Apparatus and method for secure data logging - Patents.com

By using a data logger with a hardware data diode for secure, unidirectional data transfer, the security risks associated with current data retrieval methods in process control systems are mitigated, enhancing the cybersecurity of the system while maintaining the integrity of the data logging process.

JP7676126B2Active Publication Date: 2025-05-14FISHER ROSEMOUNT SYST INC
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
JP2020177861
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Priority Date
2019-11-14
Filing Date
2020-10-23
Publication Date
2025-05-14
Estimated Expiration
2040-10-23

AI Technical Summary

Technical Problem

Current data retrieval methods in process control systems pose security risks due to the potential for cyberattacks, as they often require physical or remote computer connections that can introduce malware and compromise the safety of the system.

Method used

The implementation of a data logger with a hardware data diode that allows for secure, unidirectional data transfer from the process control system network to a data extractor, preventing the introduction of cyberattack vectors and ensuring the integrity of the data logging process.

Benefits of technology

This solution effectively eliminates the risk of cyberattacks on process control systems by ensuring that data loggers can only capture and store data in a secure, unidirectional manner, thereby enhancing the cybersecurity of the system without altering the existing SIS architecture.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007676126000001
    Figure 0007676126000001
  • Figure 0007676126000002
    Figure 0007676126000002
  • Figure 0007676126000003
    Figure 0007676126000003
Patent Text Reader

Abstract

To provide an apparatus and a method for secure data logging.SOLUTION: An example method for secure data transfer from a process control system network includes storing information received by a process controller via the process control system network, in which the process controller includes a safety instrumented system controller 108 or a process control system controller, and the method includes: storing the information uni-directionally transferred from the process control system network to data loggers 112a and 131a via data diodes 112b and 131b; identifying a trigger event on the process control system network; in response to identifying the trigger event, parsing the stored information for event data; and transferring the event data from the data loggers 112a and 131a to a data extractor.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

[Technical field]

[0001] FIELD OF THE DISCLOSURE This disclosure relates generally to process control systems and, more specifically, to an apparatus and method for secure data logging. [Background technology]

[0002] Process control systems are designed to maintain a particular process within desired ranges and typically include instrumentation positioned throughout the plant to allow for the collection of data for monitoring and troubleshooting purposes. Data collection involves measurements made by sensors, including parameters such as pressure, flow, temperature, weight, density, speed, etc. A Basic Process Control System (BPCS) receives inputs from sensors and process instrumentation, allowing the BPCS to act as a first layer of protection against unsafe conditions. A Safety Instrumented System (SIS) is implemented in addition to the BPCS to protect personnel, equipment, and the environment by reducing the likelihood or severity of emergency situations through dedicated monitoring of safety-related process control system instrumentation. Summary of the Invention

[0003] An exemplary method for secure data transfer from a process control system network includes storing information received by a process controller via the process control system network, the process controller including a safety instrumented system controller or a process control system controller, the information being transferred unidirectionally from the process control system network via a data diode to a data logger, storing the information, identifying a trigger event on the process control system network, analyzing the stored information for event data in response to identifying the trigger event, and transferring the event data from the data logger to a data extractor.

[0004] An exemplary apparatus for secure data transfer from a process control system network includes a data store that stores information received by a process controller over the process control system network, the process controller including a safety instrumented system controller or a process control system controller, the information being transferred unidirectionally from the process control system network to a data logger via a data diode, an event detector that identifies a trigger event on the process control system network, a data parser that parses the stored information for the event data in response to identifying the trigger event, and a connector that transfers the event data from the data logger to a data extractor.

[0005] An exemplary non-transitory computer readable storage medium containing instructions that, when executed, cause a machine to at least store information received by a process controller over a process control system network, including a safety instrumented system controller or a process control system controller, the information being transferred uni-directionally from the process control system network to a data logger via a data diode; identify a trigger event on the process control system network; and, in response to identifying the trigger event, analyze the stored information for event data; and transfer the event data from the data logger to a data extractor. [Brief description of the drawings]

[0006] [Figure 1] FIG. 1 is a block diagram of an example process control system that can be configured to use the example secure data logger apparatus and methods described herein for data extraction over an internal network. [Diagram 2] FIG. 1 is a block diagram of an example process control system that can be configured to use the example secure data logger apparatus and methods described herein for data extraction over an external network. [Diagram 3]FIG. 1 is a block diagram illustrating an example data logger for logging data in a process control system network in accordance with the teachings of the present disclosure. [Figure 4] 4 is a flowchart representing machine-readable instructions that may be executed to implement the example data logger of FIG. 3. [Diagram 5] FIG. 5 is a schematic diagram of an exemplary processor platform that may be used and / or programmed to perform the exemplary method of FIG. 4 and / or, more generally, to implement the exemplary secure data logger of FIGS. 1, 2 and 3. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS

[0007] Process control systems implementing critical processes (e.g., chemical processing plants, power plants, etc.) can pose significant safety risks if not properly controlled. A Basic Process Control System (BPCS) provides the first layer of protection by allowing the entire process to be continuously controlled using BPCS-associated controllers, logic solvers, and field devices. BPCSs are typically implemented using pneumatic control loops, programmable logic controllers, distributed control systems (DCS), discrete control systems, and single-loop controllers. DCSs are used to oversee complex production processes (e.g., large refineries) and include sensors, controllers, and associated computers distributed throughout the plant for the purposes of data collection, process control, and storage and graphic display. Additional safety measures can be introduced through a combination of automatic shutdown sequences and operator intervention to shut down the process using a predefined sequence.

[0008] A safety instrumented system (SIS) monitors special purpose field devices and other special purpose control elements associated with the SIS, physically and logically separated from the BPCS. The SIS is responsible for the safe shutdown of the process in response to a control condition that poses a significant safety risk. The SIS relies on dedicated logic solvers, controllers, safety-certified field devices (e.g., sensors, final control elements, shutoff valves, etc.), data redundancy devices and routines, and safety-certified software code. For example, field sensors (e.g., air pressure sensors, electrical switches, smart transmitters with on-board diagnostics, etc.) are used to collect information (e.g., temperature, pressure, flow rate, etc.) to identify emergency situations. The logic solver provides fail-safe and fault-tolerant operation to determine what action to take based on the collected information, and the final control elements (e.g., pneumatically actuated on-off valves operated by solenoid valves) implement the action determined by the logic system. For example, the SIS controller can test the safe override of a process control valve by temporarily interrupting the power signal of a solenoid valve.

