System and method for monitoring an automated system
A junction block with fixed generic rules addresses the unreliability and lack of versatility in existing monitoring systems by integrating into automated systems to detect and protect against cyberattacks and natural drifts, ensuring reliable and efficient monitoring and data integrity.
Patent Information
- Application Number
- FR2024006017
- Authority / Receiving Office
- FR · FR
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-06-07
- Publication Date
- 2025-12-12
AI Technical Summary
Existing monitoring systems for automated systems, such as those using deterministic dummy programmable logic controllers (DFPLCs), are unreliable due to vulnerability to cyberattacks and lack versatility, as they require specific programming for each PLC and assume the DFPLC is not vulnerable, which is not always the case.
A junction block with fixed generic rules, independent of any programming, is integrated into an automated system to monitor and protect against malicious acts and natural drifts by comparing input signals against universal physical laws, capable of detecting deviations and issuing alerts, with a head module for centralized data collection and analysis.
The system provides reliable and versatile protection against cyberattacks and natural degradation by intercepting and analyzing signals at the lowest level, minimizing data corruption and enabling precise visualization and rapid response to operational deviations.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
Title of the invention: System and method for monitoring an automated system. Technical field
[0001] The present invention relates to the monitoring and protection of an automated system against malfunctions. It finds, for example, particularly advantageous applications in cybersecurity, the Internet of Things, production optimization and maintenance (corrective, conditional and predictive) of an automated system, or real-time data traceability. PRINCIPAL OF THE TECHNOLOGY
[0002] In order to increase the productivity of an automated system, its responsiveness to operational disruptions must be improved. In particular, it is necessary to monitor potential operational deviations of this system. This requires access to the information circulating between the system's equipment and its control devices. Most approaches to detecting operational deviations are based on the assumption that control devices, programmable logic controllers (PLCs), physical linking elements between sensors or actuators, and digital networks offer reliable capabilities for providing the collected and aggregated information. However, in reality, PLCs are vulnerable.
[0003] US patent 11378929 B2, for example, describes a so-called "deterministic dummy" programmable logic controller (DFPLC) integrated into an industrial system, cloning a conventional programmable logic controller (PLC) and connected to a monitoring unit. The monitoring principle disclosed by US patent 11378929 B2 is thus based on a pair of identical "real" (PLC) and "dummy" (DFPLC) controllers. The monitoring unit is configured to compare the behaviors of the DFPLC dummy controller and the corresponding real PLC controller. In the event of a behavioral discrepancy, the monitoring unit issues an alert. This monitoring principle assumes that only the real PLC controller can fail, and that the second DFPLC dummy controller is not vulnerable to cyberattacks.
[0004] In the event of an attack or failure of the automated system, it is possible that the DFPLC dummy controller may also be altered or contaminated. This solution is therefore not completely reliable. Furthermore, the DFPLC is designed and programmed specifically according to the application of the monitored industrial system, in order to allow it to "disguise" itself among the industrial programmable logic controller(s). conventional. The DFPLC relies on deterministic programming and must be adapted or reprogrammed for each PLC to be cloned. Therefore, this solution is not versatile.
[0005] The present invention proposes to overcome, at least in part, the known drawbacks of monitoring systems for an automated system. In particular, an objective of the present invention is to provide a monitoring system that can be integrated into an existing automated system and that is reliable and / or versatile. SUMMARY
[0006] To achieve this objective, according to a first aspect of the invention, a junction block is provided for monitoring an automated system, the automated system comprising at least one controller configured to control at least one physical component by exchanging data signals with the at least one physical component, the junction block being configured to be connected to the at least one controller, the junction block comprising an electronic board. The electronic board incorporates a specification of fixed generic rules, based on physical processes relating to the normal operation of the at least one controller and the at least one physical component, the generic rules being independent of any programming of the at least one controller.
