Control system and control method

By introducing a master-slave unit structure into the control system, the master unit stores and distributes security protection information to the volatile memory of the slave unit, thus solving the complexity problem of security protection information management in multi-unit systems, achieving centralized management and improving system security.

CN114072793BActive Publication Date: 2025-11-07OMRON CORP
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202080046751.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2019-07-08
Filing Date
2020-03-05
Publication Date
2025-11-07
Estimated Expiration
2040-03-05

AI Technical Summary

Technical Problem

In control systems composed of multiple units, the management of security information becomes complex. In particular, with the increase of functional units, the complexity of setting passwords and managing account information increases, making it difficult to centralize and effectively manage security information.

Method used

The system employs a master unit and slave unit structure. The master unit stores security protection information in non-volatile memory and distributes it to the volatile memory of the slave unit at a predetermined time. The slave unit receives and stores the security protection information when the power is turned on, ensuring centralized management and updating of information.

Benefits of technology

It enables centralized management of security protection information, reduces the management burden on users, prevents security vulnerabilities caused by incorrect or outdated settings, improves system security and response speed, and reduces the risk of information leakage and management costs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114072793B_ABST
    Figure CN114072793B_ABST
Patent Text Reader

Abstract

A technique for centrally managing security protection information in a control system (2) composed of a plurality of units is provided. The control system (2) has a master unit (300) connected to an internal bus (10) and a slave unit (200) connected to the internal bus (10) and communicating with the master unit (300) via the internal bus (10). The master unit (300) has a nonvolatile memory (308) for holding first security protection information (330) of information as an object of concealment. The slave unit (200) has a volatile memory (206). The slave unit (200) receives the first security protection information (330) from the master unit (300) at a predetermined timing and holds the first security protection information (330) in the volatile memory (206).
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present disclosure relates to a technology for managing security information in a control system composed of a plurality of units. BACKGROUND

[0002] In a production site using FA (Factory Automation) or the like, in the control of various devices, a control unit such as a PLC (Programmable Logic Controller) is used. In recent years, control units capable of connecting with external devices are becoming widespread. With respect to such a control unit, Patent Literature 1 (Japanese Patent Application Publication No. 2016-194808) discloses a PLC capable of accessing a database of an external device.

[0003] PRIOR ART DOCUMENTS

[0004] PATENT LITERATURE

[0005] Patent Literature 1: Japanese Patent Application Publication No. 2016-194808 SUMMARY

[0006] PROBLEMS TO BE SOLVED BY THE INVENTION

[0007] A control unit can be connected with various functional units. In each functional unit, various applications can be installed. A user can add a functional unit or install an application program as needed.

[0008] Each functional unit is independent of other functional units, and information such as account information, a digital certificate (hereinafter, also referred to as "security information") needs to be managed for each functional unit. Therefore, the more the number of functional units, the more the user sets an easy-to-forget password or forgets a password, and the management of security information becomes complicated. Therefore, a technology for centrally managing security information in a control system composed of a plurality of units is desired.

[0009] MEANS FOR SOLVING THE PROBLEMS

[0010] In one example of the present disclosure, a control system composed of a plurality of units is provided. The plurality of units includes a master unit connected with an internal bus, and a slave unit connected with the internal bus and communicating with the master unit via the internal bus. The master unit has a nonvolatile memory for saving first security information of information that is an object of concealment. The slave unit has a volatile memory. The slave unit receives the first security information from the master unit at a predetermined timing, and saves the first security information in the volatile memory.

[0011] According to the present disclosure, the slave unit saves the security protection information received from the master unit into the volatile memory. Thereby, every time the power supply to the control system is stopped, the security protection information disappears from the slave unit. On the other hand, even if the power supply to the control system is stopped, the security protection information saved in the non-volatile memory of the master unit does not disappear. Thereby, the security protection information can be centrally managed.

[0012] In one example of the present disclosure, the above-described predetermined timing includes timing at which the power supply of the control system is turned on.

[0013] According to the present disclosure, the slave unit receives the security protection information from the master unit every time the power supply of the control system is turned on, and thus the security protection information can be kept in the latest state.

[0014] In one example of the present disclosure, the above-described first security protection information includes account information of a user. The slave unit requests input of the account information to an external device based on the fact that the external device configured to be able to communicate with the slave unit receives a data access request to the slave unit, and the slave unit permits data access of the slave unit by the external device in a case where the account information input to the external device is registered in the above-described first security protection information saved in the volatile memory.

[0015] According to the present disclosure, the slave unit can perform authentication processing of a user based on the account information received from the master unit.

[0016] In one example of the present disclosure, the above-described first security protection information includes a digital certificate. The slave unit transmits the digital certificate saved in the volatile memory to an external device based on the fact that the external device configured to be able to communicate with the slave unit receives a request for acquisition of data saved in the slave unit.

[0017] According to the present disclosure, the slave unit can perform communication with the external device based on the digital certificate received from the master unit.

[0018] In one example of the present disclosure, the slave unit further has a non-volatile memory for saving second security protection information which is information to be hidden. The slave unit decides which information of the conflicting information between the information included in the above-described first security protection information and the information included in the above-described second security protection information to give priority in accordance with a predetermined rule in a case where there is conflicting information between the information included in the above-described first security protection information and the information included in the above-described second security protection information.

[0019] According to the present disclosure, the conflict of information between the first security protection information and the second security protection information is eliminated.

[0020] In one example of the present disclosure, the master unit receives the second security protection information from the slave unit at the predetermined timing, and stores the second security protection information in the volatile memory of the master unit.

[0021] According to the present disclosure, security protection information can be distributed managed between the master unit and the slave unit.

[0022] In one example of the present disclosure, the slave unit includes a control unit for controlling a drive device.

[0023] According to the present disclosure, security protection information used in the control unit can be centrally managed by the master unit.

