System and method for providing security to legacy devices
By setting lock and unlock passwords in equipment of traditional industrial process control and automation systems, the vulnerability of equipment to attacks is solved, and the security protection of equipment configuration and firmware is achieved, ensuring the stable operation of the equipment.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- HONEYWELL INTERNATIONAL INC
- Filing Date
- 2023-03-10
- Publication Date
- 2026-05-12
AI Technical Summary
Traditional industrial process control and automation systems lack cybersecurity protection, making them vulnerable to attacks that could lead to malicious alterations or damage to configurations and firmware, affecting equipment control and security.
By setting lock and unlock passwords in the device indexing device, the monitoring program reads the passwords and sets the device to a locked or unlocked state, preventing changes to the configuration and firmware.
It effectively prevents unauthorized changes to device configuration and firmware, protects devices from cyberattacks, and ensures the safe and stable operation of devices.
Smart Images

Figure CN116804868B_ABST
Abstract
Description
Technical Field
[0001] This disclosure relates generally to industrial control and automation systems. More specifically, this disclosure relates to the configuration and firmware of conventional equipment for protecting industrial process control and automation systems, as well as systems and methods for preventing changes to such configuration and firmware. Background Technology
[0002] Traditional process and safety controllers, gateways, and I / O modules used in industrial process control and automation systems are deployed using older hardware technologies that lack modern cybersecurity protections such as secure boot, signed firmware, and download verification. These legacy devices and the system platforms supporting them may also lack the processing capabilities to provide secure, encrypted, and authenticated communication. Legacy devices heavily rely on the layered system security of automation systems. However, if these system protections are compromised, malicious actors could gain access to engineering workstations or process control networks, enabling them to shut down legacy devices, or worse, permanently disable them by loading counterfeit firmware. This could result in loss of control, poor control, or even irreparable damage to the devices. Summary of the Invention
[0003] This disclosure relates to the configuration and firmware of conventional equipment for protecting industrial process control and automation systems, as well as systems and methods for preventing changes to such configuration and firmware.
[0004] In a first embodiment, a method is disclosed that includes setting a lock password in a device indexing device of a legacy device. The method further includes executing a monitoring program that reads the lock password and sets the legacy device to a locked state, and executing an execution program to prevent changes to the configuration and firmware of the legacy device while it is in the locked state. The first embodiment also includes a method for releasing a legacy device from a locked state, comprising setting an unlock password in a device indexing device of the legacy device, and executing a monitoring program to read the unlock password and set the legacy device to an unlocked state. When the legacy device is in the unlocked state, the execution program allows changes to the configuration and firmware of the legacy device.
[0005] In a second embodiment, a system is disclosed that includes a device indexing device associated with a conventional device. The device indexing device can be used to input a lock password, and processing circuitry is configured to read the lock password and set the conventional device to a locked state. The device indexing device can also be used to input an unlock password, and processing circuitry is configured to read the unlock password and set the conventional device to an unlocked state.
[0006] Other technical features will be apparent to those skilled in the art from the following figures, description and claims. Attached Figure Description
[0007] To gain a more complete understanding of this disclosure, the following description is now taken in conjunction with the accompanying drawings, in which:
[0008] Figure 1 An exemplary industrial process control and automation system according to this disclosure is shown;
[0009] Figure 2 Details of an exemplary controller according to this disclosure are shown;
[0010] Figure 3 A diagram illustrating an exemplary method for setting a controller to a locked state according to this disclosure is shown;
[0011] Figure 4 The following is shown in accordance with the present disclosure: Figure 3 The method uses an indexing device and a device display;
[0012] Figure 5 A diagram illustrating an exemplary method for setting a controller to an unlocked state according to this disclosure is shown;
[0013] Figure 6 The following is shown in accordance with the present disclosure: Figure 5 The method uses an indexing device and a device display;
[0014] Figure 7 A diagram illustrating an exemplary method for a device indexing apparatus for a monitoring controller according to the present disclosure is shown; and
[0015] Figure 8 A diagram illustrating an exemplary method for executing a controller's lock state according to this disclosure is shown. Detailed Implementation
[0016] These figures (discussed below) and the various embodiments used to illustrate the principles of the invention in this patent document are by way of example only and should not be construed as limiting the scope of the invention in any way. Those skilled in the art will understand that the principles of the invention can be implemented in any type of suitably arranged device or system.