[0007] This junction block, incorporating a specification of fixed generic rules, is a component ready to be integrated into an automated system, whether already installed or not, without the need for programming specific to the automated system's application. Indeed, thanks to the specification of generic rules that are fixed and applicable to any existing or new automated system, the junction block makes it possible to protect a wide variety of pre-actuators and actuators available on the market. Whether or not an actuator complies with the generic rules during its operation allows the junction block to monitor and / or detect dangerous control signals such as malicious acts (or cyberattacks), degradation, or natural drifts of a physical component, for example, when the junction block is associated with sensors.An automated system incorporating such a junction block can be advantageously protected against these dangerous control signals. The generic rules are typically based on physical laws to which any type of actuator and / or pre-actuator is subject.
[0008] A second aspect of the invention relates to a monitoring system for an automated system, comprising at least one junction block, the monitoring system further comprising a head module configured to: • be connected to at least one junction block, and • receive in real time at least one alert issued by the junction block when at least one input signal collected by the junction block is not in accordance with generic rules and export at least one alert to a third-party system, or • receive in real time a plurality of input signals collected by a plurality of junction blocks, and issue at least one alert if at least one of said input signals violates at least one detection rule integrated into the head module.
[0009] Beyond the monitoring and alert functions in the presence of malicious use or deviant operation of the pre-actuators and / or actuators, the system comprising a head module connected to at least one junction block offers a real capacity for collecting and disseminating information collected at the lowest level - close to the physical component - to a higher level.
[0010] A third aspect of the invention relates to a method for monitoring an automated system using the monitoring system, comprising: • a collection by at least one junction block of at least one input signal emitted by at least one controller and / or at least one physical component, and • a real-time assessment of the conformity of at least one input signal with respect to generic rules.
[0011] This method minimizes the risk of intentional or unintentional alteration of data transmitted within the automated system by collecting, at the lowest level of the automated system's architecture, via the junction block, all data signals exchanged between the controller and the physical component and comparing them to generic rules. Furthermore, this method typically allows for the acquisition of this data in raw form, along with all associated fields such as timestamping, thus enabling precise visualization of the signals received by the pre-actuators, actuators, and sensors. BRIEF DESCRIPTION OF THE FIGURES
[0012] The aims, objects, features and advantages of the invention will become clearer from the detailed description of an embodiment thereof, which is illustrated by the following accompanying drawings in which:
[0013] [Fig.1] Fig.1 schematically illustrates a monitoring system comprising a junction block according to an embodiment of the present invention, integrated into an automated system.
[0014] [Fig.2] Fig.2 schematically illustrates a monitoring system comprising a plurality of junction blocks according to an embodiment of the present invention, integrated into an automated system.
[0015] [Fig.3] Fig.3 represents a flowchart illustrating steps in the process of monitoring an automated system using a monitoring system according to an example of an embodiment of the present invention.
[0016] The drawings are given by way of example and are not limiting of the invention. They constitute schematic representations of principle intended to facilitate understanding of the invention and are not necessarily to scale with practical applications. DETAILED DESCRIPTION
[0017] Before proceeding with a detailed review of embodiments of the invention, optional features that may be used in combination or alternatively are listed below:
[0018] According to one example, the junction block is configured to: • be connected in series between at least one controller and at least one physical component, • collect at least one input signal emitted by at least one controller and / or at least one physical component, and • evaluate in real time the conformity of at least one input signal with respect to generic rules.
[0019] The junction block, by connecting it between the physical inputs and outputs of a physical component (e.g., a pre-actuator, an actuator, or a sensor) and a controller (e.g., a programmable logic controller, a speed controller, etc.), allows the data exchanged between the physical component and its controller to be retrieved at the lowest level of the control architecture. This makes it possible to visualize the raw data exchanged between a conventional programmable logic controller and a pre-actuator, actuator, or sensor of the monitored industrial system. This minimizes the risk of data corruption and improves monitoring reliability.Furthermore, by applying generic rules in real time and on each collected signal, the junction block makes it possible to detect any suspicious signal originating, for example, from a natural drift, and / or any risk of modification by a cyber attacker at the lowest level of the automated system, whether at the level of the programmable logic controller, the pre-actuators or the actuators.
[0020] According to one example, the junction block is configured to issue at least one real-time alert when at least one input signal does not conform to the generic rules.
[0021] The junction block makes it possible to signal any detection of suspicious signals not conforming to generic rules by sending an alert that can be communicated to the user in real time, allowing them to act quickly to avoid degradation of the automated system or a drop in industrial production.
