System and method for monitoring an automatic system
A junction block with universal generic rules and a head module enhance the reliability and versatility of automated system monitoring by detecting cyberattacks and operational deviations, ensuring protection and data integrity.
Patent Information
- Application Number
- PCT/EP2025/065964
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-06-07
- Filing Date
- 2025-06-09
- Publication Date
- 2025-12-11
AI Technical Summary
Existing monitoring systems for automated systems are unreliable and lack versatility, as they rely on vulnerable programmable logic controllers (PLCs) and do not effectively detect cyberattacks or operational deviations, and require specific programming for each system.
A junction block with fixed generic rules, independent of controller programming, is integrated into the automated system to monitor and protect against cyberattacks by comparing input signals against universal physical laws, and a head module collects and analyzes these signals for real-time alerts and protection.
The system provides reliable and versatile monitoring by detecting malicious acts and natural drifts, protecting the system from cyberattacks and operational deviations, while minimizing data corruption and improving reliability and responsiveness.
Smart Images

Figure EP2025065964_11122025_PF_FP_ABST
Abstract
Description
[0001] "System and method for monitoring an automated system"
[0002] TECHNICAL FIELD
[0003] The present invention relates to the monitoring and protection of an automated system against malfunctions. It finds, for example, particularly advantageous applications in cybersecurity, the Internet of Things, production optimization and maintenance (corrective, conditional and predictive) of an automated system, or real-time data traceability.
[0004] STATE OF THE ART
[0005] To increase the productivity of an automated system, its responsiveness to operational disruptions must be improved. In particular, it is necessary to monitor potential operational deviations within the system. This requires access to the information flowing between the system's equipment and its control devices. Most approaches to detecting operational deviations are based on the assumption that control devices, programmable logic controllers (PLCs), physical interfaces between sensors or actuators, and digital networks offer reliable capabilities for providing collected and aggregated information. However, in reality, PLCs are vulnerable.
[0006] US patent application 11378929 B2, for example, describes a so-called "deterministic dummy logic controller" (DFPLC) integrated into an industrial system, cloning a conventional programmable logic controller (PLC) and connected to a monitoring unit. The monitoring principle disclosed by US patent 11378929 B2 is based on a pair of identical "real" (PLC) and "dummy" (DFPLC) controllers. The monitoring unit is configured to compare the behavior of the DFPLC dummy controller and the corresponding real PLC. In case of a behavioral discrepancy, the monitoring unit issues an alert. This monitoring principle assumes that only the real PLC can fail, and that the second DFPLC dummy controller is not vulnerable to cyberattacks.
[0007] In the event of an attack or failure of the automated system, it is possible that the DFPLC dummy controller could also be compromised or infected. Therefore, this solution is not entirely reliable. Furthermore, the DFPLC is designed and programmed specifically for the application of the monitored industrial system, allowing it to "disguise" itself among the conventional programmable logic controllers (PLCs). The DFPLC relies on deterministic programming and must be adapted or reprogrammed for each PLC being cloned. This solution is therefore not versatile.
[0008] Document US20070073521A1 discloses another solution for detecting failure in the operation of an automated system, specifically by monitoring vibration parameters of industrial machines.
[0009] The present invention proposes to overcome, at least in part, the known drawbacks of monitoring systems for an automated system. In particular, an objective of the present invention is to provide a monitoring system that can be integrated into an existing automated system and that is reliable and / or versatile.
[0010] SUMMARY
[0011] To achieve this objective, according to a first aspect of the invention, a junction block is provided for monitoring an automated system. The automated system comprises at least one controller configured to control at least one physical component by exchanging data signals with the at least one physical component. The junction block is configured to be connected to the at least one controller. The junction block comprises an electronic board. The electronic board incorporates a specification of fixed generic rules, based on physical processes related to the normal operation of the at least one controller and the at least one physical component. These generic rules are independent of any programming of the at least one controller.