[0024] In another example of the present disclosure, a control method of a control system composed of a plurality of units is provided. The plurality of units include a master unit connected to an internal bus, and a slave unit connected to the internal bus and communicating with the master unit via the internal bus. The control method has the steps of: the master unit storing first security protection information of information to be hidden in a non-volatile memory of the master unit; the slave unit receiving the first security protection information from the master unit at a predetermined timing; and the slave unit storing the first security protection information received from the master unit in a volatile memory of the slave unit.

[0025] According to the present disclosure, the slave unit stores security protection information received from the master unit in a volatile memory. Thereby, every time the supply of power to the control system is stopped, the security protection information disappears from the slave unit. On the other hand, in the master unit, even if the supply of power to the control system is stopped, the security protection information stored in the non-volatile memory of the master unit does not disappear. Thereby, the security protection information can be centrally managed. BRIEF DESCRIPTION OF DRAWINGS

[0026] Figure 1 is a diagram showing a configuration example of an information processing system of an embodiment.

[0027] Figure 2 is an appearance view showing a configuration example of a control system of an embodiment.

[0028] Figure 3 is a schematic diagram showing a hardware configuration example of a control unit constituting a control system of an embodiment.

[0029] Figure 4 is a schematic diagram showing a hardware configuration example of a functional unit constituting a control system of an embodiment.

[0030] Figure 5 is a schematic diagram showing a hardware configuration example of a functional unit constituting a control system of an embodiment.

[0031] Figure 6 is a diagram showing a schematic view of a hardware configuration example of an external device constituting the information processing system of the embodiment.

[0032] Figure 7 is a diagram showing an example of a unit configuration of the information processing system of the embodiment.

[0033] Figure 8 is a diagram showing a functional unit, a data flow between the functional units, and an external device.

[0034] Figure 9 is a diagram showing an example of a screen displayed on the external device of the embodiment.

[0035] Figure 10 is a diagram showing registered account information included in security protection information.

[0036] Figure 11 is a diagram showing a configuration example of the control system of the first modification.

[0037] Figure 12 is a diagram showing a process of merging security protection information.

[0038] Figure 13 is a diagram showing a configuration example of the control system of the second modification.

[0039] Figure 14 is a diagram showing a configuration example of the control system of the third modification.

[0040] Figure 15 is a diagram showing key information included in security protection information. DETAILED DESCRIPTION

[0041] Hereinafter, each embodiment of the present application will be described with reference to the accompanying drawings. In the following description, the same parts and structural elements are denoted by the same reference numerals. Their names and functions are also the same. Therefore, detailed description thereof will not be repeated.

[0042] <A. Application Examples>

[0043] With reference to Figure 1 , application examples of the present application will be described. Figure 1 is a diagram showing a configuration example of the information processing system 1 of the embodiment.

[0044] The information processing system 1 includes one or more control systems 2 and one or more external devices 500. The control system 2 is an FA system for automating a production process. The control system 2 includes a control unit 100 and function units 200, 300. The function unit 300 functions as a master unit. The control unit 100 and the function unit 200 function as slave units. The relationship of the master and the slave is set in advance.

[0045] The function unit 200 and the external device 500 are connected to an external network. Communication between the function unit 200 and the external device 500 is achieved by Ethernet (registered trademark). The external device 500 is, for example, a notebook or desktop PC (Personal Computer), a tablet terminal, a smartphone, an HMI (Human Machine Interface), or another information processing terminal.

[0046] The control unit 100, the function unit 200, and the function unit 300 are connected by an internal bus 10. These units communicate with each other via the internal bus 10.

[0047] The control unit 100 is, for example, a PLC. The control unit 100 controls a drive device (not shown) according to a user program designed in advance. The drive device includes various industrial devices for automating a production process. As an example, the drive device includes a robot controller, a servo driver, an arm robot controlled by the robot controller, a servo motor controlled by the servo driver, and the like. In addition, the drive device can include a vision sensor for capturing a workpiece, other devices used in a production process, and the like.

[0048] The control unit 100 has a volatile memory 106. The volatile memory 106 is a general term of a memory in which information stored when power supply is stopped disappears. The volatile memory 106 is, for example, a RAM (Random Access Memory) such as an SRAM (Static Random Access Memory) or a DRAM (Dynamic Random Access Memory).

[0049] The function unit 200 is connected to the control unit 100. In the function unit 200, various applications for providing various services related to the control system 2 can be installed. The function unit 200 has a volatile memory 206. The volatile memory 206 is, for example, a RAM such as an SRAM or a DRAM.

[0050] The function unit 300 is a unit for centrally managing security guard information 330 of information that is an anonymous object. The function unit 300 is, for example, an SGU (Security Guard Unit). The security guard information 330 contains, for example, account information, digital certificates, and the like that are utilized in various units. The security guard information 330 is saved in the nonvolatile memory 308 of the function unit 300.

[0051] The nonvolatile memory 308 is a general term of a memory that is capable of continuing to hold information even in a state where power supply is not provided. The nonvolatile memory 308 is, for example, a ROM (Read Only Memory), a hard disk, or a flash memory.

[0052] The function unit 300 that is the master unit transmits the security guard information 330 to the control unit 100 and the function unit 200 that are the slave units at a predetermined timing. The control unit 100 saves the security guard information 330 received from the function unit 300 to the volatile memory 106. Likewise, the function unit 200 saves the security guard information 330 received from the function unit 300 to the volatile memory 206.

[0053] The timing at which the security guard information 330 is distributed is not particularly limited. In some cases, the security guard information 330 is distributed to each slave unit at the timing when the power supply of the control system 2 is turned on. In another case, the security guard information 330 is distributed to each slave unit every predetermined period. In yet another case, the security guard information 330 is distributed to each slave unit at the timing when a retrieval instruction, an update instruction based on a user operation is received.

