Configuration verification device, configuration verification method, configuration verification program, communication identification device, communication identification method, and communication identification program
The setting verification and communication identification devices address the issue of mismatched PLC communication settings by verifying and identifying communication settings and networks, ensuring consistent and secure operation.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- FUJI ELECTRIC CO LTD
- Filing Date
- 2025-06-12
- Publication Date
- 2026-05-19
AI Technical Summary
The communication settings of multiple Programmable Logic Controllers (PLCs) may not match, leading to operational issues, and it is difficult for humans to extract specific communication from between PLCs.
A setting verification device and a communication identification device are introduced, each comprising a verification unit and an identification unit, respectively, to verify and identify communication settings and networks by comparing first and second communication setting information between control devices.
Enables verification of communication settings and identification of communications performed by control devices, ensuring consistent and secure communication between PLCs.
Smart Images

Figure 2026082624000001_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to a setting verification technique for verifying communication settings of a control device and a communication identification technique for identifying communication performed by a control device.
Background Art
[0002] Regarding the setting of a Programmable Logic Controller (PLC), a programmable logic controller setting file generation support device is known (for example, refer to Patent Document 1). A programmable logic controller engineering tool is also known (for example, refer to Patent Document 2).
Prior Art Documents
Patent Documents
[0003]
Patent Document 1
Patent Document 2
Summary of the Invention
Problems to be Solved by the Invention
[0004] When the communication settings of a plurality of PLCs do not match, there is a risk that each PLC will not operate. Also, it is difficult for a human to extract specific communication from the communication between PLCs.
[0005] In one aspect, an object of the present invention is to verify the communication settings of a control device that controls a controlled device.
[0006] In another aspect, an object of the present invention is to identify communication performed by a control device that controls a controlled device.
Means for Solving the Problems
[0007] According to one embodiment, the setting verification device includes a verification unit and an output unit. The verification unit generates a verification result by verifying the consistency between the first communication setting information set in the first control device and the second communication setting information set in the second control device. The first control device is a control device that controls the first controlled device. The second control device is a control device that communicates with the first control device and controls the second controlled device. The output unit outputs the verification result.
[0008] According to another embodiment, the communication identification device includes an identification unit and an output unit. The identification unit identifies communication between two communication networks based on first communication setting information set in the first control device and second communication setting information set in the second control device, and generates an analysis result indicating communication between the two communication networks. The first control device is a control device that controls the first controlled device. The second control device is a control device that communicates with the first control device and controls the second controlled device. The output unit outputs the analysis result. [Effects of the Invention]
[0009] From one perspective, it is possible to verify the communication settings of the control device that controls the controlled device.
[0010] From another perspective, it is possible to identify the communications performed by the control device that controls the controlled device. [Brief explanation of the drawing]
[0011] [Figure 1] This is a functional configuration diagram of the setting verification device of the embodiment. [Figure 2] This is a flowchart of the first verification process. [Figure 3] This is a diagram showing the configuration of the first control system. [Figure 4] This diagram shows the project files stored in the support device of the first control system. [Figure 5] This diagram shows the information stored in the PLC of the first control system. [Figure 6]It is a diagram showing setting data in the first control system. [Figure 7] It is a diagram showing security data in the first control system. [Figure 8] It is a functional configuration diagram of a setting verification device in the first control system. [Figure 9] It is a diagram showing metadata D1 in the first control system. [Figure 10] It is a diagram showing metadata D2 in the first control system. [Figure 11] It is a flowchart of the second verification process in the first control system. [Figure 12] It is a flowchart of a setting extraction process in the first control system. [Figure 13] It is a flowchart of a communication identification process in the first control system. [Figure 14] It is a diagram showing a communication server list in the first control system. [Figure 15] It is a diagram showing a communication client list in the first control system. [Figure 16] It is a diagram showing a certificate list in the first control system. [Figure 17] It is a flowchart of a communication setting verification process in the first control system. [Figure 18] It is a diagram showing a result list in the first control system. [Figure 19] It is a diagram showing a NG list in the first control system. [Figure 20] It is a diagram showing a display screen of verification results in the first control system. [Figure 21] It is a configuration diagram of the second control system. [Figure 22] It is a diagram showing a project file stored in an assistance device of the second control system. [Figure 23] It is a diagram showing information stored in a PLC of the second control system. [Figure 24]This figure shows the setting data for the second control system. [Figure 25] This figure shows the security data in the second control system. [Figure 26] This figure shows metadata D2 in the second control system. [Figure 27] This figure shows metadata D3 in the second control system. [Figure 28] This figure shows the communication client list in the second control system. [Figure 29] This is a diagram showing the certificate list in the second control system. [Figure 30] This figure shows the results list in the second control system. [Figure 31] This is a diagram showing the NG list in the second control system. [Figure 32] This figure shows the display screen for the verification results in the second control system. [Figure 33] This is a functional configuration diagram of the communication-specific device according to the embodiment. [Figure 34] This is a flowchart of the first specific process. [Figure 35] This is a diagram illustrating the configuration of the third control system. [Figure 36] This diagram shows the project files stored in the support device of the third control system. [Figure 37] This diagram shows the information stored in the PLC of the third control system. [Figure 38] This diagram shows the setting data for the third control system. [Figure 39] This diagram shows the communication settings information in the third control system. [Figure 40] This is a functional configuration diagram of the communication-specific device in the third control system. [Figure 41] This figure shows metadata D1 in the third control system. [Figure 42] This figure shows metadata D2 in the third control system. [Figure 43] This figure shows metadata D3 in the third control system. [Figure 44] This is a flowchart of the second specific process in the third control system. [Figure 45] This is a flowchart of the setting extraction process in the third control system. [Figure 46] This is a flowchart of the communication identification process in the third control system. [Figure 47] This is a diagram showing the communication server list in the third control system. [Figure 48] This figure shows the communication client list in the third control system. [Figure 49] This is a flowchart of the communication analysis process in the third control system. [Figure 50] This figure shows the results list in the third control system. [Figure 51] This figure shows the display screen for the analysis results in the third control system. [Figure 52] This is a hardware configuration diagram of an information processing device. [Modes for carrying out the invention]
[0012] The embodiments will be described in detail below with reference to the drawings.
[0013] Figure 1 shows an example of the functional configuration of the setting verification device of the embodiment. The setting verification device 101 in Figure 1 includes a verification unit 111 and an output unit 112.
[0014] Figure 2 is a flowchart showing an example of the first verification process performed by the setting verification device 101 in Figure 1. First, the verification unit 111 generates a verification result by verifying the consistency between the first communication setting information set in the first control device and the second communication setting information set in the second control device (step 201). The first control device is a control device that controls the first controlled device. The second control device is a control device that communicates with the first control device and controls the second controlled device. Next, the output unit 112 outputs the verification result (step 202).
[0015] According to the setting verification device 101 in Figure 1, the communication settings of the control device that controls the controlled device can be verified.
[0016] Figure 3 shows an example configuration of a first control system including the setting verification device 101 of Figure 1. The control system in Figure 3 includes the setting verification device 301, support devices 302-1 and 302-2, PLCs 303-1 and 303-2, a controlled device 304-1, and a controlled device 304-2. The setting verification device 301 is an example of the setting verification device 101 of Figure 1.
[0017] The setting verification device 301 communicates with the support device 302-1 via communication line 311-1 and with the support device 302-2 via communication line 311-2. The support device 302-1 communicates with PLC 303-1 via communication line 312-1. The support device 302-2 communicates with PLC 303-2 via communication line 312-2. PLC 303-1 communicates with PLC 303-2 via communication line 313.
[0018] PLC303-1 controls the controlled device 304-1 via communication line 314-1. PLC303-2 controls the controlled device 304-2 via communication line 314-2.
[0019] PLC303-1 is an example of the first control device, and PLC303-2 is an example of the second control device. Controlled device 304-1 is an example of the first controlled device, and controlled device 304-2 is an example of the second controlled device.
[0020] The controlled device 304-i (i=1,2) may be, for example, a manufacturing device, a conveying device, an inspection device, etc., in factory automation. The controlled device 304-i may also be a motor, encoder, pump, valve, camera, sensor, etc.
[0021] Figure 4 shows examples of project files stored by support devices 302-1 and 302-2 in Figure 3. Support device 302-i (i=1,2) stores project file 411-i for PLC303-i. Project file 411-i includes source code 421-i for PLC303-i, security management information for the device itself 422-i, and security management information for the communication destination device 423-i.
[0022] Source code 421-i includes communication FB (Function Block) 431-i, and communication FB 431-i includes configuration data 441-i.
[0023] The configuration data 441-1 included in communication FB431-1 is an example of first communication configuration information. The configuration data 441-2 included in communication FB431-2 is an example of second communication configuration information.
[0024] The security management information 422-1 of the support device 302-1 includes security data 432-1, and the security management information 423-1 of the communication destination device includes security data 432-2. The security management information 422-2 of the support device 302-2 includes security data 432-2, and the security management information 423-2 of the communication destination device includes security data 432-1.
[0025] Security data 432-i (i=1,2) is a self-signed certificate of PLC303-i, which is pre-generated by PLC303-i using a digital signature. Support device 302-i obtains security data 432-i from PLC303-i and stores it in its own device security management information 422-1.
[0026] Furthermore, the support device 302-1 acquires the security data 432-2 from the PLC 303-2 and stores it in the security management information 423-1 of the communication destination device. For example, a user may copy the security data 432-2 from the security management information 422-2 of the support device 302-2 to the security management information 423-1 of the communication destination device of the support device 302-1.
[0027] The support device 302-2 acquires the security data 432-1 from the PLC 303-1 and stores it in the communication destination device security management information 423-2. For example, a user may copy the security data 432-1 from the support device 302-1's own device security management information 422-1 to the support device 302-2's communication destination device security management information 423-2.
[0028] The security management information for this device 422-1 and the security management information for the communication destination device 423-1 are examples of first communication configuration information. The security management information for this device 422-2 and the security management information for the communication destination device 423-2 are examples of second communication configuration information.
[0029] The security data 432-1 included in the security management information 422-1 of the self-device is an example of the security information of the first control unit. The security data 432-2 included in the security management information 423-1 of the communication destination device is an example of the security information of the communication destination of the first control unit.
[0030] The security data 432-2 included in the security management information 422-2 of the self-device is an example of the security information of the second control unit. The security data 432-1 included in the security management information 423-2 of the communication destination device is an example of the security information of the communication destination of the second control unit.
[0031] Figure 5 shows an example of the information stored by PLC303-1 and PLC303-2 in Figure 3. PLC303-i (i=1,2) stores the execution program 511-i for PLC303-i, the device's own security management information 512-i, and the communication destination device's security management information 513-i.
[0032] The executable program 511-i is generated from the source code 421-i by the support device 302-i and installed on the PLC 303-i. The executable program 511-i includes the communication FB431-i.
[0033] The security management information 512-1 of PLC303-1 includes security data 432-1, and the security management information 513-1 of the communication destination device includes security data 432-2. Security data 432-2 is installed on PLC303-1 from the support device 302-1.
[0034] The security management information 512-2 of PLC303-2 includes security data 432-2, and the security management information 513-2 of the communication destination device includes security data 432-1. Security data 432-1 is installed on PLC303-2 from the support device 302-2.
[0035] The device security management information 512-i further includes a secret key corresponding to the security data 432-i.
[0036] PLC303-i controls the controlled device 304-i by executing the execution program 511-i.
[0037] Figure 6 shows examples of setting data 441-1 and setting data 441-2 in the control system shown in Figure 3. Figure 6(a) shows an example of setting data 441-1, and Figure 6(b) shows an example of setting data 441-2.
[0038] The configuration data 441-i in Figures 6(a) and 6(b) includes the FB name, local IP (Internet Protocol) address, destination IP address, protocol, local port number, destination port number, and connection type. The FB name is the identification information for communication FB431-i, while the local IP address, destination IP address, protocol, local port number, destination port number, and connection type are configuration items.
[0039] The FB name in Figure 6(a) is Communication FB1, and the FB name in Figure 6(b) is Communication FB2. Therefore, the FB name of Communication FB431-1 is Communication FB1, and the FB name of Communication FB431-2 is Communication FB2.