[0009] Unplanned but safe process shutdowns can occur as a result of false trip events related to the SIS, resulting in high operational costs. Post-mortem analysis is used to evaluate process conditions before and after a trip and to determine the potential root cause of the event. Data logging capabilities allow for the collection of data relevant to pre- and post-trip event analysis. However, such data logging capabilities need to be secure to prevent unauthorized access to the process control system network. Current data retrieval methods include connecting a computer to the control system safety network to retrieve the data and running a data logging software application on that computer or connecting remotely to the network. Data loggers that allow for physical or remote computer connections increase security risks as cyber attack vectors (e.g., malware injection) can be introduced into the SIS (e.g., cyber attack logic solver, or system controller). Cyber ​​security threats can significantly impact the availability and integrity of the SIS, which remains vulnerable to cyber incidents, as well as other industrial control systems, including distributed control systems (DCS). Given that SIS controllers protect critical assets (e.g., refineries, power plants, chemical plants, offshore oil rigs, etc.) from potentially catastrophic malfunctions, a successful cyberattack on such systems would remove well-designed safety measures that operators rely on to prevent adverse events. Similarly, an unintended SIS shutdown caused by a cyberattack could take production offline with operational and financial consequences. Global functional safety standards set by the International Electrotechnical Commission (e.g., IEC 61511), which addresses the engineering practice of systems that ensure the safety of industrial processes, require that SIS designs provide resilience against identified security risks. However, common preventative measures such as antivirus software may not be effective when new cyberattacks are implemented and signatures have not yet been developed to identify such attacks and deployed to detect anomalies.

[0010] The embodiments disclosed herein eliminate the potential of data loggers to be used to introduce a cyber attack vector into a process control system. In the embodiments disclosed herein, hardware data diodes can be incorporated into the data logger device to eliminate the risk of a successful cyber attack on a process control system via the data logger. In the embodiments disclosed herein, the data logger can listen to traffic on the process control safety network but cannot transmit information to the safety network. Additionally, the embodiments disclosed herein can capture and store metadata, log data, and time information required for post-trip event analysis and can be used to further interpret, search, and report the data. For example, recorded data related to pre- and post-trip information can be searched without compromising the safety of the process control system and the action to save the data log can be triggered by selecting a condition configured by the user. Incorporating hardware data diodes into the data logger as described herein does not require modification of the SIS architecture to enable data logging. Additionally, the data logging activities illustrated herein can be used to collect and correlate data from various layers of a process control system (e.g., SIS, BPCS), as well as a distributed control system (DCS). Such data is not limited to safety-related event data, but can include any data collection related to a triggered event. Additionally, the use of hardware data diode-based data loggers is not limited to a single process control system, but can be implemented in any industrial control system requiring increased cybersecurity protection. In embodiments disclosed herein, data loggers can be used to detect anomalous traffic patterns in a network (e.g., safety network, area control network) and initiate an alert when a significant change in the traffic pattern is detected.

[0011] 1 is a block diagram of an example process control system 100 that may be configured to use the example secure data logger apparatus and methods described herein for data extraction purposes over an internal network. The example process control system 100 includes an example operator station 102. The operator station 102 is communicatively coupled to process control system controllers, including an example Basic Process Control System (BPCS) controller 106 and an example Safety Instrumented System (SIS) controller 108, via a bus or example local area network (LAN) 104. In some examples, the LAN 104 is an area control network (ACN), which may be implemented using any desired communication medium and protocol. For example, the LAN 104 may be based on a hardware or wireless Ethernet communication protocol. However, other suitable wired or wireless communication mediums and protocols may be used instead.

[0012] The operator station 102 may be configured to perform operations related to one or more information technology applications, user interactive applications, and / or communications applications. For example, the operator station 102 may be configured to perform operations related to process control related applications and communications applications that enable the station 102 and the controller(s) 106 and / or 108 to communicate with other devices or systems using any desired communications medium (e.g., wireless, wired, etc.) and protocol (e.g., HTTP, SOAP, etc.).

[0013] Exemplary controller(s) 106 and / or 108 (e.g., BPCS controller 106 and SIS controller 108) may be configured to execute one or more process control routines and / or functions operating as one or more control loops created and downloaded and instantiated to controller(s) 106 and / or 108, for example, by a systems engineer or other system operator using operator station 102 or any other workstation. Controller(s) 106 and / or 108 may be coupled to multiple field device(s) 110 and 111, respectively, via digital data buses and input / output (I / O) devices. In some examples, field device(s) 110 and 111 may be coupled to controller(s) 106 and / or 108 via exemplary wired link(s) 109. Field device(s) 110 and 111 may include fieldbus-compliant valves, actuators, sensors, etc., where field device(s) 110 and 111 communicate over a digital data bus using a fieldbus protocol. In some examples, other types of field devices and communication protocols may be used. For example, field device(s) 110 and 111 may be Profibus, HART, or AS-i compliant devices that communicate over a data bus using Profibus, AS-i, and HART communication protocols.

[0014] Known installations in the process industry have field devices (e.g., sensors, valves, etc.) that are shared by the BPCS and SIS. For example, sensor data can be shared between the BPCS and SIS by using a signal splitter and wiring the same sensor to both systems. In other examples, the integrated control and safety system allows the logic solver to share input signal data directly with one or more process controllers. In some examples, the field devices are specific to the process controllers (e.g., field device(s) 110 are communicatively coupled to the BPCS controller 106, while field device(s) 111 are communicatively coupled to the SIS controller 108). The BPCS controller 106 and the SIS controller 108 receive signals indicative of process measurements made by the field device(s) 110 and 111, and / or other information related to the field device(s) 110 and 111, respectively, and use this information to implement control routines and generate control signals that are sent to the field devices 110 and 111 over buses and / or other communication paths to control the operation of the process. Information from field device(s) 110 and 111 and controller(s) 106 and 108 may be made available to one or more applications executed by operator station 102 to enable an operator to perform desired functions with respect to the process, such as viewing the current state of the process, altering the operation of the process, etc. For example, SIS controller 108 may read signals from field device(s) 111 (e.g., field devices that communicate directly with the SIS) and / or field device(s) 128 (e.g., field devices that communicate with both the BPCS and the SIS) and perform pre-programmed actions to prevent hazards by providing output(s) to final control elements.

[0015] 1, the exemplary SIS 140 includes a SIS controller 108, a SIS dedicated field device(s) 111, an exemplary data logger 112a, an exemplary local safety network 120, an exemplary logic solver(s) 124, and a field device(s) 128. The exemplary BPCS 150 includes a BPCS controller 106, a BPCS dedicated field device(s) 110, an exemplary data logger 131a, an exemplary area control network 132, an exemplary logic solver(s) 136, and a field device(s) 128. The local safety network 120 can be a standard Ethernet network dedicated to process safety systems, enabling communication between the SIS controller 108 and the logic solver(s) 124. Similarly, the area control network 132 can be a standard Ethernet network dedicated to process control systems, enabling communication between the BPCS controller 106 and the logic solver(s) 136. The logic solver(s) 124 and 136 may each include a smart logic solver that communicates safety parameters and inputs data to other logic solvers via the local safety network 120 and / or the area control network 132. In some embodiments, the SIS controller 108 may be connected to the area control network 132 in addition to the local safety network 120 such that the SIS dedicated logic solver(s) 124 are isolated from the process control system. For example, the local safety network 120 may remain dedicated to safety-related purposes rather than being used for both control and safety, thereby ensuring that the SIS components are not affected by failures of the area control network 132. The SIS components may be communicatively coupled via the bus 126 and / or the local safety network 120, and the BPCS components may be communicatively coupled via the bus 130 and / or the area control network 132.The local safety network 120 and the local area control network 132 may include network switches used to control the flow of data through the safety network 120 and the area control network 132 .

