Information processing device, information processing method, and information processing program
The edge-installed information processing apparatus addresses the challenge of maintaining continuous operation by detecting anomalies, managing network connections, and switching programs to ensure resilience against cyberattacks and disasters, ensuring uninterrupted infrastructure services.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- KK TOSHIBA
- Filing Date
- 2023-07-27
- Publication Date
- 2026-04-13
AI Technical Summary
Existing resilience technologies struggle to effectively defend against cyberattacks and maintain continuous operation of infrastructure systems, particularly focusing on the edge infrastructure services.
An information processing apparatus installed at the edge with an anomaly detection unit, network connection/disconnection unit, recovery detection unit, subprogram storage, and execution units to manage program switching and data storage, enabling flexible resilience against abnormalities and cyberattacks.
Enables continuous operation of edge systems by minimizing the impact of cyberattacks and natural disasters, allowing essential infrastructure services to continue even when the external network is compromised.
Smart Images

Figure 0007844398000001 
Figure 0007844398000002 
Figure 0007844398000003
Abstract
Description
Technical Field
[0001] Embodiments of the present invention relate to an information processing apparatus, an information processing method, and an information processing program related to cyber resilience.
Background Art
[0002] In recent years, with the increasing importance of the social position of information processing systems, resilience technologies that can quickly restore the operation of systems in the event of disasters and the like have attracted attention. Regarding cyberattacks, with the cyber-physical system (CPS) transformation of infrastructure systems, it has become difficult to defend against all attacks and keep the entire system operating continuously. In the IT field, the concept of cyber resilience, which minimizes the impact during attacks and enables early recovery, is becoming widespread.
Prior Art Documents
Patent Documents
[0003]
Patent Document 1
Patent Document 2
Summary of the Invention
Problems to be Solved by the Invention
[0004] However, in order to reduce the impact of attacks, a resilience function focusing on the edge, which is the essence of infrastructure services, is required.
[0005] The problem to be solved by the present invention is to provide an information processing apparatus, an information processing method, and an information processing program having a resilience function.
Means for Solving the Problems
[0006] The information processing apparatus according to the embodiment is provided at the edge and The aforementioned edge detects abnormalities When The aforementioned edge state An abnormality detection unit that considers a mode indicating an abnormal state, and when the abnormality detection unit detects an abnormality 1 A network connection / disconnection unit that performs the following processing, prescribed A subprogram storage unit for storing subprograms for executing the function, a corresponding unit for instructing the execution of the subprogram based on the state of the mode, and a subprogram execution unit for executing the subprogram. A recovery detection unit that detects a recovery indicating that the mode has changed from an abnormal state to a normal state, and a temporary storage unit for collected data that temporarily stores data collected when the mode is in an abnormal state, It is equipped with. The network connection / disconnection unit performs a second process when the recovery detection unit detects recovery. [Brief explanation of the drawing]
[0007] [Figure 1] Figure 1 is a diagram showing the overall system configuration according to the first embodiment. [Figure 2] Figure 2 shows an example of an anomaly detection database provided by the information processing device according to the first embodiment. [Figure 3] Figure 3 shows an example of the configuration of a continuously running program included in the information processing device according to the first embodiment. [Figure 4] Figure 4 shows an example of the configuration of a normal execution program included in the information processing device according to the first embodiment. [Figure 5] Figure 5 shows an example of the configuration of an abnormal execution program included in the information processing device according to the first embodiment. [Figure 6] Figure 6 shows an example of the configuration of a recovery execution program included in the information processing device according to the first embodiment. [Figure 7] Figure 7 is a flowchart showing the processing operation of the information processing device according to the first embodiment. [Figure 8] Figure 8 is a flowchart showing the processing operation when the information processing device according to the first embodiment acquires sensor data. [Figure 9] Figure 9 is a flowchart showing the processing operation when the information processing device according to the first embodiment operates an actuator. [Figure 10] Figure 10 is a flowchart showing the processing operations when the information processing device according to the first embodiment restores network operation. [Figure 11] Figure 11 is a diagram showing the overall system configuration according to the second embodiment. [Figure 12] Figure 12 is a diagram showing the configuration of the edge according to Modification 1. [Figure 13] Figure 13 is a diagram showing the configuration of the edge related to the modified example 2. [Modes for carrying out the invention]
[0008] Embodiments of the present invention will be described below with reference to the drawings. (First embodiment) This embodiment provides an example of an information processing device that can respond flexibly (resiliently) to abnormalities such as natural disasters or cyberattacks occurring in a cloud server connected via a network. The information processing device is installed at the edge (for example, in a power plant or railway control facility) and has functions to control machinery and other devices installed at the edge by exchanging data with the cloud server.