[0017] The benefit of this disclosure is that it provides a method to lock devices used in industrial process control and automation systems, such as controllers, wireless gateways, or I / O modules, against any changes to their configuration and firmware. This prevents the removal and replacement of controllers or other devices used in industrial process control and automation systems using counterfeit firmware or protects them from cybersecurity attacks. This disclosure allows for the protection of traditional process and safety controllers, gateways, and I / O modules from cybersecurity attacks simply by updating the software of the devices.
[0018] Figure 1 An exemplary industrial process control and automation system 100 according to this disclosure is shown. Figure 1 As shown, system 100 includes various components that facilitate the production or processing of at least one product or other material. For example, system 100 is used herein to facilitate the control of components within one or more plants 101a to 101n. Each plant 101a to 101n represents one or more processing facilities (or one or more portions thereof), such as one or more manufacturing facilities for producing at least one product or other material. Generally, each plant 101a to 101n may implement one or more processes and may be referred to individually or collectively as a process system. A process system generally refers to any system or portion thereof configured to process one or more products or other materials in a certain manner.
[0019] exist Figure 1 In this system, system 100 is implemented using the Pudu model of process control. In the Pudu model, "level 0" may include one or more sensors 102a and one or more actuators 102b. Sensors 102a and actuators 102b represent components in the process system capable of performing any of a variety of functions. For example, sensor 102a may measure various characteristics of the process system, such as temperature, pressure, or flow rate. Additionally, actuators 102b may alter various characteristics of the process system. Sensors 102a and actuators 102b may represent any other or additional components in any suitable process system. Each sensor in sensor 102a includes any suitable structure for measuring one or more characteristics of the process system. Each actuator in actuator 102b includes any suitable structure for operating or influencing one or more conditions in the process system.
[0020] Each of sensor 102a and actuator 102b is connected to at least one network 104 via corresponding I / O modules 105a, 105b. The I / O modules provide suitable interface connections for the type of sensor or actuator used, such as copper or fiber optic cables or communication and signaling protocols. Network 104 facilitates interaction with I / O modules 105a, 105b and with sensors 102a and actuator 102b. For example, network 104 can transmit measurement data from I / O modules 105a, 105b and sensor 102a, and provide control signals to actuator 102b via I / O modules 105a and 105b. Network 104 can represent any suitable network or combination of networks. As a specific example, network 104 can represent an Ethernet network, an electrical signal network (such as a HART or Foundation Fieldbus network), a pneumatic control signal network, or any other or additional type of network.
[0021] In the Purdue model, "Level 1" may include one or more controllers 106 coupled to network 104. Each controller 106 may, among other things, use measurements from one or more sensors 102a to control the operation of one or more actuators 102b. For example, controller 106 may receive measurement data from one or more I / O modules 105a and 105b and their associated connected sensors 102a, and use the measurement data to generate control signals for one or more actuators 102b. Each controller 106 includes any suitable structure for interacting with and controlling one or more I / O modules 105a and 105b. Each controller 106 may, for example, represent a proportional-integral-derivative (PID) controller or a multivariable controller, such as a robust multivariable predictive control technique (RMPCT) controller, or other types of controllers implementing model predictive control (MPC) or other advanced predictive control (APC). As a specific example, each controller 106 may represent a computing device running a real-time operating system.
[0022] Two networks 108 are coupled to controller 106. Networks 108 facilitate interaction with controller 106, such as by transmitting data to and from controller 106. Network 108 can represent any suitable network or combination of networks. As a specific example, network 108 can represent a pair of redundant Ethernet networks, such as a fault-tolerant Ethernet (FTE) network from Honeywell International Inc.
[0023] At least one switch / firewall 110 couples network 108 to two networks 112. The switch / firewall 110 can transmit traffic from one network to another. The switch / firewall 110 can also block traffic from one network from reaching another. The switch / firewall 110 includes any suitable construct for providing communication between networks, such as a Honeywell Control Firewall (CF9) device. Network 112 can represent any suitable network, such as an FTE network.