[0016] The data logger 112a of the SIS 140 is communicatively coupled to the local safety network 120 to capture and store all input information and specific data required to perform the trip analysis. In some embodiments, this information may be stored continuously in a data storage component (e.g., a hard disk) and overwritten after a period of time (e.g., a period configured by a user) if no trigger event is detected at the SIS 140. In some embodiments, the data logger 112a records all data before and after a trigger event is detected based on user configurable settings, as described in more detail below in connection with FIGS. 3-4. Such data may include timestamp information for each collected data point being provided by the SIS 140. In some embodiments, the data capture activity of the data logger 112a may include recording the integrity or status of each data point captured for use during trip event analysis (e.g., quality control data) or any other type of analysis performed using the data captured by the data logger 112a (e.g., data configured by a user as captured by the data logger 112a). For example, a thorough evaluation of the data may be required to ensure that data integrity is not compromised (e.g., the level of accuracy, completeness, and consistency of the data is considered during analysis). Although user configuration of the data logger 112a can be performed (e.g., to define the parameters that are collected, such as by sending information from the SIS 140 to configure collection points in the data logger 112a), no modifications to the SIS 140 are required to enable data logging using the data logger 112a.For example, unlike known data logging applications, because the data logger 112a can discover the process control network and automatically identify SIS-specific devices on the process control system network, it is not necessary to install software or enable specific services on the SIS engineering station (e.g., operator station 102) to enable the data logger 112a to perform information retrieval from the SIS 140. While the data logger 112a is a SIS-specific data logger, the exemplary data logger 131a is a BPCS-specific data logger and can be communicatively coupled to the area control network 132 and used to capture and store all incoming information and BPCS-specific data that can be retrieved as needed for off-network evaluation.

[0017] The data loggers 112a and 131a include respective integrated hardware data diodes 112b and 131b to prevent the use of the data loggers 112a and / or 131a as an attack vector (e.g., for purposes of a cybersecurity attack against the process control system 100 via malware injection). In the example of FIG. 1, the data diodes 112b and 131b are shown within the data loggers 112a and 131a, respectively. In this example, the connection between each data logger and the data diode is a physical connection. However, in some examples, the connection between the data loggers and the data diodes may be a logical connection rather than a physical connection. The data diodes 112b and 131b provide a listen-only capability to the data loggers 112a and 131a so that the data loggers 112a and 131a can capture and store input information and forward the information in one direction (e.g., unidirectional) to the respective example data extractors 116 and / or 117, but prevent input from the data extractors 116 and 117 to the process control system 100 (e.g., input to the SIS 140 via the data logger 112a and / or input to the BPCS 150 via the data logger 131a). In some examples, the data diodes 112b and 131b can include two nodes or circuits (e.g., one “send only” node and one “receive only” node) that allow data to flow in one direction only from the source (e.g., the local safety network 120 to the data logger 112a via the data diode 112b). In some embodiments, the data diodes 112b and 131b may include optical fibers with a transmitter on one side (e.g., a port that transmits information to an external device) and a receiver on the other side (e.g., a port that receives information from a process control system) to ensure that data can only be transferred in one direction.For example, data diodes 112b and 131b may include interconnected switch fabrics (e.g., a first switch fabric and a second switch fabric) such that a port of the first switch fabric that transmits data (e.g., data from BPCS controller 106 and / or SIS controller 108 and / or data from local safety network 120 and / or area control network 132) is connected to a port of the second switch fabric that receives data (e.g., data logger(s) 112a and / or 131a). However, no other connections are made between the switch fabrics to maintain a unidirectional flow of data. The switch fabrics may be configured such that link status (e.g., “link up” or “link down”) is ignored for these interconnected switch ports, allowing other ports of the first switch fabric to forward packets (e.g., data transmitted over the network) to the second switch fabric. In some embodiments, the switch fabric port that receives the data (e.g., a port of the second switch fabric, also known as an interconnect port because it can connect two separate devices, such as data logger 112a and data extractor 116) can forward the received packet to other ports. In some embodiments, the switch fabric is configured to forward traffic as described above without regard to internal MAC address tables that may be learned. For example, MAC address tables contain address information that the switch can use to forward traffic between ports, so that MAC addresses in such tables are associated with one or more ports. By disabling MAC address learning, the switch fabric can forward traffic based on a predefined configuration, facilitating a unidirectional flow of data while providing a good (e.g., connected) status to devices connected to other ports of the switch.As shown in connection with the exemplary data diodes 112b and 131b, data diodes directed out of a network (e.g., the local safety network 120 and / or the area control network 132) oriented to transfer data out of the network allow the network to remain protected by ensuring that the same connection in the opposite direction is used to reach the secure network and not impact the environment of the process control system 100. As such, data diodes can be used to segment networks, defend networks, and / or transfer information unidirectionally (e.g., from the network to a data logger and to a data extractor). In some examples, data diodes 112b and 131b can be embedded in data loggers 112a and 131a to transmit data from the local safety network 120 and / or the area control network 132 to external systems and / or users without creating a threat vector back into the secure network.

[0018] In the example of FIG. 1, data transfer occurs from data loggers 112a and 131a to data extractors 116 and 117, respectively, using a local network, while the example of FIG. 2 details the use of data loggers for data transfer over an external network. Embedding data diodes in the data loggers allows for hardware-enforced data transfer that provides a level of cybersecurity that is difficult to compromise using external attacks, as opposed to using software (e.g., like a firewall), which is also vulnerable to cyber attacks. However, the data diode-based data loggers disclosed herein are not limited to applications in safety instrumented systems or basic process control systems, and thus can be utilized in any type of industrial process control application to enhance security (e.g., in distributed control systems). For example, because data diodes 112b and 131b are hardware-based, online attacks on data diodes 112b and 131b are difficult to perform because the data diode(s) do not contain software, logic, or field programmable gate arrays, but rather allow signals to travel in one direction over a physical path. Similarly, problems with the data logger network (e.g., a set of data loggers connected to each other) do not affect the integrity of the safety network. For example, if a data diode (e.g., data diode(s) 112b and 131b) is positioned between the process control system network (e.g., local safety network 120 and / or area control network 132) and a data logger (e.g., data logger(s) 112a and / or 131a), the data logger will not affect the network it is listening to, considering that it transfers data unidirectionally from the network to the data logger through the data diode.In some examples, the data logger(s) 112a and / or 131a can be used to connect to more than one network if appropriate security protections are implemented (e.g., the data logger 112a can be used to connect to the local safety network 120 and the area control network 132). In examples where data collection is related to trip analysis, data logging can be configured to automatically discard data not needed for analysis, preventing the risk of using the data logger as a mechanism to decode safety network traffic for malicious purposes. In some examples, the SIS 140 and / or BPCS 150 can be alerted (e.g., by sending information from the data logger 112a to the SIS 140) when the data logger(s) 112a and / or 131a is not working. In such examples, there is no traffic to the safety network 120, alerting the process control system that the data logger(s) 112a and / or 131a is not functioning. For example, the data logger 112a provides information using either a physical signal (e.g., a dry contact, such as an alarm 118) or a message on a separate network other than the safety network 120 (e.g., a message to the operator station 102 via the area control network 132).