[0022] According to one example, the junction block can incorporate artificial intelligence.
[0023] According to one example, the junction block can include at least one software program.
[0024] According to one example, the number of generic rules is finite.
[0025] According to one example, the junction block comprises a housing encapsulating the card electronic, the housing being made of an electrically insulating material. As an example, the housing is configured to allow the junction block to be installed on DIN rails.
[0026] The housing encapsulating the various components of the terminal block, being compatible with standardized mounting profiles, allows the terminal block to be integrated into existing automated systems by installing the terminal blocks on DIN rails widely used for the mechanical support of electrical equipment (such as circuit breakers) and their accessories. This terminal block is therefore non-intrusive and can be installed in place of existing terminal blocks. The housing also provides galvanic isolation, which notably prevents the terminal block from interfering with the automated system.
[0027] According to one example, the monitoring system is configured to interrupt the data signals exchanged between at least one controller and at least one physical component, when at least one input signal collected by at least one junction block does not conform to the generic rules of at least one junction block.
[0028] This ability to interrupt the control signals of the pre-actuators or actuators protects them in the event of degrading or destructive control. This protection mode can be activated or deactivated as needed.
[0029] According to one example, the head module further includes a memory and is configured to store at least one alert and at least one input signal in a data format in the memory.
[0030] According to one example, the head module is encapsulated in a housing made of an electrically insulating material, the housing being configured to allow the head module to be installed on DIN rails. The advantages described above in the case of the terminal block are applicable to such a head module.
[0031] According to one example, the head module is connected to at least one junction block through a bus connector compatible with DIN rails.
[0032] These connectors are designed to be mounted directly between terminal blocks mounted on standard DIN rails and are commonly used to distribute power electrical. These connectors typically allow the distribution of power from the head module to all junction blocks connected to the head module.
[0033] According to one example, the head module is configured to communicate at least one input signal which is the origin of at least one alert, in a data format, to the third-party system.
[0034] This allows the data collected by the head module to be transmitted securely, without disrupting existing industrial networks, to third-party systems such as a "cloud" type system, "big data", SCADA (acronym for "Supervisory Control and Data Acquisition"), SIEM (acronym for "Security Information and Event Management") or mobile applications.
[0035] According to one example, the communication of the data stored in the memory of the head module to at least one third-party system is done through a wireless or wired network.
[0036] According to one example, the head module includes a microprocessor configured to correlate the data exchanged between at least one controller and at least one physical component, and to transmit this correlated data to an artificial intelligence algorithm executable by the microprocessor and / or the third-party system, the artificial intelligence algorithm being configured to detect small deviations in the operation of the automated system.
[0037] This artificial intelligence-based algorithm, using data collected from all junction blocks and centralized in the head module, enables more precise diagnosis of malfunctions in the automated system and allows for the prediction or detection, for example, at the scale of a programmable logic controller (PLC), of small desynchronizations that might go unnoticed but could translate, at the scale of all PLCs, into a sophisticated and sophisticated cyberattack attempt. Conversely, or as a complement, this allows for the elimination of potential false positives. The reliability of attack detection is improved.
[0038] According to one example, the head module further includes a clock. The clock provides a precise and continuous time reference, even in the absence of a power supply. A battery can be integrated into the head module. This allows, for example, the timestamping of data acquired at each of the junction blocks.
[0039] According to one example, the method of monitoring the automated system includes a real-time emission of at least one alert by at least one junction block to the head module, when at least one input signal is evaluated as not conforming to the generic rules.
[0040] According to one example, the method of monitoring the automated system includes a real-time transmission of at least one input signal collected by at least one junction block, to the head module.
[0041] The collection by the head module of all the data signals taken from the junction blocks allows the entire data to be centralized at the level of the head module, which then allows them to be correlated and / or analyzed.
[0042] According to one example, the method further includes real-time storage of at least one alert and at least one input signal in the form of data in memory.
[0043] According to one example, the method of monitoring an automated system further includes synchronization using the clock of the head module, between at least one junction block and the head module before the collection by at least one junction block of at least one input signal.