[0024] In the Purdue model, "Level 2" may include one or more machine-level controllers 114 coupled to network 112. Machine-level controllers 114 perform various functions to support the operation and control of controllers 106, I / O modules 105a and 105b, sensors 102a, and actuators 102b that can be associated with a specific industrial device, such as a boiler or other machine. For example, machine-level controllers 114 may record information collected or generated by controller 106, such as measurement data from sensor 102a or control signals for actuator 102b. Machine-level controllers 114 may also execute applications that control the operation of controller 106, thereby controlling the operation of actuator 102b. Furthermore, machine-level controllers 114 can provide secure access to controller 106. Each machine-level controller in machine-level controllers 114 includes any suitable structure for providing access to, control of, or operation of a machine or other individual device. Each machine-level controller in machine-level controllers 114 may, for example, represent a server computing device running the Microsoft Windows operating system. Although not shown, different machine-level controllers 114 can be used to control different devices in the process system (each device is associated with one or more controllers 106, sensors 102a and actuators 102b).
[0025] One or more operator stations 116 are coupled to network 112. Operator station 116 represents a computing or communication device that provides user access to machine-level controller 114, which in turn can provide user access to controller 106 (and possibly sensors 102a and actuators 102b). As a specific example, operator station 116 may allow a user to view the operational history of sensors 102a and actuators 102b using information collected by controller 106 and / or machine-level controller 114. Operator station 116 may also allow a user to adjust the operation of sensors 102a, actuators 102b, controller 106, or machine-level controller 114. Furthermore, operator station 116 may receive and display warnings, alerts, or other messages or displays generated by controller 106 or machine-level controller 114. Each operator station in operator station 116 includes any suitable architecture for supporting user access and control of one or more components in system 100. Each operator station in operator station 116 may, for example, represent a computing device running the Microsoft Windows operating system.
[0026] At least one router / firewall 118 couples network 112 to two networks 120. Router / firewall 118 includes any suitable structure for providing communication between the networks, such as a secure router or a combined router / firewall. Network 120 may represent any suitable network, such as an FTE network.
[0027] In the Purdue model, "Level 3" may include one or more unit-level controllers 122 coupled to network 120. Each unit-level controller 122 is typically associated with a unit in the process system, representing a collection of different machines operating together to implement at least a portion of the process. The unit-level controllers 122 perform various functions to support the operation and control of components in lower levels. For example, a unit-level controller 122 may log information collected or generated by components in lower levels, execute applications controlling components in lower levels, and provide secure access to components in lower levels. Each unit-level controller in the unit-level controllers 122 includes any suitable structure for providing access to, control of, or associated operation of one or more machines or other devices in the processing unit. Each unit-level controller in the unit-level controllers 122 may, for example, represent a server computing device running the Microsoft Windows operating system. Although not shown, different unit-level controllers 122 may be used to control different units in the process system (where each unit is associated with one or more machine-level controllers 114, controllers 106, sensors 102a, and actuators 102b).
[0028] Access to the unit-level controller 122 can be provided by one or more operator stations 124. Each operator station in the operator stations 124 includes any suitable structure for supporting user access and control of one or more components in the system 100. Each operator station in the operator stations 124 may, for example, represent a computing device running the Microsoft Windows operating system.
[0029] At least one router / firewall 126 couples network 120 to two networks 128. Router / firewall 126 includes any suitable structure for providing communication between the networks, such as a secure router or a combined router / firewall. Network 128 may represent any suitable network, such as an FTE network.
[0030] In the Purdue model, "Level 4" may include one or more plant-level controllers 130 coupled to network 128. Each plant-level controller 130 is typically associated with one of the plants 101a to 101n, which may include one or more processing units implementing the same, similar, or different processes. Plant-level controllers 130 perform various functions to support the operation and control of components in lower levels. As a specific example, a plant-level controller 130 may execute one or more Manufacturing Execution System (MES) applications, scheduling applications, or other or additional plant or process control applications. Each plant-level controller 130 includes any suitable structure for providing access to, control of, or associated operation of one or more processing units in the processing plant. Each plant-level controller 130 may, for example, represent a server computing device running the Microsoft Windows operating system.