[0012] This junction block, incorporating a set of fixed generic rules, is a ready-to-integrate component for integration into any existing or new automated system, without requiring programming specific to the system's application. Thanks to these fixed generic rules, applicable to any existing or new automated system, the junction block protects a wide variety of commercially available pre-actuators and actuators. The junction block monitors and / or detects dangerous control signals, such as malicious acts (or cyberattacks), degradation, or natural drift of a physical component, particularly when the junction block is connected to sensors.The junction block collects or receives control or setpoint data directly from the controller, as well as dynamic data from sensors associated with the physical component. A real-time comparison of the control data with the sensor data, against fixed generic rules, then allows for the autonomous evaluation of the physical component's operating status, independent of the controller's reliability. Unlike the system disclosed in document US20070073521 A1, the junction block here is configured solely to receive data from the controller. The junction block operates independently of the controller. It does not transmit signals to the controller. Therefore, the junction block can evaluate the controller's operation itself, which is particularly advantageous when the controller is faulty, for example, during a cyberattack.The automated system incorporating such a junction block can therefore be advantageously protected against these dangerous control signals emitted by the controller. The operating principle of the junction block according to the invention, based on a comparison between measured values (typically by a sensor) and expected values (typically setpoints from the controller), is thus fundamentally different from that of the monitoring system disclosed by US20070073521A1, which is based solely on sensor data aggregated and interpreted by signal processing engines. The monitoring system according to US20070073521A1 does not challenge the instructions issued by the controller. Unlike the present invention, no strategy for detecting compromise of the controller is envisaged in US20070073521A1.
[0013] Unlike prior art solutions (notably that of document US20070073521 A1) where monitoring modules operate downstream of the controller (PLC) and merely aggregate signals from input / output modules, the invention allows for cross-checking independent of the controller, making it possible to detect attacks aimed at distorting the internal commands of the control system.
[0014] The generic rules used in the junction block are typically based on physical laws to which any type of actuator and / or pre-actuator is subject.
[0015] A second aspect of the invention relates to a monitoring system for an automated system, comprising at least one junction block, the monitoring system further comprising a head module configured to:
[0016] • be connected to at least one junction block, and
[0017] • receive in real time at least one alert issued by the junction block when at least one input signal collected by the junction block does not conform to the generic rules and export at least one alert to a third-party system, or
[0018] • receive in real time a plurality of input signals collected by a plurality of junction blocks, and issue at least one alert if at least one of said input signals violates at least one detection rule integrated into the head module.
[0019] Beyond monitoring and alerting functions in the event of malicious use or deviant operation of the pre-actuators, actuators, and / or controller, the system, comprising a head module connected to at least one junction block, offers a true capacity for collecting and disseminating information gathered at the lowest level—close to the physical component—to a higher level. A third aspect of the invention relates to a method for monitoring an automated system using the monitoring system, comprising:
[0020] • a collection by at least one junction block of at least one input signal emitted by at least one controller and / or at least one physical component, and
[0021] • a real-time assessment of the conformity of at least one input signal with respect to generic rules.
[0022] This process minimizes the risk of intentional or unintentional alteration of data within the automated system. It does this by collecting, at the lowest level of the system's architecture (using the junction block), all data signals exchanged between the controller and the physical component, and comparing them to generic rules. Furthermore, this process typically allows for the acquisition of this data in raw form, along with all associated fields such as timestamping, enabling precise visualization of the signals received by pre-actuators, actuators, and sensors.
[0023] BRIEF DESCRIPTION OF THE FIGURES
[0024] The aims, objects, features and advantages of the invention will become clearer from the detailed description of an embodiment thereof, which is illustrated by the following accompanying drawings in which:
[0025] Figure 1 schematically illustrates a monitoring system comprising a junction block according to an example of an embodiment of the present invention, integrated into an automated system.
[0026] Figure 2 schematically illustrates a monitoring system comprising a plurality of junction blocks according to an example of an embodiment of the present invention, integrated into an automated system.
[0027] Figure 3 represents a flowchart illustrating steps in the process of monitoring an automated system using a monitoring system according to an example embodiment of the present invention.
[0028] The drawings are given as examples and are not limiting to the invention. They constitute schematic representations of principle intended to facilitate understanding of the invention and are not necessarily to scale with practical applications.