[0019] In some examples, the data loggers 112a and 131a can be used to detect anomalous traffic patterns in one or more safety networks. For example, the data loggers 112a and 131a can be used to detect unexpected network nodes and trigger an alarm (e.g., exemplary alarms 118, 119 connected to the data logger(s) 112a and / or 131a) in response to the detection. For example, the data logger(s) 112a and / or 131a can generate a baseline of traffic on the local safety network 120 and / or the area control network 132. If the data logger(s) 112a and / or 131a detect a significant change in the traffic patterns, the SIS 140 and / or the BPCS 150 can be alerted of this potential security issue using one or more alarm(s) 118 and / or 119. In some examples, one or more data logger(s) may be used to collect data on other networks (e.g., data logger 112a of SIS 140 may be used to collect data from area control network 132 of BPCS 150 in addition to local safety network 120). As shown in the example of FIG. 1, where data logger 112a and data logger 131a are used to collect data from both process control system networks, trigger signals may be coordinated using data collection in both SIS 140 and BPCS 150 such that recorded data may be correlated. For example, use of data collection from both SIS 140 and BPCS 150 allows for a determination of whether a SIS request was generated due to a BPCS failure. Thus, access to both sets of data via one or more data logger(s) 112a and / or 131a may improve root cause analysis. In some embodiments, the data logger(s) 112a and / or 131a can include multiple ports, and the data logger(s) 112a and / or 131a have one or more data diode(s) (e.g., a data diode per port).For example, data logger(s) 112a and / or 131a may communicate over link 113, which allows data logger 112a and / or 131a to exchange information regarding SIS 140 and / or BPCS 150. As information is exchanged between data logger 112a and 131a, SIS 140 remains isolated from BPCS 150 because data diode 112b is positioned such that the data logger receives information from safety network 120 but does not send information back to network 120. This provides additional protection to the process control system network in the event that data logger(s) 112a and / or 131a are damaged. In some implementations, use of data loggers requires a change in switch configuration (e.g., setting one port to promiscuous mode) to allow all network traffic to be sent to the port. In some embodiments, the data loggers 112a and 131a can be deployed as in-line devices to prevent the need for changing port configurations on a network switch (e.g., a network switch for the local safety network 120 and / or the area control network 132). In some embodiments, the data logger(s) 112a and / or 131a can include two ports (e.g., two ports for the SIS 140, and / or two ports for the BPCS 150, and / or one port each for the SIS 140 and the BPCS 150). This ensures that no changes need to be made to the control system network switch. For example, as shown in FIG. 1, the data logger 112a is connected between the local safety network 120, which can include a network switch, and a network node to monitor (e.g., the SIS controller 108). In some embodiments, the network node to monitor can be, for example, the logic solver(s) 124 of the SIS.1, data logger 131a is connected between a control system network switch (e.g., a network switch of area control network 132) and a network node that it monitors (e.g., BPCS controller 106). In some embodiments, data logger(s) 112a and / or 131a can have additional ports for networking with other data loggers, as well as additional dry contacts (e.g., using alarm(s) 118 and / or 119) for alarm purposes (e.g., allowing SIS-only data logger 112a to network with BPCS-only data logger 131a). In some embodiments, one of the ports of data logger(s) 112a and / or 131a can be disabled for BPCS 150 or SIS 140 connections and instead connected to an available port on the SIS 140 network (e.g., using a network switch of local safety network 120) or BPCS 150 network (e.g., using a network switch of area control network 132).

[0020] The data extractor 116 and / or 117 retrieves data stored in the data logger(s) 112a and / or 131a. For example, the data extractor 116 and / or 117 can be implemented using a computing device (e.g., a laptop or other mobile computer) that can connect to the data logger(s) 112a and / or 131a via Bluetooth. Such a connection requires physical access (e.g., access to an internal network) to the data logger(s) 112a and / or 131a, which represents a lower security risk compared to extracting data using a remote network connection (e.g., as described in connection with FIG. 2). The data extractor(s) 116 and / or 117 can also be a USB drive physically inserted into the data logger(s) 112a and / or 131a. In some embodiments, a single computer can be used as data extractor 116 or 117 to extract data from multiple data logger(s) 112a and / or 131a connected via separate and / or separated networks.

[0021] The logic solver(s) 124 are implemented using the SIS controller 108 configured to implement one or more safety instrumented functions. For example, a safety instrumented function may include monitoring one or more process conditions associated with one or more particular hazardous and / or unsafe conditions and evaluating the process conditions to determine whether a process shutdown is warranted. If a process shutdown is warranted, one or more field devices, components, and / or elements (e.g., shutdown valves) are engaged to effect or execute the shutdown. In some examples, each safety instrumented function may be implemented using at least one sensing device, one logic solver, and one field device. The logic solver(s) 124 may be configured to monitor at least one process control parameter via one or more sensors and to operate a field device (e.g., field device(s) 128) to effect a safe shutdown of the process if an unsafe condition is detected. For example, the logic solver(s) 124 may be communicatively coupled (e.g., via the bus 126) to field device(s) 128 (e.g., a pressure sensor sensing pressure in a vessel or tank) that may be configured to assist in a shutdown procedure (e.g., opening a vent valve if an unsafe overpressure condition is detected via a pressure sensor). The logic solver(s) 124 may be configured to implement one or more safety instrumented functions and may be communicatively coupled to a number of safety rated or certified field devices. As shown in FIG. 1, the logic solver(s) 124 are communicatively coupled to the SIS controller 108 via the exemplary bus 126 and / or the local safety network 120. However, the logic solver(s) 124 may alternatively be communicatively coupled within the system 100 in any other desired manner. Regardless of how the logic solver(s) 124 are coupled to the system 100 , the logic solver(s) 124 are preferably, but not necessarily, logical peers with respect to the SIS controller 108 .Unlike logic solver(s) 124, logic solver(s) 136 are separate from SIS 140 and do not have access to SIS local safety network 120, nor are they accessible by other components of BPCS 150. In some embodiments, BPCS controller 106 can receive information from logic solver(s) 124 over a different bus so that SIS information can be viewed by plant operators. In some embodiments, such information can be obtained by using a data diode-based data logger (e.g., data logger 131a) where a temporary port is used to connect to the local safety network (e.g., through a switch in local safety network 120), as described above. In some embodiments, a temporary port on data logger 131a can be used to connect to another data logger (e.g., data logger 112a) to retrieve SIS-related information.