[0031] Access to the plant-level controller 130 can be provided by one or more operator stations 132. Each operator station in the operator station 132 includes any suitable architecture for supporting user access and control of one or more components in the system 100. Each operator station in the operator station 132 may, for example, represent a computing device running the Microsoft Windows operating system.
[0032] At least one router / firewall 134 couples network 128 to one or more networks 136. Router / firewall 134 includes any suitable structure for providing communication between networks, such as a secure router or a combined router / firewall. Network 136 can represent any suitable network, such as an enterprise-wide Ethernet or other network, or all or part of a larger network (such as the Internet).
[0033] In the Purdue model, "Level 5" may include one or more enterprise-level controllers 138 coupled to network 136. Each enterprise-level controller 138 is typically capable of performing planning operations for multiple plants 101a to 101n and controlling various aspects of plants 101a to 101n. Enterprise-level controllers 138 may also perform various functions to support the operation and control of components in plants 101a to 101n. As a specific example, an enterprise-level controller 138 may execute one or more order processing applications, enterprise resource planning (ERP) applications, advanced planning and scheduling (APS) applications, or any other or additional enterprise control applications. Each enterprise-level controller in enterprise-level controller 138 includes any suitable structure for providing access to, control of, or control-related operations for one or more plants. Each enterprise-level controller in enterprise-level controller 138 may, for example, represent a server computing device running the Microsoft Windows operating system. In this document, the term "enterprise" refers to an organization having one or more plants or other processing facilities to manage. It should be noted that if a single plant 101a is to be managed, the functionality of the enterprise-level controller 138 can be integrated into the plant-level controller 130.
[0034] Access to the enterprise-level controller 138 can be provided by one or more operator stations 140. Each operator station in the operator stations 140 includes any suitable architecture for supporting user access and control of one or more components in the system 100. Each operator station in the operator stations 140 may, for example, represent a computing device running the Microsoft Windows operating system.
[0035] The various levels of the Purdue model may include other components, such as one or more databases. The database associated with each level may store any suitable information associated with that level or one or more other levels of system 100. For example, a historical database 141 may be coupled to network 136. Historical database 141 may represent a component that stores various information about system 100. Historical database 141 may, for example, store information used during production scheduling and optimization. Historical database 141 represents any suitable structure used for storing information and facilitating information retrieval. Although shown as a single centralized component coupled to network 136, historical database 141 may be located elsewhere in system 100, or multiple historical databases may be distributed across different locations within system 100.
[0036] In a particular implementation scheme, Figure 1The various controllers and operator stations in the system can represent computing devices. For example, each of controllers 106, 114, 122, 130, and 138 may include one or more processing devices 142 and one or more memories 144 for storing instructions and data used, generated, or collected by the processing devices 142. Each of controllers 106, 114, 122, 130, and 138 may also include at least one network interface 146, such as one or more Ethernet interfaces or a wireless transceiver. Additionally, each of operator stations 116, 124, 132, and 140 may include one or more processing devices 148 and one or more memories 150 for storing instructions and data used, generated, or collected by the processing devices 148. Each operator station 116, 124, 132, and 140 may also include at least one network interface 152, such as one or more Ethernet interfaces or a wireless transceiver.
[0037] System 100 also includes gateway device 160. Gateway 160 integrates factory 101a to 101n and network 136 with cloud network 162 and operator station 164. Gateway 160 may include a ONEWIRELESS gateway providing high availability and mesh capabilities. Gateway 160 may also include a general-purpose embedded platform for communication protocols, as well as redundancy, design, and security features. Gateway 160 includes Intuition and Experion for system connectivity, distributed system architecture, and service-oriented architecture. Gateway 160 includes an OPC unified architecture (UA) for legacy and future system integration.
[0038] The communication stack to cloud network 162 includes OPC UA and its core services for synchronous and asynchronous data publishing, alarm and event publishing, historical data transmission, blind logging, or “BLOB” transmission. Other cloud protocols may be supported as alternatives to or in addition to OPC UA. These other cloud protocols may offer similar services, including event streaming and data access services to an event center in the cloud. Gateway 160 provides bidirectional security protection for both cloud and on-premises systems and devices (such as devices within plant 101a, as well as enterprise controller 138 and operator station 140).