[0009] Figure 1 is a diagram showing the overall system configuration according to the first embodiment.
[0010] The information processing device 1 of the first embodiment includes an anomaly detection unit 11, a recovery detection unit 12, an anomaly detection rule DB 13, a network connection / disconnection unit 14, a response unit 15, a subprogram execution unit 16, a subprogram storage unit 17, a temporary storage unit for collected data 18, and a communication unit 19. The subprogram storage unit 17 stores one or more programs from among the normally executed PG 171, the normal execution PG 172, the anomaly execution PG 173, and the recovery execution PG 174.
[0011] The information processing device 1 is a computer equipped with computing functions, control functions, etc., and includes a CPU that executes programs such as software, and volatile and non-volatile memories that store data. It can be any computer device such as a personal computer or a smartphone. The information processing device 1 transmits control commands (e.g., number control of turbines, chemical injection amount, etc.) to the control target installed in the edge 10, or receives sensor data (e.g., temperature sensor, chemical injection amount, rotation speed data, etc.) output by measurement devices such as sensors installed in the edge 10.
[0012] More specifically, the information processing device 1 is installed in the edge 10 of, for example, a wind power plant facility or a dam facility. In the case of a wind power plant facility, the control target is, for example, a wind turbine, the control command is, for example, the number control of the turbine, and the sensor data is, for example, rotation speed data. Of course, the control target, control command, and sensor data are not limited to one each and there may be multiple cases.
[0013] The external network 2 is a network to which one or more information processing devices 1, one or more clouds 3, etc. are connected, and is, for example, the Internet. The external network 2 is not limited to wired or wireless, and may be a communication network using any communication method such as Ethernet, WiFi (registered trademark), 5G communication (5th Generation communication), etc.
[0014] The cloud 3 represents a computer system configured by cloud technology, and exchanges various data with the information processing device 1 via the external network 2. The cloud 3 in this embodiment has the function of transmitting control data to the information processing device 1 to control control targets such as machines connected to the information processing device 1, or receiving sensor data transmitted by the information processing device 1. A plurality of clouds 3 may be connected to the external network 2, and the information processing device 1 may also perform data communication with a plurality of clouds 3.
[0015] Edge 10 refers to the system controlled by the cloud, and in this embodiment, it includes the information processing device 1, the controlled object connected to the information processing device 1, sensors, etc. For example, if this embodiment is applied to a power plant, the system including the information processing device 1 and the power generation facility controlled by the information processing device 1 becomes Edge 10. Edge 10 in this embodiment can be applied to any facility, but if it is applied to a power plant, dam facility, etc., Edge 10 may be installed in remote areas or places that are difficult for people to access, and it is not possible to place people near the controlled object, so cloud control as in this embodiment is desirable.
[0016] The anomaly detection unit 11 has the function of detecting anomalies based on the communication status of the external network 2, according to the rules included in the anomaly detection rule DB 13. If an anomaly is detected, it calls the network connection / disconnection unit 14 and instructs it to disconnect communication with the external network 2. The timing at which the anomaly detection unit 11 monitors the communication status of the external network 2 is arbitrary. When the network connection / disconnection unit 14 disconnects communication with the external network 2, communication between the anomaly detection unit 11 and the recovery detection unit 12 and the external network 2 may be continued.
[0017] The recovery detection unit 12 has the function of detecting recovery from an abnormal state to a normal state according to the rules included in the abnormal detection rule DB 13 based on the communication status of the external network 2 after the abnormality detection unit 11 has disconnected the external network 2. If recovery is detected, the recovery detection unit 12 calls the network connection / disconnection unit 14 and instructs it to resume communication with the external network 2. The timing at which the recovery detection unit 12 monitors the communication status of the external network 2 can be at any time.
[0018] When the anomaly detection unit 11 detects an anomaly in the environment for the edge to operate, such as Cloud 3, it sets the state of the edge's operating environment (sometimes referred to as mode) to an abnormal state. If the recovery detection unit 12 confirms that the state is no longer abnormal in the abnormal state, it sets the edge's mode to a normal state.