[0040] The "Local IP Address" in configuration data 441-i represents the IP address of the PLC303-i that stores the communication FB431-i. The "Destination IP Address" represents the IP address of the communication destination of the PLC303-i. The "Protocol" represents the protocol used for communication. The "Local Port Number" represents the port number of the PLC303-i. The "Destination Port Number" represents the port number of the communication destination of the PLC303-i. The "Connection Configuration" represents the connection method of the PLC303-i in communication.
[0041] The local IP address included in the configuration data 441-1 in Figure 6(a) is an example of the address information of the first control unit, and the destination IP address is an example of the address information of the destination of communication for the first control unit.
[0042] The local port number included in the configuration data 441-1 in Figure 6(a) is an example of the port information of the first control unit, and the communication destination port number is an example of the communication destination port information of the first control unit.
[0043] The local IP address included in the configuration data 441-2 in Figure 6(b) is an example of the address information of the second control unit, and the destination IP address is an example of the destination address information of the second control unit.
[0044] The local port number included in the configuration data 441-2 in Figure 6(b) is an example of the port information of the second control unit, and the communication destination port number is an example of the communication destination port information of the second control unit.
[0045] The protocols in Figures 6(a) and 6(b) are set to TLS (Transport Layer Security). TLS is a protocol for secure communication.
[0046] Connection modes can be set to, for example, Active, Fullpassive, or Unpassive. Active represents an actively open connection. A PLC303-i that stores a communication FB431-i set to Active will attempt to connect to the PLC303-i indicated by the destination IP address.
[0047] Fullpassive indicates a passive open state. A PLC303-i that stores a communication FB431-i set to Fullpassive will only accept connections from the PLC303-i indicated by the destination IP address.
[0048] Unpassive indicates a passive open state. A PLC303-i that stores a communication FB431-i set to Unpassive will accept a connection from any PLC303-i indicated by an arbitrary IP address.
[0049] The connection configuration in Figure 6(a) is set to Active, and the connection configuration in Figure 6(b) is set to Fullpassive. Therefore, PLC303-1 attempts to establish a TLS connection with PLC303-2 and communicates with PLC303-2. During the TLS connection, mutual authentication is performed using security data 432-1 and security data 432-2.
[0050] Figure 7 shows examples of security data 432-1 and security data 432-2 in the control system of Figure 3. Figure 7(a) shows an example of security data 432-1, and Figure 7(b) shows an example of security data 432-2.
[0051] The security data 432-i in Figures 7(a) and 7(b) includes file name, organization (O), common name (CN), issue date, expiration date, and fingerprint. The file name is the identifying information of security data 432-i, while the organization (O), common name (CN), issue date, expiration date, and fingerprint are fields. Security data 432-i also includes other fields not shown.
[0052] The file name in Figure 7(a) is plc1.crt, and the file name in Figure 7(b) is plc2.crt. Therefore, the file name for security data 432-1 is plc1.crt, and the file name for security data 432-2 is plc2.crt.
[0053] The organization in security data 432-i represents the company name. The common name represents the IP address set in configuration data 441-i. The issue date represents the date and time security data 432-i was issued. The expiration date represents the expiration date of security data 432-i. The fingerprint is a hash value calculated for the entire security data 432-i, including items not shown.
[0054] The expiration date of security data 432-1 included in the security management information 422-1 of the device itself is an example of the expiration date of the security information of the first control unit. The expiration date of security data 432-2 included in the security management information 423-1 of the communication destination device is an example of the expiration date of the security information of the communication destination of the first control unit.
[0055] The expiration date of security data 432-2 included in the security management information 422-2 of the device itself is an example of the expiration date of the security information of the second control unit. The expiration date of security data 432-1 included in the security management information 423-2 of the communication destination device is an example of the expiration date of the security information of the communication destination of the second control unit.
[0056] Figure 8 shows an example of the functional configuration of the setting verification device 301 shown in Figure 3. The setting verification device 301 in Figure 8 includes a communication unit 811, an extraction unit 812, a specific unit 813, a verification unit 814, a display unit 815, and a storage unit 816. The verification unit 814 and the display unit 815 correspond to the verification unit 111 and the output unit 112 in Figure 1, respectively.
[0057] The communication unit 811 communicates with the support device 302-1 via communication line 311-1 and with the support device 302-2 via communication line 311-2.
[0058] The extraction unit 812 extracts information from the support device 302-1 via the communication unit 811 for generating metadata D1 for PLC 303-1. The information for generating metadata D1 consists of setting data 441-1, security data 432-1 within the local device security management information 422-1, and security data 432-2 within the communication destination device security management information 423-1. The extraction unit 812 generates metadata D1 using the extracted information.
[0059] Furthermore, the extraction unit 812 extracts information from the support device 302-2 via the communication unit 811 for generating metadata D2 for the PLC 303-2. The information for generating metadata D2 consists of setting data 441-2, security data 432-2 within the self-device security management information 422-2, and security data 432-1 within the communication destination device security management information 423-2. The extraction unit 812 generates metadata D2 using the extracted information.
[0060] The extraction unit 812 then generates metadata 821, which includes metadata D1 and metadata D2, and stores it in the storage unit 816.
[0061] Figure 9 shows an example of metadata D1 in the control system shown in Figure 3. The metadata D1 in Figure 9 includes the target, communication FB settings, local device security data, and communication destination security data.
[0062] The target is the identification information of PLC303-1 indicated by metadata D1. In the example in Figure 9, the identification information of PLC303-1 is PLC1.
[0063] The communication FB setting includes the number of data entries and the number of data entries indicated by the number of data entries. In the example in Figure 9, the number of data entries is 1, and the corresponding data entry 1 includes the setting data 441-1 in Figure 6(a). If the number of data entries is 2 or more, the number of data entries stored in the communication FB setting increases.
[0064] The device's security data includes data. In the example in Figure 9, the data includes security data 432-1 from Figure 7(a). The security data type is the device certificate.
[0065] The communication destination security data includes the data count and the number of data items indicated by the data count. In the example in Figure 9, the data count is 1, and the corresponding data 1 includes security data 432-2 in Figure 7(b). The security data type is a device certificate. If the data count is 2 or more, the number of data items stored in the communication destination security data increases.
[0066] Figure 10 shows an example of metadata D2 in the control system shown in Figure 3. The metadata D2 in Figure 10 includes the target, communication FB settings, local device security data, and communication destination security data.
[0067] The target represents the identification information of PLC303-2 indicated by metadata D2. In the example in Figure 10, the identification information of PLC303-2 is PLC2.
[0068] The communication FB setting includes the number of data entries and the number of data entries indicated by the number of data entries. In the example in Figure 10, the number of data entries is 1, and the corresponding data entry 1 includes the setting data 441-2 in Figure 6(b). If the number of data entries is 2 or more, the number of data entries stored in the communication FB setting increases.
[0069] The device's security data includes data. In the example in Figure 10, the data includes security data 432-2 from Figure 7(b). The security data type is the device certificate.
[0070] The communication destination security data includes the data count and the number of data items indicated by the data count. In the example in Figure 10, the data count is 1, and the corresponding data 1 includes security data 432-1 in Figure 7(a). The security data type is a device certificate. If the data count is 2 or more, the number of data items stored in the communication destination security data increases.
[0071] The identification unit 813 uses metadata D1 and metadata D2 contained in metadata 821 to identify the communication taking place between PLC303-1 and PLC303-2. The identification unit 813 then generates a communication server list 822, a communication client list 823, and a certificate list 824 representing the identified communication and stores them in the storage unit 816.
[0072] The communication server list 822 is a list of communication servers, and the communication client list 823 is a list of communication clients. The certificate list 824 contains information on security data 432-i used for mutual authentication when a communication client connects to a communication server.
[0073] The verification unit 814 verifies the consistency of the communication settings of PLC303-1 and PLC303-2 for the identified communication by performing a communication setting verification process using the communication server list 822, the communication client list 823, and the certificate list 824. The verification unit 814 then generates a verification result 825, which includes the results of the communication setting verification process, and stores it in the storage unit 816.
[0074] Verification result 825 includes result list 831 and NG list 832. Result list 831 is a list of the results of the communication setting verification process, and NG list 832 is a list of information showing the details of the NG results.
[0075] The display unit 815 presents the verification results 825 to the user by displaying them on the screen. The user can then confirm the consistency of the communication settings of PLC303-1 and PLC303-2 from the displayed verification results 825.
[0076] The setting verification device 301 may transmit the verification result 825 to a user terminal device (not shown) via the communication unit 811, instead of displaying it on the screen. The user terminal device displays the verification result 825 received from the setting verification device 301 on its screen.
[0077] Figure 11 is a flowchart showing an example of the second verification process performed by the setting verification device 301 in Figure 8. First, the extraction unit 812 performs a setting extraction process to generate metadata 821 (step 1101). Next, the identification unit 813 performs a communication identification process to generate a communication server list 822, a communication client list 823, and a certificate list 824 (step 1102).
[0078] Next, the verification unit 814 performs a communication setting verification process and generates a verification result 825 (step 1103). Then, the display unit 815 displays the verification result 825 on the screen (step 1104).
[0079] Figure 12 is a flowchart showing an example of the setting extraction process in step 1101 of Figure 11. First, the extraction unit 812 refers to the project file 411-i of each support device 302-i (i=1,2) via the communication unit 811 (step 1201).
[0080] In step 1201, the support device 302-i may upload the project file 411-i to the setting verification device 301, and the extraction unit 812 may refer to the uploaded project file 411-i.
[0081] Next, the extraction unit 812 analyzes the source code 421-i in each project file 411-i and identifies the communication FB 431-i. Then, the extraction unit 812 obtains the configuration data 441-i from the identified communication FB 431-i (step 1202).
[0082] If the protocol included in the configuration data 441-i is TLS, the extraction unit 812 retrieves each security data 432-i (organization, common name, issue date, expiration date, and fingerprint) from the project file 411-i (step 1203).
[0083] Next, the extraction unit 812 generates metadata 821 using the acquired configuration data 441-i and security data 432-i (step 1204).
[0084] Figure 13 is a flowchart showing an example of the communication identification process in step 1102 of Figure 11. First, the identification unit 813 obtains one metadata Di(i=1,2) from the metadata 821 (step 1301).
[0085] Next, the specific unit 813 checks the connection type included in the communication FB settings of the acquired metadata Di (step 1302).
[0086] If the connection status is Active (step 1302, YES), the identification unit 813 determines that the PLC303-i indicated by the metadata Di is a communication client. The identification unit 813 then adds the information contained in the metadata Di to the communication client list 823 and the certificate list 824 (step 1303).
[0087] If the connection status is not Active (Step 1302, NO), the identification unit 813 determines that the PLC303-i indicated by the metadata Di is a communication server. The identification unit 813 then adds the information contained in the metadata Di to the communication server list 822 and the certificate list 824 (Step 1304).
[0088] Next, the identification unit 813 checks whether all metadata Di have been acquired (step 1305). If there are any metadata Di that have not been acquired (step 1305, NO), the identification unit 813 repeats the processing from step 1301 onwards for the next metadata Di. If all metadata Di have been acquired (step 1305, YES), the identification unit 813 terminates the process.
[0089] Figure 14 shows an example of a communication server list 822 in the control system shown in Figure 3. The communication server list 822 in Figure 14 includes a communication ID, device ID, communication FBID, connection type, local IP address, destination IP address, and local port number.
[0090] The communication ID is automatically assigned when a record (row) is added to the communication server list 822. The device ID is obtained from the target of the metadata Di. The communication FBID is obtained from the FB name in the communication FB settings of the metadata Di. The connection type, local IP address, destination IP address, and local port number are obtained from the communication FB settings of the metadata Di.
[0091] In this example, metadata D2 in Figure 10 is acquired, and the connection type included in the communication FB settings of metadata D2 is checked. Since the connection type of metadata D2 is Fullpassive, it is determined that PLC303-2 is the communication server.