[0044] According to one example, the method of monitoring an automated system further includes an interruption of the data signals exchanged between the controller and at least one physical component, when at least one input signal is evaluated as not conforming to the generic rules by at least one junction block.
[0045] According to one example, the method of monitoring an automated system further includes communication by the head module of at least one alert and at least one collected input signal, in a data format to at least one third-party system.
[0046] Except in cases of incompatibility, it is understood that all the above optional features can be combined to form an embodiment that is not necessarily illustrated or described. Such an embodiment is obviously not excluded from the invention. The features and advantages of the junction block according to the invention can be applied, mutatis mutandis, to the features and advantages of the system or method according to the invention, and vice versa.
[0047] It is specified that, within the framework of the present invention, the steps of the process are understood in the broad sense of carrying out a part of the process and may optionally be carried out in several substeps. Several embodiments of the invention implementing successive steps of the monitoring process are described below. Unless explicitly stated, the adjective "successive" does not necessarily imply, although this is generally preferred, that the steps follow each other immediately; intermediate steps may separate them.
[0048] Furthermore, the term "step" does not necessarily mean that the actions carried out during a step are simultaneous or immediately successive. Certain actions of a first step may, in particular, be followed by actions related to a different step, and other actions from the first step may be repeated later. Thus, The term step does not necessarily refer to unitary actions that are inseparable in time and in the sequence of phases of the process.
[0049] Normal operation of a controller or physical component is defined as operation characterized by stable and consistent performance, without significant errors or anomalies. In normal operation of the automated system, each step of the automated process proceeds smoothly and efficiently. Indicators of normal operation may include, for example: sensor response time, measurement accuracy, the speed at which an actuator performs an action, voltage or current thresholds or ranges, etc. These indicators are applicable to any automated system.
[0050] A controller of an automated system is understood to be a control unit configured to regulate one or more operations of the automated system based on input data and predefined parameters. The control unit can thus authorize or prevent certain actions of the system components in order to achieve the desired objectives.
[0051] A physical component of an automated system is understood to be any tangible element used to perform specific functions within the system. These components may be robots, electronic devices, sensors, actuators, measuring instruments, pipes, tanks, conveyors, lifting equipment, electric motors, pneumatic or hydraulic cylinders, valves, etc.
[0052] A DIN rail is a standardized support profile, generally metallic, widely used for the mechanical support of electrical equipment (such as circuit breakers) and their accessories. DIN is the acronym for "Deutsches Institut für Normung," the organization that originated this standard.
[0053] Figures 1 and 2 do not realistically reproduce the junction block 30, the monitoring system 1 and the automated system 2. For the sake of simplification, these figures illustrate the different elements of the monitoring system 1 and the automated system 2 schematically as functional blocks, and the connections between the different elements as arrows.
[0054] As illustrated in [Fig. 1], an automated system 2 comprises at least one controller 10 and at least one physical component 20. In the absence of the monitoring system 1, the physical component 20 can be directly connected to the controller 10. This controller 10 exchanges data signals with the physical component 20, which enable the physical component 20 to be controlled to perform an action, which may or may not be physical. The controller 10 can be, for example, a programmable logic controller (PLC). The physical component 20 can be an actuator that receives a control signal from the PLC to perform a certain physical action. or mechanical in response to the control signal. The PLC can also be connected to a sensor, which sends back, for example, a feedback signal to the PLC to provide information on the state of the actuator.
[0055] The data signals exchanged between the controller 10 and the physical components 20 can be intercepted or manipulated by a cyber attacker. In order to monitor these signals exchanged between the controller 10 and the physical components 20, a junction block 30 is integrated into the automated system 2, between the controller 10 and the physical components 20.
[0056] The junction block 30 is configured to be connected to the inputs / outputs of the controller 10. The junction block 30 can also be connected to the inputs / outputs of the physical component 20. The junction block 30 includes an electronic board 31. The electronic board 31 may integrate a microprocessor and a program installed at the factory. The electronic board 31 incorporates, in particular, a specification of generic rules R. These generic rules R are fixed and are based on physical processes relating to the normal operation of the controller 10 and the physical components 20. In other words, these generic rules R describe an expected and consistent evolution of the physical quantities governing the operation of the automated system 2. The generic rules R, based on universal physical processes, are applicable to any automated system 2, whether or not it is already installed and implemented.These generic rules R are thus independent of controller programming 10.