[0019] Furthermore, if the information processing device 1 and the external network 2 are completely disconnected, and it is necessary to monitor the status of devices on the external network 2 using anomaly detection rules, the device may have a function to acquire the status via a network other than the disconnected external network 2. For example, if the disconnected network is a wired internet connection, the monitoring by the anomaly detection unit 11 and the recovery detection unit 12 may use a mobile phone network or other analog telephone lines.
[0020] The anomaly detection rule DB13 is, for example, a non-volatile memory that stores an anomaly detection rule database that is referenced by the anomaly detection unit 11, the recovery detection unit 12, etc.
[0021] Figure 2 shows an example of an anomaly detection database provided by the information processing device according to the first embodiment, and includes rules such as monitoring targets to be monitored for anomaly detection and states to be considered abnormal.
[0022] Data R1 is an example of a rule that monitors packet arrival and considers an abnormal state if packets cannot reach Cloud 3. Data R2 is an example of a rule that, if the number of connections to Information Processing Device 1 is limited, considers an abnormal state if the number of connections exceeds 100 requests / second, i.e., it is considered to be under a DoS attack. Data R3 is an example of a rule that uses remote attestation technology to monitor the Cloud 3 system and considers an abnormal state if the attestation results are abnormal, i.e., do not match the expected state.
[0023] The above example is not the only one; appropriate rules can be set according to the intended use of this embodiment. The anomaly detection unit 11 monitors the target of the anomaly detection database and considers it an abnormal state when it matches a rule. The recovery detection unit 12 monitors the target of the anomaly detection database when it is in an abnormal state and considers it to have returned to a normal state when it no longer matches a rule. If there are multiple rules in the anomaly detection database, it is acceptable to consider it an abnormal state when any one of the rules is met, or to consider it an abnormal state when a certain number of rules or all of the rules are met.
[0024] Returning to Figure 1, the network connection / disconnection unit 14 has the function of disconnecting and reconnecting communication with the external network 2 according to instructions from the recovery detection unit 12 and the anomaly detection unit 11. Specifically, the network connection / disconnection unit 14 may disconnect from the external network 2 when an anomaly is detected while the edge mode is in a normal state, and connect to the external network 2 when recovery is detected. Alternatively, the network connection / disconnection unit 14 may enable the operation of allowing only predetermined packets to pass through when an anomaly is detected while the edge mode is in a normal state, and disable the operation of allowing only predetermined packets to pass through when recovery is detected.
[0025] The network connection / disconnection unit 14 may block all communications when disconnecting communication, or it may have the function of blocking only communication from the external network 2 to the internal network within the edge 10, while allowing communication from the internal network to the external network 2. Also, when the recovery detection unit 12 and the anomaly detection unit 11 are activated, communication between the recovery detection unit 12 and the anomaly detection unit 11 and the external network 2 may not be disconnected.
[0026] Furthermore, since TCP / IP communication generally does not work with one-way communication, the network connection / disconnection unit 14 may have a function to return a response to the communication equipment on the internal network if only the communication from the external network 2 to the internal network is disconnected. The network connection / disconnection unit 14 may also have functions such as allowing or blocking only packets received by a specific protocol, for example, functions such as a general firewall or a one-way gateway. In addition, the network connection / disconnection unit 14 calls the response unit 15 in response to changes in the network status, such as connection or disconnection. The above functions of the network connection / disconnection unit 14 can reduce the impact on the edge 10 site in the event of an anomaly.
[0027] The response unit 15 has the function of changing the program executed by the subprogram execution unit 16 according to the change in the mode state. When the information processing device 1 is started up, the response unit 15 first instructs the subprogram execution unit 16 to execute the normally executed PG 171 and the normal execution PG 172 stored in the subprogram storage unit 17. When the mode becomes abnormal, the response unit 15 instructs the subprogram execution unit 16 to terminate the normal execution PG 172 and to start the execution of the abnormal execution PG 173. On the other hand, when the system recovers from an abnormal state, the response unit 15 instructs the subprogram execution unit 16 to terminate the abnormal execution PG 173, execute the recovery execution PG 174, and instructs the system to re-execute the normal execution PG 172. The response unit 15 may also have a function to switch the program to be executed, for example, the normal execution PG 172 and the abnormal execution PG 173, based on the mode.