[0092] Therefore, a record is added to the communication server list 822, and the automatically assigned number S001 is recorded as the communication ID. The target of metadata D2 is recorded as the device ID, and the FB name of the communication FB setting in metadata D2 is recorded as the communication FB ID. Furthermore, the communication FB setting information of metadata D2 is recorded in the connection type, local IP address, destination IP address, and local port number.
[0093] Figure 15 shows an example of a communication client list 823 in the control system shown in Figure 3. The communication client list 823 in Figure 15 includes a communication ID, device ID, communication FBID, connection type, local IP address, destination IP address, and destination port number.
[0094] The communication ID is automatically assigned when a record is added to the communication client list 823. The device ID is obtained from the target of the metadata Di. The communication FBID is obtained from the FB name in the communication FB settings of the metadata Di. The connection type, local IP address, destination IP address, and destination port number are obtained from the communication FB settings of the metadata Di.
[0095] In this example, metadata D1 in Figure 9 is acquired, and the connection type included in the communication FB settings of metadata D1 is checked. Since the connection type of metadata D1 is Active, it is determined that PLC303-2 is the communication client.
[0096] Therefore, a record is added to the communication client list 823, and the automatically assigned number C001 is recorded as the communication ID. The target of metadata D1 is recorded as the device ID, and the FB name of the communication FB setting in metadata D1 is recorded as the communication FB ID. Furthermore, the communication FB setting information of metadata D1 is recorded in the connection type, local IP address, destination IP address, and destination port number.
[0097] Figure 16 shows an example of a certificate list 824 in the control system shown in Figure 3. The certificate list 824 in Figure 16 includes the certificate ID, device ID, communication FBID, certificate subject, organization, common name, issue date, expiration date, and fingerprint.
[0098] The certificate ID is automatically assigned when a record is added to certificate list 824. The device ID is obtained from the target in the metadata Di. The communication FBID is obtained from the FB name in the communication FB settings of the metadata Di. The organization, common name, issue date, expiration date, and fingerprint are obtained from the local device security data or the communication destination device security data in the metadata Di.
[0099] For records containing information obtained from the security data of the local device, the local device is recorded as the certificate target. For records containing information obtained from the security data of the communication destination device, the communication destination device is recorded as the certificate target.
[0100] In this example, when metadata D1 in Figure 9 is acquired and the record shown in Figure 15 is added to the communication client list 823, two records are added to the certificate list 824. The communication IDs of the two added records are then recorded as the automatically assigned CER001 and CER002, respectively.
[0101] Next, the device ID of the CER001 record is recorded with the target of metadata D1, and the FB name of the communication FB setting in metadata D1 is recorded with the communication FB ID. Furthermore, the device itself is recorded as the certificate target, and the information from the device's security data in metadata D1 is recorded with the organization, common name, issue date, expiration date, and fingerprint.
[0102] Next, the device ID of the CER002 record is recorded with the target of metadata D1, and the FB name of the communication FB setting in metadata D1 is recorded with the communication FB ID. Furthermore, the destination device is recorded with the certificate target, and the information of the destination device security data in metadata D1 is recorded with the organization, common name, issue date, expiration date, and fingerprint.
[0103] Next, when metadata D2 in Figure 10 is acquired and the record shown in Figure 14 is added to the communication server list 822, two records are added to the certificate list 824. Then, the automatically assigned communication IDs CER003 and CER004 are recorded in the communication IDs of the two added records, respectively.
[0104] Next, the device ID of the CER003 record is recorded with the target of metadata D2, and the communication FB ID is recorded with the FB name of the communication FB setting in metadata D2. Furthermore, the device itself is recorded as the certificate target, and the organization, common name, issue date, expiration date, and fingerprint information of the device's security data in metadata D2 are recorded.
[0105] Next, the device ID of the CER004 record is recorded with the target of metadata D2, and the communication FB ID is recorded with the FB name of the communication FB setting in metadata D2. Furthermore, the destination device is recorded with the certificate target, and the organization, common name, issue date, expiration date, and fingerprint information of the destination device security data in metadata D2 are recorded.
[0106] Figure 17 is a flowchart showing an example of the communication setting verification process in step 1103 of Figure 11. First, the verification unit 814 obtains one record from the communication server list 822 as record Sm (step 1701) and one record from the communication client list 823 as record Cn (step 1702).
[0107] Next, the verification unit 814 checks whether the combination of record Sm and record Cn represents communication between PLCs (step 1703).
[0108] If the local IP address of record Sm matches the destination IP address of record Cn, the verification unit 814 determines that the combination of record Sm and record Cn represents communication between PLCs. On the other hand, if the local IP address of record Sm does not match the destination IP address of record Cn, the verification unit 814 determines that the combination of record Sm and record Cn does not represent communication between PLCs.
[0109] If the combination of record Sm and record Cn represents communication between PLCs (step 1703, YES), the verification unit 814 verifies the consistency between record Sm and record Cn (step 1704). The verification unit 814 then records the results of the consistency verification in the result list 831 and NG list 832 within the verification result 825 (step 1705). In step 1704, the verification unit 814 performs the following verifications P1 to P4.
[0110] P1: Connection type consistency
[0111] If the connection type of record Sm is Fullpassive, the verification unit 814 checks whether the following conditions are met.
[0112] Condition A1: The destination IP address of record Sm matches the local IP address of record Cn.
[0113] Condition A2: The local port number in record Sm matches the destination port number in record Cn.
[0114] If conditions A1 and A2 are met, the verification unit 814 records a check result OK in the result list 831, indicating that the connection configuration is consistent. If at least one of conditions A1 or A2 is not met, the verification unit 814 records a check result NG in the result list 831, indicating that the connection configuration is inconsistent, and records the details of the check result NG in the NG list 832.
[0115] By checking whether condition A1 is met, it is possible to verify whether the IP addresses used for communication between PLC303-i indicated by record Sm and PLC303-i indicated by record Cn are consistent.
[0116] The process of checking whether condition A1 is met is an example of a process that verifies the consistency between the address information of the first control unit included in the first communication configuration information and the address information of the communication destination of the second control unit included in the second communication configuration information.
[0117] By checking whether condition A2 is met, it is possible to verify whether the port numbers used for communication between PLC303-i indicated by record Sm and PLC303-i indicated by record Cn are consistent.
[0118] The process of checking whether condition A2 is met is an example of a process that verifies the consistency between the port information of the first control device's communication destination included in the first communication configuration information and the port information of the second control device included in the second communication configuration information.
[0119] P2: TLS Server Authentication
[0120] The verification unit 814 checks whether the following two records exist in the certificate list 824.
[0121] Record R1: A record containing the same device ID and communication FBID as Record Sm, where the certificate target is the same device.
[0122] Record R2: A record containing the same device ID and communication FBID as record Cn, where the certificate target is the communication destination device.
[0123] If records R1 and R2 exist, the verification unit 814 checks whether the fingerprint of record R1 matches the fingerprint of record R2.
[0124] If records R1 and R2 exist, and the fingerprint of record R1 matches the fingerprint of record R2, the verification unit 814 records a check result of OK in the result list 831, indicating that TLS server authentication was successful.
[0125] If the fingerprint of record R1 does not match the fingerprint of record R2, the verification unit 814 records a check result NG, indicating that TLS server authentication failed, in the result list 831, and records the details of the check result NG in the NG list 832. If at least one of record R1 or record R2 does not exist, the verification unit 814 also records a check result NG, indicating that TLS server authentication failed, in the result list 831, and records the details of the check result NG in the NG list 832.
[0126] By checking whether record R1 exists, it is possible to verify whether the security data 432-i is included in the self-device security management information 512-i of PLC303-i indicated by record Sm. By checking whether record R2 exists, it is possible to verify whether the security data 432-i is included in the communication destination device security management information 513-i of PLC303-i indicated by record Cn.
[0127] By comparing the fingerprints of record R1 and record R2, it is possible to verify whether the security data 432-i used for mutual authentication is consistent between the PLC303-i indicated by record Sm and the PLC303-i indicated by record Cn.
[0128] The P2 verification is an example of a process that verifies the consistency between the security information of the communication destination of the first control unit included in the first communication configuration information and the security information of the second control unit included in the second communication configuration information.
[0129] P3: TLS Client Authentication
[0130] The verification unit 814 checks whether the following two records exist in the certificate list 824.
[0131] Record R3: A record containing the same device ID and communication FBID as record Cn, where the certificate target is the same device.
[0132] Record R4: A record containing the same device ID and communication FBID as record Sm, where the certificate target is the communication destination device.
[0133] If records R3 and R4 exist, the verification unit 814 checks whether the fingerprint of record R3 matches the fingerprint of record R4.
[0134] If records R3 and R4 exist, and the fingerprint of record R3 matches the fingerprint of record R4, the verification unit 814 records a check result of OK in the result list 831, indicating that TLS client authentication was successful.
[0135] If the fingerprint of record R3 does not match the fingerprint of record R4, the verification unit 814 records a check result of NG in the result list 831, indicating that TLS client authentication failed. The verification unit 814 then records the details of the check result NG in the NG list 832.
[0136] If at least one of record R3 or record R4 does not exist, the verification unit 814 records a check result NG in the result list 831, indicating that TLS client authentication failed. The verification unit 814 then records the details of the check result NG in the NG list 832.
[0137] By checking whether record R3 exists, it is possible to verify whether the security data 432-i is included in the self-device security management information 512-i of PLC303-i indicated by record Cn. By checking whether record R4 exists, it is possible to verify whether the security data 432-i is included in the communication destination device security management information 513-i of PLC303-i indicated by record Sm.
[0138] By comparing the fingerprints of records R3 and R4, it is possible to verify whether the security data 432-i used for mutual authentication is consistent between the PLC303-i indicated by record Sm and the PLC303-i indicated by record Cn.
[0139] The P3 verification is an example of a process that verifies the consistency between the security information of the first control unit included in the first communication configuration information and the security information of the communication destination of the second control unit included in the second communication configuration information.
[0140] P4: Certificate expiration date
[0141] The verification unit 814 checks whether the expiration dates of each record R1 to R4 meet the following conditions.
[0142] Condition A3: The expiration date is a date and time that is at least a specified period of time in the future from the current date and time.
[0143] The specified period is, for example, a period ranging from 1 day to 5 years. If the expiration dates of each of records R1 to R4 satisfy condition A3, the verification unit 814 records a check result OK in the result list 831, indicating that the certificate expiration date is appropriate. If the expiration date of at least one of records R1 to R4 does not satisfy condition A3, the verification unit 814 records a check result NG in the result list 831, indicating that the certificate expiration date is inappropriate, and records the details of the check result NG in the NG list 832.
[0144] By checking whether the expiration date of each record satisfies condition A3, it is possible to verify whether there is sufficient remaining validity period for security data 432-i used for mutual authentication.
[0145] The P4 verification is an example of a process that checks the expiration dates of the security information of the first control unit, the security information of the communication destination of the first control unit, the security information of the second control unit, and the security information of the communication destination of the second control unit.
[0146] Next, the verification unit 814 checks whether all records have been retrieved from the communication client list 823 (step 1706). If there are any records that have not been retrieved (step 1706, NO), the verification unit 814 repeats the processing from step 1702 onwards for the next record.
[0147] If all records have been retrieved (Step 1706, YES), the verification unit 814 checks whether all records have been retrieved from the communication server list 822 (Step 1707). If there are any records that have not been retrieved (Step 1707, NO), the verification unit 814 repeats the process from Step 1701 onwards for the next record. If all records have been retrieved (Step 1707, YES), the verification unit 814 terminates the process.
[0148] Figure 18 shows an example of the result list 831 in the control system of Figure 3. The result list 831 in Figure 18 includes the verification ID, server communication ID, server device ID, server communication FBID, client communication ID, client device ID, and client communication FBID. The result list 831 in Figure 18 further includes the integrity of the connection type, TLS server authentication, TLS client authentication, and certificate expiration.
[0149] The verification ID is automatically assigned when a record is added to the result list 831. The verification unit 814 records the information of record Sm and record Cn in the result list 831.
[0150] The server communication ID is obtained from the communication ID in record Sm. The server device ID is obtained from the device ID in record Sm. The server communication FBID is obtained from the communication FBID in record Sm.
