Systems and Methods for Blockchain-Based Industrial Automation

A blockchain-based common runtime with a unikernel for PLCs addresses security vulnerabilities in industrial automation systems, ensuring secure and reliable operations with reduced computational costs and enhanced trust.

JP2025522639AActive Publication Date: 2025-07-15MITSUBISHI ELECTRIC CORP
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
JP2025514882
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2022-06-27
Filing Date
2023-03-09
Publication Date
2025-07-15
Estimated Expiration
2043-03-09

AI Technical Summary

Technical Problem

Industrial automation systems face security vulnerabilities and operational interruptions due to insecure interfaces with external networks, particularly in critical industries, necessitating a secure and reliable connection mechanism.

Method used

Implementing a blockchain-based common runtime for programmable logic controllers (PLCs) using a blockchain-integrated unikernel to ensure secure, reliable, and auditable operations, with a lightweight client that verifies updates and commands through a permissioned blockchain network.

Benefits of technology

Provides secure, reliable, and fault-tolerant industrial automation by ensuring integrity and immutability of operations, reducing computational costs, and enhancing trust and transparency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025522639000001_ABST
    Figure 2025522639000001_ABST
Patent Text Reader

Abstract

A method and system for blockchain-based monitoring and management of an industrial automation system are provided. The industrial automation system comprises a blockchain-based common runtime for a programmable logic controller (PLC) used in the industrial automation system, in the form of a blockchain-integrated unikernel for the PLC. The unikernel is configured to provide functions related to, among other things, security checks available with blockchain technology, an immutable audit trail of operations within the industrial automation system, reliable remote updates of industrial firmware by authenticating updates through the blockchain, and an automated integrity check of controller functions by comparison to the blockchain.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure generally relates to industrial systems, and more specifically, to methods and systems for implementing blockchain-based automation in industrial systems.

Background Art

[0002] An industrial system is an environment consisting of several components related to each other by industrial processes, such as machines, tools, field devices, personnel, support equipment, raw materials, products, etc. Industrial processes are related to the control, production, transportation, monitoring, operation, maintenance, and testing of machinery and equipment in the industrial environment for the purpose of achieving industrial goals. Industrial goals can be related to product manufacturing, product transportation, energy generation, process control, process operation, product transportation, etc. Many of these industrial goals and processes are automated using computing devices in modern industrial automation systems. Therefore, industrial automation systems include the use of computing devices to operate various machines and processes in industrial systems in order to reduce human intervention and increase the efficiency of repetitive operations by automating them using computing. Industrial automation has recently been used in most industries, such as the oil industry, FMCG sector, textile industry, manufacturing or production plants, chemical plants, pharmaceutical industry, paper industry, etc.

[0003] In these industries, industrial automation includes the automation of process control and machine control functions performed using a series of computing devices. The processes and controls are related to various types of equipment existing in the industrial world, and such equipment includes one or a combination of industrial or field devices such as sensors, actuators, valves, pumps, pipes, mechanical and tools, plant control equipment, temperature and humidity control equipment, logistics and transportation equipment, etc. Each type of equipment performs functions that form an industrial process. Such industrial processes require control and monitoring, which are performed using special computing devices used in the industry. One such type of device is the programmable logic controller (PLC).

[0004] A PLC is an industrial digital computer used for controlling manufacturing and plant control processes. A PLC generally consists of components such as a CPU module, I / O modules, and a backplane. The CPU module consists of a central processing unit (CPU), read-only memory (ROM), and random access memory (RAM). The CPU is a computing unit that executes computer instructions constituted by a computer program and an operating system. ROM is a type of non-volatile memory that can store its contents even when power is interrupted. This is in contrast to RAM, whose contents are lost when the power is turned off. The ROM in a PLC is generally used to store the OS and its related states. This is due to the requirements of industrial applications where power interruptions occur more frequently, and industrial processes need to resume operations from where they were interrupted. However, since restarting does not flush the system state, this can also cause security risks. Additionally, the I / O modules are components that enable the PLC to interface with other devices including, but not limited to, sensors, switches, network connections, and other PLCs. Therefore, the I / O modules enable modularization of functions in the PLC. In addition to this, the backplane of the PLC is a bus that enables communication between the CPU and the I / O modules.

[0005] Unlike commercial computers in that a PLC is a highly durable hard real-time system, for the system to be considered to be operating correctly, the output in response to an input must be generated within a limited time. This is why a PLC is an essential component of the control layer in an industrial automation system. Therefore, the efficient operation of a PLC is a direct parameter for realizing an efficient industrial automation solution. At the same time, the secure operation of a PLC is important for ensuring smooth, reliable, and error-free operation of both highly important and less important industrial functions.

[0006] In some industrial automation systems, the PLC is further connected to a second-level computing device that provides an interface for the PLC to connect to the external world. Such a connection is advantageous for providing better means for efficient monitoring, analysis of industrial processes, and collaboration between or within industries. However, at the same time, due to such interfacing, the industrial system is exposed to many security vulnerabilities, threats, attempts at tampering, and scenarios where the entire industrial process is interrupted. This can lead to very serious consequences, especially in critical industries such as petrochemicals, energy, and power plants. Therefore, it is desirable to provide a secure and reliable interface for the industrial automation system to connect to the external world.

[0007] Therefore, there is a need for an efficient system that controls the operation of various processes and devices in an industrial automation system while providing security and smooth operation of the industrial process.

Summary of the Invention

[0008] In recent years, blockchain technology has attracted great attention as one of the safest and most reliable computing and networking technologies due to its decentralized architecture and reliance on strong trust and security mechanisms. A blockchain network represents a digital ledger that is a record of transactions stored on computers. Transactions represent changes in the state of the system. Therefore, the digital ledger represents the state of systems such as financial systems, industrial systems, medical systems, and educational systems.

[0009] The digital ledger can be implemented in a centralized system, which records all transactions and stores changes to the record without generating an audit trail of the changes made by the centralized system, even if the records it has do not match those of another system. Another way is a non - centralized or distributed approach that can record transactions and implement a way to determine consensus among multiple systems. This is useful for deterring the digital ledger from being changed in a way that a particular system with a distributed system behaves selfishly and impairs the trust of the distributed system. This itself can enhance the user's trust in the distributed system and can be useful for that reason. The blockchain network is based on such a non - centralized digital ledger system.

[0010] A blockchain is an append - only data structure consisting of blocks linked to each other using a linked list structure, etc. A block is a container for digital information and consists of a header, metadata, and a list of transactions. The header and metadata can include information about the software version, cryptographic hashes used to compress the data volume for storage, timestamps, etc. A transaction is a list of all transactions of digital tokens and may be hashed to reduce the data volume for storage. A block lists all transactions from one user to another. Transactions between users are realized through transactions between the corresponding digital addresses of the users.

[0011] Transactions in a distributed ledger are mostly realized using two models: the transaction output (UTXO) model and the account model. In the UTXO model, a transaction has inputs and outputs. In the account model, a transaction is a message, i.e., a list of key-value pairs. One difference between the UTXO model and the account model is that the UTXO model is stateless and the system state has to be constructed from the genesis block (the starting block). The account model is more flexible than the UTXO model but is more expensive in terms of computational requirements because it is more difficult to prove the system's validity. Therefore, computing requirements can be measured from the perspective of computing resources such as power, processing capacity, storage, and operating system requirements.

[0012] Operating systems generally follow two architectures: the monolithic kernel and the unikernel. A monolithic kernel is an operating system where a high-level virtual interface known as a system call is provided as an API on top of the underlying computer hardware. The monolithic kernel has two purposes: to free programmers from having to worry about the low-level details of the underlying hardware and to provide security to the system by ensuring that processes running on the kernel do not interfere with other processes or the kernel itself. Examples of monolithic kernels include major operating systems such as Linux and OpenBSD. In contrast, a unikernel is a special machine image where applications are linked against the necessary kernel functions in the form of libraries. Examples of unikernels include MirageOS, u-root, and the Linux Kernel Library (LKL). Due to its special nature, the unikernel is lighter and more performant than the monolithic kernel.

[0013] Some embodiments are based on the recognition that the unikernel provides a function for implementing application-specific programming and logic, and using this function, a lightweight blockchain-integrated client can be realized. Therefore, lightweight clients can be associated with application-oriented computing systems with limited processing and storage capabilities, such as dedicated computing devices used in industrial automation systems, rather than computing-oriented ones. One such type of dedicated computing device described above is a PLC.

[0014] Some embodiments are based on the recognition that since the blockchain is one of the most secure computing technologies available today, the security requirements of a PLC as described above can be met by integrating the PLC with the blockchain. However, one drawback of blockchain-based systems is their high computing and storage requirements.

[0015] Some embodiments are further based on the recognition that by integrating the unikernel into a blockchain-based system to realize a lightweight client such as a PLC, the limitations of the blockchain-based system can be overcome.

[0016] Therefore, some embodiments disclosed herein provide an industrial automation system with a blockchain-based common runtime for PLCs by introducing a blockchain-integrated unikernel for PLCs. An important recognition when realizing such an industrial automation system solution is that a common blockchain integration layer can protect the privacy and intellectual property of various users in the industrial automation system and also guarantee an immutable audit trail of operations within the industrial automation system.

[0017] Therefore, some embodiments provide an encryption technique that enables verification of whether calculations have been performed on a PLC, and the PLC functions as a lightweight blockchain client that performs the verification.

[0018] Some embodiments are further based on the recognition that by implementing such a solution, these lightweight blockchain clients do not need to download the entire blockchain, which has too high a computational cost and storage cost. Instead, a lightweight blockchain client with the initial blockchain state only needs to download the latest blocks and associated encryption certificates from the blockchain to prove that the state transition associated with the calculations performed on the PLC is valid or verified, that is, it can reach the current block from the previous block.