[0028] The subprogram execution unit 16 has the function of calling and executing a program instructed by the response unit 15 from the subprogram storage unit 17, and terminating the instructed program when instructed to do so by the response unit 15. In addition, if communication is not possible due to disconnection or other reasons on the external network 2, the subprogram execution unit 16 has the function of temporarily storing data to be sent to the external network 2, collected by the continuously running PG 171 and the abnormal execution PG 173, in the temporary data storage unit 18, and sending it to the external network 2 when it is restored. For example, if the information processing device 1 is intended to collect data such as sensor data and send it to a server on the external network 2, the sensor data will be temporarily stored in the temporary data storage unit 18 when the external network 2 is disconnected, and the sensor data will be sent to the server on the external network 2 when the connection to the external network 2 is reconnected.
[0029] The subprogram execution unit 16 always executes the continuously running PG171 and, based on the mode state of the edge, executes one or more of the following: normal execution PG172, abnormal execution PG173, and recovery execution PG174.
[0030] The temporary data storage unit 18 has the function of temporarily storing data specified by the instructions of the subprogram execution unit 16.
[0031] The subprogram storage unit 17 has the function of storing one or more subprograms. This program includes subprograms such as the normally running PG171, the normal execution PG172, the abnormal execution PG173, and the recovery execution PG174.
[0032] The continuously operating PG171 is a subprogram that includes the procedure for acquiring data from the sensor.
[0033] The normal execution program PG172 is a subprogram that includes a procedure for transmitting data acquired by the continuously operating PG171 via the external network 2. The normal execution program may also include a procedure for transmitting actuator operation commands received via the external network 2 to the actuator being controlled.
[0034] The abnormal execution program PG173 is a subprogram that includes a procedure for saving data acquired by the continuously operating program PG171 to the temporary data storage unit 18. The abnormal execution program may also include a procedure for sending all or part of the actuator operation command to the controlled actuator according to predetermined rules.
[0035] The recovery execution PG174 is a subprogram that includes a procedure for transmitting the data stored in the temporary data storage unit 18 via the external network 2.
[0036] The communication unit 19 is a communication function that connects to the external network 2 and communicates data with external devices such as the cloud 3, and is, for example, a communication interface that can connect to the internet. The communication unit 19 may be any one or more communication interfaces, such as wired or wireless. The communication unit 19 may also consist of one or more physical communication interfaces.
[0037] For example, if the communication unit 19 has one physical communication interface, the anomaly detection unit 11, the recovery detection unit 12, the network connection / disconnection unit 14, etc., may each be logically connected to the external network 2 independently. On the other hand, if the communication unit 19 has multiple physical communication interfaces, the anomaly detection unit 11, the recovery detection unit 12, the network connection / disconnection unit 14, etc., may each be connected to the external network 2 independently using a physical communication interface. Furthermore, the anomaly detection unit 11 and the recovery detection unit 12 may have the function to communicate with the cloud 3 using a communication network other than the external network 2 without using the communication unit 19.
[0038] The following describes a typical application example of this embodiment, in which sensor data is collected and transmitted to an external network 2, and an actuator, which is an example of a control target, is operated in response to commands from the external network 2. Note that the program configuration shown below is just one example, and the program structure will vary depending on the application; therefore, it is not limited to the following example.
[0039] Figure 3 shows an example of the configuration of a continuously running program included in the information processing device according to the first embodiment.
[0040] The normally running PG 171 includes procedures for a computer or the like to execute the functions of the sensor data acquisition unit 1711 and the actuator operation unit 1712. The sensor data acquisition unit 1711 has the function of acquiring data from the sensor and transmitting the data to the data network transmission unit 1721 of the normally running PG 172 when the normally running PG is operating in the subprogram execution unit 16, and transmitting the data to the data temporary storage control unit 1731 of the abnormal execution PG 173 when the abnormal execution PG 173 is operating in the subprogram execution unit 16.
[0041] Furthermore, the actuator operating unit 1712 has the function of operating the actuator by receiving actuator operation commands from the data network receiving unit 1722 of the normal execution PG 172 when the normal execution PG 172 is operating in the subprogram execution unit 16, and from the degraded control unit 1732 of the abnormal execution PG 173 when the abnormal execution PG 173 is operating in the subprogram execution unit 16.
