Security

Security lock

Secure Access to Industrial Data

Cogent DataHub™ software from Skkynet provides secure access to industrial process data.  It offers a unique combination of outbound-only connections from the plant, multiple protocol integration through a unified namespace, DMZ support, and convenient node and networking security options to ensure that only qualified users gain access to the data, and only to the data they need.

Unlike most industrial data protocols, DataHub software can make outbound-only connections from the plant to the cloud, IT department, or a DMZ.  It keeps all inbound firewall ports closed and uses no VPNs, for zero attack surface. SSL is fully supported for all networked protocols.

Outbound Connections diagram

The system can be configured for one-way or bidirectional data flow.  It supports all major industrial data protocols—OPC UA, OPC DA, A&E, MQTT, Modbus, ODBC, TCP, and more—converting between them in real-time within a unified namespace.

Flexible Data Flow diagram

Each DataHub instance provides multi-factor authentication (MFA), including time-based one-time passwords (TOTP). User access permissions can be configured by connection source (i.e., IP address, CIDR) protocol (e.g., OPC UA, MQTT, TCP) and DataHub domain (data set). SSL encryption with support for PQC (post-quantum cryptography) is built in.

Sophisticated Security Model diagram

The NIS2 Directive, NIST CSF 2.0, and leading security experts all point to network segmentation using a DMZ as critical for securing access to operations data.  Unlike OPC UA or MQTT, DataHub software can pass data securely along the multiple daisy-chained connections that are necessary for DMZ support.

DMZ Support diagram

Data diode mode provides an extra layer of security, ensuring that absolutely no data passes into the OT system.  This feature can be used to support data diode hardware, or as a software-only option.

Data Diode Mod diagram

LDAP authentication

Import user accounts from an external LDAP (Lightweight Directory Access Protocol) server or local Windows machine.  Enjoy the convenience of LDAP to manage security and upgrade passwords from a central location.

LDAP Security diagram

Multi-Factor Authentication (TOTP and more)

Authenticate users with TOTP (time-based one-time passwords), for multi-factor authentication. This works with Windows Authenticator, Google Authenticator, or other service to send a temporary code to a user’s mobile device, which must be entered in addition to the password to access the DataHub instance.

Multi-Factor Authentication Security diagram

Securely connect your plant through a DMZ to the AI system of your choice.  Connect to DataHub for Azure, Apache Kafka, Azure Event Hubs, or virtually any other cloud-based AI system. All inbound firewall ports stay closed, and no VPN is used.

Secure Industrial AI connections diagram

The only closed-firewall or data-diode solution for networking process data. Integrate and network OPC UA, OPC DA, A&E, MQTT, Modbus, ODBC, TCP, and more through a DMZ, all in a unified namespace.

Connect your OPC or MQTT system securely through a DMZ to the Cogent DataHub service for Azure or any other cloud server of your choice.  Choose between firewall or data diode modes to enable bidirectional or one-way data flow.

Secure Industrial IoT diagram