Data Flows Under Plant Control
The Skkynet Secure Cloud Services allows third-party connection to plant-floor data without opening ports in the firewall.
The service allows users to connect plant-floor equipment to management, as well as to partner and third-party companies, using software at the plant site that is configured by the client company to allow specific datastreams to be uploaded or downloaded to and from Skkynet's secure server.
"The conventional recommendation has been to use a VPN, but you need to trust every machine on a VPN because you've opened your system to it. Security is not very good, it's complex, and it's virtually impossible to set up between two or more different companies.”
The cloud system solves that by providing a limited access log-in to suppliers, without allowing them to join the company network. "The primary source of security exploits is holes in inbound connections,” Thomas says. "These are removed, so there's no attack surface on the plant.” Once the connection is established, data can flow both ways. But that data flows through completely closed firewalls, he says. "With no ports open, you never expose the plant or the control systems to Internet attacks.”
The plant installs Skkynet software designed to connect to any industrial system, using open, standard protocols like OPC, TCP and ODBC. It can be added to a SCADA system, function as an HMI for an individual machine, or access RTUs or even individual embedded devices.
The plant decides what data to send to the cloud. "It can set each data stream to be one-way or two-way, and can send some or all of the data, depending on its needs,” Thomas says. "The configuration is set by the customer and enforced by the connector. It's set entirely in the connector, not in the cloud — the cloud can't change the settings.”
The result is a robust and secure feed of live process data for real-time monitoring, collaboration, predictive maintenance, etc. "The primary problem we're solving is remote access without opening the plant to the Internet,” Thomas says. "It's like having a local HMI over the web.”
Scheduled for release Aug. 13, the Skkynet Secure Cloud Service will be demonstrated at the M2M Conference on Aug. 12-14 in Las Vegas.
For more information, visit Skkynet.com.