[0151] The client communication ID is obtained from the communication ID in record Cn. The client device ID is obtained from the device ID in record Cn. The client communication FBID is obtained from the communication FBID in record Cn.
[0152] Connection type integrity represents the result of the P1 verification check. TLS server authentication represents the result of the P2 verification check. TLS client authentication represents the result of the P3 verification check. Certificate expiration represents the result of the P4 verification check.
[0153] In this example, the record S001 in Figure 14 is retrieved as record Sm, and the record C001 in Figure 15 is retrieved as record Cn. The local IP address of the record S001 and the destination IP address of the record C001 are then compared.
[0154] The local IP address in record S001 is "192.168.32.63", and the destination IP address in record C001 is "192.168.32.63". Therefore, since they match, it is determined that the combination of record Sm and record Cn represents communication between PLCs. Then, one record is added to result list 831, and the automatically assigned number CK001 is recorded as the verification ID of the added record.
[0155] Next, the server communication ID, server device ID, and server communication FBID are recorded in the server communication ID, server device ID, and server communication FBID fields, respectively. Then, the client communication ID, client device ID, and client communication FBID are recorded in the client communication ID, client device ID, and client communication FBID fields, respectively.
[0156] Since the connection type of record S001 is Full Passive, verification of P1 is performed. The destination IP address of record S001 is "192.168.32.54" and the local port number is "443". Similarly, the local IP address of record C001 is "192.168.32.54" and the destination port number is "443". Therefore, conditions A1 and A2 are met, and OK is recorded for connection type consistency.
[0157] Next, verification of P2 is performed. Of the four records included in the certificate list 824 in Figure 16, the device ID and communication FBID of record CER003 are the same as the device ID and communication FBID of record S001, and the certificate target is the own device. Therefore, record CER003 corresponds to record R1.
[0158] The device ID and communication FBID in record CER002 are the same as those in record C001, and the certificate target is the communication destination device. Therefore, record CER002 corresponds to record R2.
[0159] The fingerprint of the CER003 record is "e0fbbc..................1fc", and the fingerprint of the CER002 record is "e0fbbc..................1fc". Therefore, since they match, OK is recorded for TLS server authentication.
[0160] Next, verification of P3 is performed. Of the four records included in the certificate list 824 in Figure 16, the device ID and communication FBID of the CER001 record are the same as the device ID and communication FBID of the C001 record, and the certificate target is the own device. Therefore, the CER001 record corresponds to record R3.
[0161] The device ID and communication FBID in record CER004 are the same as those in record S001, and the certificate target is the communication destination device. Therefore, record CER004 corresponds to record R4.
[0162] The fingerprint of the record for CER001 is "Cdf280..................234", and the fingerprint of the record for CER004 is "Cdf280..................234". Therefore, since they match, OK is recorded for TLS client authentication.
[0163] Next, P4 verification is performed. The expiration dates for records CER001 and CER004 are "2026 / 7 / 1 9:00", and the expiration dates for records CER002 and CER003 are "2026 / 6 / 1 9:00". If the specified period in condition A3 is one year, and the current date and time when P4 verification is performed is "2024 / 7 / 16 14:32", then the expiration dates of all records satisfy condition A3. Therefore, OK is recorded for the certificate expiration date.
[0164] Figure 19 shows an example of the NG list 832 in the control system shown in Figure 3. The NG list 832 in Figure 19 includes the verification ID, NG item, server device ID, client device ID, and a description of the NG content.
[0165] The Verification ID, Server Device ID, and Client Device ID are recorded in Result List 831, respectively. The NG items are recorded in Result List 831, specifically regarding the integrity of the connection type, TLS server authentication, TLS client authentication, or certificate expiration date. The NG content explanation records the reason why the check result was NG.
[0166] Since the result list 831 in Figure 18 does not contain any NG results, no records have been added to the NG list 832 in Figure 19.
[0167] Figure 20 shows an example of the display screen for verification results 825 in the control system shown in Figure 3. The display screen in Figure 20 includes the server device ID, server communication FBID, client device ID, client communication FBID, connection type consistency, TLS server authentication, TLS client authentication, and certificate expiration information from Figure 18.
[0168] Box 2001 displays the communication configuration verification results. The communication configuration verification result is OK if all checks—connection type integrity, TLS server authentication, TLS client authentication, and certificate expiration—are successful. If any of these checks fail, the communication configuration verification result is NG. In this example, the communication configuration verification result is OK.
[0169] Box 2002 displays information from NG list 832. Since NG list 832 in Figure 19 contains no records, box 2002 is blank.
[0170] According to the control system in Figure 3, the setting verification device 301 verifies the consistency of the connection configuration, TLS server authentication, TLS client authentication, and certificate expiration date for communication between PLC303-1 and PLC303-2, which operate while communicating with each other. This allows for the automatic verification of the communication settings of PLC303-1 and PLC303-2.
[0171] The setting verification device 301 presents the verification results 825 to the user, allowing the user to confirm the consistency of the communication settings of PLC303-1 and PLC303-2 and take measures to circumvent any problems. This reduces the risk of PLC303-1 and PLC303-2 malfunctioning due to inconsistent communication settings and prevents communication failures.
[0172] Figure 21 shows an example configuration of a second control system, including the setting verification device 101 of Figure 1. The control system in Figure 21 has a configuration that adds a support device 302-3, a PLC 303-3, and a controlled device 304-3 to the control system in Figure 3.
[0173] The setting verification device 301 communicates with the support device 302-3 via the communication line 311-3. The support device 302-3 communicates with the PLC 303-3 via the communication line 312-3. The PLC 303-2 communicates with the PLC 303-3 via the communication line 315. The PLC 303-3 controls the controlled device 304-3 via the communication line 314-3.
[0174] PLC303-1 and PLC303-3 are examples of the first control device, and PLC303-2 is an example of the second control device. Controlled devices 304-1 and 304-3 are examples of the first controlled devices, and controlled device 304-2 is an example of the second controlled device.
[0175] The controlled device 304-3 may be, for example, a manufacturing device, a conveying device, an inspection device, etc., in factory automation. The controlled device 304-3 may also be a motor, encoder, pump, valve, camera, sensor, etc.
[0176] Figure 22 shows examples of project files stored by support devices 302-1 to 302-3 in Figure 21. Project file 411-1 stored by support device 302-1 is the same as project file 411-1 in Figure 4. Security data 432-3 is added to the communication destination device security management information 423-2 of project file 411-2 stored by support device 302-2.
[0177] The support device 302-3 stores the project file 411-3 for PLC303-3. The project file 411-3 includes the source code 421-3 for PLC303-3, the device's own security management information 422-3, and the communication destination device security management information 423-3.
[0178] Source code 421-3 includes communication FB431-3, and communication FB431-3 includes configuration data 441-3. The configuration data 441-3 included in communication FB431-3 is an example of first communication configuration information.
[0179] The security management information 422-3 of the support device 302-3 includes security data 432-3, and the security management information 423-3 of the communication destination device includes security data 432-2.
[0180] Security data 432-3 is a self-signed certificate of PLC303-3, which is pre-generated by PLC303-3 using a digital signature. Support device 302-3 obtains security data 432-3 from PLC303-3 and stores it in its own device security management information 422-3.
[0181] Furthermore, the support device 302-3 acquires the security data 432-2 from the PLC 303-2 and stores it in the communication destination device security management information 423-3. For example, the user may copy the security data 432-2 from the support device 302-2's own device security management information 422-2 to the support device 302-3's communication destination device security management information 423-3.
[0182] The support device 302-2 acquires the security data 432-3 from the PLC 303-3 and stores it in the security management information 423-2 of the communication destination device. For example, the user may copy the security data 432-3 from the security management information 422-3 of the support device 302-3 to the security management information 423-2 of the communication destination device of the support device 302-2.
[0183] The security management information for the local device 422-3 and the security management information for the communication destination device 423-3 are examples of first communication setting information. The security data 432-3 included in the security management information for the local device 422-3 is an example of the security information for the first control unit. The security data 432-2 included in the security management information for the communication destination device 423-3 is an example of the security information for the communication destination of the first control unit.
[0184] Figure 23 shows an example of the information stored by PLC303-1 to PLC303-3 in Figure 21. The information stored by PLC303-1 is the same as the information stored by PLC303-1 in Figure 5. Security data 432-3 is added to the communication destination device security management information 513-2 stored by PLC303-2. Security data 432-3 is installed from support device 302-2 to PLC303-2.
[0185] PLC303-3 stores the execution program 511-3 for PLC303-3, its own device security management information 512-3, and the security management information 513-3 of the communication destination device.
[0186] The executable program 511-3 is generated from the source code 421-3 by the support device 302-3 and installed in the PLC 303-3. The executable program 511-3 includes the communication FB 431-3.
[0187] The security management information 512-3 of PLC303-3 includes security data 432-3, and the security management information 513-3 of the communication destination device includes security data 432-2. Security data 432-2 is installed on PLC303-3 from the support device 302-3.
[0188] The device security management information 512-3 further includes a secret key corresponding to the security data 432-3.
[0189] PLC303-3 controls the controlled device 304-3 by executing the execution program 511-3.
[0190] Figure 24 shows an example of configuration data 441-3 in the control system shown in Figure 21. The configuration data 441-3 in Figure 24 includes the FB name, local IP address, destination IP address, protocol, local port number, destination port number, and connection type.
[0191] The FB name in Figure 24 is Communication FB3. Therefore, the FB name for Communication FB431-3 is Communication FB3.
[0192] The "Local IP Address" in configuration data 441-3 represents the IP address of PLC303-3, which stores the communication FB431-3. The "Destination IP Address" represents the IP address of the communication destination of PLC303-3. The "Protocol" represents the protocol used for communication. The "Local Port Number" represents the port number of PLC303-3. The "Destination Port Number" represents the port number of the communication destination of PLC303-3. The "Connection Configuration" represents the connection method of PLC303-3 in communication.
[0193] The local IP address included in the configuration data 441-3 in Figure 24 is an example of the address information of the first control unit, and the destination IP address is an example of the address information of the destination of communication for the first control unit.
[0194] The local port number included in the configuration data 441-1 in Figure 24 is an example of the port information of the first control unit, and the communication destination port number is an example of the communication destination port information of the first control unit.
[0195] The protocol in Figure 24 is set to TLS, and the connection type is set to Active. Therefore, PLC303-3 attempts to establish a TLS connection with PLC303-2 and communicates with PLC303-2. Mutual authentication is performed using security data 432-3 and security data 432-2 during the TLS connection.
[0196] Figure 25 shows an example of security data 432-3 in the control system shown in Figure 21. The security data 432-3 in Figure 25 also includes other items not shown.
[0197] The file name in Figure 25 is plc3.crt. Therefore, the file name of security data 432-3 is plc3.crt.
[0198] The organization in security data 432-3 represents the company name. The common name represents the IP address set in configuration data 441-3. The issue date represents the date and time security data 432-3 was issued. The expiration date represents the expiration date of security data 432-3. The fingerprint is a hash value calculated for the entire security data 432-3, including items not shown.
[0199] The expiration date of security data 432-3 included in the security management information 422-3 of the device itself is an example of the expiration date of the security information of the first control unit. The expiration date of security data 432-2 included in the security management information 423-3 of the communication destination device is an example of the expiration date of the security information of the communication destination of the first control unit.
[0200] The communication unit 811 in Figure 8 communicates with the support device 302-3 via the communication line 311-3. The extraction unit 812 generates metadata D3 for the PLC 303-3 in the same manner as metadata D1 and metadata D2. Then, the extraction unit 812 generates metadata 821, which includes metadata D1, metadata D2, and metadata D3, and stores it in the storage unit 816.
[0201] The metadata D1 generated in the control system shown in Figure 21 is the same as the metadata D1 shown in Figure 9.
[0202] Figure 26 shows an example of metadata D2 in the control system shown in Figure 21. The metadata D2 in Figure 26 has a configuration similar to the metadata D2 in Figure 10, but with the number of data points for the communication destination security data changed to 2, and data 2 added. Data 2 includes security data 432-3 from Figure 25. The security data type is device certificate.