[0057] As illustrated in [Fig. 1], the junction block 30 can be connected in series between the controller 10 and the physical component(s) 20. The intermediate position of the junction block 30 allows this junction block 30 to intercept all the signals exchanged between the controller 10 and the physical component(s) 20. The junction block 20 can thus receive and collect an input signal I emitted by the controller 10 to the physical component 20 and / or by the physical component 20 to the controller 10.
[0058] By applying the generic rules R to each of the input signals I, the junction block 30 evaluates the input signal I in real time against the generic rules R. If the input signal conforms and is consistent with the generic rules R, the junction block 30 acts passively and allows the signal to flow to the controller 10 or the physical component 20. Conversely, if the input signal I does not conform to the generic rules R, or is inconsistent with them, the junction block 30 issues at least one alert A. The junction block 30 can be configured to allow this suspect signal to pass, or it can be configured to interrupt this signal.
[0059] The junction block 30 described above can be integrated into a monitoring system 1. The monitoring system 1 further comprises a head module 40, referred to as the "master," connected to at least one junction block 30, referred to as the "slave." The module The head module 40 is configured to be connected to the junction block 30, as illustrated in [Fig.1], which allows it to collect in real time the signals I entering the junction block 30, whether or not they conform to the generic rules R. This data can come from several junction blocks 30, and can thus be centralized in the head module 40.
[0060] The head module 40 may include a microcontroller and a memory 41, and may be configured to perform at least two tasks, typically the export of centralized data and / or high-level detection. The head module 40 may securely store the collected data in its memory 41. The head module 40 may further include a data communication interface via a network specific to the monitoring system 1. Preferably, this network is wireless to ensure the non-intrusive nature of the monitoring system 1. The data collected by the head module 40, in particular the input signals I that trigger the alerts A, can thus be securely communicated to a third-party system 3, as illustrated in [Fig. 1].
[0061] When the data export mode is activated, the head module 40 receives in real time the alerts A issued by at least one junction block 30 when an input signal I collected by the junction block 30 does not conform to the generic rules R. The head module 40 can export this alert A to the tier system 3 via a secure communication protocol.
[0062] The tier 3 system may correspond to a cloud-type system (or cloud computing), big data (or massive data), SCADA (“Supervisory Control and Data Acquisition” or Control and Data Acquisition System), SIEM (“Security Information and Event Management” or Security Information and Event Management) or mobile applications.
[0063] When the high-level detection mode is activated, the head module 40 can receive in real time a plurality of input signals I collected by a plurality of junction blocks 30. This "field" data from the various junction blocks 30 can be cross-correlated using the microprocessor of the head module 40. This makes it possible to generate detection rules in the form of logical equations. The head module 40 can thus be configured to issue at least one alert A if one of the input signals I violates a generated detection rule.
[0064] The head module 40 can also be configured to correlate the data exchanged between the controller 10 and the physical component 20. This correlated data can be transmitted to an artificial intelligence algorithm executable by the microprocessor and / or the third-party system 3. This artificial intelligence algorithm is configured to detect small malfunctions of the automated system 2. It allows for more precise diagnosis of the malfunctions of the Automated system 2 and to predict or detect, for example, small desynchronizations at the scale of an industrial programmable logic controller (PLC). These minor desynchronizations, which may go unnoticed in isolation, can correspond to a signature of a large-scale cyberattack aimed at disrupting all PLCs. The use of an artificial intelligence algorithm makes it possible, for example, to improve the detection of subtle and sophisticated attacks. This also makes it possible to eliminate potential false positives. The reliability of attack detection is improved.
[0065] The monitoring system 1 can be configured to protect the physical component 20 against any intentional or unintentional threat, or against natural degradation. In this protection configuration, the junction block 30 can be programmed to interrupt the data signals exchanged between the controller 10 and the physical component 20 when it detects an input signal I that does not conform to the generic rules R. This feature makes it possible to protect, for example, pre-actuators or actuators by interrupting the transmission of suspicious control signals emitted by the programmable logic controller (PLC). This prevents the actuators from executing these destructive or degrading commands, thus ensuring their safety. This protection feature is configurable and can be enabled or disabled.