[0019] Therefore, some embodiments provide a blockchain-based industrial automation system that implements such a lightweight controller computer, i.e., a PLC, with at least one processor or CPU associated with performing the above verification. The blockchain-based industrial automation system provides a distributed and reliable information source to the entire industrial automation system where the PLC and other devices above the control level can read and write to the blockchain.

[0020] Therefore, the blockchain network associated with the blockchain-based industrial automation system includes data required in the context of industrial automation, such as, but not limited to, PLC firmware updates, PLC controller functions, records of commands sent to the PLC, and variables associated with the PLC.

[0021] Some embodiments are based on the recognition that a unified API can be provided in a secure and auditable manner for interaction with a PLC. The unified API is implemented at the unikernel level and is configured to function as a common runtime by interpreting incoming commands. These incoming commands are described in a domain-specific language (DSL) or as raw PLC commands and can be interpreted after first verifying that the commands are valid by referencing a blockchain network. If valid, a record of the command is sent as a transaction and recorded on the blockchain network. This is done to provide audibility throughout the blockchain-based industrial automation system. Existing industrial automation systems lack such audibility. Once validated, the incoming commands are passed to the PLC for execution.

[0022] According to one embodiment of the present disclosure, a blockchain-based industrial automation system that can access a blockchain network is provided. The blockchain-based industrial automation system includes at least one controller computer, such as a PLC, and the at least one controller computer includes at least one processor, such as a CPU, and a memory (such as a ROM) in which instructions are stored. When the instructions are executed by the at least one processor, they cause the at least one controller computer to perform operations. The operations include downloading the latest block and the associated cryptographic certificate of the latest block from the blockchain network. Using the downloaded latest block and the associated cryptographic certificate, update operations, such as incoming commands for at least one controller, are authenticated. Based on the authentication, a response for controlling the execution operations on the at least one controller is generated from the operations.

[0023] In some embodiments, the authentication of at least one command is performed based on the invocation of one or more types of system call requests.

[0024] In some embodiments, the blockchain-based industrial automation further comprises one or more industrial devices. The one or more industrial devices comprise one or more of a sensor device and an actuator device, each of which is configured to transmit device status data to at least one controller computer. The device status data is associated with a corresponding incoming command.

[0025] Some embodiments provide a server computing system on at least one controller computer, where the at least one controller computer is configured to send an incoming command to the server computing system, and the server computing system is configured to execute operations previously performed by the at least one controller computer. These operations include downloading the latest block and the associated cryptographic certificate of the latest block from the blockchain network. Further, based on the downloaded latest block and the associated cryptographic certificate, authenticate the incoming command of the at least one controller computer. Finally, based on the authentication, generate a response for controlling the operations on the at least one controller computer.

[0026] Some embodiments are based on the recognition that the incoming command is one of a firmware update command, an industrial automation process execution command, and the like.

[0027] In some embodiments, the memory comprises a unikernel for storing instructions for implementing the blockchain-based industrial automation system. The unikernel is associated with an edge computing architecture in some embodiments.

[0028] In various embodiments, a communication protocol that relies on the protocol of a blockchain network is used to exchange messages between at least one controller computer and the blockchain network. The protocol may be, for example, the protocol of a permissioned blockchain network.

[0029] In some embodiments, blockchain-based industrial automation is used to execute verifiable computing commands.

[0030] According to one embodiment, a method for providing blockchain-based industrial automation is disclosed. The method includes downloading the latest block and the associated cryptographic certificate of the latest block from a blockchain network. The method further includes authenticating the update operation of at least one controller computer based on the downloaded latest block and the associated cryptographic certificate. In addition, the method includes generating a response for controlling the execution operation on at least one controller computer based on the authentication.

[0031] According to one embodiment, a non-transitory computer-readable storage medium having a program executable by a processor to implement the above-described method for providing blockchain-based industrial automation is disclosed.

Brief Description of the Drawings

[0032]

Figure 1A

Figure 1B

Figure 1C

Figure 1D

Figure 2

Figure 3

Figure 4A

Figure 4B

Figure 5A

Figure 5B

Figure 5C

Figure 6

Figure 7

DETAILED DESCRIPTION OF THE INVENTION

[0033] In the following description, for the sake of explanation, numerous specific details are set forth in order to provide a thorough understanding of the present disclosure. However, it will be apparent to those skilled in the art that the present disclosure may be practiced without these specific details. In other instances, in order to avoid obscuring the present disclosure, the apparatus and methods are shown in block diagram form.

[0034] As used in this specification and the claims, the terms "for example," "as an example," and "such as," as well as the verbs "comprising," "having," "including," and their other verb forms, each should be construed as open-ended when used in conjunction with a listing of one or more components or other items, meaning that the listing should not be considered as excluding additional components or items. The term "based on" means based at least in part on. Further, it should be understood that the style and terminology used herein are for the purpose of description and should not be regarded as limiting. Any headings used herein are for convenience only and have no legal or limiting effect.

[0035] Various embodiments disclose systems and methods for secure industrial automation. The industrial automation systems and methods disclosed herein provide means for ensuring the integrity of devices. Specifically, when devices are "dumb" devices or devices with limited computing capabilities (e.g., field devices, factory floor controllers, CNC machines, etc.), their security can be easily compromised. Thus, since these devices have limited computing power, limited memory, and some may be battery-powered, it is difficult with current technology to ensure their integrity. Accordingly, the various methods and systems disclosed herein are based on the use of blockchain technology to ensure the integrity of these devices. Therefore, blockchain technology is used to ensure the integrity of the devices. The device needs to log all relevant transactions / operations performed by the device to the blockchain so that others on the blockchain network, such as verifiers, can read this data to ensure the integrity of the device.

[0036] Some embodiments are based on the recognition that this can be done in a number of ways, such as 1) using blockchain transactions to ensure the integrity of these devices, 2) implementing a lightweight blockchain client on the device side, 3) performing forced logging of dumb devices at the kernel level (such as via syscall), and 4) using smart contracts. Therefore, the combination of all four techniques may be used to ensure the integrity of these devices.

[0037] Various embodiments provide an industrial automation system that can perform updates to control-level devices such as PLCs in an automated and reliable manner using blockchain to ensure the integrity of devices that use a PLC as a controller computer. This is done by providing a blockchain-based common runtime, which provides security and integrity for the operating system of the PLC in a way that was not previously possible. The blockchain can be used to store and distribute firmware and controller updates.

[0038] The operating system of the controller computer is secured by implementing the controller computer as a lightweight client of the blockchain network used to implement the blockchain-based industrial automation network. This blockchain-based industrial automation network provides implicit trust and security depending on how the blockchain network is implemented and constructed. That is, the decentralized nature of the blockchain network guarantees the security and integrity of the industrial automation network and the underlying devices. In addition, the immutability of the blockchain provides audibility.

[0039] The objective of some embodiments is to provide a robust and fault-tolerant distributed computing system that also ensures transaction and individual participant accountability, trust, and audibility.

[0040] Therefore, some embodiments of the present disclosure are based on considering the advantages of secure logging, tamper resistance and verifiability of audit data, access control, and a decentralized architecture provided by a permissioned blockchain network. In addition to this, various embodiments disclosed herein utilize the advantages provided by smart contracts when identifying, isolating, and blocking malicious participants that threaten the integrity of the entire distributed computing system, and by using a permissioned blockchain architecture, revoke the privileges of malicious participants (such as both read-related and write-related privileges) to achieve the goal of eliminating obstacles. Also, some embodiments utilize a unikernel architecture using syscalls to run a blockchain-based common runtime for an industrial automation system, thus providing an additional layer of transparency and audibility for the entire system.

[0041] FIG. 1A shows the architecture of a blockchain-based industrial automation system 100a according to some embodiments of the present disclosure. The blockchain-based industrial automation system 100a includes one or more industrial devices 102, such as industrial device 102a, industrial device 102b, and industrial device 102n, which communicate with at least one controller computer 108.

[0042] One or more industrial devices 102 may include one or more of the sensors and actuators deployed in the industrial automation system 100a. A sensor is a device used to measure one or more process variables in an industrial process. These process variables are related to pressure and temperature measurements, conductivity measurements, flow rate measurements, pH measurements, fill level measurements, etc., and record the corresponding process variables such as pressure, temperature, conductivity, pH value, level, flow rate, etc. An actuator is a device used to affect a process variable. These include, for example, pumps or valves that can affect the flow of liquid in a pipe or the fill level in a container. Therefore, one or more industrial devices 102 also include remote I / O, wireless adapters, and common devices located at the field level (e.g., factory floor) in the industry. One or more industrial devices 102 (also referred to as "dumb" devices) have few computing and power resources available for free use. Some industrial devices operate using batteries. Therefore, any control operations specified for one or more industrial devices 102 are performed by communication between the industrial device 102 and at least one controller computer 108.

[0043] In some embodiments, communication between one or more industrial devices 102 and at least one controller computer 108 is performed by sending incoming commands 104 of the corresponding industrial device 102 to the at least one controller computer 108. The at least one controller computer 108 authenticates the corresponding industrial device 102 using blockchain technology and generates a response 106 to be sent to the corresponding industrial device 102. The at least one controller computer 108 is configured to authenticate the corresponding industrial device 102 by using a connection to a blockchain network 120, and the blockchain network 120 implements blockchain technology for providing a secure, reliable, fault-tolerant, and robust security mechanism for ensuring the integrity of the one or more industrial devices 102.