[0029] DETAILED DESCRIPTION
[0030] Before proceeding with a detailed review of embodiments of the invention, the following are optional features that may be used in combination or alternatively:
[0031] In one example, the junction block is configured to:
[0032] • be connected in series between at least one controller and at least one physical component,
[0033] • collect at least one input signal emitted by at least one controller and / or at least one physical component, and
[0034] • Evaluate in real time the conformity of at least one input signal with respect to generic rules. The junction block, by connecting it between the physical inputs and outputs of a physical component (e.g., a pre-actuator, an actuator, or a sensor) and a controller (e.g., a programmable logic controller (PLC), a speed controller, etc.), allows the data exchanged between the physical component and its controller to be retrieved at the lowest level of the control architecture. This enables the visualization of the raw data exchanged between a conventional PLC and a pre-actuator, actuator, or sensor of the monitored industrial system. This minimizes the risk of data corruption and improves monitoring reliability.Furthermore, by applying generic rules in real time and on each collected signal, the junction block makes it possible to detect any suspicious signal originating for example from a natural drift, and / or any risk of modification by a cyber attacker at the lowest level of the automated system, whether at the level of the programmable logic controller, the pre-actuators or the actuators.
[0035] In one example, the junction block is configured to issue at least one real-time alert when at least one input signal does not conform to the generic rules.
[0036] The junction block allows for the detection of any suspicious signals that do not conform to generic rules by sending an alert that can be communicated to the user in real time, allowing them to act quickly to avoid degradation of the automated system or a decrease in industrial production.
[0037] As an example, the junction block can incorporate artificial intelligence.
[0038] As an example, the junction block can include at least one software program.
[0039] According to one example, the number of generic rules is finite.
[0040] In one example, the junction block comprises a housing encapsulating the electronic board, the housing being made of an electrically insulating material. In another example, the housing is configured to allow the junction block to be installed on DIN rails.
[0041] The housing encapsulating the various components of the terminal block, being compatible with standardized mounting profiles, allows the terminal block to be integrated into existing automated systems by installing it on DIN rails, which are widely used for the mechanical support of electrical equipment (such as circuit breakers) and their accessories. This terminal block is therefore non-intrusive and can be installed in place of existing terminal blocks. The housing also provides galvanic isolation, which helps prevent the terminal block from interfering with the automated system.
[0042] As an example, a monitoring system for an industrial system is planned, comprising:
[0043] • at least one signal processing module configured to receive dynamic data from sensors associated with industrial equipment,
[0044] • at least one logic processing module configured to combine said dynamic data with control or setpoint data coming directly from the industrial programmable controller (PLC) or equivalent module, said logic processing module being further configured to compare in real time the sensor data with this control data according to at least one predefined algorithm, in order to evaluate the operating state of the industrial equipment autonomously, independently of the reliability of the PLC.
[0045] According to one example, the monitoring system is configured to interrupt data signals exchanged between at least one controller and at least one physical component, when at least one input signal collected by at least one junction block does not conform to the generic rules of at least one junction block.
[0046] This ability to interrupt the control signals of the pre-actuators or actuators protects them in the event of degrading or destructive control. This protection mode can be activated or deactivated as needed.
[0047] According to one example, the head module further includes memory and is configured to store at least one alert and at least one input signal in a data format in memory.
[0048] As an example, the head module is encapsulated in a housing made of an electrically insulating material, the housing being configured to allow the head module to be installed on DIN rails. The advantages described above for the terminal block are applicable to such a head module.
[0049] In one example, the head module is connected to at least one junction block through a DIN rail compatible bus connector.
[0050] These connectors are designed for direct mounting between terminal blocks on standard DIN rails and are commonly used to distribute power. Typically, these connectors distribute power from the head module to all terminal blocks connected to the head module.
[0051] In one example, the head module is configured to communicate at least one input signal that triggers at least one alert, in a data format, to the third-party system.
[0052] This allows the data collected by the head module to be transmitted securely, without disrupting existing industrial networks, to third-party systems such as a "cloud" type system, "big data", SCADA (acronym for "Supervisory Control and Data Acquisition"), SIEM (acronym for "Security Information and Event Management") or mobile applications.
[0053] According to one example, the communication of data stored in the memory of the head module to at least one third-party system is done through a wireless or wired network.