[0066] Each of the junction blocks 30 and the head module 40 is preferably encapsulated in a housing made of a material that provides galvanic isolation of the internal components. This galvanic isolation ensures non-intrusive behavior of the junction block 30, particularly when integrated into an automated system 2 that is already installed and operational.
[0067] The housing can be configured to allow the installation of the terminal block 30 and the head module 40 on DIN rails. The housing can thus be equipped with mounting pins compatible with a DIN rail. These DIN rails are widely used for the mechanical support of electrical equipment because they allow for the compact connection of multiple devices, reducing manual wiring. The terminal block 30, isolated in such a housing, can therefore replace a conventional terminal block installed on a DIN rail between a controller 10 and a physical component 20, without disrupting the operation and positioning of the controller 10 and the physical component 20. The terminal block 30 is thus non-intrusive.
[0068] The head module 40 can be connected to the junction block 30 using a DIN rail compatible bus connector B. The head module 40 can collect the data read from the junction block 30 through the connector bus B. This data collection can preferably be done using an I2C protocol (acronym for "Inter Integrated Circuit").
[0069] As illustrated in [Fig.2], by way of example, the head module 40 can be connected to several terminal blocks 30 through the bus connector B, and can communicate via the I2C protocol with each of these terminal blocks 30. One head module can be connected to sixteen terminal blocks 30 for example.
[0070] The head module 40 can be powered by a 24 V DC supply. The power supply to the head module 40 can be provided via a standard wired connection from the main power supply of the electrical cabinet of the automated system 2.
[0071] The bus connector B allows the power supply from the head module 40 to be distributed to all the terminal blocks 30 connected to the head module 40. Thus, only the head module 40 requires additional space on the DIN rail and access to a power supply. Alternatively, or in addition, the head module 40 can be powered by a rechargeable battery.
[0072] The head module 40 may include a clock 42. This clock 42 makes it possible to provide a precise and continuous time reference, even in the absence of power supply, which allows the real-time timestamping of the data acquired at each of the junction blocks 30.
[0073] Each junction block 30 may further include one or more relays.
[0074] The memory 41 of the head module 40 can be of the Micro SD type. It is Encryption is preferred to secure the stored data.
[0075] The monitoring system 1 described above thus enables the acquisition, monitoring, protection, and dissemination of data collected between the controller 10 and the physical components 20. By connecting between the physical inputs and outputs of the controller 10 and the physical components 20, the monitoring system 1 allows data to be collected at the lowest level of the control architecture, without disrupting the existing or planned installation. This improves the reliability and user-friendliness of the monitoring system.
[0076] Thanks to the specification of generic rules R, the monitoring system 1 typically makes it possible to protect all types of pre-actuators and actuators on the market. The conformity of the collected signals with the generic rules R allows the monitoring system 1 to detect and / or protect the installation or automated system with respect to dangerous control signals.
[0077] Advantageously, the monitoring system 1 allows for non-intrusive acquisition of signal flows passing between the control system and the physical process. It also allows for the discrimination of operational deviations according to a suspicion of malicious acts (i.e. cyber-attacks) or natural degradation (i.e. failure of a physical component).
[0078] For security reasons, the head module 40 is preferably not user-reprogrammable. It may only have "push" communication functions. Furthermore, the configuration of the head module 40 only occurs when the monitoring system 1 is commissioned, which significantly minimizes intentional or unintentional manipulation of the monitoring system 1. Preferably, the head module 40 and the terminal blocks 30 are free of operating systems.
[0079] The method of monitoring an automated system 2, using the monitoring system 1, is now described with reference to [Fig.3] which represents a flowchart illustrating steps of the process.
[0080] As illustrated in [Fig.3], the method includes a collection 102 by the junction block 30, connected between the controller 10 and the physical component 20, of an input signal I emitted by the controller 10 and / or the physical component 20. The method further includes a real-time evaluation 104 of the conformity of each of the input signals I with respect to the generic rules R.