[0054] As described above, the control system 2 has the function unit 300 that centrally undertakes management of security guard information. Thereby, the user does not need to perform management of account information, digital certificates, and the like for each unit, and the complexity of management of security guard information is eliminated. As a result, it is possible to prevent security guard vulnerabilities due to erroneous settings, old settings. In addition, if the security guard information 330 is managed at one location, it is possible to reduce the locations that should be confirmed at the time of an anomaly, and it is possible to promptly respond to anomalies.

[0055] Further, since the security guard information is distributed via the internal bus 10, it is not necessary to be connected to an external network. Thereby, the possibility of leakage of the security guard information to the outside is low, and the security guard level of the control system 2 is improved.

[0056] Furthermore, the security protection information 330 is stored in volatile memories 106 and 206. Therefore, the security protection information 330 will not remain on the slave unit after the power supply to the control system 2 is cut off. On the other hand, even if the power supply to the control system 2 is stopped, the security protection information 330 stored in the non-volatile memory 308 of the functional unit 300 will not disappear. Thus, the security protection information 330 will not be duplicated, and centralized management of the security protection information 330 can be achieved more reliably.

[0057] Furthermore, if security protection information 330 is centrally managed, users do not need to implement information leakage countermeasures for all units. That is, users can improve the security level by focusing on implementing information leakage countermeasures for the non-volatile memory 308 of functional unit 300. For example, when encrypted memory is used in non-volatile memory 308, the risk of leakage of security protection information 330 can be reduced. Additionally, since users only need to implement information leakage countermeasures for non-volatile memory 308, costs can also be controlled.

[0058] <B. Control System 2>

[0059] Reference Figure 2 ,right Figure 1 The control system 2 shown will be described. Figure 2 This is an external view showing an example of the structure of control system 2.

[0060] Reference Figure 2 The control system 2 includes one or more control units 100, one or more functional units 200, one or more functional units 300, one or more functional units 400, and a power supply unit 450.

[0061] The control unit 100 and the functional unit 200 are connected via any data transmission path. The control unit 100, the functional unit 200, and one or more functional units 300 and 400 are connected via an internal bus 10 (see reference). Figure 1 And connect.

[0062] The control unit 100 performs central processing within the control system 2. The control unit 100 executes control calculations for controlling the controlled object according to arbitrary design specifications. Figure 2 In the illustrated structural example, the control unit 100 has one or more communication ports. The control unit 100 is equivalent to a processing execution unit that executes standard control according to a standard control program.

[0063] Functional unit 200 is connected to control unit 100 and is responsible for communication functions with other devices. Figure 2 In the structural example shown, functional unit 200 has one or more communication ports.

[0064] The functional unit 300 is an optional unit that is connected to the control unit 100 as needed. The functional unit 300 typically can include an SGU (Security Guard Unit), a communication unit having a data exchange function based on OPC UA (Object Linking and Embedding for Process Control Unified Architecture), an AI unit having a preventive maintenance function based on AI (Artificial Intelligence), and the like.

[0065] The functional unit 400 provides various functions for realizing control of various control objects by the control system 2. The functional unit 400 typically can include an I / O unit, a safety I / O unit, a communication unit, a motion controller unit, a temperature adjustment unit, a pulse counter unit, and the like. As the I / O unit, for example, a digital input (DI) unit, a digital output (DO) unit, an analog input (AI) unit, an analog output (AO) unit, a pulse capture input unit, and a composite unit having a plurality of kinds mixed, and the like can be cited. The safety I / O unit is responsible for I / O processing involved in safety control.

[0066] The power supply unit 450 supplies a prescribed voltage to each unit constituting the control system 2.

[0067] <Hardware structure example of each unit>

[0068] Next, a hardware structure example of each unit constituting the control system 2 of the present embodiment will be described.

[0069] (c1: Control unit 100)

[0070] Figure 3 is a schematic diagram showing a hardware structure example of the control unit 100 constituting the control system 2 of the present embodiment. Referring to Figure 3 , as main components, the control unit 100 includes a processor 102 such as a CPU (Central Processing Unit) or a GPU (Graphical Processing Unit), a chipset 104, a volatile memory 106, a non-volatile memory 108, a communication controller 110, a USB (Universal Serial Bus) controller 112, a memory card interface 114, network controllers 116, 118, 120, an internal bus controller 122, an indicator 124.

[0071] The processor 102 reads out various programs stored in the nonvolatile memory 108, expands them in the volatile memory 106, and executes them, thereby implementing control operations involved in standard control and various processes described later. The chipset 104 mediates data exchange between the processor 102 and each component, thereby implementing processing as a whole of the control unit 100.

[0072] In the nonvolatile memory 108, in addition to the system program, a control program that operates on an execution environment provided by the system program is stored.

[0073] The communication controller 110 is responsible for data exchange with the functional unit 300. As the communication controller 110, for example, a communication chip corresponding to an internal bus or Ethernet, etc. can be employed.

[0074] The USB controller 112 is responsible for data exchange with an arbitrary information processing device via a USB connection.

[0075] The memory card interface 114 is configured to be able to attach and detach the memory card 115, and is able to write data such as a control program and various settings to the memory card 115, or read out data such as a control program and various settings from the memory card 115.

[0076] The network controllers 116, 118, 120 are each responsible for data exchange with an arbitrary device via a network. The network controllers 116, 118, 120 can also employ an industrial network protocol such as EtherCAT (registered trademark), EtherNet / IP (registered trademark), DeviceNet (registered trademark), CompoNet (registered trademark), etc.

[0077] The internal bus controller 122 is responsible for data exchange with the functional unit 200, the one or more functional units 300, or the one or more functional units 400 that constitute the control system 2. The internal bus can use a communication protocol unique to a vendor, or a communication protocol that is the same as or compliant with an arbitrary industrial network protocol.

[0078] The indicator 124 is a device that notifies the operating state or the like of the control unit 100, and is constituted by one or more LEDs or the like arranged on the surface of the unit.