[0042] Figure 4 shows an example of the configuration of a normal execution program included in the information processing device according to the first embodiment.
[0043] The normal execution program includes procedures for a computer or other device to execute the functions of the data network transmission unit 1721 and the data network reception unit 1722. The data network transmission unit 1721 has the function of transmitting data received from the sensor data acquisition unit 1711 via the external network 2. The data network reception unit 1722 has the function of transmitting actuator operation commands received from the external network 2 to the actuator operation unit 1712.
[0044] Figure 5 shows an example of the configuration of an abnormal execution program included in the information processing device according to the first embodiment.
[0045] The abnormal execution PG173 includes procedures for a computer or other device to execute the functions of the temporary data storage control unit 1731 and the degraded control unit 1732. The temporary data storage control unit 1731 has the function of storing data received from the sensor data acquisition unit 1711 in the temporary data storage unit 18. The degraded control unit 1732 has the function of issuing operation instructions to the actuator operation unit 1712 according to predetermined rules, even when there are no actuator operation commands from an external device such as Cloud 3 via the external network 2. These rules can be determined in advance and set in the degraded control unit 1732. For example, rules can be set according to the application, such as omitting complex operations such as power-optimized control and continuing simple operations that meet certain operating criteria, even if they are power-inefficient, or a function to safely stop the actuator. Alternatively, the rules set in the degraded control unit 1732 can be dynamically set by Cloud 3 to the information processing device 1 according to the situation. Alternatively, rules can be set in the degraded control unit 1732 according to the degree of abnormality, and the degraded control unit 1732 can determine the rules according to the detected degree of abnormality.
[0046] Figure 6 shows an example of the configuration of a recovery execution program included in the information processing device according to the first embodiment.
[0047] The recovery operation PG173 includes a procedure for a computer or other device to execute the functions of the temporary data network retransmission unit 1741. The temporary data network retransmission unit 1741 has the function of retrieving data stored in the collected data temporary storage unit 18 and transmitting it via the external network 2.
[0048] Figure 7 is a flowchart showing the processing operation of the information processing device according to the first embodiment.
[0049] When the information processing device 1 is started (step S101), the subprogram execution unit 16 starts the normally executed PG 171 (step S102), and then starts the normal execution PG 172 (step S103). After that, the abnormality detection unit 11 refers to the abnormality detection rule DB 13 and determines whether the edge mode is in an abnormal state according to predetermined rules, and if it is not in an abnormal state, it returns to determining whether it is in an abnormal state again (step S104 No). On the other hand, if it is in an abnormal state, the network connection / disconnection unit 14 disconnects the external network 2 (step S105). Next, the subprogram execution unit 16 terminates the normal execution PG 172 (step S106) and starts the abnormal execution PG 173 (step S107).
[0050] Furthermore, the abnormality detection unit 11 determines whether an abnormal state exists, and if it remains abnormal (Yes in step S108), it returns to determining whether an abnormal state exists. On the other hand, if the abnormal state is gone, the network connection / disconnection unit 14 restores the network (step S109), and the subprogram execution unit 16 terminates the abnormal execution PG 173 (step S110) and simultaneously starts the recovery execution PG (step S111). In step S111, the subprogram execution unit 16 starts the normal execution PG 172 according to the procedure of the recovery execution PG 174. Once the normal execution PG 172 is started, it returns to step S103, and the processing from step S104 onwards is repeated. Once the normal execution PG 172 is started, the recovery execution PG terminates.
[0051] Figure 8 is a flowchart showing the processing operation when the information processing device according to the first embodiment acquires sensor data.
[0052] When the subprogram execution unit 16 acquires sensor data (step S121), it determines whether the abnormality execution PG is running. If it is not running (No in step S122), it sends the acquired sensor data to the original destination (for example, cloud 3) via the external network 2 (step S123). If it is running (Yes in step S122), it temporarily stores the acquired sensor data in the information processing device 1 (step S124).
[0053] Figure 9 is a flowchart showing the processing operation when the information processing device according to the first embodiment operates an actuator.