[0022] The field device(s) 110, 111, and 128 may be smart or non-smart field devices, including sensors, actuators, and / or other process control devices that may be used to monitor process conditions and / or effectuate a controlled shutdown of the process control system 100. For example, the field devices 110, 111, and 128 may be safety certified or rated flow sensors, temperature sensors, pressure sensors, shutdown valves, vent valves, shutoff valves, critical on / off valves, etc. Any number of field devices and / or logic solvers may be implemented in the process control system for any number of desired process control or safety instrumented functions. For example, if the field device(s) 128 are smart devices, the logic solver(s) 124 may communicate with the field device(s) 128 using a wired digital communication protocol (e.g., HART, Fieldbus, etc.). However, other types of communication media (e.g., wired, wireless, etc.) and protocols may be used instead.

[0023] FIG. 2 is a block diagram of an example process control system 200 that can be configured to use the example secure data logger apparatus and methods described herein for the purpose of data extraction over an external network. Some elements of the example shown in FIG. 2 are identical to those described above in connection with FIG. 1, and therefore the description of identical elements will not be repeated here. Instead, identical elements are indicated with identical reference numbers in FIG. 2, and a full description of those similarly numbered elements will be provided. In contrast to the example shown in FIG. 1, in the example process control system 200 of FIG. 2, the example data loggers 112a and 131a have the additional capability of being able to transfer data to a data extractor over an external network (e.g., external network 212). For example, the data loggers 112a and 131a of FIG. 2 can provide edge gateway capabilities (e.g., access to external networks beyond the process control network, including the local safety network 120 and the area control network 132). For example, data loggers 112a and 131a can be used to pre-process data locally at the edge before sending it to the cloud (e.g., external network 212), providing a gateway between networks by controlling data flow at the boundary between the networks. So, instead of using separate edge gateways and data logging devices, data logger(s) 112a and / or 131a can use the collected data to enable transfer of it to end users via external network 212. For example, data logger(s) 112a and / or 131a can route information from a control system (e.g., SIS 240 and / or BPCS 250) that is not being used by the control system (e.g., BPCS controller 108 and / or SIS controller 108) and make it available to external applications in a secure manner.

[0024] In some examples, the data logger(s) 112a and / or 131a can be connected to one or more input / output (I / O) system(s) 208 and / or 216 of the SIS 240 and / or BPCS 250, as shown in the example of FIG. 2. The I / O system(s) 208 and / or 216 receive data from the field device(s) 128 and convert the data into communications that the example controller(s) 106 and / or 108 can process. Similarly, the I / O system(s) 208 and / or 216 can convert data or communications from the controller(s) 106 and / or 108 into a data format that the corresponding field device(s) 128 can process. In some examples, the I / O subsystem is a main control system I / O subsystem that receives information from field devices (e.g., field device(s) 128) deployed in the process control system. In such an embodiment, the data loggers 112a and 131a can listen for available data from the area control network 132 and / or the local safety network 120 via the I / O system and transmit the data via the external network. In such an embodiment, the data logger(s) 112a and / or 131a do not require access to the individual process control system networks. Communication from the data logger(s) 112a and / or 131a to the external network 212 can occur via, for example, an Ethernet connection, a coaxial cable system, a satellite system, a line-of-site wireless system, etc.

[0025] 3 is a block diagram illustrating an example data logger for logging data in the process control system networks 100 and / or 200 in accordance with the teachings of the present disclosure. The example data logger 300 can be used to implement the data loggers 112a and 131a and includes an example data store 302, an example configurator 304, an example timer 306, an example event detector 308, an example data parser 310, an example identifier 312, and an example connector 314.

[0026] The data store 302 stores information received by the process controllers (e.g., Basic Process Control System (BPCS) controller 106 and / or Safety Instrumented System (SIS) controller 108). The process control system information stored by the data store 302 may include any information received by the controller(s) 106 and / or 108 and captured by the data logger 300. In some examples, the input information may be stored continuously in the data store 302 (e.g., a hard disk). The data store 302 may include data related to the activity of the controllers 106 and / or 108 occurring over a period of time, such as data captured from the field device(s) 110, 111, and / or 128 (e.g., sensors, final control elements, shutoff valves, etc.). In some examples, the data stored in the data store 302 may be overwritten after a period of time specified via user-based configuration. The data captured by the data logger(s) 112a and / or 131a and stored in the data store 302 may include information relevant to performing trip analysis (e.g., resulting from a trip event associated with an unplanned but safe process control system shutdown). Such information may include a timestamp for each collected data point provided by the controller 106 and / or 108, where the data points correspond to information (e.g., temperature, pressure, flow rate, weight, stress, etc.) related to the status of the process control system (e.g., SIS 240 and / or BPCS 250). In some examples, the data store 302 stores metadata, logged data, and time information when delivered, allowing the data logger 300 to be used in applications developed to interpret, search, and report the data. In some examples, the data store 302 exists to record data as soon as the data logger 300 is connected to the process control system network.For example, the data logger 300 may engage in process control system self-discovery to enable automatic detection of devices on a process control system network.

[0027] The configurator 304 can be used to configure the data logger 300. For example, the configurator 304 can be used to set (e.g., via the timer 306) the period of time that collected data is stored in the data store 302 before being overwritten. The timer 306 can be used to determine when a time interval has elapsed (e.g., a user-configured data collection time interval) such that the data logger 300 will overwrite existing information stored in the data store 302. In some examples, the data logger 300 can be configured using the configurator 304 to store safety-related event data, such as log data, metadata, and timestamp information. In some examples, the configurator 304 can be used to configure the data store 302 based on the type of data evaluation to be performed using the collected process control system-based information. In some examples, the configurator 304 is used to configure the storage and recording of pre- and post-trip data for purposes of analyzing safety-related event information, with the action of saving a particular log using the data store 302 based on the process control system parameters of interest for safety-related event evaluation. For example, certain data logs can help determine the integrity level of a protection system, such as the reliability of process control system components that can be established through testing.

[0028] The event detector 308 identifies an event of interest (e.g., a trigger event) in the network of the process control systems 100 and / or 200. For example, the trigger event may be a safety-related event that occurs in the network of the SIS 240 and / or the BPCS 250. A safety-related event may include the appearance of an unexpected node on one or more process control network(s) or a change in a traffic pattern of one or more process control network(s) that corresponds to a deviation from a traffic pattern designated as normal. In some examples, the event may be any event of interest that may occur in an industrial system network (e.g., a change in a particular process control system parameter).