[0054] In one example, the head module includes a microprocessor configured to correlate the data exchanged between at least one controller and at least one physical component, and to transmit this correlated data to an artificial intelligence algorithm executable by the microprocessor and / or the third-party system. This artificial intelligence algorithm is configured to detect minor operational deviations in the automated system. Minor operational deviations typically correspond to deviations of less than 10%, preferably less than 5%, for example, on the order of 1%, or even 0.1%.This artificial intelligence-based algorithm, using data collected from all junction blocks and centralized in the head module, enables more precise diagnosis of malfunctions in the automated system. It can predict or detect, for example, small desynchronizations at the scale of a programmable logic controller (PLC) that might go unnoticed but could translate, at the scale of all PLCs, into a sophisticated and sophisticated cyberattack. Conversely, or as a complement, it helps eliminate potential false positives. The reliability of attack detection is improved.
[0055] As an example, the head module also includes a clock. The clock provides a precise and continuous time reference, even in the absence of a power supply. A battery can be integrated into the head module. This allows, for example, the timestamping of data acquired at each of the junction blocks.
[0056] According to one example, the automated system monitoring process includes a real-time emission of at least one alert by at least one junction block to the head module, when at least one input signal is evaluated as not conforming to the generic rules.
[0057] According to one example, the automated system monitoring process includes a real-time transmission of at least one input signal collected by at least one junction block, to the head module.
[0058] The collection by the head module of all the data signals taken from the junction blocks allows all the data to be centralized at the level of the head module, which then allows them to be correlated and / or analyzed.
[0059] According to one example, the process further includes real-time storage of at least one alert and at least one input signal in the form of data in memory.
[0060] According to one example, the method of monitoring an automated system further includes synchronization using the clock of the head module, between at least one junction block and the head module before the collection by at least one junction block of at least one input signal.
[0061] According to one example, the method of monitoring an automated system further includes an interruption of the data signals exchanged between the controller and at least one physical component, when at least one input signal is evaluated as not conforming to the generic rules by at least one junction block.
[0062] According to one example, the monitoring process of an automated system further includes communication by the head module of at least one alert and at least one collected input signal, in a data format to at least one third-party system.
[0063] Unless otherwise required, it is understood that all the optional features described above can be combined to form an embodiment that is not necessarily illustrated or described. Such an embodiment is obviously not excluded from the invention. The features and advantages of the junction block according to the invention can be applied, mutatis mutandis, to the features and advantages of the system or method according to the invention, and vice versa. It is specified that, within the scope of the present invention, the steps of the method are understood in the broad sense of carrying out a part of the method and may optionally be carried out in several sub-steps. Several embodiments of the invention implementing successive steps of the monitoring method are described below.Unless explicitly stated, the adjective "successive" does not necessarily imply, although this is generally preferred, that the steps follow each other immediately; intermediate steps may separate them.
[0064] Furthermore, the term "step" does not necessarily imply that the actions carried out during a step are simultaneous or immediately successive. Some actions in a first step may be followed by actions related to a different step, and other actions from the first step may be repeated later. Thus, the term "step" does not necessarily refer to unitary actions that are inseparable in time and in the sequence of phases of the process.
[0065] Normal operation of a controller or physical component is defined as operation characterized by stable and consistent performance, without significant errors or anomalies. In normal operation of an automated system, each step of the automated process unfolds smoothly and efficiently. Indicators of normal operation can include, for example: sensor response time, measurement accuracy, the speed at which an actuator performs an action, voltage or current thresholds or ranges, etc. These indicators are applicable to any automated system.
[0066] A controller in an automated system is a control unit configured to regulate one or more operations of the automated system based on input data and predefined parameters. The control unit can thus authorize or prevent certain actions of the system components in order to achieve the desired objectives.
[0067] A physical component of an automated system is any tangible element used to perform specific functions within the system. These components can be robots, electronic devices, sensors, actuators, measuring instruments, pipes, tanks, conveyors, lifting equipment, electric motors, pneumatic or hydraulic cylinders, valves, etc.
[0068] A DIN rail is a standardized support profile, usually metallic, widely used for the mechanical support of electrical equipment (such as circuit breakers) and their accessories. DIN is the acronym for "Deutsches Institut für Normung," the organization that created this standard.
[0069] Figures 1 and 2 do not realistically reproduce the junction block 30, the monitoring system 1 and the automated system 2. For the sake of simplification, these figures illustrate the different elements of the monitoring system 1 and the automated system 2 schematically as functional blocks, and the connections between the different elements as arrows.
