continuity (2)
Provisional Application 63014866 · Apr 24, 2020
Related Publication 20210336930A1 · Oct 28, 2021