[0203] Figure 27 shows an example of metadata D3 in the control system shown in Figure 21. The metadata D3 in Figure 27 includes the target, communication FB settings, local device security data, and communication destination security data.
[0204] The target represents the identification information of PLC303-3 indicated by metadata D3. In the example in Figure 27, the identification information of PLC303-3 is PLC3.
[0205] The communication FB setting includes the number of data points and the number of data points indicated by the number of data points. In the example in Figure 27, the number of data points is 1, and the corresponding data point 1 includes the setting data 441-3 in Figure 24.
[0206] The device's security data includes data. In the example in Figure 27, the data includes security data 432-3 from Figure 25. The security data type is the device certificate.
[0207] The communication destination security data includes the data count and the number of data items indicated by the data count. In the example in Figure 27, the data count is 1, and the corresponding data 1 includes security data 432-2 in Figure 7(b). The security data type is a device certificate.
[0208] The identification unit 813 uses metadata D1, metadata D2, and metadata D3 contained in metadata 821 to identify the communication taking place between PLC303-1 and PLC303-3. The identification unit 813 then generates a communication server list 822, a communication client list 823, and a certificate list 824 representing the identified communication and stores them in the storage unit 816.
[0209] The communication server list 822 generated in the control system shown in Figure 21 is the same as the communication server list 822 in Figure 14.
[0210] Figure 28 shows an example of the communication client list 823 in the control system shown in Figure 21. The communication client list 823 in Figure 28 has the same configuration as the communication client list 823 in Figure 15, with the addition of the record C002.
[0211] After the record for C001 is added in the same manner as the communication client list 823 in Figure 15, the metadata D3 in Figure 27 is retrieved, and the connection type included in the communication FB settings of metadata D3 is checked. Since the connection type in metadata D3 is Active, it is determined that PLC303-3 is the communication client.
[0212] Therefore, a record is added to the communication client list 823, and the automatically assigned number C002 is recorded as the communication ID. The target of metadata D3 is recorded as the device ID, and the FB name of the communication FB setting in metadata D3 is recorded as the communication FB ID. Furthermore, the communication FB setting information of metadata D3 is recorded in the connection type, local IP address, destination IP address, and destination port number.
[0213] Figure 29 shows an example of the certificate list 824 in the control system shown in Figure 21. The certificate list 824 in Figure 29 has the same configuration as the certificate list 824 in Figure 16, with the addition of records CER005 to CER007.
[0214] In the same manner as the certificate list 824 in Figure 16, when the record for C001 shown in Figure 28 is added to the communication client list 823, the records for CER001 and CER002 are also added.
[0215] Next, when the record shown in Figure 14 is added to the communication server list 822, three records are added to the certificate list 824. The communication IDs of the three added records are then recorded with the automatically assigned CER003, CER004, and CER005, respectively. Then, in the same manner as the certificate list 824 in Figure 16, records for CER003 and CER004 are added.
[0216] Next, the device ID of the CER005 record is recorded with the target of metadata D2, and the communication FB ID is recorded with the FB name of the communication FB setting in metadata D2. Furthermore, the destination device is recorded with the certificate target, and the organization, common name, issue date, expiration date, and fingerprint information from data 2 of the destination device security data in metadata D2 are recorded.
[0217] Next, when metadata D3 in Figure 27 is acquired and the record C002 shown in Figure 28 is added to the communication client list 823, two records are added to the certificate list 824. Then, the automatically assigned communication IDs CER006 and CER007 are recorded in the communication IDs of the two added records, respectively.
[0218] Next, the device ID of the CER006 record is recorded with the target of metadata D3, and the communication FB ID is recorded with the FB name of the communication FB setting in metadata D3. Furthermore, the device itself is recorded as the certificate target, and the organization, common name, issue date, expiration date, and fingerprint information of the device's security data in metadata D3 are recorded.
[0219] Next, the device ID of the CER007 record is recorded with the target of metadata D3, and the communication FB ID is recorded with the FB name of the communication FB setting in metadata D3. Furthermore, the destination device is recorded with the certificate target, and the organization, common name, issue date, expiration date, and fingerprint information of the destination device security data in metadata D3 are recorded.
[0220] The verification unit 814 verifies the consistency of the communication settings of PLC303-1 to PLC303-3 for the identified communication by performing a communication setting verification process using the communication server list 822, the communication client list 823, and the certificate list 824. The verification unit 814 then generates a verification result 825, which includes the results of the communication setting verification process, and stores it in the storage unit 816. The display unit 815 presents the verification result 825 to the user by displaying it on the screen.
[0221] Figure 30 shows an example of the result list 831 in the control system of Figure 21. The result list 831 in Figure 30 has the same configuration as the result list 831 in Figure 18, with the addition of the record CK002.
[0222] The record S001 in Figure 14 is acquired as record Sm, the record C001 in Figure 28 is acquired as record Cn, and after the record CK001 is added, the record C002 in Figure 28 is acquired as record Cn. Then, the local IP address of the record S001 and the destination IP address of the record C002 are compared.
[0223] The local IP address of record S001 is "192.168.32.63", and the destination IP address of record C002 is "192.168.32.63". Therefore, since they match, it is determined that the combination of record Sm and record Cn represents communication between PLCs. Then, one record is added to result list 831, and the automatically assigned ID CK002 is recorded as the verification ID of the added record.
[0224] Next, the communication ID, device ID, and communication FBID of the record S001 are recorded in the server communication ID, server device ID, and server communication FBID fields. Then, the communication ID, device ID, and communication FBID of the record C002 are recorded in the client communication ID, client device ID, and client communication FBID fields.
[0225] Since the connection type of record S001 is Full Passive, verification of P1 is performed. The destination IP address of record S001 is "192.168.32.54" and the local port number is "443". Also, the local IP address of record C002 is "192.168.32.72" and the destination port number is "443". Therefore, condition A2 is met, but condition A1 is not met, so NG is recorded for connection type consistency.
[0226] Next, verification of P2 is performed. Of the seven records included in the certificate list 824 in Figure 29, the device ID and communication FBID of record CER003 are the same as the device ID and communication FBID of record S001, and the certificate target is the own device. Therefore, record CER003 corresponds to record R1.
[0227] The device ID and communication FBID in record CER007 are the same as those in record C002, and the certificate is for the communication destination device. Therefore, record CER007 corresponds to record R2.
[0228] The fingerprint of the CER003 record is "e0fbbc..................1fc", and the fingerprint of the CER007 record is "e0fbbc..................1fc". Therefore, since they match, OK is recorded for TLS server authentication.
[0229] Next, verification of P3 is performed. Of the seven records included in the certificate list 824 in Figure 29, the device ID and communication FBID of record CER006 are the same as the device ID and communication FBID of record C002, and the certificate subject is the own device. Therefore, record CER006 corresponds to record R3.
[0230] The device ID and communication FBID in record CER005 are the same as those in record S001, and the certificate target is the communication destination device. Therefore, record CER005 corresponds to record R4.
[0231] The fingerprint of the CER006 record is "ac87db..................6e3", and the fingerprint of the CER005 record is "ac87db..................6e3". Therefore, since they match, OK is recorded for TLS client authentication.
[0232] Next, P4 verification is performed. The expiration dates for records CER003 and CER007 are "2026 / 6 / 1 9:00", and the expiration dates for records CER005 and CER006 are "2024 / 9 / 1 9:00".
[0233] If the specified period in condition A3 is one year, and the current date and time when P4 verification is performed is "2024 / 7 / 16 14:32", then the expiration dates of records CER003 and CER007 satisfy condition A3. However, the expiration dates of records CER005 and CER006 do not satisfy condition A3. Therefore, "NG" is recorded for the certificate expiration date.
[0234] Figure 31 shows an example of the NG list 832 in the control system shown in Figure 21. The NG list 832 in Figure 31 contains two records. The validation ID for these records is CK002.
[0235] The first record's NG item is connection type consistency, the server device ID is PLC2, the client device ID is PLC3, and the NG description is "The server is in Full Passive mode and the destination IP address does not match the client's own IP address."
[0236] The NG item in the second record is the certificate expiration date, the client device ID is PLC3, and the NG description is "Less than one year remaining until the certificate expires. Current date and time: 2024 / 7 / 16 14:32 Expiration date: 2024 / 9 / 1 9:00".
[0237] Figure 32 shows an example of the display screen for verification result 825 in the control system shown in Figure 21. The display screen in Figure 32 includes the server device ID, server communication FBID, client device ID, client communication FBID, connection type integrity, TLS server authentication, TLS client authentication, and certificate expiration information for the two records in Figure 30.
[0238] In this example, the connection type integrity and certificate expiration check results for the CK002 record in Figure 30 are NG, so the communication settings verification result in Box 2001 is also NG. Box 2002 displays the NG content descriptions for the two records included in the NG list 832 in Figure 31.
[0239] The user recognizes from the NG content explanation displayed in box 2002 that there is a problem with the expiration dates of the communication FB431-2 of PLC303-2 and the security data 432-3 of PLC303-3. In this case, the user can prevent the communication failure from occurring by adding the setting data for PLC303-3 to the communication FB431-2 of PLC303-2 or by replacing the security data 432-3 with security data that satisfies condition A3.
[0240] Incidentally, effective security measures for control systems include blocking traffic other than that generated by PLC operation using a firewall, or monitoring and detecting such other traffic. To do this, it is necessary to understand all traffic generated by PLC operation.
[0241] The communications generated by the operation of a PLC can be identified from the specifications of the application programs running within the PLC. However, manually extracting these communications from specifications is time-consuming and prone to oversight.
[0242] Another method involves capturing communications within the control system for a certain period to identify them, but communications that do not occur within that period will not be detected, so there is still a possibility of overlooking something.
[0243] If communications are overlooked, legitimate communications that occur very rarely may be mistakenly identified as cyberattacks or other malicious activities. Furthermore, such legitimate communications may be blocked by firewall traffic restrictions. Therefore, technology that identifies communications within control systems with as little oversight as possible is desirable.
[0244] Figure 33 shows an example of the functional configuration of the communication identification device according to the embodiment. The communication identification device 3301 in Figure 33 includes an identification unit 3311 and an output unit 3312.
[0245] Figure 34 is a flowchart illustrating an example of the first identification process performed by the communication identification device 3301 in Figure 33. First, the identification unit 3311 identifies the communication between the two communication networks based on the first communication setting information set in the first control device and the second communication setting information set in the second control device (step 3401). Then, the identification unit 3311 generates an analysis result indicating the communication between the two communication networks (step 3402).
[0246] The first control device is a control device that controls the first controlled device. The second control device communicates with the first control device and controls the second controlled device. Next, the output unit 3312 outputs the analysis results (step 3403).
[0247] According to the communication identification device 3301 in Figure 33, it is possible to identify the communication performed by the control device that controls the controlled device.
[0248] Figure 35 shows an example configuration of a third control system including the communication identification device 3301 shown in Figure 33. The control system in Figure 35 includes the communication identification device 3501, support devices 3502-1 to 3502-3, PLCs 3503-1 to 3503-3, and controlled devices 3504-1 to 3504-3. The communication identification device 3501 is an example of the communication identification device 3301 shown in Figure 33.
[0249] The control system in Figure 35 further includes hub 3505-1, hub 3505-2, and router 3506. PLC 3503-1, PLC 3503-2, and hub 3505-1 are located within communication network 3511-1, while PLC 3503-3 and hub 3505-2 are located within communication network 3511-2. Router 3506 is located at the boundary between communication network 3511-1 and communication network 3511-2. Communication network 3511-1 and communication network 3511-2 are subnets.
[0250] The communication identification device 3501 communicates with the support device 3502-1 via the communication line 3521-1, with the support device 3502-2 via the communication line 3521-2, and with the support device 3502-3 via the communication line 3521-3.
[0251] Support device 3502-1 communicates with PLC 3503-1 via communication line 3522-1. Support device 3502-2 communicates with PLC 3503-2 via communication line 3522-2. Support device 3502-3 communicates with PLC 3503-3 via communication line 3522-3.