[0044] Therefore, at least one controller computer 108 comprises one or more components including at least one processor 110, a memory 112, an input unit 114, an output unit, and a bus 118. The at least one processor 110 is configured to execute instructions stored in the memory 112. The instructions are executed to perform operations specified for the at least one controller computer 108. These operations are, in one embodiment, related to the control, management, and operation of one or more industrial devices 102. Specifically, the operations comprise authenticating one or more industrial devices 102 based on blockchain technology. Therefore, the operations include instructions related to downloading the latest block and the associated cryptographic certificate of the latest block from the blockchain network 120. Further, the one or more industrial devices 102 are validated based on the downloaded latest block and the associated cryptographic certificate, and a response for transmission to the one or more industrial devices 102 is generated based on the authentication. The response indicates the success or failure of the authentication of the one or more industrial devices 102. Accordingly, the execution operations related to the operation of the one or more industrial devices 102 controlled by the at least one controller computer 108 are executed or halted based on the authentication. For example, if the authentication is successful, the execution operations are executed, but if the authentication fails, the execution operations are blocked or halted.

[0045] Communication between at least one controller computer 108 and one or more industrial devices 102, and further between a blockchain network 120, is performed via an input unit 114 for receiving incoming data and an output unit 116 for transmitting outgoing data. The input / output communication between at least one controller computer 108 and one or more industrial devices 102 may be performed using an appropriate industrial communication protocol including, but not limited to, fieldbuses such as Profibus (registered trademark), Foundation (registered trademark) Fieldbus, Highway Addressable Remote Transducer Protoco (HART (registered trademark)), Control and Communication Link (CC-Link), Common Industrial Protocol (CIP), Ethernet IP, ControlNet, Factory instrumentation protocol (FIP), Modbus (registered trademark), Profinet (registered trademark), SafetyNET-p, SafetyBUS.

[0046] The input / output communication between at least one controller computer 108 and the blockchain network 120 is performed using any appropriate wired or wireless network communication protocol including the Internet.

[0047] Communication between different components within at least one controller computer 108 is performed using a bus 118. At least one controller computer includes a memory 112 for storing instructions as described above. The memory 112 can include a random access memory (RAM), read-only memory (ROM), flash memory, or any other appropriate memory system. The memory 112 can be one or more volatile memory units and / or one or more non-volatile memory units. The memory 112 may be another form of computer-readable medium such as a magnetic or optical disk.

[0048] In some embodiments, memory 112 also stores an operating system associated with at least one controller computer. The operating system may be based on a unikernel architecture, where the unikernel functions as a special machine image and any application operating on at least one controller computer 108 is linked to the required kernel functions in the form of a library. For example, the unikernel may be implemented using well-known unikernel solutions including, but not limited to, MirageOS, u-root, and Linux Kernel Library (LKL).

[0049] Accordingly, the unikernel is used to provide a lightweight client for the blockchain network 120 operating on at least one controller computer 108. The lightweight client further provides edge computing support to at least one controller computer 108 by shifting application-specific computing operations closer to the controlled device (the industrial device 102), i.e., to the edge, and pushing other complex operations (related to the blockchain) away from the edge towards the blockchain network 120.

[0050] The unikernel is executed as a blockchain-based common runtime in some embodiments. The common runtime comprises code, programs, or software having a managed execution environment. The common runtime code is code compiled into an intermediate form of a computer language and can be executed across platforms supporting different programming languages. The platform or end computer can execute the common runtime code by using their respective native compilers. Therefore, the blockchain network 120 is configured to distribute a binary or compilable copy on the common runtime to all controller computers connected on the blockchain network 120. In some embodiments, the blockchain network 120 is a permissioned blockchain network and the common runtime is executed through smart contracts associated with the permissioned blockchain network.

[0051] In the context of a blockchain network, a smart contract can be defined as an executable computer program that defines a set of rules, data, and relationships that must be implemented when the smart contract is executed. A smart contract is immutable in the sense that it cannot be manipulated after it has been added to the distributed ledger architecture of the blockchain network for which it is defined. Further, when a node or computing system in the blockchain network calls a smart contract, a transaction is performed, and the transaction is then recorded on the blockchain network. A smart contract functions as a trusted network service within a permissioned blockchain network and can be used as a tool to ensure fault tolerance and removal capabilities of nodes within a permissioned blockchain network. A smart contract may be distributed to nodes of a permissioned blockchain network in at least one of the forms of a source code file or a trusted binary file. In this case, the nodes of the permissioned blockchain network may be one or more controller computers connected to the blockchain network 120. These nodes compile and execute the smart contract and return the execution result of the smart contract to the blockchain network 120 and post it to the blockchain network 120. Thereafter, the blockchain network 120 authenticates each node by verifying the execution results posted by each node based on a verification algorithm (such as a consensus algorithm such as a proof-of-work algorithm or a proof-of-stake algorithm).

[0052] In some embodiments, the smart contract may include rules related to the device status data of one or more industrial devices 102, and the rules are transmitted from at least one of the one or more industrial devices 102 to at least one controller computer 108 via an incoming command 104. The incoming command may be a firmware update command, an industrial automation process execution command, an industrial automation variable update command (such as temperature or pressure update), and the like. The device status data is associated with the corresponding incoming command and is verified by the execution of the smart contract by at least one controller computer 108, and the verification result is returned to and published on the blockchain network 120.

[0053] In some embodiments, at least one controller computer 108 downloads only the latest block from the blockchain network 120 instead of the entire copy of the blockchain in order to implement a lightweight blockchain client on at least the controller computer 108. The latest block includes the latest updated copy of the smart contract. Then, the execution of the smart contract verifies one or more industrial devices 102 connected to at least one controller computer 108. Further, access to the smart contract or the common runtime provided by the latest block of the blockchain network 120 is performed via a syscall that functions as an API for accessing the unikernel.

[0054] Therefore, at least one controller computer 108 is configured to receive updates from the blockchain network 120, and these updates are signed and encrypted such that only the intended controller computer 108 can interpret the updates. For this reason, at least one controller 108 is configured to download the latest block from the blockchain network 120. Each block on the blockchain network 120 has a unique encryption certificate associated with it. This encryption certificate is used to authenticate the corresponding block. Thus, when at least one controller computer 108 receives an update from the blockchain network 120, it is in the form of the latest block and its associated encryption certificate for that block. Thereafter, using asymmetric encryption techniques (public and private keys), the updates intended for at least one controller computer 108 are signed by the update party and encrypted with the public key of the at least one controller computer 108 targeted in order to provide traceability.

[0055] The update is received by at least one controller computer 108 based on a set of rules or subscription guidelines included in a blockchain-based common runtime or unikernel operating on at least one controller computer 108. Thus, each controller computer 108 can subscribe to the blockchain network 120 for block updates. If the blockchain-based common runtime cannot interpret a block, i.e., cannot successfully decrypt the content of the block with its private key, it means the block does not contain a relevant update, and the block is discarded. If the blockchain-based common runtime can successfully decrypt the block update and thereby interpret the block update, it checks the associated cryptographic certificate to confirm that the block update is valid, i.e., that it can be reached from the original block to the current block. If the block is valid, the update is applied to at least one controller computer 108.

[0056] In this way, the integrity of the low-computing and low-power (or "dumb") industrial devices 102 is verified using secure blockchain technology via at least one controller computer 108.

[0057] At least one controller computer 108 includes industrial control layer devices such as stored program control (SPC) devices or PLC devices. FIG. 1B shows an example of a PLC-based industrial automation system.

[0058] Figure 1B shows a block diagram of an example of a PLC-based system 100b using the architecture of Figure 1A, according to some embodiments of the present disclosure. The PLC-based system 100b includes a sensor 102a and one or more manual input sources 102b (such as on-site personnel or machine operators). The sensor 102a and the manual input source 102b represent one or more industrial devices 102 described in Figure 1A.

[0059] The sensor 102a is communicatively coupled to a PLC 108a having a blockchain-based common runtime 112a. The manual input source 102b is communicatively coupled to a PLC 108b having a blockchain-based common runtime 112b. The PLCs 108a and 108b correspond to at least one controller computer 108 shown in Figure 1A.

[0060] The PLCs 108a and 108b are further communicatively coupled to a factory automation blockchain network 120 (the same as the blockchain network 120 shown in Figure 1A), and the factory automation blockchain network 120 can be further coupled to one or more web clients 122. The one or more web clients 122 are computing systems that can be used to perform some computing and power-intensive functions related to the factory automation blockchain network 120. These functions can include participating in a consensus algorithm, functioning as a full node storing a copy of the factory automation blockchain network 120, generating transactions for the factory automation blockchain network 120, functioning as a miner to mint rewards from the factory automation blockchain network 120, and the like.

[0061] The factory automation blockchain network 120 is used to securely update a PLC such as PLC108a or PLC108b and further ensure the integrity of its operating system or program. For this purpose, the factory automation blockchain network 120 functions as a reliable source of information for firmware updates to the PLC108 and helps to guarantee the security and integrity of the PLC108 and their associated industrial devices 102. At the same time, the firmware updates distributed by the factory automation blockchain network 120 help to make the maintenance and management of the PLC auditable and tamper-proof.

[0062] Some embodiments provide an industrial automation system 100b that prevents tampering by a process line operator who provides one or more manual inputs 100b. In current industrial systems, an operator can directly access the PLC and make on-the-fly adjustments without an audit trail. For example, a manual input 102b is passed directly to the PLC108b without being monitored and authenticated. This is changed in the industrial automation system 100b. As a result, the operator who generates the manual input 102b interacts with the PLC108b by sending an input command 104b, and the input command 104b is validated by the PLC108b using a blockchain-based common runtime 112b implemented using a unikernel architecture and the factory automation blockchain network 120. If the validation is successful, a command is passed to the underlying PLC108b, and the PLC108b sends a response 106b regarding the success of the command execution to the operator 102b.

[0063] In some embodiments, the blockchain-based common runtime 112 comprises a copy of the operating system distributed by the blockchain network 120 to all PLCs 108 connected on the blockchain network 120.