[0054] The subprogram execution unit 16 determines whether the abnormal execution PG 173 is running (step S141). If it is not running (No in step S141), the subprogram execution unit 16 receives control data from the cloud 3 via the original external network 2 (step S142) and outputs a control command to perform actuator control according to the received control content (step S143). On the other hand, if the abnormal execution PG 173 is running (Yes in step S141), the subprogram execution unit 16 determines the execution content of the abnormal execution PG 173 (step S144) and outputs a control command to perform actuator control according to the determined control content (step S143). In step S144, the execution content of the abnormal execution PG 173 determined by the subprogram execution unit 16 may be, for example, a degraded version of the control content by the normally executed PG 171 or the normal execution PG 172 (degraded control content), and the degraded control content may be predetermined, such as by being set in the program.
[0055] Figure 10 is a flowchart showing the processing operations when the information processing device according to the first embodiment restores network operation.
[0056] When the recovery detection unit 12 detects recovery from an abnormal state, the subprogram execution unit 16 retrieves the temporarily stored data in the temporary data storage unit 18 and transmits it to the cloud 3 or the like via the external network 2 (step S162).
[0057] By following the above procedure, even if the external network 2 malfunctions or if equipment connected to the external network 2, such as the cloud 3 system, enters an abnormal state, i.e., if the mode of the edge 10 becomes abnormal, a resilience function is enabled that allows the edge 10 to continue minimum processing. For example, if this embodiment is applied to a power generation facility, even if the cloud 3 stops, power generation can continue without stopping.
[0058] Furthermore, according to this embodiment, it is possible to realize functions such as continuously collecting sensor data and collecting it again from the external network 2 when the network state is restored, and continuing minimal control operations (e.g., actuator operation) even without instructions from the external network 2, making it possible to provide services at edge 10 without completely stopping them. According to this embodiment, it is possible to strengthen the infrastructure system, and in the event of attacks on the CPS system, abnormalities in the network / cloud 3, or disasters, minimal processing can continue to operate at edge 10. (Second embodiment) Figure 11 is a diagram showing the overall system configuration according to the second embodiment.
[0059] If the names of the functional blocks in this figure are the same as the names of the functional blocks in the information processing device 1 in Figure 1, then detailed explanations of the functions, etc., are omitted, and the symbol A is assigned to the functional block of the information processing device 1.
[0060] In the configuration shown in the first embodiment, an example was shown in which all functions were placed within a single information processing device 1. However, in this embodiment, as shown in Figure 11, the anomaly detection unit 11A, the recovery detection unit 12A, the anomaly detection rule DB 13A, and the network connection / disconnection unit 14 are configured as a single information processing device 1A1 (also referred to as the first information processing device 1A1), while the response unit 15A, the subprogram execution unit 16A, the subprogram storage unit 17A, and the collected data temporary storage unit 18A are configured as another information processing device 1A2 (also referred to as the second information processing device 1A2).
[0061] For example, in this embodiment, the first information processing device 1A1 is equipped with functions common to the control targets installed at edge 10A, and the second information processing device 1A2 is equipped with a program corresponding to the connected control target. This allows the functions of the information processing device 1 (functions shown in the first embodiment) to be flexibly provided at edge 10 even when different control targets are provided at edge 10. Furthermore, the first information processing device 1A1 may exchange data with multiple clouds 3A1 and 3A2.
[0062] Furthermore, if various functions exist within the system (edge 10A), three or more second information processing units 1A2 may be provided, and the programs stored in the subprogram storage unit 17A of each second information processing unit 1A2 may be changed. Also, for example, if there are two second information processing units 1A2, one may have only the always-on PG171A, and the other may have the normal execution PG172A, the abnormal execution PG173A, and the recovery operation PG174A, and the functions to be flexibly divided according to the purpose and constraints of the device.
[0063] According to this modified example, by using multiple information processing devices 1A at the edge 10A, a more flexible configuration enables resilience functionality. (Variation 1) The embodiments described above can also be used, for example, to control wind power generation equipment. This modified example describes a case where multiple wind power generation equipment is installed and operated simultaneously within edge 10B. For example, since multiple wind power generation equipment may have different manufacturing dates, modifications, or different characteristics depending on the manufacturer, it may be necessary to prepare programs and parameters that are suitable for each wind power generation equipment.
[0064] Figure 12 is a diagram of the edge configuration according to Modification 1, and is mainly an example of a change in the configuration of the second information processing device 1A2 in Figure 11. In Figure 12, functional blocks with the same names as the functional blocks in Figure 11 are denoted with B instead of A, and unless otherwise specified, their functions are the same.