[0029] The data parser 310 parses the information stored in the data store 302 for trigger event related data. For example, in the presence of a safety related event, the data parser 310 searches for data before and after the safety related event. Such data can include log data, metadata, and time stamp information. This allows for a thorough evaluation of process control system activity and can include evaluation of data from one or more process control system networks (e.g., the local safety network 120 and / or the area control network 132 of FIGS. 1-2). In some examples, if the data parser 310 cannot identify data (e.g., input) coming into the data store 302 from a process controller (e.g., the processor controller(s) 106 and / or 108), the data parser 310 triggers an alarm (e.g., the alarm 118 of FIGS. 1-2) outside of the process control system network, and the alarm is used when the input information to the process controller is not accessible.

[0030] Once the data parser 310 has retrieved data from the data store 302 corresponding to data before and / or after the trigger event, the identifier 312 identifies specific data content from the retrieved data necessary for a given evaluation (e.g., root cause analysis). For example, the identifier 312 may retrieve signal value information, data integrity information, and timestamp information captured by the process controller(s) 106 and / or 108.

[0031] The connector 314 transfers the event data to a data extractor (e.g., data extractor 116). In some examples, a data diode (e.g., data diode 112b) can be incorporated into the data logger (e.g., data logger 112a) to transfer data unidirectionally from the process control system network (e.g., local safety network 120) to the data logger (e.g., data logger 112a), such that the data extractor can receive information from the data logger 300, but the data logger 300 does not allow for the transfer of information to the process control system network (e.g., local safety network 120). The data logger 300 can have multiple connectors (e.g., ports) that allow for the transfer of information (e.g., over an internal network or an external network). In some examples, the connector 314 can be used to connect one data logger to another data logger (e.g., a data logger that stores data from different process controllers) to receive information about separate process control systems (e.g., aggregating data from both the SIS 240 and the BPCS 250). In some examples, the connector 314 is used to transfer data from the area control network 132 and / or the local safety network 120 via an I / O system (e.g., I / O system(s) 208 and / or 216) to a data extractor (e.g., USB drive, laptop, etc.) or an external network (e.g., external network 212) without requiring access to the individual process control system networks. In some examples, the connector 314 connects to an embedded computer instead of a general-purpose computer to prevent remote connections and improve hardening (e.g., removing unnecessary applications and services that may pose security risks). In some examples, retrieval of data can be limited to methods that enforce a physical presence (e.g., requiring computer connectivity or other means of data retrieval that can be accomplished via direct connection to the data logger(s)).

[0032] An example method of implementing the data logger apparatus of Figures 1-2 is illustrated in Figure 3, although one or more of the elements, processes, and / or devices illustrated in Figure 3 may be combined, divided, rearranged, omitted, deleted, and / or implemented in any other manner. Additionally, the example data store 302, example configurator 304, example timer 306, example event detector 308, example data parser 310, example identifier 312, example connector 314, and / or, more generally, the example data logger 300 may be implemented by hardware, software, firmware, and / or any combination of hardware, software, and / or firmware. Thus, for example, any of the example data store 302, the example configurator 304, the example timer 306, the example event detector 308, the example data parser 310, the example identifier 312, the example connector 314, and / or, more generally, the example data logger 300 may be implemented by one or more analog or digital circuit(s), logic circuit(s), programmable processor(s), programmable controller(s), graphics processing unit(s) (GPUs), digital signal processor(s) (DSPs), application specific integrated circuit(s) (ASICs), programmable logic device(s) (PLDs), and / or field programmable logic device(s) (FPLDs). When reading any of the apparatus or system claims of this patent covering purely software and / or firmware implementations, the exemplary data store 302, the exemplary configurator 304, the exemplary timer 306, the exemplary event detector 308, the exemplary data parser 310, the exemplary identification device 312, and / or the exemplary connector 314 are hereby expressly defined to include a non-transitory computer-readable storage device or storage disc, such as a memory, a digital versatile disc (DVD), a compact disc (CD), a Blu-ray disc, etc., that contains software and / or firmware.Additionally, the example data logger 300 may include one or more elements, processes, and / or devices in addition to or instead of those shown in Figure 3, and / or may include two or more of any or all of the depicted elements, processes, and devices. As used herein, the phrase "communicate," including variations thereof, encompasses direct communication and / or indirect communication through one or more intermediate components and does not require direct physical (e.g., wired) communication and / or constant communication, but rather further includes selective communication at periodic intervals, scheduled intervals, non-periodic intervals, and / or one-time events.

[0033] A flow chart representing exemplary machine-readable instructions for implementing the data logger 300 of FIG. 3 is shown in FIG. 4. The machine-readable instructions may be one or more executable programs or portions of executable programs for execution by a processor, such as the processor 506 shown in the exemplary processor platform 500 discussed below in connection with FIG. 5. The programs may be embodied in software stored on a non-transitory computer-readable storage medium, such as a CD-ROM, a floppy disk, a hard drive, a digital versatile disk (DVD), a Blu-ray disk, or a memory associated with the processor 506, although the entire program and / or portions thereof may alternatively be executed by a device other than the processor 506 and / or embodied in firmware or dedicated hardware. Additionally, although the exemplary program is described with reference to the flow chart shown in FIG. 4, many other ways of implementing the exemplary data logger 300 may alternatively be used. For example, the order of execution of the blocks may be changed and / or some of the described blocks may be changed, eliminated, or combined. Additionally or alternatively, any or all of the blocks may be implemented by one or more hardware circuits (e.g., discrete and / or integrated analog and / or digital circuits, FPGAs, ASICs, comparators, operational amplifiers (opamps), logic circuits, etc.) configured to perform the corresponding operations without executing software or firmware.

[0034] The machine-readable instructions described herein may be stored in one or more of a compressed format, an encrypted format, a fragmented format, a packaged format, and the like. The machine-readable instructions described herein may be stored as data (e.g., portions of instructions, code, representations of code, and the like) that can be utilized to create, manufacture, and / or generate machine-executable instructions. For example, the machine-readable instructions may be fragmented and stored in one or more storage devices and / or computing devices (e.g., servers). The machine-readable instructions may require one or more of installation, modification, adaptation, updating, combination, supplementation, configuration, decryption, decompression, unpacking, distribution, reallocation, and the like to make them directly readable or executable by the computing device and / or other machines. For example, the machine-readable instructions may be individually compressed, encrypted, and stored in multiple portions stored in separate computing devices, which portions, when decrypted, decompressed, and combined, form a set of executable instructions that implement a program as described herein. In another example, the machine-readable instructions may be stored in a state in which they can be read by a computer, but additional libraries (e.g., dynamic link libraries (DLLs)), software development kits (SDKs), application programming interfaces (APIs), etc., are required to execute the instructions on a particular computing device or other device. In another example, the machine-readable instructions may need to be configured (e.g., storing settings, entering data, recording network addresses, etc.) before the machine-readable instructions and / or corresponding program(s) can be executed in whole or in part. Thus, the disclosed machine-readable instructions and / or corresponding program(s) are intended to encompass such machine-readable instructions and / or program(s) regardless of the particular form or state of the machine-readable instructions and / or program(s) when stored or otherwise stored or transported.