[0064] The blockchain network 120 provides a reliable information source to the industrial automation system 100b and can collate a blockchain-integrated unikernel in the form of a blockchain-based common runtime 112 with this information source. The blockchain-integrated unikernel can download blocks with the latest updates at random timings and check the equivalence of programs through hashes and the like. This provides a level of system integrity that would be impossible without a blockchain-based system.

[0065] The blockchain-based common runtime 112 provides the blockchain client functions on the controller computers 108 such as the PLCs 108a and 108b, together with a library that provides PLC system features. The library includes, but is not limited to, libraries for I / O, compliance with IEC 61131-3, and interfacing with one or more industrial devices 102. The library is constructed using recent programming language toolchains including, but not limited to, Go or C++, and generates a single binary that can be loaded onto the ROM modules of the PLCs 108a and 108b.

[0066] In some embodiments, PLCs 108a and 108b are configured to receive updates from the factory automation blockchain network 120, and these updates are signed and encrypted such that only the intended PLCs can interpret the updates. For this purpose, a unique encryption certificate is associated with each PLC, and using asymmetric encryption techniques (public and private keys), updates intended for a particular PLC are signed by the update party to provide traceability and encrypted with the public key of the target PLC. The blockchain-based common runtime 112 on each PLC subscribes to the factory automation blockchain network 120 for block updates. If the blockchain-based common runtime 112 cannot interpret a block, i.e., if it cannot successfully decrypt the contents of the block with its private key, it means that the block does not contain a relevant update, and the block is discarded. If the blockchain-based common runtime 112 can successfully decrypt the block update and thereby interpret the block update, it checks the associated encryption certificate to confirm that the block update is valid, i.e., that it can be reached from the original block to the current block. If the block is valid, the update is applied to the PLC.

[0067] In this way, the industrial automation system 100b can implement the architecture of FIG. 1A for blockchain-based industrial automation with high security, reliability, fault tolerance, and verifiability.

[0068] Another architecture for implementing a blockchain-based industrial automation system is shown in FIG. 1C.

[0069] Figure 1C shows another architecture of the industrial automation system 100c according to some embodiments of the present disclosure. The architecture of the industrial automation system 100c is substantially the same as the architecture of the industrial automation system 100a, with the only exception that it has an additional server computing system 124 on the controller computer 108 to interact with the blockchain network 120.

[0070] Similar to the blockchain-based industrial automation system 100a, the blockchain-based industrial automation system 100c includes one or more industrial devices 102, such as industrial device 102a, industrial device 102b, and industrial device 102n, which communicate with at least one controller computer 108. Communication between the one or more industrial devices 102 and the at least one controller computer 108 is performed by transmitting the incoming command 104 of the corresponding industrial device 102 to the at least one controller computer 108. The at least one controller computer 108 authenticates the corresponding industrial device 102 using blockchain technology and generates a response 106 to be transmitted to the corresponding industrial device 102. The at least one controller computer 108 is configured to authenticate the corresponding industrial device 102 by using the connection to the blockchain network 120 via the server computing system 124.

[0071] As shown previously, the at least one controller computer 108 includes, among other things, one or more components including at least one processor 110 (shown previously in Figure 1A) and a memory 112. Thus, the server computing system 124 may also include a processor and a memory, but may be configured to have a higher computing power than the at least one controller 108.

[0072] Therefore, the server computing system 124 is configured to provide the functions provided by at least one controller computer 108 described above in connection with FIGS. 1A and 1B. Specifically, the server computing system 124 is configured to function as an interface between at least one controller computer 108 and the blockchain network 120.

[0073] In some embodiments, the server computing system 124 is configured to receive updates from the blockchain network 120 based on subscription rules included in a smart contract or unikernel associated with at least one controller computer 108. The at least one controller computer 108 may send a copy of the smart contract to the server computing system 124. The server computing system 124 receives the updates in the form of the latest blocks and their associated cryptographic certificates. The server computing system 124 then authenticates the blocks using their associated cryptographic certificates and passes the authentication results to the at least one controller computer 108.

[0074] In some embodiments, at least one controller computer 108 is configured to send an incoming command 104 (such as any of incoming commands 104a - 104c) to a server computing system 124. Thereafter, the server computing system 124 is configured to download the latest block and the associated encrypted certificate of the latest block from the blockchain network 120. Thereafter, the server computing system 124 is configured to authenticate the incoming command of the at least one controller computer 108 based on the downloaded latest block and the associated encrypted certificate. To that end, the server computing system 124 is configured to check whether the incoming command is included in the list of valid commands included in the downloaded latest block. Based on the authentication result, the server computing system 124 is configured to generate a response for controlling the execution operation on the at least one controller computer 108.

[0075] One common implementation example of architecture 100c is by a Supervisory Control and Data Acquisition (SCADA) system shown in FIG. 1D.

[0076] FIG. 1D shows a block diagram of an example of a SCADA - based system 100d using the architecture of FIG. 1C, according to some embodiments of the present disclosure.

[0077] The SCADA-based system 100d includes one or more industrial devices 102 such as industrial device 102a and industrial device 102b. In one example, industrial device 102a includes a sensor and industrial device 102b corresponds to a manual input device. The manual input may be provided to the industrial field device by a field or machine operator. The industrial device 102 is communicatively coupled to at least one controller computer 108 such as controller computer 108a and controller computer 108b using any of the aforementioned industrial communication protocols. The at least one controller computer 108 may be a PLC such as PLC 108a and PLC 108b. And each of the PLCs is connected to a server computing system 124 which is a centralized SCADA server in the industrial automation system 100d. The centralized SCADA server 124 is further connected to a SCADA database 126 that stores data associated with the control, processes, and authentication of the industrial devices 102. In some embodiments, the SCADA database 126 stores data offloaded to the SCADA database 126 by the centralized SCADA server 124. This data may be related to blockchain-related data (e.g., a copy of the blockchain, smart contracts, unikernel, etc.). The centralized SCADA server 124 is further connected to one or more web clients 122, and the web clients 122 may be further connected to a blockchain network.

[0078] SCADA is a centralized system that manages PLCs and provides features such as PLC updates and data recording from PLCs. Traditional systems at the monitoring level were isolated from the Internet. However, this significantly increases the attack target area of industrial systems that are not designed with cyber security in mind as monitoring systems become increasingly connected to the Internet. Furthermore, since PLCs execute a special monolithic operating system, it is economical for hackers to attempt to exploit at the OS level that can be accessed through the Internet. Finally, due to the requirements of most industrial systems, it is difficult to apply software updates and security patches to the system. However, this is avoided in industrial system 100d by using a unikernel within the PLC that is updated only based on updates provided by a blockchain network connected to the centralized SCADA network 124. This may be the same blockchain network 120 shown in FIG. 1C that sends updates managed by smart contracts, and the updates are in the form of the latest blocks of the blockchain network 120 and their associated encrypted certificates.

[0079] Therefore, the centralized SCADA server 124 may obtain smart contracts from the blockchain network 120 and store them in the SCADA database 126. Also, when there is an update, the centralized SCADA server 124 receives the latest block from the blockchain network 120, authenticates the block using its associated encrypted certificate and smart contract, and passes the authentication result to PLCs 108a and 108b. If the authentication is successful, PLCs 108a and 108b are updated, such as by updating their unikernels. If the authentication fails, the update is not passed to PLCs 108a and 108b.

[0080] In some embodiments, one or more types of system call (hereinafter also referred to as syscall) requests to the unikernel of PLCs 108a and 108b are invoked by authentication by the centralized SCADA server 124. Thereafter, the result of the invocation is sent back to the centralized SCADA server 124, and the centralized SCADA server 124 checks whether the result is valid. If the result is valid, the update received from the blockchain network 120 is applied to PLCs 108a and 108b. If the result is not valid, the update is discarded.

[0081] In some embodiments, when PLCs 108a and 108b each receive some incoming command from their corresponding industrial devices 102a and 102b, etc., the incoming command is sent to the centralized SCADA server 124. Thereafter, the centralized SCADA server 124 is configured to download the latest block and the associated cryptographic certificate of the latest block from the blockchain network 120. Thereafter, the centralized SCADA server 124 is configured to authenticate the incoming command of at least one controller PLC 108 based on the downloaded latest block and the associated cryptographic certificate. To that end, the centralized SCADA server 124 is configured to check whether the incoming command is included in the list of valid commands included in the downloaded latest block. Based on the authentication result, the centralized SCADA server 124 is configured to generate a response for controlling the execution operation on at least one PLC 108.

[0082] In any of the above scenarios, PLC108a need not perform much processing, and most of the blockchain-based authentication and computing tasks are offloaded to the centralized SCADA server 124. This requires little computing power from end-field devices such as PLCs and controller devices, and helps integrate security and trust mechanisms incorporated into blockchain technology at the industrial automation and device levels. Also, instead of downloading the entire copy of the blockchain network by the centralized SCADA server 124, authentication by downloading only the latest blocks of the blockchain network further helps to implement a lightweight blockchain client even at the level of the centralized SCADA server 124.

[0083] Therefore, the lightweight centralized SCADA server 124 is further coupled to one or more web clients 122. The one or more web clients 122 are computing systems that can be used to perform some computing and power-intensive functions related to blockchain technology. These functions can include participating in consensus algorithms, functioning as a full node storing a copy of the entire blockchain network, generating transactions for the industrial automation system 100d, functioning as a miner to mint rewards from the blockchain network 120, and so on.

[0084] The architecture of the industrial automation system 100d shown in FIG. 1D is used to implement an industrial automation system using edge computing when viewed in combination with FIGS. 1A, 1B, and 1C.

[0085] Edge computing provides a decentralized infrastructure for computing that can distribute computing resources and application services among the participants of an edge computing system. "Edge" can refer to the data points where the data being operated on is actually collected or used. Edge computing offers several advantages, such as high throughput, reduced response time, enhanced data privacy and data security, and in some cases, even reduced operational costs. In the case of an industrial automation system, such as any of the systems described in FIGS. 1A, 1B, 1C, and 1D, the edge computing system architecture can be represented by using a control layer stack as shown in FIG. 2.