[0252] PLC3503-1 is connected to hub 3505-1 via communication line 3523-1 within communication network 3511-1. PLC3503-2 is connected to hub 3505-1 via communication line 3523-2 within communication network 3511-1. Hub 3505-1 is connected to router 3506 via communication line 3523-3 within communication network 3511-1.
[0253] PLC3503-3 is connected to hub 3505-2 via communication line 3523-4 within communication network 3511-2. Hub 3505-2 is connected to router 3506 via communication line 3523-5 within communication network 3511-2.
[0254] PLC3503-1 communicates with PLC3503-2 via communication line 3523-1, hub 3505-1, and communication line 3523-2.
[0255] PLC3503-1 communicates with PLC3503-3 via communication line 3523-1, hub 3505-1, communication line 3523-3, router 3506, communication line 3523-5, hub 3505-2, and communication line 3523-4.
[0256] PLC3503-2 communicates with PLC3503-3 via communication line 3523-2, hub 3505-1, communication line 3523-3, router 3506, communication line 3523-5, hub 3505-2, and communication line 3523-4.
[0257] PLC3503-1 controls the controlled device 3504-1 via communication line 3524-1. PLC3503-2 controls the controlled device 3504-2 via communication line 3524-2. PLC3503-3 controls the controlled device 3504-3 via communication line 3524-3.
[0258] PLC3503-3 is an example of a first control device, and PLC3503-2 is an example of a second control device. The controlled device 3504-3 is an example of a first controlled device, and the controlled device 3504-2 is an example of a second controlled device.
[0259] The controlled device 3504-i (i = 1, 2, 3) may be, for example, a manufacturing device, a conveying device, an inspection device, etc. in factory automation. The controlled device 3504-i may be a motor, an encoder, a pump, a valve, a camera, a sensor, etc.
[0260] Figure 36 shows an example of the project files stored in the support devices 3502-1 to 3502-3 of Figure 35. The support device 3502-i (i = 1, 2, 3) stores the project file 3611-i for PLC3503-i. The project file 3611-i includes the source code 3621-i and communication setting information 3622-i for PLC3503-i.
[0261] The source code 3621-i includes the communication FB3631-i, and the communication FB3631-i includes the setting data 3641-i.
[0262] The configuration data 3641-3 and communication configuration information 3622-3 included in communication FB3631-3 are examples of first communication configuration information. The configuration data 3641-2 and communication configuration information 3622-2 included in communication FB3631-2 are examples of second communication configuration information.
[0263] Figure 37 shows an example of the information stored by PLC3503-1 to PLC3503-3 in Figure 35. PLC3503-i (i=1,2,3) stores the execution program 3711-i and communication setting information 3622-i for PLC3503-i.
[0264] The executable program 3711-i is generated from the source code 3621-i by the support device 3502-i and installed on the PLC 3503-i. The executable program 3711-i includes the communication FB 3631-i. The communication configuration information 3622-i is installed on the PLC 3503-1 from the support device 3502-i.
[0265] PLC3503-i controls the controlled device 3504-i by executing the execution program 3711-i.
[0266] Figure 38 shows examples of setting data 3641-1 to 3641-3 in the control system shown in Figure 35. Figure 38(a) shows an example of setting data 3641-1, Figure 38(b) shows an example of setting data 3641-2, and Figure 38(c) shows an example of setting data 3641-3.
[0267] The configuration data 3641-i in Figures 38(a) to 38(c) includes the FB name, destination IP address, protocol, local port number, destination port number, and connection type.
[0268] The FB name in Figure 38(a) is Communication FB1, the FB name in Figure 38(b) is Communication FB2, and the FB name in Figure 38(c) is Communication FB3. Therefore, the FB name of Communication FB3631-1 is Communication FB1, the FB name of Communication FB3631-2 is Communication FB2, and the FB name of Communication FB3631-3 is Communication FB3.
[0269] The protocols in Figures 38(a) to 38(c) are set to TLS.
[0270] Connection modes can be set to, for example, Active, Fullpassive, or Unpassive. Active represents an actively open connection. A PLC3503-i that stores a communication FB3631-i set to Active will attempt to connect to the PLC3503-i indicated by the destination IP address.
[0271] Fullpassive indicates a passive open state. A PLC3503-i that stores a communication FB3631-i set to Fullpassive will only accept connections from the PLC3503-i indicated by the destination IP address.
[0272] Unpassive represents a passive open state. A PLC3503-i that stores a communication FB3631-i set to Unpassive will accept a connection from any PLC3503-i indicated by an arbitrary IP address.
[0273] The connection configurations in Figures 38(a) and 38(c) are set to Active, while the connection configuration in Figure 38(b) is set to Unpassive. Therefore, PLC3503-1 and PLC3503-3 attempt to establish a connection with PLC3503-2 using TLS and communicate with PLC3503-2.
[0274] The destination IP address included in the configuration data 3641-3 in Figure 38(c) is an example of the destination address information of the first control unit.
[0275] Figure 39 shows examples of communication setting information 3622-1 to 3622-3 in the control system shown in Figure 35. Figure 39(a) shows an example of communication setting information 3622-1, Figure 39(b) shows an example of communication setting information 3622-2, and Figure 39(c) shows an example of communication setting information 3622-3.
[0276] The communication setting information 3622-i in FIGS. 39(a) to 39(c) includes the self IP address, network mask, and default gateway. The self IP address, network mask, and default gateway are basic setting items for TCP / IP (Transmission Control Protocol / Internet Protocol) communication.
[0277] The network mask of the communication setting information 3622-i is a mask indicating the range of the bit string representing the network address of the subnet to which the PLC 3503-i storing the communication setting information 3622-i belongs among the bit string of the IP address. The default gateway represents the IP address of the router 3506 in the subnet to which the PLC 3503-i storing the communication setting information 3622-i belongs.
[0278] The self IP address included in the communication setting information 3622-3 in FIG. 39(c) is an example of the address information of the first control device. The self IP address included in the communication setting information 3622-2 in FIG. 39(b) is an example of the address information of the second control device.
[0279] FIG. 40 shows a functional configuration example of the communication identification device 3501 in FIG. 35. The communication identification device 3501 in FIG. 40 includes a communication unit 4011, an extraction unit 4012, an identification unit 4013, an analysis unit 4014, a display unit 4015, and a storage unit 4016. The identification unit 4013 and the analysis unit 4014 correspond to the identification unit 3311 in FIG. 33, and the display unit 4015 corresponds to the output unit 3312 in FIG. 33.
[0280] The communication unit 4011 communicates with the support device 3502-1 via the communication line 3521-1, communicates with the support device 3502-2 via the communication line 3521-2, and communicates with the support device 3502-3 via the communication line 3521-3.
[0281] The extraction unit 4012 extracts information from the support device 3502-i via the communication unit 4011 for generating metadata Di for PLC3503-i (i=1,2,3). The information for generating metadata Di consists of setting data 3641-i and communication setting information 3622-i. The extraction unit 4012 generates metadata Di using the extracted information.
[0282] Then, the extraction unit 4012 generates metadata 4021, which includes metadata D1 to D3, and stores it in the storage unit 4016.
[0283] Figure 41 shows an example of metadata D1 in the control system of Figure 35. Metadata D1 in Figure 41 includes the target, communication settings, and communication FB settings.
[0284] The target represents the identification information of PLC3503-1 indicated by metadata D1. In the example in Figure 41, the identification information of PLC3503-1 is PLC1.
[0285] The communication settings include the number of data items and the number of data items indicated by the number of data items. In the example in Figure 41, the number of data items is 1, and the corresponding data item 1 includes the communication setting information 3622-1 in Figure 39(a).
[0286] The communication FB setting includes the number of data entries and the number of data entries indicated by the number of data entries. In the example in Figure 41, the number of data entries is 1, and the corresponding data entry 1 includes the setting data 3641-1 in Figure 38(a). If the number of data entries is 2 or more, the number of data entries stored in the communication FB setting increases.
[0287] Figure 42 shows an example of metadata D2 in the control system of Figure 35. Metadata D2 in Figure 42 includes the target, communication settings, and communication FB settings.
[0288] The target represents the identification information of PLC3503-2 indicated by metadata D2. In the example in Figure 42, the identification information of PLC3503-2 is PLC2.
[0289] The communication settings include the number of data items and the number of data items indicated by the number of data items. In the example in Figure 42, the number of data items is 1, and the corresponding data item 1 includes the communication setting information 3622-2 in Figure 39(b).
[0290] The communication FB setting includes the number of data entries and the number of data entries indicated by the number of data entries. In the example in Figure 42, the number of data entries is 1, and the corresponding data entry 1 includes the setting data 3641-2 in Figure 38(b). If the number of data entries is 2 or more, the number of data entries stored in the communication FB setting increases.
[0291] Figure 43 shows an example of metadata D3 in the control system shown in Figure 35. The metadata D3 in Figure 43 includes the target, communication settings, and communication FB settings.
[0292] The target represents the identification information of PLC3503-3 indicated by metadata D3. In the example in Figure 43, the identification information of PLC3503-3 is PLC3.
[0293] The communication settings include the number of data items and the number of data items indicated by the number of data items. In the example in Figure 43, the number of data items is 1, and the corresponding data item 1 includes the communication setting information 3622-3 in Figure 39(c).
[0294] The communication FB setting includes the number of data entries and the number of data entries indicated by the number of data entries. In the example in Figure 43, the number of data entries is 1, and the corresponding data entry 1 includes the setting data 3641-3 in Figure 38(c). If the number of data entries is 2 or more, the number of data entries stored in the communication FB setting increases.
[0295] The identification unit 4013 uses metadata D1, metadata D2, and metadata D3 contained in metadata 4021 to identify the communication taking place between PLC3503-1 and PLC3503-3. The identification unit 4013 then generates a communication server list 4022 and a communication client list 4023 representing the identified communication and stores them in the storage unit 4016.
[0296] Communication server list 4022 is a list of communication servers, and communication client list 4023 is a list of communication clients.
[0297] The analysis unit 4014 identifies communication between the two subnets by performing communication analysis processing using the communication server list 4022 and the communication client list 4023. The analysis unit 4014 then generates an analysis result 4024 showing the communication between the two subnets and stores it in the storage unit 4016.
[0298] Analysis result 4024 includes result list 4031. Result list 4031 is a list of the results of the communication analysis process.
[0299] The display unit 4015 presents the analysis results 4024 to the user by displaying them on the screen. The user can then confirm the communication between the two subnets from the displayed analysis results 4024.
[0300] The communication identification device 3501 may transmit the analysis results 4024 to a user terminal device (not shown) via the communication unit 4011, instead of displaying them on the screen. The user terminal device displays the analysis results 4024 received from the communication identification device 3501 on its screen.
[0301] Figure 44 is a flowchart showing an example of the second identification process performed by the communication identification device 3501 in Figure 40. First, the extraction unit 4012 performs a setting extraction process to generate metadata 4021 (step 4401). Next, the identification unit 4013 performs a communication identification process to generate a communication server list 4022 and a communication client list 4023 (step 4402).
[0302] Next, the analysis unit 4014 performs communication analysis processing to generate analysis results 4024 (step 4403). Then, the display unit 4015 displays the analysis results 4024 on the screen (step 4404).
[0303] Figure 45 is a flowchart showing an example of the setting extraction process in step 4401 of Figure 44. First, the extraction unit 4012 references the project file 3611-i of each support device 3502-i (i=1,2,3) via the communication unit 4011 (step 4501).
[0304] In step 4501, the support device 3502-i may upload the project file 3611-i to the communication identification device 3501, and the extraction unit 4012 may refer to the uploaded project file 3611-i.
[0305] Next, the extraction unit 4012 analyzes the source code 3621-i within each project file 3611-i to identify the communication FB 3631-i. Then, the extraction unit 4012 obtains the configuration data 3641-i from the identified communication FB 3631-i (step 4502).
[0306] Next, the extraction unit 4012 retrieves the communication configuration information 3622-i from the project file 3611-i (step 4503).
[0307] Next, the extraction unit 4012 generates metadata 4021 using the acquired configuration data 3641-i and communication configuration information 3622-i (step 4504).
