Remote Service Security

A dedicated solution for Field Engineers

- at the office, at home, or on the road
 

 

Traditional remote access is based on dial-up modems which is managed though an excel sheet with phone numbers and different setting for individual customers - which is time consuming and error phrone, as well as being practically impossible to reclaim when a field engineer leaves your company.

 

The LinkManager technology is based on a revolutionary dynamic communication technology (patent pending) which automatically adapts itself to all updates from the central GateManager.

 

If a new customer domain is created or new equipment is added (e.g. af new PLC), this will automatically appear in the LinkManager, and then access to the device is just a mouse click away.

 

Security for your customers

 

One of the biggest barriers for enabling remote support over the internet is the security concerns raised by the customer (end-user).

 

Therefore, the SiteManager components have been designed with this in mind. The SiteManager has a local web interface which enables the customer to control remote access, local access rights, and view the local system log.

 

On top of this, state-of-the-art security standards are built in, such as authentication using x.509 digital certificate, confidentiality using strong AES encryption up to 256-bit, and a stateful inspection firewall, which dynamically adapts itself so only the absolutely necessary traffic is allowed to pass through.

 

 

Firewall friendly communication


All communication is initiated by the SiteManager/LinkManager to the GateManager, meaning from the inside and out. With the unique ability to use port as 80 (http) / 443 (https) means that no changes in the customer firewalls are required.

 

 

Wireless or wired communication


A SiteManager can utilize multiple communication methods at the customer production site.

 

The uplink port supports communicating through the customer LAN (Local Area Network) or it can be connected directly to the Internet. If neither of these are applicable, it also has the possibility for wireless communicating through GRPS/EDGE/3G.

 

Whatever communication method is used, the SiteManager does not require a public or fixed IP address, but can of course support this if required.

 

 

Avoiding local IP conflicts


The IP address range on the industrial equipment (PLC, HMI, SCADA) it often the same at each production site. Due to these IP address conflicts, using traditional VPN solutions for remote service access often causes major challenges in complex configuration and maintenance.

 

With the Remote Device Management solution from Secomea, all such IP address conflicts are automatically and transparently handled by the LinkManager, meaning that you can maintain the same IP address ranges, which often already are used in the analog modem setup.

 

  

Smooth centralised administration

 

The centralised administrationis done using the GateManager – service and support portal.

This is developped with security, flexibility and business logic in mind.

 

It provides the overview of all customers, sites, and field engineers, and controls the access rights of each field engineer. It even takes care of the daily maintenance such as back-up, audit logging, etc.

 

GateManager also adapts to the security policies within your company. This server application can be hosted by your own IT department and is often placed in a DMZ (De-Militarized- Zone), ensuring no risk to administration, ERP system etc.

 

But even though your IT department may take care of running the server, all daily operation and usage is preformed by the automation division itself.