[0035] As mentioned above, the exemplary process of Figure 4 may be implemented using executable instructions (e.g., computer and / or machine readable instructions) stored on a non-transitory computer and / or machine readable medium, such as a hard disk drive, flash memory, read only memory (ROM), compact disk (CD), digital versatile disk (DVD), cache, random access memory (RAM), and / or any other storage device or storage disk in which information is stored for any duration (e.g., long term, permanently, short term, during temporary buffering, and / or during caching of information). As used herein, the term non-transitory computer readable storage medium is expressly defined to include any type of computer readable storage device and / or storage disk, to exclude propagating signals, and to exclude transmission media.

[0036] "Including" and "comprising" (and all forms and tenses thereof) are used herein as open-ended terms. Thus, when a claim uses any form of "including" or "comprising" as a preamble or within any type of claim recitation (e.g., comprises, includes, comprising, including, having, etc.), it should be understood that additional elements, terms, etc. may be present without departing from the scope of the corresponding claim or recitation. As used herein, the phrase "at least," when used as a transitional term, for example, in a claim preamble, is open-ended in the same manner that the terms "comprising" and "comprising" are open-ended. For example, the term "and / or" when used in a form such as A, B, and / or C, refers to any combination or subset of A, B, C, such as (1) A only, (2) B only, (3) C only, (4) A and B, (5) A and C, (6) B and C, and (7) the combination of A, B, and C. As used herein in the context of describing a structure, component, item, object, and / or thing, the phrase "at least one of A and B" is intended to refer to an implementation that includes any of (1) at least one A, (2) at least one B, and (3) at least one A and at least one B. Similarly, as used herein in the context of describing a structure, component, item, object, and / or thing, the phrase "at least one of A or B" is intended to refer to an implementation that includes any of (1) at least one A, (2) at least one B, and (3) at least one A and at least one B. As used herein in the context of describing the implementation or execution of a process, instruction, action, activity, and / or step, the phrase "at least one of A and B" is intended to refer to an implementation that includes any of (1) at least one A, (2) at least one B, and (3) at least one A and at least one B.Similarly, as used herein in the context of describing the implementation or performance of a process, instruction, action, activity, and / or step, the phrase “at least one of A or B” is intended to refer to implementations that include any of: (1) at least one A; (2) at least one B; and (3) at least one A and at least one B.

[0037] FIG. 4 is a flow chart 400 representing machine-readable instructions that may be executed to implement the example data logger 300 of FIG. 3. The configurator 304 configures data collection points for the data logger based on user input. For example, a user may indicate a time interval during which data collection (e.g., data stored in the data store 302 of the data logger 300) should occur before data is overwritten in the data store 302 (block 402). When the data logger 300 connects to a process control system network (e.g., the SIS 240 and / or the BPCS 250) via a data diode (e.g., the data diode(s) 112b and / or 131b), the data store 302 stores input information from the local safety network 120 and / or the area control network 132 to the process controller(s) 106 and / or 108 (block 404). The event detector 308 monitors the process control system network information to determine if a trigger event is detected (block 406). For example, the trigger event may include a safety-related event on the SIS 240 network, such as a trip event (e.g., an unexpected shutdown of the SIS 240). In other examples, the trigger event may be any event defined by a user to be interpreted as a trigger event (e.g., a change in a process control system parameter, an unexpected change in network traffic, etc.). If a trigger event is not detected, the timer 306 determines whether a given time interval (T) (e.g., a user-configured time interval) has elapsed (block 408). If the time interval has not yet elapsed and a trigger event has not been detected, the data logger 300 continues to capture and store data from the process control system (block 404). If the time interval has elapsed, the data store 302 begins overwriting the existing data with new data (block 410).

[0038] If the event detector 308 detects a trigger event in block 406, the data parser 310 uses the data store 302 to identify data before and after the trigger event (block 412). For example, if the trigger event is a safety-related event, such as a trip event, evaluation of the event for purposes of identifying its potential cause may require the use of data captured before and after the trigger event. In some embodiments, the data parser 310 parses the data for trigger event analysis-specific data (block 414). Such data may include log data, metadata, and timestamp information. In some embodiments, the configurator 304 is used to determine the type of data that is of interest (e.g., required input for an application to perform a thorough evaluation of the trigger event). In some embodiments, the data logger 300 obtains event-related data from one or more other data logger(s) that capture information from the process control system (block 416). For example, the data logger 300 may include several connector(s) 314 that allow for the transfer of information to the data extractors 116 and / or 117, or to the external network 212, as well as to another data logger. Thus, if the user configuration calls for retrieval of data from the entire process control system (e.g., not limited to the SIS 240 and / or BPCS 250), the connector 314 may be used to retrieve event-related data to supplement the data available from the monitored process control system (block 418). If the information is collected via the data extractor(s) 116 and / or 117, the connector 314 is connected to the data extractor(s) 116 and / or 117 (block 420). The data diodes 112b and / or 131b allow for the unidirectional transfer of data from the process control system network to the data logger 300, so that this data can be retrieved using the data extractor 116.In some embodiments, the data logger 300 has two or more ports (e.g., one port for transferring information to another data logger and another port for transferring information to a data extractor) for transferring information via the connector(s) 314. The captured data is then used to perform a post-mortem analysis (block 422), for example, to determine the root cause of a trip event or other trigger event (block 424). For example, to increase security by limiting the type and amount of data transferred to the data extractor 116, the identification device 312 identifies data required for the post-mortem analysis (e.g., signal value information, data integrity information, and timestamp information captured by the process controllers 106 and / or 108). The connector 314 transfers only this data or any type of data included in the configuration of the data logger(s) 112a and / or 131a using, for example, the configurator 304 to the data extractor 116.

[0039] Figure 5 is a block diagram of an example processor platform that may be used and / or programmed to perform the example method of Figure 4 and / or more generally to implement the example secure data logger of Figures 1-3. The processor platform 500 may be, for example, a server, a personal computer, a workstation, a self-learning machine (e.g., neural networks), a mobile device (e.g., a mobile phone, a smart phone, a tablet such as an iPad®), a personal digital assistant (PDA), an Internet appliance, a DVD player, a CD player, a digital video recorder, a Blu-ray player, a game console, a personal video recorder, a set-top box, a headset or other wearable device, or any other type of computing device.

[0040] The processor platform 500 of the illustrated embodiment includes a processor 506. The processor 506 of the illustrated embodiment is hardware. For example, the processor 506 can be implemented by one or more integrated circuits, logic circuits, microprocessors, GPUs, DSPs, or controllers from any desired family or manufacturer. The hardware processor can be a semiconductor-based (e.g., silicon-based) device. In this embodiment, the processor 506 implements the configurator 304, the timer 306, the event detector 308, the data parser 310, the identifier 312, and the connector 314 of the data logger(s) 112a and / or 131a.