[0308] Figure 46 is a flowchart showing an example of the communication identification process in step 4402 of Figure 44. First, the identification unit 4013 obtains one metadata Di (i=1,2,3) from the metadata 4021 (step 4601).
[0309] Next, the specific unit 4013 checks the connection type included in the communication FB settings of the acquired metadata Di (step 4602).
[0310] If the connection status is Active (step 4602, YES), the identification unit 4013 determines that the PLC3503-i indicated by the metadata Di is a communication client. The identification unit 4013 then adds the information contained in the metadata Di to the communication client list 4023 (step 4603).
[0311] If the connection status is not Active (step 4602, NO), the identification unit 4013 determines that the PLC3503-i indicated by the metadata Di is a communication server. Then, the identification unit 4013 adds the information contained in the metadata Di to the communication server list 4022 (step 4604).
[0312] Next, the identification unit 4013 checks whether all metadata Di have been acquired (step 4605). If there are any metadata Di that have not been acquired (step 4605, NO), the identification unit 4013 repeats the processing from step 4601 onwards for the next metadata Di. If all metadata Di have been acquired (step 4605, YES), the identification unit 4013 terminates the process.
[0313] Figure 47 shows an example of a communication server list 4022 in the control system of Figure 35. The communication server list 4022 in Figure 47 includes a communication ID, device ID, communication FBID, connection type, local IP address, network mask, destination IP address, and local port number.
[0314] The communication ID is automatically assigned when a record (row) is added to the communication server list 4022. The device ID is obtained from the target of the metadata Di. The communication FBID is obtained from the FB name in the communication FB settings of the metadata Di. The connection type, destination IP address, and local port number are obtained from the communication FB settings of the metadata Di. The local IP address and network mask are obtained from the communication settings of the metadata Di.
[0315] In this example, metadata D2 in Figure 42 is acquired, and the connection type included in the communication FB settings of metadata D2 is checked. Since the connection type of metadata D2 is Unpassive, it is determined that PLC3503-2 is the communication server.
[0316] Therefore, a record is added to the communication server list 4022, and the automatically assigned number S001 is recorded as the communication ID. Then, the target of metadata D2 is recorded as the device ID, and the FB name of the communication FB setting in metadata D2 is recorded as the communication FB ID. Furthermore, the communication FB setting information of metadata D2 is recorded as the connection type, destination IP address, and local port number, and the communication setting information of metadata D2 is recorded as the local IP address and network mask.
[0317] Figure 48 shows an example of a communication client list 4023 in the control system shown in Figure 35. The communication client list 4023 in Figure 48 includes a communication ID, device ID, communication FBID, connection type, local IP address, network mask, destination IP address, and destination port number.
[0318] The communication ID is automatically assigned when a record is added to the communication client list 4023. The device ID is obtained from the target of the metadata Di. The communication FBID is obtained from the FB name in the communication FB settings of the metadata Di. The connection type, destination IP address, and destination port number are obtained from the communication FB settings of the metadata Di. The local IP address and network mask are obtained from the communication settings of the metadata Di.
[0319] In this example, metadata D1 in Figure 41 is acquired, and the connection type included in the communication FB settings of metadata D1 is checked. Since the connection type of metadata D1 is Active, it is determined that PLC3503-1 is the communication client.
[0320] Therefore, a record is added to the communication client list 4023, and the automatically assigned number C001 is recorded as the communication ID. The target of metadata D1 is recorded as the device ID, and the FB name of the communication FB setting in metadata D1 is recorded as the communication FB ID. Furthermore, the communication FB setting information of metadata D1 is recorded as the connection type, destination IP address, and destination port number, and the communication setting information of metadata D1 is recorded as the local IP address and network mask.
[0321] Next, metadata D3 in Figure 43 is acquired, and the connection type included in the communication FB settings of metadata D3 is checked. Since the connection type of metadata D3 is Active, it is determined that PLC3503-3 is the communication client.
[0322] Therefore, a record is added to the communication client list 4023, and the automatically assigned number C002 is recorded as the communication ID. The target of metadata D3 is recorded as the device ID, and the FB name of the communication FB setting in metadata D3 is recorded as the communication FB ID. Furthermore, the communication FB setting information of metadata D3 is recorded as the connection type, destination IP address, and destination port number, and the communication setting information of metadata D3 is recorded as the local IP address and network mask.
[0323] Figure 49 is a flowchart showing an example of the communication analysis process in step 4403 of Figure 44. First, the analysis unit 4014 obtains one record as record Sm from the communication server list 4022 (step 4901) and one record as record Cn from the communication client list 4023 (step 4902).
[0324] Next, the analysis unit 4014 checks whether the combination of record Sm and record Cn represents communication between PLCs (step 4903).
[0325] If the local IP address of record Sm matches the destination IP address of record Cn, the analysis unit 4014 determines that the combination of record Sm and record Cn represents communication between PLCs. On the other hand, if the local IP address of record Sm does not match the destination IP address of record Cn, the analysis unit 4014 determines that the combination of record Sm and record Cn does not represent communication between PLCs.
[0326] If the combination of record Sm and record Cn represents communication between PLCs (step 4903, YES), the analysis unit 4014 analyzes record Sm and record Cn (step 4904). The analysis unit 4014 then records the results of its analysis of record Sm and record Cn in the result list 4031 within the analysis result 4024 (step 4905).
[0327] In step 4904, the analysis unit 4014 calculates the network address of record Sm by performing a logical AND operation between the local IP address and network mask of record Sm. Next, the analysis unit 4014 calculates the network address of record Cn by performing a logical AND operation between the local IP address and network mask of record Cn. Finally, the analysis unit 4014 compares the network address of record Sm with the network address of record Cn.
[0328] If the network address of record Sm matches the network address of record Cn, the analysis unit 4014 determines that the communication between PLC3503-i indicated by record Sm and PLC3503-i indicated by record Cn is communication within the same subnet. The analysis unit 4014 then records a check result of Yes, indicating that the communication is within the same subnet, in the result list 4031.
[0329] If the network address of record Sm and the network address of record Cn are different, the analysis unit 4014 determines that the communication between PLC3503-i indicated by record Sm and PLC3503-i indicated by record Cn is communication between two subnets. The analysis unit 4014 then records a check result No. indicating that it is communication between two subnets in the result list 4031.
[0330] In this way, by comparing the network address of record Sm with the network address of record Cn, it is possible to determine whether the communication between the PLC3503-i indicated by record Sm and the PLC3503-i indicated by record Cn is communication within the same subnet.
[0331] Next, the analysis unit 4014 checks whether all records have been retrieved from the communication client list 4023 (step 4906). If there are any records that have not been retrieved (step 4906, NO), the analysis unit 4014 repeats the processing from step 4902 onwards for the next record.
[0332] If all records have been retrieved (Step 4906, YES), the analysis unit 4014 checks whether all records have been retrieved from the communication server list 4022 (Step 4907). If there are any records that have not been retrieved (Step 4907, NO), the analysis unit 4014 repeats the process from Step 4901 onwards for the next record. If all records have been retrieved (Step 4907, YES), the analysis unit 4014 terminates the process.
[0333] Figure 50 shows an example of the results list 4031 in the control system of Figure 35. The results list 4031 in Figure 50 includes the analysis ID, server communication ID, server device ID, server communication FBID, client communication ID, client device ID, client communication FBID, and communications within the subnet.
[0334] The analysis ID is automatically assigned when a record is added to result list 4031. The analysis unit 4014 records the information of record Sm and record Cn in result list 4031.
[0335] The server communication ID is obtained from the communication ID in record Sm. The server device ID is obtained from the device ID in record Sm. The server communication FBID is obtained from the communication FBID in record Sm.
[0336] The client communication ID is obtained from the communication ID in record Cn. The client device ID is obtained from the device ID in record Cn. The client communication FBID is obtained from the communication FBID in record Cn.
[0337] Communication within a subnet is represented by comparing the network address of record Sm with the network address of record Cn.
[0338] In this example, the record S001 in Figure 47 is retrieved as record Sm, and the record C001 in Figure 48 is retrieved as record Cn. The local IP address of record S001 and the destination IP address of record C001 are then compared.
[0339] The local IP address of record S001 is "192.168.32.63", and the destination IP address of record C001 is "192.168.32.63". Therefore, since they match, it is determined that the combination of record Sm and record Cn represents communication between PLCs. Then, one record is added to result list 4031, and the automatically assigned number CK001 is recorded as the analysis ID of the added record.
[0340] Next, the server communication ID, server device ID, and server communication FBID are recorded in the server communication ID, server device ID, and server communication FBID fields, respectively. Then, the client communication ID, client device ID, and client communication FBID are recorded in the client communication ID, client device ID, and client communication FBID fields, respectively.
[0341] Next, the network address of record S001 is compared with the network address of record C001.
[0342] The local IP address of record S001 is "192.168.32.63" and the network mask is "255.255.255.0". Therefore, the logical AND of the local IP address and the network mask is "192.168.32.0". Thus, the network address of record S001 is "192.168.32.0".
[0343] The local IP address of record C001 is "192.168.32.54" and the network mask is "255.255.255.0". Therefore, the logical AND of the local IP address and the network mask is "192.168.32.0". Thus, the network address of record C001 is "192.168.32.0".
[0344] In this case, since the network address of record S001 matches the network address of record C001, the combination of record Sm and record Cn is determined to represent communication within the same subnet. Therefore, "Yes" is recorded for communication within the subnet.
[0345] Next, the record C002 in Figure 48 is acquired as record Cn, and the local IP address in the record S001 is compared with the destination IP address in the record C002.
[0346] The local IP address of record S001 is "192.168.32.63", and the destination IP address of record C002 is "192.168.32.63". Therefore, since they match, it is determined that the combination of record Sm and record Cn represents communication between PLCs. Then, one record is added to result list 4031, and the automatically assigned number CK002 is recorded as the analysis ID of the added record.
[0347] Next, the communication ID, device ID, and communication FBID of the record S001 are recorded in the server communication ID, server device ID, and server communication FBID fields. Then, the communication ID, device ID, and communication FBID of the record C002 are recorded in the client communication ID, client device ID, and client communication FBID fields.
[0348] Next, the network address of record S001 is compared with the network address of record C002.
[0349] The local IP address of record S001 is "192.168.32.63" and the network mask is "255.255.255.0". Therefore, the logical AND of the local IP address and the network mask is "192.168.32.0". Thus, the network address of record S001 is "192.168.32.0". The network address of record S001 is an example of a network address indicated by the address information of the second control unit.
[0350] The local IP address of record C002 is "192.168.46.72" and the network mask is "255.255.255.0". Therefore, the logical AND of the local IP address and the network mask is "192.168.46.0". Thus, the network address of record C002 is "192.168.46.0". The network address of record C002 is an example of a network address indicated by the address information of the first control unit.
[0351] In this case, since the network address of record S001 and the network address of record C002 are different, the combination of record Sm and record Cn is determined to represent communication between two subnets. Therefore, "No" is recorded for communication within the subnet.
[0352] Figure 51 shows an example of the display screen for analysis results 4024 in the control system shown in Figure 35. The display screen in Figure 51 includes the client device ID, client communication FBID, server device ID, server communication FBID, and communication information within the subnet, as shown in Figure 50.
[0353] The display screen in Figure 51 also includes information on the client IP address, server IP address, and server port number. The client IP address represents the local IP address in Figure 48, and the server IP address and server port number represent the local IP address and local port number in Figure 47.
[0354] Box 5101 displays the number of identified communications. In this example, there is one identified communications within the same subnet and one identified communications between the two subnets.
[0355] According to the control system in Figure 35, communication between PLC3503-1 and PLC3503-3, which operate while communicating with each other, is analyzed by the communication identification device 3501. This makes it possible to determine whether each communication between PLC3503-1 and PLC3503-3 is within the same subnet. Therefore, the possibility of overlooking communications that only occur when certain conditions are met, such as communications between two different subnets, is reduced.
[0356] The communication identification device 3501 presents the analysis results 4024 to the user, allowing the user to verify the communication between the two subnets and take appropriate security measures for such communication.
[0357] The configuration of the setting verification device 101 shown in Figure 1 is merely an example, and some components may be omitted or changed depending on the intended use or conditions of the setting verification device 101.