[0039] In one implementation, network 136 may represent a cloud network configured to facilitate wireless communication between gateway 160 and enterprise controller 138, operator station 140, historical database 141, or at least one of plants 101b to 101n.
[0040] Although Figure 1 An example of an industrial process control and automation system 100 is shown, but it is possible to... Figure 1 Various changes can be made. For example, control and automation systems can include any number of sensors, actuators, I / O modules, controllers, servers, operator stations, networks, risk managers, and other components. Additionally, networks 120 and 128 can be a single network or a non-FTE network with a single cable or dual cables (such as those connecting to multiple sections). Figure 1 The composition and arrangement of System 100 shown are for illustrative purposes only. Components may be added, omitted, combined, or placed in any other suitable configuration as needed. Furthermore, specific functions have been described as being performed by specific components of System 100. This is for illustrative purposes only. Generally, control systems and automation systems are highly configurable and can be configured in any suitable manner as needed.
[0041] Figure 2 An example of a controller 106 according to this disclosure is shown. Figure 2 As shown, the controller 106 includes a bus system 205 that supports communication between at least one processing device 210, at least one storage device 215, at least one communication unit 220, at least one input / output (I / O) unit 225, a device display 240, and a device indexing device 250.
[0042] Processing device 210 executes instructions that can be loaded into memory 230. Processing device 210 may include any suitable number and type of processors or other devices arranged in any suitable manner. Exemplary types of processing device 210 include microprocessors, microcontrollers, digital signal processors, field-programmable gate arrays, application-specific integrated circuits, and discrete circuits.
[0043] Memory 230 and persistent storage device 235 are examples of storage device 215, which represents any structure capable of storing information (such as data, program passwords, and / or other suitable temporary or permanent information) and facilitating information retrieval. Memory 230 may represent random access memory or any other suitable volatile or non-volatile storage device. Persistent storage device 235 may include one or more components or devices supporting longer-term storage of data, such as read-only memory, hard disk, flash memory, or optical disk.
[0044] Communication unit 220 supports communication with other systems or devices. For example, communication unit 220 may include a network interface card, such as an Ethernet network interface for communication via Ethernet network 104 or a wireless transceiver for facilitating communication via network 136. Communication unit 220 can support communication via any suitable physical or wireless communication link.
[0045] I / O unit 225 allows for data input and output. For example, I / O unit 225 can provide connectivity for user input via a keyboard, mouse, keypad, touchscreen, or other suitable input device. I / O unit 225 can also send output to a display, printer, or other suitable output device.
[0046] The device display 240 may consist of a multi-character multi-line message display, a single alphanumeric character display, or various light-emitting diodes (LEDs) that can provide information to the user using color or flashing effects. The display device 240 is used to display information and notify the user of the controller 106 of current operating conditions and status. For the display device 240 of this disclosure, the exemplary single-line multi-character display will be used to illustrate the benefits of this disclosure; however, those skilled in the art will understand that other displays incorporating the aforementioned benefits can be used to provide information to the user at the controller 106.
[0047] The indexing device 250 is a set of electrical switches or other switch-type devices that can be physically altered by hand or with the aid of tools such as a screwdriver. The electrical switches may include single or multiple dual in-line package (DIP) or rotary dial switches. Other electrical devices used in industry for switching between functions may also be used, such as shorting jumper pins, manipulating push-button pins, or simply using connector wires that can be physically inserted into a socket to set a password for locking or unlocking the controller.
[0048] Controllers used in industry, especially those that transmit data using the Ethernet Internet Protocol (IP), include electrical switches for entering the Internet IP address or portions of the IP address (such as the last eight bytes used to identify the controller in an Ethernet network). In such controllers, it would be advantageous to use Ethernet IP switches to also enter the controller's lock and unlock passwords.