[0041] The processor 506 of the illustrated embodiment includes a local memory 508 (e.g., a cache). The processor 506 of the illustrated embodiment communicates with a main memory, including a volatile memory 502 and a non-volatile memory 504, via a bus 518. The volatile memory 502 may be implemented by Synchronous Dynamic Random Access Memory (SDRAM), Dynamic Random Access Memory (DRAM), RAMBUS® Dynamic Random Access Memory (RDRAM®), and / or any other type of random access memory device. The non-volatile memory 504 may be implemented by flash memory and / or any other desired type of memory device. Access to the main memory 502, 504 is controlled by a memory controller.

[0042] The processor platform 500 of the illustrated embodiment also includes an interface circuit 514. The interface circuit 514 may be implemented with any type of interface standard, such as an Ethernet interface, a Universal Serial Bus (USB), a Bluetooth interface, a Near Field Communication (NFC) interface, and / or a PCI Express interface.

[0043] In the illustrated embodiment, one or more input device(s) 512 are connected to the interface circuitry 514. The input device(s) 512 allow a user to enter data and commands into the processor 506. The input device(s) may be implemented, for example, by an audio sensor, a microphone, a (still or video) camera, a keyboard, buttons, a mouse, a touch screen, a track pad, a track ball, an isopoint device, and / or a voice recognition system.

[0044] One or more output devices 516 are also connected to the interface circuitry 514 of the illustrated embodiment. The output device 516 may be implemented by, for example, a display device (e.g., a light emitting diode (LED), an organic light emitting diode (OLED), a liquid crystal display (LCD), a cathode ray tube display (CRT), an in-place switching (IPS) display, a touch screen, etc.), a tactile output device, a printer, and / or a speaker. Thus, the interface circuitry 514 of the illustrated embodiment typically includes a graphics driver card, a graphics driver chip, or a graphics driver processor.

[0045] The interface circuitry 514 of the illustrated embodiment also includes communications devices, such as a transmitter, receiver, transceiver, modem, home gateway, wireless access point, and / or network interface, to facilitate data exchange with external machines (e.g., computing devices of any type) over the network 524. Communications may be via, for example, an Ethernet connection, a digital subscriber line (DSL) connection, a telephone line connection, a coaxial cable system, a satellite system, a line-of-site wireless system, a cellular phone system, etc.

[0046] The processor platform 500 of the illustrated embodiment also includes one or more mass storage devices 510 for storing software and / or data. Examples of such mass storage devices 510 include floppy disk drives, hard drive disks, compact disk drives, Blu-ray disk drives, redundant array of independent disks (RAID) systems, and digital versatile disk (DVD) drives. The mass storage includes the exemplary data storage 302.

[0047] The machine-executable instructions 400 of FIG. 4 may be stored in a mass storage device 510, in a volatile memory 502, in a non-volatile memory 504, and / or on a removable non-transitory computer-readable storage medium such as a CD or DVD.

[0048] Although certain example methods, apparatus, and systems have been disclosed herein, the scope of coverage of this patent is not limited thereto. Rather, this patent covers all methods, apparatus, and articles of manufacture that fall within the substantial scope of the claims of this patent.

Claims

1. 1. A method for secure data transfer from a process control system network, comprising: storing information received by a process controller via the process control system network, the process controller including a safety instrumented system controller or a process control system controller, the information being transferred unidirectionally from the process control system network through a data diode to a data logger; identifying a trigger event on the process control system network; analysing the information obtained from the data logger for event data in response to identifying the trigger event; transferring the event data from the data logger to a data extractor.

2. The method of claim 1 , wherein analyzing the information includes retrieving data before and after the trigger event.

3. 3. The method of claim 1 or claim 2, wherein forwarding the event data includes forwarding only one or more of signal value information, data integrity information, and time stamp information captured by the process controller if the triggering event is a safety-related event.

4. The method of claim 1 , wherein the process control system network comprises a local safety network or an area control network.

5. The method of claim 4 , wherein analyzing the information includes analyzing the event data of at least one of the local safety network or the area control network.

6. The method of claim 1 , wherein the event data includes log data, metadata, and timestamp information.

7. 7. The method of claim 1, wherein the trigger event is a safety-related event, the safety-related event including an unexpected node appearance on the process control system network or a change in a traffic pattern of the process control system network, the change corresponding to a deviation from a traffic pattern designated as normal.

8. The method of claim 1 , further comprising configuring the event data based on user input, the user input including a data collection time interval of interest.

9. 9. The method of claim 8, further comprising determining when a user-configured time interval has elapsed and overwriting the information when the user-configured time interval has elapsed.

10. The method of claim 1 , further comprising initiating an alarm external to the process control system network, the alarm being used when input information to the process controller is not accessible.

11. 1. An apparatus for secure data transfer from a process control system network, comprising: a data store for storing information received by a process controller via the process control system network, the process controller including a safety instrumented system controller or a process control system controller, the information being transferred unidirectionally from the process control system network through a data diode to a data logger; an event detector that identifies a trigger event on the process control system network; a data parser that parses the information obtained from the data logger for event data in response to identifying the trigger event; a connector for transferring the event data from the data logger to a data extractor.

12. The apparatus of claim 11 , wherein the data parser is to retrieve data before and after the triggering event if the triggering event is a safety-related event.

13. The apparatus of claim 12 , wherein the connector is to transfer the event data including one or more of signal value information captured by the process controller, data integrity information, and time stamp information.

14. The apparatus of any of claims 11 to 13, wherein the data parser is adapted to parse the event data of at least one of a local safety network or an area control network.

15. The apparatus of claim 11 further comprising a configurator for configuring event data based on user input, said user input including a data collection time interval of interest.

16. 16. The apparatus of claim 15, further comprising a timer that determines when a user-configured time interval has elapsed, and wherein the information is overwritten when the user-configured time interval has elapsed.

17. A non-transitory computer-readable storage medium containing instructions that, when executed, cause a machine to perform at least: storing information received by a process controller via a process control system network, the process controller including a safety instrumented system controller or a process control system controller, the information being transferred unidirectionally from the process control system network via a data diode to a data logger; Identifying a trigger event on the process control system network; responsive to identifying the trigger event, analyzing the information obtained from the data logger for event data; A non-transitory computer readable storage medium that causes the event data to be transferred from the data logger to a data extractor.

18. 20. The computer-readable storage medium of claim 17, wherein the instructions, when executed, further cause the machine to transfer one or more of signal value information captured by the process controller, data integrity information, and time stamp information.

19. 19. The computer readable storage medium of claim 17 or claim 18, wherein the instructions, when executed, further cause the machine to analyze the event data of at least one of a local safety network or an area control network.

20. 20. The computer-readable storage medium of claim 17, wherein the instructions, when executed, further cause the machine to determine when a user-configured time interval has elapsed, and wherein the information is overwritten when the user-configured time interval has elapsed.

Citation Information

Patent Citations

  • Process data recording device and process data recording method

    JP2008129754A

  • Process device condition and performance monitoring

    JP2018073417A