[0070] As illustrated in Figure 1, an automated system 2 comprises at least one controller 10 and at least one physical component 20. In the absence of the monitoring system 1, the physical component 20 can be directly connected to the controller 10. This controller 10 exchanges data signals with the physical component 20, enabling it to control the physical component 20 to perform an action, which may be physical or non-physical. The controller 10 could be, for example, a programmable logic controller (PLC). The physical component 20 could be an actuator that receives a control signal from the PLC to perform a specific physical or mechanical action in response to the control signal. The PLC could also be connected to a sensor, which, for example, sends a feedback signal back to the PLC to provide information on the actuator's state.
[0071] The data signals exchanged between the controller 10 and the physical components 20 can be intercepted or manipulated by a cyber attacker. To monitor these signals exchanged between the controller 10 and the physical components 20, a junction block 30 is integrated into the automated system 2, between the controller 10 and the physical components 20.
[0072] The junction block 30 is configured to be connected to the inputs / outputs of the controller 10. The junction block 30 can also be connected to the inputs / outputs of the physical component 20. The junction block 30 includes an electronic board 31. The electronic board 31 may integrate a microprocessor and a program installed at the factory. The electronic board 31 incorporates, in particular, a specification of generic rules R. These generic rules R are fixed and are based on physical processes related to the normal operation of the controller 10 and the physical components 20. In other words, these generic rules R describe an expected and consistent evolution of the physical quantities governing the operation of the automated system 2. The generic rules R, based on universal physical processes, are applicable to any automated system 2, whether it is already installed and implemented or not.These generic rules R are therefore independent of controller programming 10.
[0073] As illustrated in Figure 1, the junction block 30 can be connected in series between the controller 10 and the physical component(s) 20. The intermediate position of the junction block 30 allows it to intercept all signals exchanged between the controller 10 and the physical component(s) 20. The junction block 20 can thus receive and collect an input signal I emitted by the controller 10 to the physical component 20 and / or by the physical component 20 to the controller 10.
[0074] By applying generic rules R to each of the input signals I, the junction block 30 evaluates the input signal I in real time against the generic rules R. If the input signal conforms to and is consistent with the generic rules R, the junction block 30 acts passively and allows the signal to flow to the controller 10 or the physical component 20. Conversely, if the input signal I does not conform to the generic rules R, or is inconsistent with them, the junction block 30 issues at least one alert A. The junction block 30 can be configured to allow this suspect signal to pass, or it can be configured to interrupt this signal. The junction block 30 described above can be integrated into a monitoring system 1. The monitoring system 1 further includes a "master" head module 40 connected to at least one "slave" junction block 30.The head module 40 is configured to be connected to the junction block 30, as illustrated in Figure 1, which allows it to collect in real time the signals I entering the junction block 30, whether or not they conform to the generic rules R. This data can come from several junction blocks 30, and can thus be centralized in the head module 40.
[0075] The junction block 30 typically incorporates independent comparison logic, enabling real-time comparison of data from sensors associated with the physical component 20 against setpoint values dynamically extracted from the programmable logic controller (PLC) 10, or stored locally. This configuration allows for the identification of not only hardware malfunctions, but also abnormal deviations caused by software compromises in the PLC 10, or any control system.
[0076] The head module 40 may include a microcontroller and a memory 41, and may be configured to perform at least two tasks, typically the export of centralized data and / or high-level detection. The head module 40 may securely store the collected data in its memory 41. The head module 40 may further include a data communication interface via a network specific to the monitoring system 1. Preferably, this network is wireless to ensure the non-intrusive nature of the monitoring system 1. The data collected by the head module 40, including the input signals I that trigger the alerts A, can thus be securely communicated to a third-party system 3, as illustrated in Figure 1.
[0077] When the data export mode is enabled, the head module 40 receives in real time the alerts A issued by at least one junction block 30 when an input signal I collected by the junction block 30 does not conform to the generic rules R. The head module 40 can export this alert A to the tier system 3 via a secure communication protocol.
[0078] Tier 3 systems can correspond to cloud computing, big data, SCADA (Supervisory Control and Data Acquisition), SIEM (Security Information and Event Management), or mobile applications.