[0049] To facilitate explanation of the benefits of this disclosure, the indexing device 250 will be described using a set of rotary dial switches comprising three dials, each of which can be set to a unique number from 0 to 9. Figure 4 and Figure 6 As shown, the leftmost dial represents the most significant bit (MSD), and the rightmost dial represents the least significant bit (LSD). The dials are used to assign the IP address to controller 106, providing network interface identification and location addressing for controller 106 within a system 100 using an Ethernet network, such as Ethernet network 104. Other electrical switches known in the industry for changing the state of controller 106 or setting its IP network address, such as those described above, can replace the rotary dials to form the device indexing device 250.
[0050] It should be noted that this disclosure will use controller 106 as an example to explain the invention, and those skilled in the art will understand that other devices used in system 100, such as any of the Ethernet networks 136, 128, 120, 112, 108 and 104 connected to system 100 and using I / O modules 105a, 105b of the device indexing device, gateway 160, and machine controller 114, unit controller 122 and plant controller 130, can be used to practice the invention.
[0051] This disclosure provides a secure locked state for the conventional controller 106 by setting a lock password using the device indexing device 250. The controller 106 can also be set to an unlocked state by setting an unlock password using the device indexing device 250. The monitoring software program reads the lock password or unlock password set in the device indexing device 250. If the controller 106 is in a locked state, the execution software program prevents certain controller operations from being performed. Both the monitoring software program and the execution software program are stored in memory 230 and executed by the processing device 210. The monitoring software periodically monitors the device indexing device 250 and sets the controller 106 to a locked or unlocked state based on the password set on the dial of the device indexing device 250. When an attempt is made to make certain changes to the controller 106 configuration and firmware, the execution software is executed. The execution software checks and determines whether the controller 106 is in a locked or unlocked state, thereby preventing attempted changes and returning an error if the controller is set to a locked state.
[0052] Figure 3 and Figure 4 A method for setting the controller to a locked state is illustrated. In step 300, a user, such as a plant operator or other authorized user, copies or records the digital settings currently set on the dial of the equipment indexing device 250.
[0053] Next, in step 305, the user uses a tool such as a screwdriver to change the device indexing device 250 to a lock code, using the dial of the device indexing device 250 to set the lock code. As mentioned above, other devices can be used to input the lock or unlock code, including, for example, DIP switches, jumper pins, push-button pins, or connectors, which can be physically manipulated to set the code for locking or unlocking the controller 106. Using the rotary dial, the lock code can be a preset single number or multiple combinations of numbers that the monitoring software understands as a code for locking the controller 106. The code is set by inputting any combination on the rotary dial of the device indexing device 250. For example, numbers from 0 to 9 can be set using only the MSD of the dial of the device indexing device 250, or numbers from 0 to 9 can be set in the LSD dial of the device indexing device. Alternatively, more complex codes, such as 123 or 789, can be used by setting appropriate numbers in all three dials. In another more complex method, a combination of three different codes and a set time interval between code settings can be used to set the lock code. For example, set 123 on the dial, wait 10 seconds, set 234 on the dial, wait another 10 seconds, and finally set 567.
[0054] Next, in step 310, the monitoring software reads the password set in the dial of the device indexing device 250. If it matches the lock password expected by the monitoring software, the controller 106 state is changed to locked. In step 315, the locked state of the controller 106 is visually indicated to the user on the device display 240, thus confirming that the lock password has been accepted and the controller 106 is now in a locked state. Finally, in step 320, the user physically changes the dial of the device indexing device 250 back to the network IP address copied from step 300.
[0055] exist Figure 4 In step 300, the network IP address was changed by the user before step 305. Step 305 shows the user using a tool to change the MSD dial of the device indexing device 250. Step 315 shows an example of verifying with the user that the controller has accepted the lock password 106 and that the controller is now in a locked state on the device display 240. Finally, step 320 shows the dial of the device indexing device 250 reset to the network IP address copied from step 300.
[0056] Figure 5 and Figure 6 A method for setting the controller to an unlocked state is shown. In step 500, the user copies or records the digital settings currently set on the dial of the device indexing device 250.
[0057] Next, in step 505, the user uses a tool such as a screwdriver to change the device indexing device 250 to an unlock password, using the dial of the device indexing device 250 to set the unlock password. The unlock password can be a preset single number or a combination of multiple numbers that the monitoring software understands as a password used to unlock the controller 106, as described above for setting the lock password.