[0079] In Figure 3In the present embodiment, a structure example in which the required functions are provided by execution of a program by the processor 102 is shown, but a part or all of these provided functions can also be installed using a dedicated hardware circuit (for example, an ASIC (Application Specific Integrated Circuit) or an FPGA (Field-Programmable Gate Array), or the like). Alternatively, a main part of the control unit 100 can also be implemented using a hardware that follows a general architecture (for example, an industrial personal computer based on a general personal computer). In this case, a virtualization technology can also be used to execute a plurality of OSs (Operating Systems) that differ in use in parallel, and the required applications can be executed on each OS.

[0080] (c2: Function Unit 200)

[0081] Figure 4 is a schematic diagram showing a hardware structure example of the function unit 200 that constitutes the control system 2 of the present embodiment. Referring to Figure 4 , as main components, the function unit 200 includes a processor 202 such as a CPU or a GPU, a chipset 204, a volatile memory 206, a non-volatile memory 208, a communication controller 210, a communication interface 212, a memory card interface 214, network controllers 216, 218, and an indicator 224.

[0082] The processor 202 reads out various programs saved in the non-volatile memory 208, expands and executes them in the volatile memory 206, thereby realizing various communication functions described later. The chipset 204 mediates data exchange between the processor 202 and each component, thereby realizing processing as a whole of the function unit 200.

[0083] In the non-volatile memory 208, in addition to a system program, various data such as a communication control program 232 that works on an execution environment provided by the system program are also saved.

[0084] The communication controller 210 is responsible for data exchange with the control unit 100 and the function unit 300. As the communication controller 210, for example, a communication chip corresponding to an internal bus or an Ethernet, or the like can be adopted.

[0085] The communication interface 212 is responsible for data exchange with an arbitrary information processing device via a USB connection.

[0086] The memory card interface 214 is configured to enable attachment and detachment of the memory card 215, and enables writing of control programs, various settings, and the like to the memory card 215, or reading of control programs, various settings, and the like from the memory card 215.

[0087] The network controllers 216, 218 are each responsible for data exchange with any device via a network. The network controllers 216, 218 can also employ a general-purpose network protocol such as Ethernet. As an example, the functional unit 200 communicates with the external device 500 via the network controller 216 or the network controller 218.

[0088] The indicator 224 is a device that notifies the operating state and the like of the functional unit 200, and is constituted by one or more LEDs or the like disposed on the surface of the unit.

[0089] In Figure 4 , a structure example is shown in which the required functions are provided by execution of programs by the processor 202, but a part or all of these provided functions can also be installed using a dedicated hardware circuit (for example, an ASIC or an FPGA, or the like). Alternatively, a hardware that follows a general-purpose architecture (for example, an industrial personal computer based on a general-purpose personal computer) can also be used to implement a main part of the functional unit 200. In this case, a virtualization technology can also be used to execute a plurality of OSs for different uses in parallel, and the required applications can be executed on each OS.

[0090] (c3: Functional Unit 300)

[0091] Figure 5 is a schematic diagram showing a hardware structure example of the functional unit 300 that constitutes the control system 2 of the present embodiment. Referring to Figure 5 , as main components, the functional unit 300 includes a processor 302 such as a CPU or a GPU, a chipset 304, a volatile memory 306, a non-volatile memory 308, a memory card interface 314, an internal bus controller 322, and an indicator 324.

[0092] The processor 302 reads out various application programs saved in the non-volatile memory 308, expands and executes them in the volatile memory 306, thereby implementing server functions and various functions. The chipset 304 implements processing as a whole of the functional unit 300 by mediating data exchange between the processor 302 and each component.

[0093] In the non-volatile memory 308, in addition to a system program, an application program that works on an execution environment provided by the system program, and the above-mentioned security protection information 330 (refer to Figure 1 ) are also saved.

[0094] The memory card interface 314 is configured to enable attachment and detachment of the memory card 315, and enables writing of application programs, various settings, and the like to the memory card 315, or reading of application programs, various settings, and the like from the memory card 315.

[0095] The internal bus controller 322 is responsible for data exchange with the control unit 100 and the functional unit 200 via the internal bus.

[0096] The indicator 324 is a device that notifies the operating state and the like of the functional unit 300, and is constituted by one or a plurality of LEDs and the like disposed on the surface of the unit.

[0097] In Figure 5 , a structure example in which the required functions are provided by execution of the program by the processor 302 is shown, but a part or all of these provided functions can also be installed using a dedicated hardware circuit (for example, an ASIC or an FPGA, and the like). Alternatively, a hardware that follows a general architecture (for example, an industrial personal computer based on a general personal computer) can also be used to realize the main part of the functional unit 300. In this case, a virtualization technology can also be used to execute a plurality of OSs for different uses in parallel, and the required applications can be executed on each OS.

[0098] <D. Hardware structure example of the external device 500>

[0099] Next, the hardware structure of the external device 500 will be explained in order with reference to Figure 6 . Figure 6 is a schematic view showing a hardware structure example of the external device 500 that constitutes the information processing system 1 of the embodiment.

[0100] As an example, the external device 500 is composed of a computer that is constituted based on a general computer architecture. The external device 500 includes a processor 502 such as a CPU or an MPU, a volatile memory 504, a non-volatile memory 510, a communication interface 511, an I / O (Input / Output) interface 514, and a display interface 520. These components are connected in a manner that enables communication with each other via an internal bus 525.

[0101] The processor 502 controls the operation of the external device 500 by executing various control programs such as a development support program 510A and a browser application (not shown). The development support program 510A is a program that provides an environment for developing a control program (user program) of the control system 2. The processor 502 reads out the control program that is an execution object from the non-volatile memory 510 to the volatile memory 504 based on the fact that an execution command of the development support program 510A, the browser application, and the like has been accepted.