[0065] Inside the second information processing device 1B2, a sub-PG storage unit 17B is provided, which stores execution programs for each of the multiple wind turbines 100B-1, 100B-2, 100B-3, and 100B-N, which are designated as Unit 1, Unit 2, Unit 3, and Unit N (where N is a natural number greater than or equal to 2). For example, for wind turbine Unit N, a normally running PG 171B-N, a normal operation PG 172B-N, an abnormal operation PG 173B-N, and a recovery operation PG 174B-N are provided.
[0066] Each subprogram execution unit 16B controls each wind turbine and exchanges data with each wind turbine using its own pre-prepared execution program. This means that when maintenance is performed, it is done at a single information processing unit 1B2, minimizing the need for workers to move around. Furthermore, it is convenient for the information processing unit 1B2 to transmit control commands to each wind turbine and to collect sensor data from each wind turbine via wireless communication. (Modification 2) This modified example illustrates a case where a second information processing device is installed for each of the multiple wind power generation devices.
[0067] Figure 13 is a diagram of the edge configuration related to Modification 2. Functional blocks with the same names as those in Figure 11 are denoted with "C" instead of "A" in their reference numerals, and unless otherwise specified, their functions are the same.
[0068] For wind turbines No. 1 and No. N (where N is a natural number greater than or equal to 2), a second information processing unit 1C2-1 and 1C2-N are prepared and connected, respectively. The internal configurations of the second information processing units 1C2-1 and 1C2-N are the same, and unless otherwise specified, they are referred to as the second information processing unit 1C2. The following explanation will use the second information processing unit 1C2-N as an example, but the same applies to the second information processing unit 1C2-1.
[0069] The second information processing device 1C2-N stores the normally executed PG171B-N, normal execution PG172B-N, abnormal execution PG173B-N, and recovery execution PG174B-N, which are prepared for wind turbine No. N, in the subprogram storage unit 17C-N and executes them in the subprogram execution unit 16C-N.
[0070] Furthermore, at edge 10C, since the first information processing device connected to the external network 2 is one of the information processing devices 1C1, the first information processing device 1C1 communicates with multiple second information processing devices 1C2-1 and 1C2-N.
[0071] This modification is effective when you want to use a program tailored to each of multiple wind turbines, or when multiple wind turbines (e.g., Unit 1, Unit N) and their corresponding second information processing units (corresponding to information processing units 1C2-1 and 1C2-N) are integrated. Furthermore, even if multiple wind turbines have different manufacturing dates, different modifications, or different characteristics depending on the manufacturer, this modification makes it possible to prepare a program tailored to each wind turbine. In addition, this modification makes it possible to perform repair and inspection even if one wind turbine is stopped, while the other turbines are running.
[0072] Furthermore, according to this modified version, the second information processing devices 1C2-1 and 1C2-N can be installed at the corresponding locations of the wind power generation equipment, and system construction can be easily carried out by exchanging data between the first information processing device 1C1-1 and the second information processing device (corresponding to information processing devices 1C2-1 and 1C2-N) via wireless communication.
[0073] According to the embodiments and modifications described above, an information processing device, an information processing method, and an information processing program can be provided. According to these embodiments and modifications, even if the number of attack interfaces increases in various ways in the future due to the implementation of CPS, the impact on the edge during an attack can be minimized, and essential infrastructure services can be continuously provided.
[0074] It should be noted that the present invention is not limited to the embodiments described above, and the components can be modified and implemented in practice without departing from the spirit of the invention. Furthermore, various inventions can be formed by appropriately combining the multiple components disclosed in the embodiments. For example, some components may be deleted from all the components shown in the embodiments. Furthermore, components from different embodiments may be appropriately combined. In addition, the processing steps shown in the flowcharts, sequence charts, etc., in the embodiments are also within the scope of the present invention even if the order of the steps is changed, steps are deleted, or steps are added, without departing from the spirit of the invention.
[0075] The processes shown in flowcharts, sequence charts, etc., may be implemented by hardware such as a CPU, IC chip, digital signal processor (DSP), or by software (such as a program) running on a computer including a microcomputer, or by a combination of hardware and software.