[0358] The configuration of the communication identification device 3301 shown in Figure 33 is merely an example, and some components may be omitted or changed depending on the intended use or conditions of the communication identification device 3301.
[0359] The control system configurations shown in Figures 3, 21, and 35 are merely examples, and some components may be omitted or modified depending on the application or conditions of the control system. For example, the control system may include four or more PLCs.
[0360] The configuration of the setting verification device 301 shown in Figure 8 is merely an example, and some components may be omitted or changed depending on the application or conditions of the control system. For example, if the verification result 825 is to be transmitted to a user terminal device instead of being displayed on the screen, the display unit 815 can be omitted.
[0361] The configuration of the communication identification device 3501 in Figure 40 is merely an example, and some components may be omitted or modified depending on the application or conditions of the control system. For example, if the analysis results 4024 are transmitted to a user terminal device instead of being displayed on the screen, the display unit 4015 can be omitted.
[0362] The flowcharts in Figures 2, 11-13, 17, 34, 44-46, and 49 are merely examples, and some processes may be omitted or modified depending on the configuration or conditions of the setting verification device 101, the communication identification device 3301, or the control system.
[0363] The project files shown in Figures 4, 22, and 36 are merely examples, and project files vary depending on the application or conditions of the control system. The information shown in Figures 5, 23, and 37 is also merely an example, and the information stored by the PLC varies depending on the project file.
[0364] The configuration data shown in Figures 6, 24, and 38 are merely examples, and the configuration data will vary depending on the use or conditions of the control system. The security data 432-i shown in Figures 7 and 25 are merely examples, and the security data 432-i will vary depending on the use or conditions of the control system. The communication configuration information 3622-i shown in Figure 39 are merely examples, and the communication configuration information 3622-i will vary depending on the use or conditions of the control system.
[0365] The metadata Di shown in Figures 9, 10, 26, 27, and 41-43 is merely an example, and the metadata Di changes depending on the configuration data, security data 432-i, and communication configuration information 3622-i. The communication server list shown in Figures 14 and 47, the communication client list shown in Figures 15, 28, and 48, and the certificate list 824 shown in Figures 16 and 29 are merely examples. The communication server list, communication client list, and certificate list 824 change depending on the metadata Di.
[0366] The result list 831 shown in Figures 18 and 30, and the NG list 832 shown in Figures 19 and 31, are merely examples, and the result list 831 and NG list 832 will vary depending on the communication server list 822, the communication client list 823, and the certificate list 824. The result list 4031 shown in Figure 50 is also merely an example, and the result list 4031 will vary depending on the communication server list 4022 and the communication client list 4023.
[0367] The display screens shown in Figures 20 and 32 are merely examples; the display screen for verification result 825 changes according to result list 831 and NG list 832. The display screen shown in Figure 51 is merely an example; the display screen for analysis result 4024 changes according to result list 4031.
[0368] Figure 52 shows an example of the hardware configuration of an information processing device (computer) used as the setting verification device 101 in Figure 1, the setting verification device 301 in Figure 8, the communication identification device 3301 in Figure 33, and the communication identification device 3501 in Figure 40. The information processing device in Figure 52 includes a CPU (Central Processing Unit) 5201, memory 5202, input device 5203, output device 5204, auxiliary storage device 5205, media drive device 5206, and network connection device 5207. These components are hardware and are connected to each other by a bus 5208.
[0369] Memory 5202 is a semiconductor memory such as ROM (Read Only Memory) or RAM (Random Access Memory), and stores the program and data used for processing. Memory 5202 may operate as the storage unit 816 in Figure 8 or the storage unit 4016 in Figure 40.
[0370] The CPU 5201 (processor) operates as the verification unit 111 in Figure 1, for example, by executing a program using the memory 5202. The CPU 5201 also operates as the extraction unit 812, the identification unit 813, and the verification unit 814 in Figure 8 by executing a program using the memory 5202.
[0371] The CPU 5201 also operates as the identification unit 3311 in Figure 33 by executing a program using the memory 5202. The CPU 5201 also operates as the extraction unit 4012, identification unit 4013, and analysis unit 4014 in Figure 40 by executing a program using the memory 5202.
[0372] The input device 5203 is, for example, a keyboard, a pointing device, etc., and is used for inputting instructions or information from the user or operator. The output device 5204 is, for example, a display device, a printer, etc., and is used for inquiries or instructions to the user or operator, and for outputting processing results. The output device 5204 may operate as the output unit 112 in Figure 1, the display unit 815 in Figure 8, the output unit 3312 in Figure 33, or the display unit 4015 in Figure 40, and the processing result may be the verification result 825 or the analysis result 4024.
[0373] The auxiliary storage device 5205 is, for example, a magnetic disk drive, an optical disk drive, a magneto-optical disk drive, a tape drive, etc. The auxiliary storage device 5205 may also be a hard disk drive or an SSD (Solid State Drive). The information processing device can store programs and data in the auxiliary storage device 5205 and load them into the memory 5202 for use. The auxiliary storage device 5205 may operate as the storage unit 816 in Figure 8 or the storage unit 4016 in Figure 40.
[0374] The media drive unit 5206 drives the portable recording medium 5209 and accesses its recorded contents. The portable recording medium 5209 is a memory device, flexible disk, optical disk, magneto-optical disk, etc. The portable recording medium 5209 may also be a CD-ROM (Compact Disk Read Only Memory), DVD (Digital Versatile Disk), USB (Universal Serial Bus) memory, etc. The user or operator can store programs and data on the portable recording medium 5209 and load them into the memory 5202 for use.
[0375] Thus, the computer-readable recording medium that stores the programs and data used in the processing is a physical (non-temporary) recording medium such as memory 5202, auxiliary storage device 5205, or portable recording medium 5209.
[0376] The network connection device 5207 is a communication device connected to communication lines 311-1 to 311-3 or 3521-1 to 3521-3, and performs data conversion associated with communication. The information processing device can receive programs and data from external devices via the network connection device 5207, load them into memory 5202, and use them. The network connection device 5207 may also operate as the output unit 112 in Figure 1, the communication unit 811 in Figure 8, the output unit 3312 in Figure 33, or the display unit 4015 in Figure 40.
[0377] Note that the information processing device does not need to include all the components shown in Figure 52, and some components may be omitted or modified depending on the use or conditions of the information processing device. For example, if the portable recording medium 5209 is not used, the media drive device 5206 can be omitted.
[0378] As the support devices 302-i in Figures 3 and 21 and 3502-i in Figure 35, the same information processing devices as in Figure 52 can be used.
[0379] Although embodiments of the disclosure and their advantages have been described in detail above, those skilled in the art will be able to make various modifications, additions, and omissions without departing from the scope of the invention as clearly stated in the claims. [Explanation of symbols]
[0380] 101, 301 Setting Verification Device 111, 814 Verification Department 112, 3312 Output section 302-1~302-3, 3502-1~3502-3 Support equipment 304-1~304-4, 3504-1~3504-3 Controlled Devices 311-1~311-3, 312-1~312-3, 313, 314-1~314-3, 315, 3521-1~3521-3, 3522-1~3522-3, 3523-1~3523-5, 3524-1~3524-3 Communication lines Project files 411-1~411-3, 3611-1~3611-3 Source code for 421-1~421-3 and 3621-1~3621-3 422-1~422-3, 512-1~512-3 Self-device security management information 423-1~423-3, 513-1~513-3 Communication destination device security management information 431-1~431-3, 3631-1~3631-3 Communication FB 432-1~432-3 Security Data 441-1~441-3, 3641-1~3641-3 Configuration Data 511-1~511-3, 3711-1~3711-3 Executable Programs 811, 4011 Communications Department 812, 4012 Extraction part 813, 3311, 4013 Specific part 815, 4015 Display section 816, 4016 Storage section 821, 4021 metadata 822, 4022 Communication Server List 823, 4023 Communication Client List 824 Certificate List 825 Verification Results 831, 4031 Result List 832 NG List 2001, 2002, 5101 Box 3301, 3501 Communication-specific equipment 3511-1, 3511-2 Communication Network 3505-1, 3505-2 hub 3506 Router 3622-1~3622-3 Communication Settings Information 4014 Analysis Department 4024 Analysis results 5201 CPU 5202 memory 5203 Input device 5204 Output device 5205 Auxiliary storage device 5206 Media drive device 5207 Network Connection Device 5208 Bus 5209 Portable recording media
Claims
1. A verification unit generates a verification result by verifying the consistency between first communication setting information set in a first control device that controls a first controlled device and second communication setting information set in a second control device that communicates with the first control device and controls a second controlled device. An output unit that outputs the verification results, A setting verification device characterized by comprising the following features.
2. The first communication setting information includes the address information of the first control device and the address information of the communication destination of the first control device. The second communication setting information includes the address information of the second control device and the address information of the communication destination of the second control device. The setting verification device according to claim 1, characterized in that the verification unit verifies the consistency between the address information of the first control device included in the first communication setting information and the address information of the communication destination of the second control device included in the second communication setting information.
3. The first communication configuration information further includes port information of the first control device and port information of the communication destination of the first control device. The second communication configuration information further includes port information of the second control device and port information of the communication destination of the second control device. The setting verification device according to claim 2, characterized in that the verification unit further verifies the consistency between the port information of the first control device's communication destination included in the first communication setting information and the port information of the second control device included in the second communication setting information.
4. The first communication setting information includes the security information of the first control unit and the security information of the communication destination of the first control unit. The second communication setting information includes the security information of the second control device and the security information of the communication destination of the second control device. The setting verification device according to any one of claims 1 to 3, characterized in that the verification unit verifies the consistency between the security information of the communication destination of the first control device included in the first communication setting information and the security information of the second control device included in the second communication setting information.
5. The setting verification device according to claim 4, characterized in that the verification unit further verifies the consistency between the security information of the first control device included in the first communication setting information and the security information of the communication destination of the second control device included in the second communication setting information.
6. The setting verification device according to claim 5, characterized in that the verification unit checks the expiration dates of the security information of the first control device, the security information of the communication destination of the first control device, the security information of the second control device, and the security information of the communication destination of the second control device, and includes the result of the expiration date check in the verification result.
7. By verifying the consistency between the first communication setting information set in the first control device that controls the first controlled device and the second communication setting information set in the second control device that communicates with the first control device and controls the second controlled device, a verification result is generated. Output the verification results mentioned above. A configuration verification method characterized by the processing being performed by a computer.
8. By verifying the consistency between the first communication setting information set in the first control device that controls the first controlled device and the second communication setting information set in the second control device that communicates with the first control device and controls the second controlled device, a verification result is generated. Output the verification results mentioned above. A configuration verification program for executing a process on a computer.
9. An identification unit identifies communication between two communication networks and generates an analysis result indicating communication between the two communication networks, based on first communication setting information set in a first control device that controls a first controlled device, and second communication setting information set in a second control device that communicates with the first control device and controls a second controlled device. An output unit that outputs the aforementioned analysis results, A communication-specific device characterized by comprising:
10. The first communication setting information includes the address information of the first control device and the address information of the communication destination of the first control device. The second communication setting information includes the address information of the second control device, The communication identification device according to claim 9, characterized in that the identification unit identifies the communication between the first control device and the second control device as communication between the two communication networks when the address information of the first control device included in the first communication setting information matches the address information of the second control device included in the second communication setting information, and the network address indicated by the address information of the first control device included in the first communication setting information is different from the network address indicated by the address information of the second control device included in the second communication setting information.
11. Based on the first communication setting information set in the first control device that controls the first controlled device, and the second communication setting information set in the second control device that communicates with the first control device and controls the second controlled device, the communication between the two communication networks is identified. The analysis results showing the communication between the two aforementioned communication networks are generated, Output the above analysis results. A method for identifying communications, characterized in that the processing is performed by a computer.
12. Based on the first communication setting information set in the first control device that controls the first controlled device, and the second communication setting information set in the second control device that communicates with the first control device and controls the second controlled device, the communication between the two communication networks is identified. The analysis results showing the communication between the two aforementioned communication networks are generated, Output the above analysis results. A communication-specific program that causes a computer to execute a process.