[0102] The communication interface 511 exchanges data with other communication devices via a network. The other communication devices include, for example, the functional unit 200, a server, and the like. The external device 500 can also be configured to be able to download various control programs such as the development assistance program 510A from the other communication devices via the communication interface 511.

[0103] The I / O interface 514 is connected to the input device 515, and acquires a signal representing a user operation from the input device 515. The input device 515 is typically constituted by a keyboard, a mouse, a touch panel, a touch pad, or the like, and receives an operation from a user. In addition, in the example of Figure 6 , the external device 500 and the input device 515 are shown as separate bodies, but the external device 500 and the input device 515 can also be constituted as one body.

[0104] The display interface 520 is connected to the display 521, and transmits an image signal for displaying an image to the display 521 in accordance with an instruction from the processor 502 or the like. The display 521 is, for example, an LCD (Liquid Crystal Display) or an organic EL (Electro Luminescence) display, and prompts various information to a user. In the display 521, various screens provided by the development assistance program 510A can be displayed. In addition, in the example of Figure 6 , the external device 500 and the display 521 are shown as separate bodies, but the external device 500 and the display 521 can also be constituted as one body.

[0105] <E. Example of Configuration of Information Processing System 1>

[0106] Figure 7 is a diagram showing an example of the configuration of the information processing system 1. Referring to Figure 7 , a specific example of the configuration of the information processing system 1 will be described.

[0107] As shown in Figure 7 , the information processing system 1 includes the control system 2 and the external device 500. The control system 2 includes the control unit 100, the functional unit 200A, the functional unit 200B, and the functional unit 300. The functional unit 200A and the functional unit 200B are examples of the functional unit 200 described above (see Figure 2 ). The control unit 100, the functional unit 200A, the functional unit 200B, and the functional unit 300 are connected via the internal bus 10. These units communicate with each other via the internal bus 10. This communication is realized by, for example, virtual Ethernet.

[0108] The functional unit 200 and the external device 500 are connected to the external network NWl. The external device 500 is assigned an IP address "192.168.250.3". The functional unit 200 and the external device 500 each have a physical communication port via which they are connected to the external network NWl.

[0109] The control unit 100, the functional units 200A, 200B, 300 are connected to the internal network NW2. The control unit 100 is assigned a virtual IP address "192.168.250.1". In addition, the control unit 100 is assigned a unit name "Unit #0".

[0110] The functional unit 200A is assigned an IP address "192.168.250.2". In addition, the functional unit 200A is assigned a unit name "Unit #1". The functional unit 200A functions as a Web server "Web 1". The applications "App 11", "App 12" are installed in the functional unit 200A. The applications "App 11", "App 12" are accessed from the Web server "Web 1".

[0111] The functional unit 200B is assigned a virtual IP address "192.168.251.100". In addition, the functional unit 200B is assigned a unit name "Unit #2". The functional unit 200B functions as a Web server "Web 2". The applications "App 21", "App 22" are installed in the functional unit 200B. The applications "App 21", "App 22" are accessed from the Web server "Web 2".

[0112] The functional unit 300 is assigned a virtual IP address "192.168.251.101". In addition, the functional unit 300 is assigned a unit name "Unit #3". The functional unit 300 functions as a Web server "Web 3". The applications "App 31", "App 32" are installed in the functional unit 300. The applications "App 31", "App 32" are accessed from the Web server "Web 3".

[0113] <F. Sequence Flow>

[0114] Next, the control flow of the control system 2 will be described with reference to Figure 8-10 The control flow of the control system 2 will be described. Figure 8 is a diagram showing the data flow between the functional unit 200, the functional unit 300, and the external device 500.

[0115] In step S20, the control system 2 is started. In response thereto, the master and slave relationship is set between the functional units 200, 300. The master and slave relationship can be set in advance or arbitrarily set by the user. In Figure 8 the example, the functional unit 200 is set as a slave unit, and the functional unit 300 is set as a master unit. The functional unit 200 as the slave unit transmits a request for acquisition of the security protection information 330 to the functional unit 300 as the master unit. The functional unit 300 transmits the security protection information 330 to the functional unit 200 in response to the reception of the request for acquisition.

[0116] In step S22, the functional unit 200 saves the security protection information 330 received from the functional unit 300 in the volatile memory 206.

[0117] In step S30, it is assumed that the external device 500 receives a request for data access to the functional unit 200 from the user. At the point of time of step S30, the login process to the functional unit 200 is not performed, and thus the input of the account information is requested to the external device 500. More specifically, the functional unit 200 transmits the URL of the login page to the external device 500 and causes it to be redirected to the login page in response to the reception of the request for data access from the external device 500.

[0118] In step S32, the external device 500 transmits a request for access to the login page to the functional unit 200 on the basis of the URL received from the functional unit 200. In response thereto, the functional unit 200 transmits the accessed login page to the external device 500.

[0119] In step S34, the external device 500 displays the login page received from the functional unit 200 on the display 521 (refer to Figure 6 ). Figure 9 is a drawing showing an example of a screen displayed on the external device 500. In Figure 9 , the login page 700 is shown as an example of a screen displayed on the external device 500. The login page 700 accepts the input of the account information such as the user ID, the password, and the like. In the case where the login button of the login page 700 is pressed, the input account information is transmitted to the functional unit 200. In the case where the cancel button of the login page 700 is pressed, the input account information is discarded, and the login page 700 is closed.

[0120] In step S36, it is assumed that the login button of the login page 700 is pressed. Thereby, the external device 500 transmits the account information input to the login page 700 to the functional unit 200.

[0121] In step S50, the functional unit 200, in response to receiving the account information from the external device 500, refers to the security guard information 330 held by the volatile memory 206, and performs authentication processing of the account information (refer to Fig. 9). Figure 1 In the case where the account information input to the external device 500 is registered in the security guard information 330 held by the volatile memory 206, the functional unit 200 permits the data access of the functional unit 200 by the external device 500.

