Software platform for remote maintenance
IT security in remote maintenance
Remote maintenance is a central component of Industry 4.0, but security is a critical aspect, for example protection against unauthorized access. This case study shows how this can be guaranteed.
Rapid assistance is the be-all and end-all when problems occur in a system. However, remote maintenance also plays an important role outside of crisis situations, for example when it comes to regular maintenance or services.
The Swiss SFS Group, a company for mechanical fastening systems and precision molded parts, also relies on remote maintenance of its production facilities and uses Endian Connect for this purpose. This Industry 4.0 management solution offers all relevant functions via a central platform: distribution of granular access rights, standard VPN protection for remote communication and protection of the systems through industrial firewalls. It was also important for the company to have a precise separation between office and plant networks for greater security and clarity. Another advantage for SFS was that Endian Connect reduced the response time in support. "We can deploy our service personnel efficiently," explains Franziska Bucher, Project Manager Control Technology STE. "We also reduce maintenance times and thus offer our customers a high level of delivery reliability."
Multi-client capability for individual access rights
SFS uses various processes and machines for cold forming, deep drawing, plastic injection molding and precision machining to produce its fastening systems and precision molded parts. The SFS Group supplies industries in which time-critical projects are realized, for example in industry or construction. For example, 40,000 threaded rods developed by SFS Group specifically for this project were used to fix the entire catenary system in the Gotthard Base Tunnel over a distance of 107 km. Faultless production and precise adherence to delivery deadlines are therefore essential for SFS.
This is another reason why SFS opted for remote maintenance of its production systems via the Internet early on, as this minimizes downtimes and maintenance times in production. Previously, SFS used an ISDN connection with corresponding modems for remote maintenance. The switch from ISDN connections to digital IP connections was the reason for using Industry 4.0 technology from security manufacturer Endian.
At SFS, technical personnel from the system manufacturers and internal service technicians have access to the production systems. A solution was therefore required for remote maintenance that would allow different users or user groups to be granted appropriate access rights. The Endian Connect platform meets these requirements. Thanks to the multi-client capability, users only have access to the functions that are relevant to them and for which they have previously received access authorization.
If different technicians - internal and external - access the systems, it is important to log the access history. Endian Connect saves the historical log files and thus offers complete control of all accesses.
IT security as a central aspect
Ensuring IT security efficiently is a key aspect of remote maintenance. As soon as any device, machine or production plant is connected to the internet, a potential gateway for malware or other attacks from the internet is created via the interface. Only recently, the attacks by the encryption Trojans Petya and WannaCry demonstrated the extent to which industrial companies have become the focus of cyber criminals. The Endian Connect platform is secured via UTM (Unified Threat Management). At the same time, industry-standard encryption technology protects the data during transmission so that third parties cannot copy or manipulate it.
In addition to central management by the Endian Switchboard and VPN encryption, securing the production systems themselves is an important point. SFS has equipped the systems with an Endian 4i appliance for this purpose. These are industrial firewalls that filter harmful traffic and secure the data flow. The devices can be integrated into existing IT infrastructures. If a company has its own firewalls, the 4i devices can also be integrated behind them. The devices can be easily connected to the central management tool and ensure smooth management of the devices. As the systems themselves did not have a public IP address, SFS was able to connect its systems to the Internet via Network Address Translation (NAT) using Endian 4i.
Separation of the system networks
With the aim of further increasing security and clarity in the networks, Robert Steiger, Project Manager Business Application & Security, attached great importance to separating the office and plant networks as well as the warehouse management systems. "Phishing attacks can infect office computers with malware," he explains. "Separating the networks prevents malware from spreading to the production systems."
When selecting a suitable solution, Steiger also attached great importance to user-friendly operability. Endian impressed the project manager with its high functional density and ease of use. "The central management tool Endian Switchboard is ideally suited to our requirements, as all machines can be centrally controlled, secured and maintained globally," says Steiger.
To date, SFS has equipped eight production plants with an Endian-i device. The plants are spread across locations in Germany, France, Turkey, the Czech Republic and China, and there are already plans to connect ten more plants. Different production plants with the same subnet are one of the most common challenges in industrial networks. Implementing a central VPN management tool without significant intervention is therefore practically impossible. Endian Connect solves this routing problem and thus ensures secure operation.