[0079] When high-level detection mode is activated, the head module 40 can receive in real time a plurality of input signals I collected by a plurality of terminal blocks 30. This "field" data from the various terminal blocks 30 can be cross-correlated using the microprocessor of the head module 40. This allows the generation of detection rules in the form of logical equations. The head module 40 can thus be configured to issue at least one alert A if any of the input signals I violates a generated detection rule.
[0080] The head module 40 can also be configured to correlate the data exchanged between the controller 10 and the physical component 20. This correlated data can be transmitted to an artificial intelligence algorithm executable by the microprocessor and / or the third-party system 3. This artificial intelligence algorithm is configured to detect minor malfunctions in the automated system 2. It enables more precise diagnosis of these malfunctions and allows for the prediction or detection, for example, at the scale of an industrial programmable logic controller (PLC), of small desynchronizations. These minimal desynchronizations, which may go unnoticed in isolation, can be a signature of a large-scale cyberattack aimed at disrupting all PLCs. The use of an artificial intelligence algorithm, for example, improves the detection of sophisticated and subtle attacks.This also helps eliminate potential false positives. The reliability of attack detection is improved.
[0081] The monitoring system 1 can be configured to protect the physical component 20 against any intentional or unintentional threat, or against natural degradation. In this protection configuration, the junction block 30 can be programmed to interrupt the data signals exchanged between the controller 10 and the physical component 20 when it detects an input signal I that does not conform to the generic rules R. This feature makes it possible to protect, for example, pre-actuators or actuators by interrupting the transmission of suspicious control signals issued by the programmable logic controller (PLC). This prevents the actuators from executing these destructive or degrading commands, thus ensuring their safety. This protection feature is configurable and can be enabled or disabled.Each of the terminal blocks 30 and the head module 40 is preferably encapsulated in a housing made of a material that provides galvanic isolation of the internal components. This galvanic isolation ensures non-intrusive behavior of the terminal block 30, particularly when integrated into an automated system 2 that is already installed and operational.
[0082] The housing can be configured to allow the installation of the terminal block 30 and the head module 40 on DIN rails. The housing can therefore be equipped with DIN rail-compatible mounting pins. These DIN rails are widely used for the mechanical support of electrical equipment because they allow for the compact connection of multiple devices, reducing manual wiring. The terminal block 30, housed in such an enclosure, can thus replace a conventional terminal block installed on a DIN rail between a controller 10 and a physical component 20, without disrupting the operation or positioning of the controller 10 and the physical component 20. The terminal block 30 is therefore non-intrusive.
[0083] The head module 40 can be connected to the junction block 30 using a DIN rail compatible bus B connector. The head module 40 can collect data from the junction block 30 via the bus B connector. This data collection can preferably be performed using the I2C protocol (Interconnected Integrated Circuit).
[0084] As illustrated in Figure 2, by way of example, the head module 40 can be connected to several terminal blocks 30 via the bus connector B and can communicate with each of these terminal blocks 30 using the I2C protocol. For example, one head module can be connected to sixteen terminal blocks 30. The head module 40 can be powered by a 24 V DC supply. Power to the head module 40 can be supplied via a standard wired connection from the main power supply of the automated system's electrical cabinet 2.
[0085] The B bus connector distributes power from the head module 40 to all terminal blocks 30 connected to the head module 40. Therefore, only the head module 40 requires additional space on the DIN rail and access to a power supply. Alternatively, the head module 40 can be powered by a rechargeable battery.
[0086] The head module 40 may include a clock 42. This clock 42 provides a precise and continuous time reference, even in the absence of power supply, which allows real-time time stamping of the data acquired at each of the junction blocks 30.
[0087] Each junction block 30 may also include one or more relays.
[0088] The memory 41 of the head module 40 can be of the Micro SD type. It is preferably encrypted to secure the stored data.
[0089] The monitoring system 1 described above enables the acquisition, monitoring, protection, and dissemination of data collected between the controller 10 and the physical components 20. By connecting between the physical inputs and outputs of the controller 10 and the physical components 20, the monitoring system 1 allows data to be collected at the lowest level of the control architecture, without disrupting the existing or planned installation. This improves the reliability and user-friendliness of the monitoring system.
[0090] Thanks to the specification of generic rules R, monitoring system 1 typically protects all types of pre-actuators and actuators on the market. The conformity of the collected signals to the generic rules R allows monitoring system 1 to detect and / or protect the installation or automated system from dangerous control signals.