[0122] Figure 10 is a view showing the registered account information 330A included in the security guard information 330. The registered account information 330A is associated with a password or the like by a user ID. The functional unit 200 takes the password corresponding to the user ID included in the input account information received from the external device 500 as a key from the registered account information 330A. Next, the functional unit 200 compares the password taken from the registered account information 330A with the password included in the input account information received from the external device 500. In the case where these passwords coincide with each other, the functional unit 200 judges that the input account information received from the external device 500 is registered in the registered account information 330A.

[0123] In step S52, the functional unit 200 transmits an HTML (Hyper Text Markup Language) document of the portal site to the external device 500 as a response to the data access request in step S30

[0124] In step S54, the external device 500 constitutes the portal site based on the received HTML document, and displays the portal site on the display 521 (refer to Fig. 7) Figure 6 . Figure 9 An example of the portal site 710 displayed on the external device 500 is shown.

[0125] In the portal site 710, links to the applications installed in the functional unit 200 are shown by hyperlinks. In the example of Fig. 7, a link to the application program "App 11" (refer to Fig. 8) installed in the functional unit 200 is shown as a hyperlink 710A, and a link to the application program "App 12" (refer to Fig. 9) installed in the functional unit 200 is shown as a hyperlink 710B. When the user selects the hyperlink 710A, the user can use the function of the application "App 11", and when the user selects the hyperlink 710B, the user can use the function of the application "App 12". Figure 9 Figure 7 Figure 7

[0126] <G. 1st Modification Example>

[0127] ​​​Next, a modification of the control system 2 will be described with reference to Figure 11 and Figure 12 The control system 2 will be described in detail below. Figure 11 is a diagram showing a configuration example of the control system 2A of the first modification.

[0128] In the control system 2 described above, the functional unit 200 as a slave unit utilizes the security protection information 330 distributed from the functional unit 300 as a master unit. In contrast, in the control system 2A of the present modification, the functional unit 200 utilizes not only the security protection information 330 received from the functional unit 300 but also the security protection information 230 preliminarily stored in the functional unit 200. Other aspects are as described above, and thus the following description will not be repeated.

[0129] As shown in Figure 11 , the security protection information 230 is preliminarily stored in the nonvolatile memory 208 of the functional unit 200. In addition, the functional unit 200 stores the security protection information 330 distributed from the functional unit 300 in the volatile memory 206. As a result, the functional unit 200 has the security protection information 230 and the security protection information 330.

[0130] The functional unit 200 merges the security protection information 230 and the security protection information 330. Figure 12 is a diagram showing a process of merging the security protection information 230 and the security protection information 330. More specifically, in Figure 12 , the registered account information 230A included in the security protection information 230, the registered account information 330A included in the security protection information 330, and the merging result 233 of the registered account information 230A and 330A are shown.

[0131] As shown in Figure 12 , there is a case where the presence information collides between the information included in the security protection information 230 and the information included in the security protection information 330. The "collision" herein refers to duplication of unique information such as a user ID. In the example of Figure 12 , the user ID "user2" included in the registered account information 230A collides with the user ID "user2" included in the registered account information 330A.

[0132] In a case where the information included in the security protection information 230 (first security protection information) collides with the information included in the security protection information 330 (second security protection information), the functional unit 200 determines which of the colliding information to give priority in accordance with a predetermined merging rule.

[0133] As an example, the functional unit 200 prioritizes information acquired from a unit having a higher priority. For example, the priority is set in such a manner that the functional unit 300 as the master unit has a higher priority than the functional unit as the slave unit. In this case, the functional unit 200 prioritizes the security protection information 330 received from the functional unit 300 over the security protection information 230 stored in the functional unit 200. As a result, the account information of the user ID "user2" and the password "pass2A" is prioritized over the account information of the user ID "user2" and the password "pass2B". Thus, the conflict of the account information is prevented.

[0134] <H. Second Modification Example>

[0135] Next, the above-described control system 2 will be described in detail with reference to Figure 13 Another modification example of the above-described control system 2 will be described. Figure 13 Fig. 2B is a diagram showing a configuration example of a control system 2B as the second modification example.

[0136] In the above-described control system 2, the master unit distributes the security protection information to the slave unit. In contrast, in the control system 2B of the present modification example, not only the master unit but also the slave unit distributes the security protection information to other units. The other aspects are as described above, and thus the repeated description will not be made below.

[0137] As shown in Fig. 2B, the control unit 100 as the slave unit has a volatile memory 106 and a non-volatile memory 108. The security protection information 130 is stored in advance in the non-volatile memory 108. Figure 13 The functional unit 200 as the slave unit has a volatile memory 206 and a non-volatile memory 208. The security protection information 230 is stored in advance in the volatile memory 206.

[0138] The functional unit 300 as the master unit has a volatile memory 306 and a non-volatile memory 308. The security protection information 330 is stored in advance in the volatile memory 306.

[0139] The control unit 100 distributes the security protection information 130 stored in the non-volatile memory 108 to the functional units 200, 300 at a predetermined timing. The functional unit 200 stores the security protection information 130 received from the control unit 100 in the volatile memory 206. Similarly, the functional unit 300 stores the security protection information 130 received from the control unit 100 in the volatile memory 306.

[0140]

[0141] ​At a predetermined time, functional unit 200 distributes security protection information 230 stored in non-volatile memory 208 to control unit 100 and functional unit 300 respectively. Control unit 100 saves the security protection information 230 received from functional unit 200 to volatile memory 106. Similarly, functional unit 300 saves the security protection information 230 received from functional unit 200 to volatile memory 306.

[0142] At a predetermined time, functional unit 300 distributes security protection information 330 stored in non-volatile memory 208 to control unit 100 and functional unit 200 respectively. Control unit 100 saves the security protection information 330 received from functional unit 300 to volatile memory 106. Similarly, functional unit 200 saves the security protection information 330 received from functional unit 300 to volatile memory 206.