[0086] FIG. 2 shows a block diagram of a control layer stack 200 of an industrial automation system according to some embodiments of the present disclosure. The control layer stack 200 includes a field level 202, a control level 204, and a monitoring level 206. The field level 202 includes one or more industrial devices 102 such as sensors and actuators 208. The control level 204 includes at least one controller computer 108 such as a PLC 210. The monitoring level 206 includes a server computing system 124 such as an industrial PC 212.

[0087] In some embodiments, PLC 210 is an essential component of control level 204 of control layer stack 200 in an industrial automation system. PLC 210 is configured to interface with many other devices such as devices from field level 202 or other PLCs. PLC 210 also interfaces with higher-level devices, namely industrial PC 212 at monitoring level 206. Industrial PC 212 at monitoring level 206 is composed of a commodity PC that executes a standard operating system with special software capable of interfacing with lower-level devices. Therefore, industrial PC 212 can function as the centralized SCADA server 124 shown in FIG. 1D. One or more of control level 204 and monitoring level 206 are further configured to interface with a blockchain network (not shown in FIG. 2) to perform the functions of the blockchain-based industrial automation system described in the foregoing embodiments.

[0088] Therefore, devices in one or more of control level 204 and monitoring level 206 are configured to exchange messages with the blockchain network using communication protocols that rely on the protocols of the blockchain network. These protocols may include Hyperledger protocol, MultiChain protocol, protocols implemented using Ethereum blockchain, protocols implemented using Solana blockchain, and the like.

[0089] Various embodiments provide for implementing the control layer stack 200 in a custom manner, with control and computing operations being distributed across different levels in order to obtain the benefits of edge computing for the previously disclosed blockchain-based industrial automation system. Broadly, the control and computing operations include one or more of: 1) collecting industrial device data, 2) authenticating updates to an industrial automation system such as the industrial automation system 100a shown in FIG. 1A by way of example, 3) authenticating commands provided to industrial devices, and 4) providing blockchain-based verifiability of commands and updates to the industrial automation system. Of these, the most computationally intensive functions include control and computing operations 2, 3, and 4. These control and computing operations may be distributed between the control level 204 and the monitoring level 206 based on the deployment of a preferred edge computing architecture of the control layer stack 200.

[0090] Accordingly, the control layer stack 200 may be configured to provide Internet of Industrial Things (IIoT) functionality based on the installation of a custom edge computing architecture. Each layer of the control layer stack 200 becomes more complex and aggregates multiple system functions as control progresses from bottom to top. The computing layer ascends the architecture stack and aggregates processing power, information, and data from the bottom up. The goal of any implementation is to provide fast and local computing at the edge while, on the other hand, obtaining the benefits of "wisdom of the cloud" provided in a blockchain network where global computing, model development, management, and security are realized above the monitoring level 206.

[0091] For example, in an environment such as a thermal power plant, the problem to be solved may be to maintain the accurate temperature of the furnace. In this case, the edge device may be a pump that circulates water in the cooling pipes of the furnace and always maintains the desired flow of water or coolant in the pipes to maintain the temperature requirements. Therefore, at the field level 202, there may be a temperature sensor that collects the temperature data of the cooling pipes and sends it to the edge computing device at the control level 204. The edge computing device executes a control algorithm and adjusts the flow of the liquid through the pump to regulate the temperature. If the purpose is to adjust the temperature across several devices or an entire area, the edge becomes the temperature controller at the control level 204 (regardless of whether it is an individual component or a stand-alone system), and the edge computing layer becomes a system that coordinates the control, usually a PLC 210 or a SCADA system 212.

[0092] In some other embodiments, the PLC 210 is configured to receive an update of an operating system or unikernel running on the PLC 210 and authenticate that the update is valid before applying the update. This is shown in the architecture 100b of FIG. 1B. In this case, the PLC 210 becomes the edge device.

[0093] In this way, a blockchain-based industrial automation system that supports custom edge computing and IIoT can be realized by using the blockchain-based systems shown in FIGS. 1A, 1B, 1C, and 1D and the control stack architecture of FIG. 2. Such a system can utilize the security, accountability, verifiability, and reliability of the blockchain system, as well as the faster computing, shorter turnaround time, enhanced data privacy, less or selective data exposure, and enhanced scalability provided by the edge computing architecture. Therefore, the combination of the above-mentioned edge computing and blockchain-based industrial automation is realized using lightweight clients closer to the edge level.

[0094] FIG. 3 shows a block diagram of a blockchain system 300 that supports one or more lightweight clients according to some embodiments of the present disclosure. The blockchain system 300 includes one or more lightweight clients or nodes of the blockchain network 308, namely lightweight client 302 and lightweight client 304. The lightweight client 304 further includes an embedded device 306. The blockchain network 308 has the same function as the blockchain network 120 shown in FIGS. 1A, 1B, and 1C.

[0095] The lightweight clients 302 and 304 may comprise any recent computer, such as an embedded computer, laptop, mobile phone, smartphone, tablet, smartwatch, wearable computer, point of sale (POS) terminal, kiosk, routing device, monitoring terminal in a power plant, electronic instrument, etc. Thus, the lightweight clients 302 and 304 may be at least one of the controller computers 108 shown in FIGS. 1A, 1B, 1C, and 1D. In some embodiments, the lightweight clients 302 and 304 may be the server computing systems 124 shown in FIGS. 1C and 1D.

[0096] Some embodiments are based on the recognition that lightweight clients are computers with limited computing power (such as the PLCs and SCADA servers described in connection with the foregoing figures). Thus, these lightweight clients cannot store a complete copy of the blockchain 308 of which they are a part. However, using the architectures of the industrial automation systems described in these and the foregoing embodiments, even these lightweight systems with low computing power can be fully reliable, secure, and efficiently monitor malicious behavior. This may be made possible by the combination of smart contracts, unikernels, and up-to-date block-based authentication implemented in the industrial automation systems 100a - 100d disclosed in various embodiments described herein.

[0097] In some embodiments, lightweight clients 302 and 304 are implemented using the process of zero-knowledge proofs in zksnark or the like. A zk-SNARK, i.e., a zero-knowledge succinct non-interactive argument of knowledge-based system, is based on the concept of zero-knowledge proofs. Zero-knowledge proof is a situation where each of the two parties in a transaction can prove to the other party that they have certain information without revealing the content of that information. A zero-knowledge proof-based system provides enhanced privacy and security in terms of the implementation of blockchain-based lightweight clients compared to traditional password-based systems well-known in the art.

[0098] In some embodiments, lightweight clients 302 and 304 are implemented using software libraries and APIs such as filter commitments, e.g., those using Bitcoin's BIP37, the Electrum lightweight client, the Bloom filter of Bitcoin's BIP37, the public addresses of Electrum, the Bloom filter supported by Dogecoin, etc. The lightweight client uses a filter-based commitment to receive a filter of all transactions or addresses within a given block. Then, the lightweight client requests the block if the filter matches those addresses / transactions.

[0099] In some embodiments, a lightweight client such as node 302 is configured to download the latest block associated with blockchain 308 and authenticate the update operations intended for node 302 based on the latest downloaded block and its associated cryptographic certificate. The update operations may be firmware update operations, command execution operations, or the like.

[0100] In various embodiments, the blockchain network 308 is a permissioned blockchain network. Thus, node 302 (or equivalently node 304) is configured to communicate messages with other nodes within the permissioned blockchain network 308 to coordinate the actions of all nodes that are part of the permissioned blockchain network 308. When this coordination occurs, a consensus regarding the current state of the permissioned blockchain network 308 is reached among all nodes within the permissioned blockchain network 308 according to a distributed computing program (commonly known as a consensus algorithm). An example of a consensus algorithm that may be used by the permissioned blockchain network 308 to reach consensus is the Practical Byzantine Fault Tolerant (PBFT) algorithm, in which nodes are configured to receive approvals from all other nodes within the permissioned blockchain network 308 regarding the validity of the node's transactions. Subsequently, a consensus is reached based on the total number of approvals received by the node.

[0101] In various embodiments, the smart contract is stored on node 302 (or node 304) as part of the node's unikernel program. A unikernel is an operating system on which nothing else is running. The unikernel receives the smart contract in the form of a smart contract distributed to all nodes connected to the blockchain network 308. Subsequently, the smart contract is invoked using a syscall at the device level (in this case lightweight client 302 or 304). The syscall is part of the unikernel. In some embodiments, the smart contract may be the operating system of lightweight client 302 or 304, or part of the operating system. This will be further described below in connection with FIGS. 4A and 4B.

[0102] FIG. 4A is a block diagram showing the components of a computing system 402 including a memory 404 and a processor 406. The memory 404 further includes a user space 404 and a kernel space 410. The computing system 402 may represent at least one of the controllers 108 or the central computing server 124 described above.

[0103] The memory 404 of the computing system 402 includes a portion for storing user programs such as application programs, application data, APIs, software or code libraries, stored procedures, algorithms, computer instructions, user files, etc. This portion is the user space 408. User programs in the user space 408 are generally written in any of well-known high-level languages such as C#, C++, Java®, Python, Solidity, JavaScript®. The user space 408 may also include various processes such as industrial control processes, business processes, or network interface processes that define algorithms and logical instructions for executing one or more functions. The functions are application-specific. One type of user program in the user space 408 is a smart contract. A smart contract defines enforceable rules that are executed when the smart contract is executed. And, upon execution of the smart contract, one or more processes that require access to system (operating system) resources may be invoked. System resources are stored in a portion of the memory 404 separate from the user space 408 known as the kernel space 410.