[0058] Next, in step 510, the monitoring software reads the password set in the dial of the device indexing device 250. If it matches the unlock password expected by the monitoring software, the controller state is changed to unlocked. In step 515, the unlocked state of the controller 106 is visually indicated to the user on the device display 240, thereby confirming that the unlock password has been accepted and the controller 106 is now in the locked state.
[0059] Finally, in step 520, the user uses a tool to physically change the dial of the device indexing device 250 back to the network IP address copied from step 500, thereby returning the IP address of the controller 106.
[0060] Step 500 Figure 6 The image shows the network IP address before it was changed by the user in step 505. Step 505 shows the user using a tool to change the MSD dial of the device indexing device 250. Step 515 shows the device display 240 verifying that the unlock password has been accepted by the controller 106 and that the controller is now in the unlocked state. Step 520 shows the dial of the device indexing device 250 being reset to the network IP address copied from step 500.
[0061] Figure 7 A diagram illustrating an exemplary method 700 of the monitoring software of this disclosure is shown. Method 700 operates as a periodic task that checks whether the dial of the device indexing device 250 has been physically altered to place the controller 106 in a locked or unlocked state. Method 700 is executed by processing device 210. The method first reads the value set on the dial in the device indexing device 250 in step 710. Next, in step 720, the method checks whether the device indexing device 250 has been changed to a password for locking the controller 106. If the device indexing device 250 has not yet been changed to a lock password, method 700 continues and checks in step 730 whether the device indexing device 250 has been changed to an unlock password. If the device indexing device has not yet been changed to an unlock password, method 700 enters a sleep state in step 740 for a preset time period. After the sleep period ends, the method returns to step 710 to read the device indexing device 250 again.
[0062] If a lock password is encountered in step 720, controller 106 changes to a locked state in step 725, and method 700 enters a sleep state in step 740. After the sleep period 740 ends, method 700 returns to rereading the device indexing device 250. Controller 106 remains in the locked state until the device indexing device 250 changes to an unlocked state. If method 700 encounters an unlock password in step 730, the controller's state is changed to an unlocked state in step 735, and method 700 enters a sleep state 740. After the sleep period ends, the monitoring software returns to 710 to reread the device indexing device 250. Controller 106 remains in the unlocked state until the device indexing device 250 is changed to require an input lock password.
[0063] When controller 106 is locked, any attempt to change the configuration or firmware of controller 106, such as upgrading controller firmware, restoring controller to factory settings, setting controller to idle, shutting down controller, changing or deleting the configuration of applications running by controller, or changing any runtime data such as setpoints, will be rejected and not allowed to proceed. A notification will be sent to the operator station monitoring controller 106, such as operator station 116 of system 100, indicating that the attempt to change the locked controller is rejected.
[0064] Figure 8 An exemplary method 800 for executing the software of this disclosure is illustrated. Method 800 is executed by processing device 210 and is triggered when a specific attempt to change the specific operation or configuration of controller 106 is detected, as shown in step 810. Next, in step 820, method 800 checks whether the controller is in a locked state. If the controller is in an unlocked state, the attempt to change the controller is allowed to continue via step 830, and method 800 terminates. However, if method 800 encounters a locked state for controller 106, any attempt to change controller 106 is blocked in step 840, and an error is returned to operator station 116, thereby notifying the user of the attempted change to controller 106.
[0065] It may be advantageous to define certain words and phrases used throughout this patent document. The term “communication” and its derivatives encompass both direct and indirect communication. The terms “comprising” and “including” and their derivatives mean, but are not limited to, this. The term “or” is inclusive, meaning and / or. The phrase “associated with” and its derivatives may mean, including, contained within, interconnected with, contained, contained in, connected to or connected with, coupled to or coupled with, communicable with, cooperating with, interleaved, juxtaposed, proximate, combined with or combined with, having, possessing the properties of, having a relationship with or having a relationship with, etc. When used with a list of items, the phrase “at least one of” means that different combinations of one or more of the listed items may be used, and only one item in the list may be required. For example, “at least one of A, B, and C” includes any of the following combinations: A, B, C, A and B, A and C, B and C, and A and B and C.