[0143] There is no particular limitation on when safety protection information 130, 230, and 330 are distributed to other units. In one scenario, safety protection information 130, 230, and 330 are distributed to each unit when the power to control system 2B is turned on. In another scenario, safety protection information 130, 230, and 330 are distributed to each unit at predetermined intervals. In yet another scenario, safety protection information 130, 230, and 330 are distributed to each unit upon receiving an acquisition instruction or update instruction based on user operation.

[0144] After receiving security protection information from other units, each unit of control unit 100 and functional units 200 and 300 merges security protection information 130, 230, and 330 according to a predetermined merging rule. In the event of a conflict between security protection information 130, 230, and 330, each unit eliminates the conflict using the method described in “G. First Modification” above.

[0145] In addition, Figure 13 The example illustrates how security information is distributed to all other units, but security information does not necessarily need to be distributed to all other units. For instance, units that are permitted to distribute security information and units that are prohibited from distributing security information can be predetermined, and each unit can distribute security information only to other units that have been permitted to distribute it.

[0146] <I. Third Variation>

[0147] Next, refer to Figure 14 and Figure 15 Other variations of the control system 2 described above will be explained. Figure 14is a diagram showing a configuration example of the control system 2C of the third modification example.

[0148] In the above-described example, the security protection information 330 contains the account information. In contrast, in the present modification example, the security protection information 330 contains key information 330B such as a secret key for encryption, a digital certificate, and the like. Other aspects are as described above, and thus the following description will not be repeated.

[0149] As shown in Figure 14 , the security protection information 330 containing the key information 330B is stored in the nonvolatile memory 308 of the functional unit 300 as the master unit. Figure 15 is a diagram showing the key information 330B contained in the security protection information 330. The key information 330B contains one or more groups of a digital certificate and a secret key.

[0150] The digital certificate contains a public key for encryption. The digital certificate refers to a data set for proving the owner of the public key. Typically, the digital certificate is issued in advance by a certification authority called a certificate authority (CA).

[0151] Referring back to Figure 14 , the functional unit 300 as the master unit transmits the security protection information 330 containing the key information 330B to the control unit 100 and the functional unit 200 as the slave units at a predetermined timing. The control unit 100 saves the security protection information 330 received from the functional unit 300 into the volatile memory 106. Likewise, the functional unit 200 saves the security protection information 330 received from the functional unit 300 into the volatile memory 206.

[0152] Each unit constituting the control system 2C uses the key information 330B held by itself to achieve secure communication with the external device 500. In Figure 14 , an example of the functional unit 200 performing secure communication with the external device 500A and an example of the functional unit 300 performing secure communication with the external device 500B are shown.

[0153] As an example, the functional units 200 and 300 perform secure communication with the external devices 500A and 500B by SSL (Secure Sockets Layer) communication.

[0154] More specifically, the function unit 200, which is a unit from the unit, transmits the digital certificate Cl held by the volatile memory 206 to the external device 500A in response to receiving a request for acquisition of data held by the function unit 200 from the external device 500A. Normally, the digital certificate Cl contains the host name of the enrollee. As described above, the digital certificate Cl is distributed from the function unit 300, and when the host name prescribed in the digital certificate Cl is the function unit 300 although the sender of the digital certificate Cl is the function unit 200, the external device 500A cannot properly authenticate the sender. Therefore, a multi-domain certificate and a wildcard certificate are used as the digital certificate Cl. The multi-domain certificate is a certificate that enables authentication of multiple domains with 1 digital certificate Cl. The wildcard certificate is a certificate that enables authentication of all subdomains belonging to the same level as "*" by appending "*" as the common name.

[0155] The external device 500A verifies the digital certificate Cl received from the function unit 200, and determines whether the sender of the digital certificate Cl is a proper sender. The external device 500A generates a public key (not shown) in a case where it is determined that the sender of the digital certificate Cl is a proper sender. Thereafter, the external device 500A encrypts the generated public key using the public key contained in the digital certificate Cl, and transmits the encrypted public key to the function unit 200.

[0156] The function unit 200 decrypts the encrypted public key using the secret key Kl contained in the key information 330B in response to receiving the encrypted public key from the external device 500A. Through the above processing, the public key is securely transmitted from the function unit 200 to the external device 500A. In the following communication, the function unit 200 and the external device 500A exchange data with each other after encrypting data using the public key.

[0157] Similarly, the function unit 300 performs SSL communication with the external device 500B using the key information 330B held in the nonvolatile memory 308.

[0158] <Notes>

[0159] As described above, the present embodiment includes the following disclosure.

[0160] [Structure 1]

[0161] A control system 2 configured of a plurality of units, in which

[0162] The plurality of units include:

[0163] a master unit 300 connected to the internal bus 10; and

[0164] The slave unit 200 is connected to the internal bus 10 and communicates with the master unit 300 via the internal bus 10,

[0165] The master unit 300 has a nonvolatile memory 308 for holding first security protection information that is an object of concealment,

[0166] The slave unit 200 has a volatile memory 206,

[0167] The slave unit 200 receives the first security protection information from the master unit 300 at a predetermined timing and holds the first security protection information in the volatile memory 206.

[0168] [Structure 2]

[0169] In the control system described in Structure 1,

[0170] The predetermined timing includes a timing at which a power supply of the control system 2 is turned on.

[0171] [Structure 3]

[0172] In the control system described in Structure 1 or 2,

[0173] The first security protection information includes account information of a user,

[0174] The slave unit 200 requests input of account information from an external device 500 configured to be able to communicate with the slave unit 200, based on a case where a data access request to the slave unit 200 is received from the external device 500,

[0175] The slave unit 200 permits data access to the slave unit 200 by the external device 500, in a case where the account information input to the external device 500 is registered in the first security protection information held in the volatile memory 206.