[0091] Advantageously, monitoring system 1 allows for non-intrusive acquisition of signal flows between the control system and the physical process. It also makes it possible to differentiate between operational deviations based on suspected malicious acts (e.g., cyberattacks) and natural degradation (e.g., failure of a physical component).
[0092] For security reasons, the head module 40 is preferably not user-reprogrammable. It may only have "push" communication functions. Furthermore, the configuration of the head module 40 only occurs when the monitoring system 1 is commissioned, which significantly minimizes intentional or unintentional manipulation of the monitoring system 1. Preferably, the head module 40 and the terminal blocks 30 are free of operating systems.
[0093] The method for monitoring an automated system 2, using the monitoring system 1, is now described with reference to Figure 3, which represents a flowchart illustrating the steps of the method. As shown in Figure 3, the method includes a collection 102, via the junction block 30, connected between the controller 10 and the physical component 20, of an input signal I emitted by the controller 10 and / or the physical component 20. The method further includes a real-time evaluation 104 of the conformity of each of the input signals I with the generic rules R.
[0094] Generic rules R can include, as a non-limiting example, a first rule called a frequency rule, which can be applied to on / off (digital) outputs. This frequency rule detects when a pre-actuator's response time is not met. Violation of this frequency rule can lead to damage to the pre-actuator and the entire actuation chain. As another example, generic rules R can include a second rule related to a continuously varying setpoint. In the context of a control setpoint (e.g., speed, torque, etc.), the setpoint(s) are not expected to vary continuously over time. A PLC program will typically set fixed setpoints, depending on the mode (e.g., rotate at 5000 rpm in a preparation mode and then at 10000 rpm in a normal production mode).In this context, the second rule may relate to the detection of a continuous positive or negative drift of the setpoint (example of stuxnet).
[0095] In another example, generic rules R can include a third rule concerning the voltage threshold of a setpoint. This third rule protects an installation from a setpoint exceeding the capabilities of a functional chain (e.g., requesting a rotational speed higher than the capabilities of a motor / effector). Generic rules R can also include a fourth rule concerning the maximum frequency of a PWM (Pulse Width Modulation) setpoint. This fourth rule, like the third rule, protects an installation from a setpoint exceeding the capabilities of a functional chain, the setpoint being a PWM setpoint.
[0096] When the input signal I conforms to the generic rules R, and therefore to normal and risk-free operation of the automated system 2, the junction block 30 can act passively by allowing the signal I to pass to the controller 10 or the physical component 20.
[0097] When the input signal I is evaluated as not conforming to one or more generic rules R, the method includes the transmission 105 of at least one real-time alert A by the junction block 30 to the head module 40. Thus, when one or more generic rules R are violated, the junction block 30 reacts by transmitting at least one alert. Protective measures can then be implemented.
[0098] The method further includes a real-time transmission 107 of the input signals I passing through the junction block(s) 30, as well as the alerts A, to the head module 40. This transmission 107 of signals I allows the head module 40 to centralize all the raw information collected from the various junction blocks 30, so that it can be exported or stored. Therefore, the method can include storing the alerts A and the input signals I in a data format in the memory 41 of the head module 40. Since the acquired data is raw data, it represents an exact picture of the signals received by the sensors and actuators of the automated system 2. This transmission 107 of field data can also be used to process this data for traceability or maintenance purposes, in addition to the monitoring function of the automated system 2.
[0099] The process can also include transmitting this data to a third-party system (tier 3) without disrupting any existing network. This also allows the data to be stored by the third-party system, such as a cloud storage service. The acquired data can also be disseminated to a Security Information and Event Management (SIEM) system for diagnostic analysis, predictive maintenance, and the detection of cyberattacks using tools based on artificial intelligence, for example. Depending on the chosen third-party system, the user of the monitoring system can configure the head module by adding one or more addresses.
[0100] The method may further include a synchronization 101 using the clock 42 of the head module 40, between the junction blocks 30 and the head module 40 before the collection 102 of the input signals I by the junction blocks 30.
[0101] When the input signal I is evaluated as non-compliant with the generic rules R, the process may also include an interrupt 106 of the signals exchanged between the controller 10 and the physical component 20, particularly when the physical component is an actuator intended to perform a physical action. These erroneous or altered signals I can lead to the degradation or destruction of the actuator. This interrupt 106, which remains optional and at the customer's discretion, prevents this degradation or destruction, thus protecting the operation of the entire automated system 2. This interrupt can be configured and activated as needed.