[0066] The descriptions in this application should not be construed as implying that any particular element, step, or function is a fundamental or critical element that must be included within the scope of the claims. The scope of the subject matter protected by the patent is defined only by the permitted claims. Furthermore, none of the claims is intended to invoke 35 U.SC §112(f) with respect to any of the appended claims or claim elements, unless the exact words “means for…” or “steps for…” followed by a participle phrase identifying the function are used in a particular claim. The use of terms such as (but not limited to) “mechanism,” “module,” “device,” “unit,” “component,” “element,” “part,” “construct,” “device,” “machine,” “system,” or “controller” in the claims is understood to refer to structures known to a person skilled in the art, as further modified or enhanced by features of the claims themselves, and is not intended to invoke 35 U.SC §112(f).
[0067] While this disclosure has described certain embodiments and generally associated methods, variations and substitutions of these embodiments and methods will be apparent to those skilled in the art. Therefore, the foregoing description of exemplary embodiments does not limit or restrict this disclosure. Other changes, substitutions, and modifications are possible without departing from the spirit and scope of this disclosure as defined in the following claims.
Claims
1. A method for protecting configuration and firmware of legacy devices of an industrial process control and automation system and preventing changes to the configuration and firmware, the method comprising: reading a device index of the legacy device as a first state; executing, by a system, a monitoring program, the monitoring program configured to: determine whether the device index has been changed to another state other than the first state, and based on reading the device index, determine whether the another state corresponds to at least a locked state or an unlocked state, wherein the locked state is determined based on the device index representing a locked password, and wherein the unlocked state is determined based on the device index representing an unlocked password; placing, by the system, the legacy device in a hibernation state for a set time period based on at least determining that the another state does not correspond to at least the locked state or the unlocked state; in response to the set time period expiring, determining, based on reading the device index, whether the another state corresponds to at least the locked state or the unlocked state; and executing, by the system, an enforcement program that prevents changes to the configuration and firmware of the legacy device when the legacy device is in the locked state.
2. The method of claim 1, wherein the method further comprises releasing the legacy device from the locked state, the method comprising: when determining that the another state corresponds to the locked state, locking the legacy device from the unlocked state, wherein the locking of the legacy device comprises: executing the monitoring program that reads the locked password in the device index and places the legacy device in the locked state; and executing the enforcement program that prevents changes to configuration and firmware of the legacy device in the locked state; when determining that the another state corresponds to the unlocked state, releasing the legacy device from the locked state, wherein the releasing of the legacy device comprises: setting the unlocked password in the device index of the legacy device; executing the monitoring program to read the unlocked password and set the legacy device to the unlocked state; and when the legacy device is in the unlocked state, executing the enforcement program to allow changes to the configuration and firmware of the legacy device.
3. A system, the system comprising: a device index associated with a legacy device, the device index capable of being manipulated to enter a first state; and processing circuitry configured to execute a monitoring program, wherein the monitoring program is configured to: determine whether the device index has been changed to another state other than the first state; based on reading the device index, determine whether the another state corresponds to at least a locked state or an unlocked state, wherein the locked state is determined based on the device index representing a locked password, and wherein the unlocked state is determined based on the device index representing an unlocked password; placing the legacy device in a sleep state for a set time period based at least on determining that the other state does not correspond to at least the locked state or the unlocked state; in response to the set time period expiring, determining whether the other state corresponds to at least the locked state or the unlocked state based on reading the device index; and executing an enforcement program that prevents configuration and firmware changes to the legacy device in the locked state.
4. The system of claim 3, wherein the legacy device is locked from the unlocked state when it is determined that the other state corresponds to the locked state, wherein to lock the legacy device, the processing circuit is further configured to: execute the monitor program that reads the lock password in the device index and places the legacy device in the locked state; and execute the enforcement program that prevents configuration and firmware changes to the legacy device; and wherein the legacy device is released from the locked state by entering the unlock password in the device index, wherein the monitor program is configured to read the unlock password and place the legacy device in the unlocked state, thereby allowing the enforcement program to make configuration and firmware changes to the legacy device.