[0176] [Structure 4]

[0177] In the control system described in any one of Structures 1 to 3,

[0178] The first security protection information includes a digital certificate,

[0179] The slave unit 200 transmits the digital certificate held in the volatile memory 206 to the external device 500, based on a case where a request for acquisition of data held in the slave unit 200 is received from the external device 500 configured to be able to communicate with the slave unit 200.

[0180] [Structure 5]

[0181] In the control system described in any one of Structures 1 to 4,

[0182] The slave unit 200 also has a nonvolatile memory 208 for holding second security protection information of information that is an object of concealment,

[0183] The slave unit 200 decides which of the conflicting information is given priority in accordance with a predetermined rule in the case where there is a conflict between the information included in the first security protection information and the information included in the second security protection information.

[0184] [Structure 6]

[0185] In the control system described in Structure 5,

[0186] The master unit 300 receives the second security protection information from the slave unit 200 at the predetermined timing and holds the second security protection information in the volatile memory 306 of the master unit 300.

[0187] [Structure 7]

[0188] In the control system described in any one of Structures 1 to 6,

[0189] The slave unit 200 includes a control unit 100 for controlling a drive device.

[0190] [Structure 8]

[0191] A control method of a control system 2 composed of a plurality of units, wherein

[0192] The plurality of units include:

[0193] a master unit 300 connected to an internal bus 10; and

[0194] a slave unit 200 connected to the internal bus 10 and communicating with the master unit 300 via the internal bus 10,

[0195] The control method has the following steps:

[0196] The master unit 300 holds first security protection information of information that is an object of concealment in a nonvolatile memory 308 of the master unit 300;

[0197] The slave unit 200 receives the first security protection information from the master unit 300 at a predetermined timing; and

[0198] The slave unit 200 stores the first security information received from the master unit 300 in the volatile memory 206 of the slave unit 200.

[0199] The embodiments disclosed this time should be considered illustrative and not restrictive. The scope of the application is not represented by the above description but by the claims, and intended to include all modifications within the meaning and range of equivalency of the claims.

[0200] Explanation of Reference Numerals

[0201] 1: information processing system; 2, 2A, 2B, 2C: control system; 10, 525: internal bus; 100: control unit; 102, 202, 302, 502: processor; 104, 204, 304: chipset; 106, 206, 306, 504: volatile memory; 108, 208, 308, 510: nonvolatile memory; 110, 210: communication controller; 112: USB controller; 114, 214, 314: memory card interface; 115, 215, 315: memory card; 116, 118, 120, 216, 218: network controller; 122, 322: internal bus controller; 124, 224, 324: indicator; 130, 230, 330: security information; 200, 200A, 200B, 300, 400: functional unit; 212, 511: communication interface; 230A, 330A: registered account information; 232: communication control program; 233: merged result; 330B: key information; 450: power supply unit; 500, 500A, 500B: external device; 510A: development support program; 514: interface; 515: input device; 520: display interface; 521: display; 700: login page; 710: portal site; 710A, 710B: hyperlink.

Claims

1. A control system constituted by a plurality of units, wherein the plurality of units include: a master unit connected to an internal bus; and a slave unit connected to the internal bus and communicating with the master unit via the internal bus, the master unit has a nonvolatile memory for holding first security protection information of information as an object to be hidden, the first security protection information includes account information of a user, the slave unit has a volatile memory and a nonvolatile memory for holding second security protection information of information as an object to be hidden, the slave unit receives the first security protection information from the master unit at a predetermined timing and holds the first security protection information in the volatile memory, the slave unit requests input of account information to an external device based on a case where a data access request to the slave unit is received from the external device constituted so as to be able to communicate with the slave unit, the slave unit permits data access of the slave unit by the external device in a case where the account information input to the external device is registered in the first security protection information held in the volatile memory of the slave unit, the slave unit decides which information of conflicting information between information included in the first security protection information held in the volatile memory of the slave unit and information included in the second security protection information held in the nonvolatile memory of the slave unit to be given priority in accordance with a predetermined rule in a case where there is the conflicting information.

2. The control system according to claim 1, wherein the predetermined timing includes a timing at which a power supply of the control system is turned on.

3. The control system according to claim 1 or 2, wherein the first security protection information includes a digital certificate, the slave unit transmits the digital certificate held in the volatile memory of the slave unit to the external device based on a case where a request for acquisition of data held by the slave unit is received from the external device constituted so as to be able to communicate with the slave unit.

4. The control system according to claim 1 or 2, wherein the master unit receives the second security protection information from the slave unit at the predetermined timing and holds the second security protection information in the volatile memory of the master unit.

5. The control system according to claim 1 or 2, wherein the slave unit includes a control unit for controlling a drive device.

6. A control method of a control system constituted by a plurality of units, wherein the plurality of units include: a master unit connected to an internal bus; and a slave unit connected to the internal bus and communicating with the master unit via the internal bus, the control method has the following steps: the master unit holds first security protection information of information as an object to be hidden in a nonvolatile memory of the master unit, the first security protection information including account information of a user; the slave unit receives the first security protection information from the master unit at a predetermined timing; and the slave unit holds the first security protection information in a volatile memory of the slave unit. The slave unit saves the first security protection information received from the master unit in a volatile memory of the slave unit; The slave unit requests input of account information from an external device based on a case where a data access request to the slave unit is received from the external device configured to be able to communicate with the slave unit; The slave unit permits data access to the slave unit by the external device in a case where the account information input to the external device is registered in the first security protection information saved in the volatile memory of the slave unit; and The slave unit decides which information of the conflicting information to give priority in accordance with a predetermined rule in a case where there is conflicting information between information included in the first security protection information saved in the volatile memory of the slave unit and information included in second security protection information saved in a non-volatile memory of the slave unit as information to be hidden.

Citation Information

Patent Citations

  • Programmable logic controller, data collection device, database access method and database access program

    JP2016194808A

  • Control system and control method

    CN113544668A

  • Industrial control system redundant communications / control modules authentication

    US20150046710A1