[0104] The kernel space 410 defines a part of the memory 404 where the core of the computing device 402 in the form of an operating system and its related programs is stored. The kernel space 410 stores special programs that enable the interfacing of various system resources such as hardware and file systems. The kernel space 410 may include special programs and data such as device drivers, memory management programs, I / O management programs, process management programs, etc. Generally, kernel space programs are written in a low-level language such as C.

[0105] The system resources included in the kernel space 410 may be accessed from the user space 408 processes through special requests sent to the kernel space 410 in the form of system calls or syscalls 412. Each resource access requires a separate syscall 412. In the various embodiments described above, in relation to the blockchain-based industrial automation system shown in FIGS. 1A, 1B, 1C, and 1D, the kernel space 410 comprises a unikernel (a dedicated stand-alone kernel specialized at compile time). The unikernel stores instructions specialized for a particular type of application. Since the unikernel is compiled directly into the application space, the attack target area of the unikernel is limited to the special application for which the unikernel is designed. The unikernel is more suitable for edge computing applications compared to a monolithic kernel because the attack target area is limited. Also, the unikernel is more suitable for lightweight clients because it is application-specific.

[0106] Various embodiments are based on the recognition that the kernel 410 storing the unikernel is used to implement an edge computing architecture (such as the edge computing architecture described in connection with FIG. 2). Further, the unikernel is used to implement a lightweight client on at least one controller computer 108 or on a server computing system 124 associated with the blockchain network 120 described in FIGS. 1A, 1B, and 1C.

[0107] Some embodiments are based on the recognition that the unikernel comprises binary files that are compiled at application time. These binary files are received as updates from the blockchain network 120 and are then authenticated by at least one controller computer 108 or server computing system 124 based on the download of the latest block of the blockchain network 120 as described in the foregoing embodiments.

[0108] Some embodiments are further based on the recognition that the unikernel is obtained as a copy of a smart contract distributed by the blockchain network 120 and, when the smart contract is invoked, its authenticity is verified using the latest block of the blockchain network 120. Thus, the unikernel is common to all participants in the blockchain network and can also be viewed by all participants in the blockchain network 120 upon invocation of the corresponding smart contract.

[0109] Some embodiments provide the unikernel as common runtime software or code accessed using syscall 412.

[0110] Figure 4B is a block diagram showing the execution of a unikernel common runtime in a blockchain-based industrial automation system 400b according to some embodiments of the present disclosure. The blockchain-based industrial automation system 400b corresponds to the blockchain-based industrial automation systems 100a, 100b, 100c, and 100d shown in FIGS. 1A, 1B, 1C, and 1D, respectively. The blockchain-based industrial automation system 400b includes at least one controller computer 108 shown as a computing system 402. Alternatively or in addition, the blockchain-based industrial automation system 400b includes at least one server computing system 124 as a computing system 402. The computing system 402 is connected to a blockchain network 414. The blockchain network 414 corresponds to the blockchain network 120 described in FIGS. 1A, 1B, and 1C.

[0111] As previously explained with reference to FIG. 4A, the computing system 402 includes a user space 408. The user space 408 includes one or more application programs such as program 1 408a and program N 408b. These application programs are configured for industrial control applications in some embodiments. For example, the application program may be a control program for temperature control, pressure control, maintaining an industrial control process variable within defined limits, valve opening and closing schedules, etc. The application program may be described using well-known programming languages for industrial automation (ladder diagrams, function block diagrams, statement lists, logical functions, etc.). Therefore, the computing device 402 may be a PLC device or a SCADA computer, and the application program is the corresponding control program for industrial control applications.

[0112] Furthermore, computing system 402 includes a kernel space 410, which further includes a common runtime or unikernel 410a and a hardware abstraction layer 410b.

[0113] In one embodiment, unikernel 410a includes a binary file for operating computing device 402, and this unikernel 410a is common to all such computing devices connected on blockchain network 414. Blockchain network 414 is an industrial automation blockchain network corresponding to blockchain network 120 shown in FIGS. 1A, 1B, and 1C. Therefore, blockchain network 414 distributes a verified common runtime to all nodes or computing devices 402 connected on blockchain network 414 to ensure the integrity, security, and trust of unikernel 410 (which is very important for the reliable operation of computing device 402). Therefore, computing device 402 may be at least one controller computer 108 or PLC 108a or 108b shown in FIGS. 1A and 1B respectively, and the reliable operation of the PLC enhances the reliability of the entire industrial automation system of which PLC 108a or 108b (and any other additional PLCs) are a part.

[0114] In one embodiment, unikernel 410a is executed as a smart contract distributed to all participants in blockchain network 414. Thus, blockchain network 414 is a permissioned blockchain network 414 on which any transaction is verified by consensus among all participants of the nodes, as described above. Further, when a smart contract is called, one or more types of syscall requests (the only interface between user space 408 and kernel space 410) are called. In one example, the smart contract is called when an update to the common runtime is made by the developer of the common runtime, which may be an organization, a party, a consortium, an open source platform, or an individual developer who generates these common runtimes for industrial automation blockchain networks. Such an update is downloaded on computing device 402 in the form of a download of the latest block of blockchain network 414, along with its associated cryptographic certificate. Before installing or applying this to computing system 402, a call to the smart contract is made on computing system 402 via syscall. This call executes some of the operations specified in the smart contract, and the results are returned onto blockchain network 414 and published onto blockchain network 414. If these results are verified, the updated common runtime is applied to computing system 402, and if the results are not verified, the updated common runtime is not applied and an error message may be returned on a display associated with computing device 402. Also, an error notification is sent back to blockchain network 414, notifying that an unverified update is circulating. Thus, blockchain network 414 may be configured for repair actions.

[0115] In one embodiment, unikernel 410 is executed as a smart contract that is called when an incoming command is received by computing device 402. The command is then verified by the execution of the smart contract, and the execution result of the smart contract is published on blockchain network 414 to check whether the command is a valid command. If it is confirmed to be legitimate, the command is executed; otherwise, the execution is blocked.

[0116] In one embodiment, unikernel 410a is distributed as a blockchain operating system by blockchain network 414, and most of the authentication, processing, and verification are pushed to the blockchain network 414 cloud. Computing system 402 downloads the latest block, executes the smart contract, and returns the execution result of the smart contract to the blockchain network 414 cloud and publishes it on the blockchain network 414 cloud to perform the basic function. In the blockchain network 414 cloud, this result is verified using one or more well-known verification algorithms such as proof of work (PoW), proof of stake (PoS), proof of history (in the SOLANA (registered trademark) blockchain), delegated proof of stake (dpos), zero-knowledge proof, or zk-SNARKS.

[0117] Unikernel 410a is accessed through a syscall that also functions as an interface of computing system 402 to blockchain network 414. In some embodiments, syscall Ankur is configured as a special syscall for accessing blockchain network 414 via the syscall.

[0118] The unikernel 410a, which functions as a common runtime for all computing devices connected to the blockchain network 414, functions as an operating system common to all possible hardware of all device manufacturers that subscribe to the blockchain network 414. Hardware-specific and manufacturer-specific OS code is encapsulated in the hardware abstraction layer 410b. The code for the hardware abstraction layer is supplied by a manufacturer such as the manufacturer of the PLC (which is the computing device 402 in this example). This enables the PLC manufacturer to retain its unique functions while still utilizing the reliable common runtime 410a provided through the blockchain network 414. In this example, since all participants utilize the same common runtime 410a component, customers or industry owners can trust the blockchain network 414 regardless of which vendor's PLC they purchase.

[0119] By implementing the blockchain-enabled industrial automation system in the above-described manner, the security and trust of blockchain technology are guaranteed, and blockchain-related functions are pushed to the network or cloud level, providing scalability by making it easy to add or remove any number of computing devices 402 without incurring additional computational costs, allowing hardware manufacturers such as PLC manufacturers to configure only their unique functions, and providing the flexibility to leave reliability management to the blockchain provider.

[0120] FIG. 5A shows a flowchart of a method 500 for managing a blockchain-based industrial automation system according to some embodiments of the present disclosure. The method 500 is implemented by a processor configured to execute computer-readable instructions stored in a memory. For example, the method 500 may be implemented by the controller computer 108 shown in FIGS. 1A, 1B, and 1C, or alternatively or in addition to, by the server computing system 124 shown in FIGS. 1C and 1D.

[0121] The method 500 includes, at step 502, downloading the latest block from a blockchain network. The blockchain network may be an industrial automation-related blockchain network 120. Downloading only the latest block instead of the entire copy of the blockchain is done to lighten the computing device (e.g., the controller computer 108 or the server computing system 124) that executes the method 500. The processing power required to download and store only the latest block of the blockchain network is much smaller compared to the case of downloading the entire copy of the blockchain. Therefore, the method 500 is executed in a much more computationally efficient way compared to the authentication method based on downloading the entire blockchain.

[0122] In some embodiments, the downloading of the latest block is performed by calling a smart contract on the computing device that executes the method 500. This has been previously described in relation to the foregoing embodiments.

[0123] In some embodiments, the smart contract is implemented as a common runtime or unikernel that accesses the computing resources of the computing device that executes the method 500 via one or more syscalls. This has been described in detail in FIGS. 4A and 4B.

[0124] In some embodiments, the smart contract functions as an operating system (OS) that controls a computing device, and since the OS is distributed by a trust-based blockchain network, it can be trusted.

[0125] In some embodiments, the downloaded latest block is processed after an update operation is initiated by the blockchain network. The update operation may be a firmware update operation for the computing device that executes method 500 or an operation related to executing incoming commands.

[0126] Next, at step 504, the update operation is authenticated based on the downloaded latest block of the blockchain network. Authentication of the latest block is performed by downloading the latest block along with its associated cryptographic certificate in a computing device (such as controller computer 108 or server computing device 124) that executes method 500. Before installing or applying this update to the computing device, a call to the smart contract is made via syscall on the computing device. By this call, some operations specified in the smart contract are executed, and the results are returned onto and published on the blockchain network. If these results are verified, the update is applied to the computing device, and if the results are not verified, an error message may be generated if an update is attempted. This is also described in detail in FIGS. 4A and 4B.