[0081] Generic rules R may include, by way of non-limiting example, a first rule called a frequency rule, which can be applied to on / off (digital) outputs. This frequency rule makes it possible to detect non-compliance with the response times of a pre-actuator. Violation of this frequency rule can lead to damage to the pre-actuator and the actuation chain in general. As another example, generic rules R may include a second rule relating to a continuous variation of a setpoint. In the context of a setpoint in control (for example, speed, torque, etc.), the setpoint(s) are not assumed to vary continuously over time. A PLC program will typically set fixed setpoints, depending on the modes (for example, rotate at 5000 rpm in a preparation mode and then at 10000 rpm in a normal production mode).In this context, the second rule may concern the detection of a continuous positive or negative drift of the setpoint (example of Stuxnet).
[0082] According to another example, the generic rules R may include a third rule relating to the voltage threshold of a setpoint. This third rule makes it possible to protect an installation from a setpoint exceeding the capabilities of a functional chain (i.e., requesting a rotational speed higher than the capabilities of a motor / effector). The generic rules R may also include a fourth rule on the maximum frequency of a PWM (Pulse Width Modulation) setpoint. This fourth rule, like the third rule, makes it possible to protect an installation against a setpoint exceeding the capabilities of a functional chain, the setpoint being a PWM setpoint.
[0083] When the input signal I conforms to the generic rules R, and therefore to normal and risk-free operation of the automated system 2, the junction block 30 can act passively by allowing the signal I to pass to the controller 10 or the physical component 20.
[0084] When the input signal I is evaluated as not conforming to one or more generic rules R, the method includes the transmission 105 of at least one real-time alert A by the junction block 30 to the head module 40. Thus, when one or more generic rules R are violated, the junction block 30 reacts by transmitting at least one alert. Protective measures can then be implemented.
[0085] The method further includes a real-time transmission 107 of the input signals I passing through the junction block(s) 30, as well as the alerts A, to the head module 40. This transmission 107 of signals I allows the head module 40 to centralize all the raw information collected from the various junction blocks 30, so that it can be exported or stored. Therefore, the method may include storing the alerts A and the input signals I in a data format in the memory 41 of the head module 40. Since the acquired data is raw data, it represents an exact picture of the signals received by the sensors and actuators of the automated system 2. This transmission 107 of field data can also be used to exploit this data for traceability or maintenance purposes, in addition to the monitoring function of the automated system 2.
[0086] The method may also include communicating this data 109 to a tier 3 system, without disrupting any existing network. This also allows the data to be stored by the tier 3 system, such as a cloud storage service. The acquired data can also be disseminated to a SIEM (Security Information and Event Management) system for diagnostic analysis, predictive maintenance, and the detection of cyberattacks using tools based, for example, on artificial intelligence. Depending on the choice of tier 3 system, the user of the monitoring system 1 can configure the head module 40 by adding one or more addresses.
[0087] The method may further include a synchronization 101 using the clock 42 of the head module 40, between the junction blocks 30 and the head module 40 before the collection 102 of the input signals I by the junction blocks 30.
[0088] When the input signal I is evaluated as not conforming to the generic rules R, the method may also include an interrupt 106 of the signals exchanged between the controller 10 and the physical component 20, particularly when the physical component is an actuator intended to perform a physical action. These erroneous or altered signals I can lead to the degradation or destruction of the actuator. This interrupt 106, which remains optional and at the customer's discretion, prevents this degradation or destruction, thus protecting the operation of the entire automated system 2. This interrupt can be configured and activated as needed.
[0089] The invention is not limited to the embodiments described above. Various specific examples of the monitoring system of an automated system and the associated method have been described. Other embodiments are possible, for example, by combining features described above, without departing from the principle of the present invention. Furthermore, the features described with respect to one aspect of the invention can be combined with another aspect of the invention.