[0076] Furthermore, the present invention applies to any claim expressed as control logic, as a program containing instructions for a computer to execute, or as a computer-readable recording medium containing such instructions. The use of names and terms is also not limited; other expressions, if substantially the same in content and intent, are included in the present invention. [Explanation of symbols]
[0077] 1... Information processing device, 2... External network, 3... Cloud, 11... Recovery detection unit, 12... Anomaly detection unit, 13... Anomaly detection rule DB, 14... Network connection / disconnection unit, 15... Response unit, 16... Subprogram execution unit, 17... Subprogram storage unit, 18... Collected data temporary storage unit, 171... Always running PG, 172... Normal execution PG, 173... Anomaly execution PG, 174... Recovery execution PG.
Claims
1. Equipped on the edge, An abnormality detection unit that, when it detects an abnormality in the edge, sets the mode indicating the state of the edge to an abnormal state, The network connection / disconnection unit performs a first process when the abnormality detection unit detects an abnormality, A subprogram storage unit that stores subprograms for executing a predetermined function, A corresponding unit that instructs the execution of the subprogram based on the state of the aforementioned mode, A subprogram execution unit that executes the aforementioned subprogram, A recovery detection unit that detects a recovery indicating that the mode has changed from an abnormal state to a normal state, The system includes a temporary storage unit for collected data that temporarily stores data collected when the aforementioned mode is in an abnormal state. The network connection / disconnection unit is an information processing device that performs a second process when the recovery detection unit detects recovery.
2. The information processing apparatus according to claim 1, wherein the first process includes a network disconnection process, and the second process includes a network connection process.
3. The information processing apparatus according to claim 1, wherein the network connection / disconnection unit enables the operation of allowing only predetermined packets to pass when the abnormality detection unit detects an abnormality while the mode is in a normal state, and disables the operation of allowing only predetermined packets to pass when the recovery detection unit detects the recovery.
4. The continuously running program includes a procedure for acquiring data from a sensor, The program that runs under normal circumstances includes a procedure for transmitting the aforementioned data over the network. The abnormal execution program includes a procedure for saving the data to the temporary storage unit for collected data. The recovery execution program includes a procedure for transmitting the data stored in the temporary storage unit for collected data via the network. The information processing apparatus according to claim 1, wherein the subprogram comprises the normally executed program, the normal execution program, the abnormal execution program, and the recovery execution program.
5. The subprogram execution unit is: The aforementioned always-on program is run continuously, The information processing apparatus according to claim 4, which executes one or more of the normal execution program, the abnormal execution program, and the recovery execution program based on the state of the mode.
6. The normal execution program includes a procedure for transmitting an actuator operation command received via the network to the actuator, The abnormal execution program includes a procedure for transmitting all or part of the actuator operation commands to the actuator. The information processing apparatus according to claim 5, characterized in that the corresponding unit has a function to switch between the normal execution program and the abnormal execution program that are executed based on the mode.
7. An information processing method for an information processing device provided at an edge, When an abnormality is detected in the edge, the mode indicating the state of the edge is set to an abnormal state. When the aforementioned abnormality is detected, the first process is performed. The execution of a subprogram for performing a predetermined function, which is stored in the subprogram storage unit, is instructed based on the state of the mode. Execute the aforementioned subprogram, The system detects a recovery that indicates the mode has changed from an abnormal state to a normal state. When the aforementioned mode is in an abnormal state, the collected data is stored in the temporary storage unit for collected data. An information processing method that performs a second process when it detects the aforementioned recovery.
8. A computer provided at the edge, When an abnormality is detected in the edge, the abnormality detection unit sets the mode indicating the state of the edge to an abnormal state. The network connection / disconnection unit performs a first process when the abnormality detection unit detects an abnormality, A subprogram storage unit that stores subprograms for executing a predetermined function, A corresponding unit that instructs the execution of the subprogram based on the state of the aforementioned mode, A subprogram execution unit that executes the aforementioned subprogram, A recovery detection unit that detects a recovery indicating that the mode has changed from an abnormal state to a normal state, The aforementioned mode is configured to function as a temporary storage unit for collected data, which temporarily stores the data collected when the mode is in an abnormal state. A program for causing the network connection / disconnection unit to perform a second process when the recovery detection unit detects recovery.
Citation Information
Patent Citations
Illegal access coping type server changeover method and device
JP2001256138A
Abnormality detecting device, monitoring control system, abnormality detection method, program and recording medium
JP2012168686A
Control unit and control method
JP2021060778A
Event monitoring and management
US20050015624A1