[0127] In one embodiment, when the update operation is related to the execution of incoming commands on a computing device, step 504 may further include several method steps as shown in FIG. 5B.

[0128] Figure 5B shows a flowchart of steps or a sub-step of step 504 for the authentication of an update operation for managing a blockchain-based industrial automation system according to some embodiments of the present disclosure.

[0129] Method 504 comprises, at step 504a, transmitting device state data in an incoming command to a computing device. The device state data is received from one or more industrial devices such as industrial device 102 shown in FIGS. 1A, 1B, 1C, and 1D. The incoming command is also shown as incoming command 104 in FIGS. 1A and 1C. Thus, the device state is related to the operating state of the corresponding industrial device 102 and is measured by process parameter data of a process executed by the industrial device 102.

[0130] The device state data in the incoming command is authenticated at step 504b based on the latest downloaded block and its associated encrypted certificate. Thus, the latest downloaded block comprises data associated with a set of valid commands for one or more industrial devices 102, and if the incoming command is included in the set of valid commands, the incoming command is authenticated for execution. However, if the incoming command and the device state data included therein do not exist in the list of valid commands included in the latest downloaded block, the corresponding incoming command is not validated. As a result, further execution of the incoming command is suppressed.

[0131] In any case, the result of the authentication performed at step 504 of method 500 is used to determine a further series of actions of method 500.

[0132] Therefore, referring back to FIG. 5A, in step 506, based on the authentication performed in step 504, a response for controlling the operation is generated. The response is generated by the computing device executing method 500. For example, FIG. 5C shows some additional steps performed to generate a response according to method step 506.

[0133] Method step 506, in one embodiment, comprises transmitting control instructions from the computing device to one or more industrial devices connected to the computing device. For example, referring to FIGS. 1A and 1C, a response 106 generated by at least one controller computer 108 is transmitted to one or more industrial devices 102. For example, if the authentication in step 504 is successful, in step 506b, the response includes control instructions for modifying the device state of one or more industrial devices based on the control instructions specified in the incoming command. On the other hand, if the authentication in step 504 is successful, in step 506b, the response includes preventing the execution of control instructions on one or more industrial devices 102. This may be done by displaying an error message, generating an alarm, providing an audio notification, providing an image notification, etc.

[0134] In one embodiment, the authentication of at least one incoming command is performed based on the invocation of one or more types of system call requests. This occurs when the computing device executing method 500 includes a unikernel, and any operation on the computing device is performed through the unikernel using syscalls. Therefore, the incoming command is at least one of a firmware update command and an industrial process automation command as described in the foregoing embodiments, and is embedded in an industrial automation system. An example of an industrial automation system based on blockchain is shown in FIG. 6.

[0135] Figure 6 shows a use case 600 of a blockchain-based industrial automation system according to an exemplary embodiment of the present disclosure. Use case 600 corresponds to a factory floor that includes one or more industrial devices or manual input operators (such as an industrial machine equipped with a line operator 602 and a sensor 604). The factory floor is equipped with one or more PLCs such as PLC 606, which includes a blockchain-based common runtime 606a stored in the memory of PLC 606. PLC 606 is connected to a factory automation blockchain network 608 via one or more of wired or wireless connections. Also, PLC 606 is communicatively coupled to one or more industrial devices or manual input operators (such as an industrial machine equipped with a line operator 602 and a sensor 604) through an industrial communication protocol.

[0136] In an exemplary scenario for illustration, PLC 606 downloads the latest block from the factory automation blockchain network 608. This download invokes the blockchain-based common runtime 606a, and the common runtime 606a further executes one or more syscalls to access the underlying hardware of PLC 606. Next, PLC 606 executes the authentication of the downloaded latest block by re-encoding the data collected via syscalls on the factory automation blockchain network 608. The factory automation blockchain network further verifies this data and sends back a notification of the verification to PLC 606. The verification performed in the blockchain network 608 uses standard blockchain protocols such as POW, POS. PLC 606 checks the result of the verification and applies an update to PLC 606 based thereon. For example, the update may be a firmware update to update the version of the current common runtime 606a operating on PLC 606.

[0137] In this way, the PLC 606 with limited computing resources can utilize the trust and security provided by blockchain technology and trust the firmware provided via an external network such as the Internet.

[0138] FIG. 7 shows an exemplary use case 700 for the realization of an industrial automation system based on blockchain technology for verifiable computing according to some embodiments of the present disclosure.

[0139] The use case 700 corresponds to a factory floor that includes one or more industrial devices 704 for manufacturing a product 702. The factory floor is equipped with one or more PLCs such as PLC 706, and the PLC 706 includes a blockchain-based common runtime 706a stored in the memory of the PLC 706. The PLC 706 is connected to the factory automation blockchain network 710 via one or more of wired or wireless connections. The PLC 706 is configured to download a verification contract 708 from the factory automation blockchain network 710 for the execution of verifiable computing commands. Also, the PLC 706 is communicatively coupled to one or more industrial devices 704 through an industrial communication protocol.

[0140] In an exemplary scenario for illustration, the PLC 706 downloads the latest block containing the latest copy of the verification contract 708 from the factory automation blockchain network 710. This download triggers the blockchain-based common runtime 706a, which further executes one or more syscalls to access the hardware underlying the PLC 706. Next, the PLC 706 authenticates the downloaded latest block by re-encoding the data collected via the syscall on the factory automation blockchain network 710. The factory automation blockchain network 710 further verifies this data and sends back a verification notification to the PLC 706. The verification performed in the blockchain network 710 uses standard blockchain protocols such as POW, POS. The PLC 706 checks the result of the verification and applies an update to the PLC 706 based on it. For example, the update may approve the state sequence of the industrial device according to a verifiable computing execution command and perform a machining operation on the product 702 accordingly.

[0141] The state sequence corresponds to the device state data of the industrial device 704. Based on the downloaded verification contract 708, a valid state sequence is identified.

[0142] At a high level, verifiable computing typically involves the following interaction among three parties. The client specifies a function f to be computed and provides input data (denoted as x). The server computes f(x). Finally, the verifier checks that the result is correct, i.e., that y = f(x). A verifiable computing scheme enables the client to generate cryptographic objects, and both the server and the verifier use these cryptographic objects to convince the client that the computation was performed correctly. In a typical environment considered for verifiable computing, the function f to be verified and the input x vary for each instance of the problem. This reflects the typical workload faced in a cloud computing environment (i.e., a large number of individual computations from different users). However, the workload found in a manufacturing environment such as the factory floor shown in use case 700 is composed of repeatedly applying the same function (i.e., some physical transformation f) to a large number of identical but uniquely identifiable instances of input xi, where i is within a finite set of possibilities. Directly applying verifiable computing to a manufacturing environment is infeasible because cryptographic proofs would be generated for each product 702 on the manufacturing line. Each proof is not identical due to entropy, but is functionally redundant because each proof verifies the same function on the same input. Generating verifiable proofs for each product with identical specifications is computationally wasteful, can introduce unacceptable latency in the manufacturing process, and unnecessarily increases storage requirements by retaining redundant proofs for each manufactured product.

[0143] However, the blockchain-based factory automation network 710 helps reduce this wasteful computing and storage requirement by making it a blockchain-based verifiable computing system for the manufacturing process. This blockchain-based verifiable computing system consists of two main components: verifiability at the industrial device 704 level and a permissioned blockchain network 710 that reduces the computational cost of verification at the industrial device 704 level.

[0144] Verifiability at the industrial device 704 level is achieved by ensuring the verifiability of the controller (i.e., the PLC 706 at the control level of the industrial automation hierarchy). The factory automation blockchain network 710 is used to enable the use of a single proof to verify all items manufactured according to the same specifications. This verifiability is often desirable because otherwise, the manufacturing company cannot visualize the manufacturing process employed by the supplier. The supplier is essentially a black box that provides products that meet the specifications. Errors in industrial automation usually have a very large impact because they often lead to physical failures. For example, a small configuration error that is almost impossible to detect can cause significant damage to downstream OEMs (customer brand manufacturers). For this reason, downstream OEMs usually expend additional effort to test upstream products to guarantee the specifications.

[0145] Industrial device 704 has a finite number of atomic operations, each of which can be modeled as a state in a finite state machine. A sequence of states or "state sequence" corresponds to the industrial device 704 performing a physical transformation, i.e., there is a one-to-one relationship between the state sequence and the physical transformation. For these reasons, the state sequence corresponds to the physical transformation, but the state transition occurs on the PLC 706 and not on the industrial device 704. When the PLC 706 goes through the state transitions of the state sequence, it instructs the corresponding industrial device 704 to execute an operation. At the same time or after the operation is completed, the industrial device 704 returns device state information (feedback regarding the current state of the industrial device 704, whether an error was encountered when the industrial device 704 executed an operation, the configuration of the industrial device 704, etc.) to the PLC 706. The PLC 706 uses this information to determine whether to transition to a subsequent state.

[0146] In this way, the verifiability of the manufacturing process executed by the industrial device 704 becomes possible.

[0147]

Number

[0148]

Number

[0149] These state sequences are converted into arithmetic circuits for proper distribution to participants such as PLC 706. A verifiable proof, by itself, does not enable the verifiability of the manufacturing process. Assuming that the verifiable proof is in some reliable shared location or distributed to the verifiers, the prover (i.e., PLC 706) can send a copy of the state sequence to the verifiers. However, in this case, important aspects of verification such as attempting to verify the physical transformations applied to physical objects and the subsequent immutable recording of the results are not carried out. These aspects are surely possible by distributing the verification contract 708 in which the verifiable proof verified by PLC 706 is incorporated, using the factory automation blockchain network 710. Furthermore, without a common network built on top of the factory automation blockchain network 710, the manufacturer might be able to fudge the results by sending different verifiable proofs to different parties. For these reasons, the blockchain is an essential component for applying verifiable computing to physical manufacturing processes.