Claims
Demands
1. Junction block (30) for monitoring an automated system (2), said automated system (2) comprising at least one controller (10) configured to control at least one physical component (20) by exchanging data signals with the at least one physical component (20), said junction block (30) being configured to be connected to the at least one controller (10), said junction block (30) comprising an electronic card (31), said junction block (30) being characterized in that the electronic card (31) incorporates a specification of fixed generic rules (R) based on physical processes relating to a normal operation of the at least one controller (10) and the at least one physical component (20), the generic rules (R) being independent of a programming of the at least one controller (10).
2. Junction block (30) according to the preceding claim, configured to: • be connected in series between at least one controller (10) and at least one physical component (20), • collect at least one input signal (I) emitted by at least one controller (10) and / or at least one physical component (20), and • evaluate in real time the conformity of at least one input signal (I) with respect to the generic rules (R).
3. Junction block (30) according to the preceding claim, configured to issue in real time at least one alert (A) when at least one input signal (I) does not conform to the generic rules (R).
4. Junction block (30) according to any one of the preceding claims, comprising a housing encapsulating the electronic board (31), the housing being based on an electrically insulating material and configured to allow installation of the junction block (30) on DIN rails.
5. A monitoring system (1) for an automated system (2), comprising at least one junction block (30) according to any one of the preceding claims, said monitoring system (1) further comprising a head module (40) configured to: • be connected to at least one junction block (30), and • receive in real time at least one alert (A) issued by the junction block (30) when at least one input signal (I) collected by the junction block (30) does not conform to the generic rules (R) and export to a third-party system at least one alert (A), or • receive in real time a plurality of input signals (I) collected by a plurality of junction blocks (30), and issue at least one alert (A) if at least one of said input signals (I) contravenes at least one detection rule integrated into the head module (40).
6. Monitoring system (1) according to the preceding claim, configured to interrupt the data signals exchanged between at least one controller (10) and at least one physical component (20), when at least one input signal (I) collected by at least one junction block (30) does not conform to the generic rules (R) of said at least one junction block (30).
7. Monitoring system (1) according to any one of the two preceding claims, wherein the head module (40) is configured to communicate at least one input signal (I) which originates at least one alert (A), in a data format, to the third-party system (3).
8. Monitoring system (1) according to any one of claims 5 to 7, wherein the head module (40) comprises a microprocessor configured to correlate the data exchanged between at least one controller (10) and at least one physical component (20), and to transmit this correlated data to an artificial intelligence algorithm executable by the microprocessor and / or the third-party system (3), said artificial intelligence algorithm being configured to detect small deviations in the operation of the automated system (2).
9. Monitoring system (1) according to any one of claims 5 to 8, wherein the head module (40) includes a clock (42).
10. A method for monitoring an automated system (2) using the monitoring system (1) according to any one of claims 5 to 9, comprising: • a collection (102) by at least one junction block (30) of at least one input signal (I) emitted by at least one controller (10) and / or at least one physical component (20), and • a real-time evaluation (104) of the conformity of at least one input signal (I) with the generic rules (R).
11. A method for monitoring the automated system (2) according to the preceding claim, further comprising: • a real-time emission (105) of at least one alert (A) by at least one junction block (30) to the head module (40), when at least one input signal (I) is evaluated as not conforming to the generic rules (R), or • a real-time transmission (107) of at least one input signal (I) collected by at least one junction block (30), to the head module (40).
12. Method of monitoring an automated system (2) according to any one of the two preceding claims, further comprising a synchronization (101) using the clock (42) of the head module (40), between at least one junction block (30) and the head module (40) before the collection (102) by at least one junction block (30) of at least one input signal (I).
13. Method of monitoring an automated system (2) according to any one of claims 10 to 12, further comprising an interruption (106) of the data signals exchanged between the controller (10) and at least one physical component (20), when at least one input signal (I) is evaluated as non-compliant with the generic rules (R) by at least one junction block (30).
14. Method of monitoring an automated system (2) according to any one of claims 10 to 13, further comprising communication (109) by the head module (40) of at least one alert (A) and at least one input signal (I) collected, in a data format to at least one third-party system (3).
Citation Information
Patent Citations
Threat detection system for industrial controllers
US11378929B2
Machinery Condition Assessment Module
US20070073521A1
Systems and methods for displaying a probe gap value on a sensor system
US20150168181A1