[0150] In some embodiments, the verifiable proof is incorporated within a smart contract distributed as the verification contract 708. As is well known, a smart contract is a program stored and executed on a blockchain, has its own address, is called by sending a transaction to those addresses, and is stored and executed by all full nodes participating in the blockchain network. By combining the verifiable proof with the smart contract, there is no need to manage the keys associated with the verifiable proof, and there is no need for all participants to trust that they have received the same verifiable proof.

[0151] In some embodiments, at step 712, the PLC program enters the PLC 706 and starts an instruction to the industrial device 704. Next, at 714, the product 702 is provided to the industrial device 704. The industrial device 704, at 716, applies a physical transformation to the manufactured product, and at the same time the industrial device 704 sends feedback to the PLC 706 about its operating state and any other auxiliary information. When the state sequence is completed, the PLC 706 transfers the state sequence to the network 710 for verification by calling the verification contract 708 at 718. Only the verification result and the unique identifier of the manufactured item are written to the blockchain network 710 at 718. Next, the item proceeds to the next industrial device 704 through the production line.

[0152] In this way, with this method supported by the permissioned blockchain network 710, the industrial device 704 can be made verifiable through the verifiability of the control device. This is done by verifying the physical transformation in the form of device state data, including the verification of the state sequence representing the physical transformation. The proof of verification in the form of the latest copy of the verification contract is downloaded from the blockchain network 710.

[0153] In this way, the various embodiments described herein provide a secure, trust-based, efficient, reliable, scalable, modular, and cost-effective industrial automation system. Further, by being able to implement the various techniques described herein using lightweight clients as well as full embedded blockchain nodes, the overall system becomes very efficient, scalable, and cost-effective. Additionally, the presence of lightweight clients also enables the realization of an appropriate edge computing architecture on the industrial automation system.

[0154] The above description provides only embodiments as specific examples and is not intended to limit the scope of the disclosure, its applicability, or its configuration. Rather, the above description of embodiments as specific examples will provide those skilled in the art with an explanation that enables the implementation of one or more embodiments as specific examples. Various changes can be made to the functions and configurations of the elements without departing from the spirit and scope of the disclosed subject matter as recited in the appended claims.

[0155] Specific details are provided in the above description to obtain a full understanding of the embodiments. However, those skilled in the art will understand that the embodiments can be practiced without these specific details. For example, systems, processes, and other elements in the disclosed subject matter may sometimes be shown as components in block diagram form so as not to obscure the embodiments with unnecessary details. In other instances, well-known processes, structures, and techniques may be shown without unnecessary detail so as not to obscure the embodiments. Further, like reference numbers and designations in the various drawings indicate like elements.

[0156] Also, individual embodiments may be described as a process shown as a flowchart, a flow diagram, a data flow diagram, a structure diagram, or a block diagram. A flowchart may describe operations as a sequential process, but many of the operations can be performed in parallel or simultaneously. In addition, the order of the operations may be rearranged. A process may end when its operations are completed, but may have additional steps that are not discussed or are not included in the figure. Further, all of the operations in any specifically described process may not occur in all embodiments. A process may correspond to a method, a function, a procedure, a subroutine, a subprogram, etc. When a process corresponds to a function, the end of the function may correspond to returning the function to the calling function or the main function.

[0157] Furthermore, embodiments of the disclosed subject matter may be implemented, at least in part, either manually or automatically. The manual or automatic implementation may be executed or at least assisted through the use of a machine, hardware, software, firmware, middleware, microcode, a hardware description language, or any combination thereof. When implemented in software, firmware, middleware or microcode, the program code or code segments for performing the necessary tasks may be stored on a machine-readable medium. A processor (or processors) may perform the necessary tasks.

[0158] The various methods or processes outlined herein may be encoded as software executable on one or more processors employing any one of a variety of operating systems or platforms. Additionally, such software may be written using any of a plurality of suitable programming languages and / or programming or scripting tools and may be compiled as executable machine language code or intermediate code that is executed on a framework or virtual machine. Typically, the functionality of program modules may be combined or distributed as desired in various embodiments.

[0159] Embodiments of the present disclosure may be embodied as a method, and an example thereof is provided. The order of operations executed as part of this method may be determined in any suitable way. Accordingly, embodiments may be configured so that operations are performed in an order different from that illustrated, which may include performing some operations simultaneously that are shown as a series of operations in the exemplary embodiments. Although the present disclosure has been described with reference to several preferred embodiments, it should be understood that various other adaptations and modifications can be made within the spirit and scope of the present disclosure. Accordingly, it is the aspect of the following claims to cover all such variations and modifications that fall within the true spirit and scope of the present disclosure.

Claims

1. A blockchain-based industrial automation system capable of accessing a blockchain network, wherein the blockchain-based industrial automation system comprises at least one controller computer, and the at least one controller computer includes at least one processor and a memory storing instructions which, when executed by the at least one processor, cause the at least one controller computer to download the latest block and the associated encrypted certificate from the blockchain network, authenticate the update operation of the at least one controller based on the downloaded latest block and the associated encrypted certificate, and generate a response for controlling the execution operation on the at least one controller based on the authentication. A blockchain-based industrial automation system.

2. further comprises one or more industrial devices, each of the one or more industrial devices being configured to transmit device status data to the at least one controller computer, the device status data being associated with corresponding incoming commands associated with the update operation. The blockchain-based industrial automation system according to claim 1.

3. The update operation is a verifiable computing execution command associated with verification of the device status data of the one or more industrial devices based on a verification contract. The blockchain-based industrial automation system according to claim 1.

4. The one or more industrial devices comprise one or more of a sensor device and an actuator device. The blockchain-based industrial automation system according to claim 2.

5. further comprises a server computing system, the at least one controller system being configured to transmit the incoming commands to the server computing system, and the server computing system Download the latest block and the associated encrypted certificate from the blockchain network, Based on the downloaded latest block and the associated encrypted certificate, authenticate the update operation of the at least one controller computer, The blockchain-based industrial automation system according to claim 1, configured to generate the response for controlling the execution operation on the at least one controller computer based on the authentication.

6. The blockchain-based industrial automation system according to claim 1, wherein the update operation is a firmware update command.

7. The blockchain-based industrial automation system according to claim 1, wherein the update operation is an industrial automation process execution command.

8. The blockchain-based industrial automation system according to claim 1, wherein the memory comprises a unikernel for storing the instructions.

9. The blockchain-based industrial automation system according to claim 8, wherein the unikernel is associated with an edge computing architecture.

10. The blockchain-based industrial automation system according to claim 1, wherein the at least one controller is configured to communicate messages with the blockchain network using a communication protocol that depends on the protocol of the blockchain network.

11. The blockchain-based industrial automation system according to claim 1, wherein the at least one controller is configured to communicate messages with the blockchain network using a communication protocol that depends on the protocol of a permissioned blockchain network.

12. The blockchain-based industrial automation system according to claim 1, wherein the authentication of the update operation is performed based on the invocation of one or more types of system call requests.

13. A method for providing blockchain-based industrial automation, the method comprising: Downloading the latest block from a blockchain network and the associated encrypted certificate of the latest block; Based on the downloaded latest block and the associated encrypted certificate, authenticating an update operation of at least one controller computer; Generating a response for controlling an execution operation on the at least one controller computer based on the authentication. A method comprising the steps of:

14. Authenticating the update operation includes: Sending device state data in an incoming command associated with the update operation from one or more industrial devices to the at least one controller computer; Further comprising authenticating the incoming command based on the device state data, the downloaded latest block, and the associated encrypted certificate. The method according to claim 13.

15. Authenticating the update operation further includes executing a verifiable computing execution command associated with verification of the device state data of the one or more industrial devices based on a verification contract. The method according to claim 14.

16. The downloaded latest block comprises data associated with a set of valid commands for the one or more industrial devices, and when the incoming command is included in the set of valid commands, the incoming command is authenticated for execution. The method according to claim 14.

17. Generating a response for controlling an operation on the at least one controller computer includes permitting transmission of a control command from the at least one controller computer to the one or more industrial devices, the control command being associated with modification of the device state data of the one or more industrial devices. The method according to claim 16.

18. Further comprising sending the incoming command of the at least one controller computer to a server computing system, the server computing system: Downloading the latest block from the blockchain network and the associated encrypted certificate of the latest block; Based on the downloaded latest block and the associated encrypted certificate, authenticate the update operation of the at least one controller computer, The method according to claim 13, configured to generate the response for controlling the execution operation on the at least one controller computer based on the authentication.

19. The method according to claim 13, wherein the update operation is at least one of a firmware update command and an industrial process automation command.

20. The method according to claim 13, wherein the at least one controller comprises a memory with a unikernel for storing one or more computer-executable instructions for executing the method according to claim 13.

21. The method according to claim 13, wherein the authentication of the update operation is performed based on the invocation of one or more types of system call requests.

22. A non-transitory computer-readable storage medium having a program executable by a processor implemented for a method for blockchain-based industrial automation, the method comprising: Downloading a latest block and an associated encrypted certificate of the latest block from a blockchain network; Authenticating an update operation of at least one controller computer based on the downloaded latest block and the associated encrypted certificate; Generating a response for controlling an execution operation on the at least one controller computer based on the authentication.

Citation Information

Patent Citations

  • Method and control system for controlling and / or monitoring equipment

    JP2021500789A

  • Version history management using blockchain

    JP2022529689A

  • Blockchain based secure naming and update verification

    US20190245680A1