[0102] The invention is not limited to the embodiments described above. Several specific examples of the monitoring system for an automated system and the associated method have been described. Other embodiments are possible, for example, by combining features described above, without departing from the principle of the present invention. Furthermore, the features described with respect to one aspect of the invention can be combined with another aspect of the invention.
Claims
Demands 1. Junction block (30) for monitoring an automated system (2), said automated system (2) comprising at least one controller (10) configured to control at least one physical component (20) by exchanging data signals with the at least one physical component (20), said junction block (30) being configured to be connected to the at least one controller (10), said junction block (30) comprising an electronic card (31), said junction block (30) being characterized in that the electronic card (31) incorporates a specification of fixed generic rules (R) based on physical processes relating to a normal operation of the at least one controller (10) and the at least one physical component (20), the generic rules (R) being independent of a programming of the at least one controller (10).
2. Junction block (30) according to the preceding claim, configured for: • be connected in series between at least one controller (10) and at least one physical component (20), • collect at least one input signal (I) emitted by at least one controller (10) and / or at least one physical component (20), and • evaluate in real time a conformity of at least one input signal (I) with respect to the generic rules (R).
3. Junction block (30) according to the preceding claim, configured to emit in real time at least one alert (A) when at least one input signal (I) does not conform to the generic rules (R).
4. Junction block (30) according to any one of the preceding claims, comprising a housing encapsulating the electronic board (31), the housing being based on an electrically insulating material and configured to allow installation of the junction block (30) on DIN rails.
5. Monitoring system (1) of an automated system (2), comprising at least one junction block (30) according to any one of the preceding claims, said monitoring system (1) further comprising a head module (40) configured to: • be connected to at least one junction block (30), and • receive in real time at least one alert (A) issued by the junction block (30) when at least one input signal (I) collected by the junction block (30) does not conform to the generic rules (R) and export to a third-party system at least one alert (A), or • receive in real time a plurality of input signals (I) collected by a plurality of junction blocks (30), and issue at least one alert (A) if at least one of said input signals (I) contravenes at least one detection rule integrated into the head module (40).
6. A monitoring system (1) according to the preceding claim, configured to interrupt the data signals exchanged between at least one controller (10) and at least one physical component (20), when at least one input signal (I) collected by at least one junction block (30) does not conform to the generic rules (R) of said at least one junction block (30).
7. Monitoring system (1) according to any one of the two preceding claims, wherein the head module (40) is configured to communicate at least one input signal (I) which originates at least one alert (A), in a data format, to the third-party system (3).
8. Monitoring system (1) according to any one of claims 5 to 7, wherein the head module (40) comprises a microprocessor configured to correlate the data exchanged between at least one controller (10) and at least one physical component (20), and to transmit this correlated data to an artificial intelligence algorithm executable by the microprocessor and / or the third-party system (3), said artificial intelligence algorithm being configured to detect small deviations in the operation of the automated system (2), typically deviations in operation of less than 10%, for example on the order of 1%.
9. Monitoring system (1) according to any one of claims 5 to 8, wherein the head module (40) includes a clock (42).
10. A method for monitoring an automated system (2) using the monitoring system (1) according to any one of claims 5 to 9, comprising: • a collection (102) by at least one junction block (30) of at least one input signal (I) emitted by at least one controller (10) and / or at least one physical component (20), and • a real-time evaluation (104) of the conformity of at least one input signal (I) with the generic rules (R).
11. Method for monitoring the automated system (2) according to the preceding claim, further comprising: • a real-time transmission (105) of at least one alert (A) by at least one junction block (30) to the head module (40), when at least one input signal (I) is evaluated as not conforming to the generic rules (R), or • a real-time transmission (107) of at least one input signal (I) collected by at least one junction block (30), to the head module (40).
12. Method of monitoring an automated system (2) according to any one of the two preceding claims, further comprising a synchronization (101) using the clock (42) of the head module (40), between at least one junction block (30) and the head module (40) before the collection (102) by at least one junction block (30) of at least one input signal (I).
13. Method of monitoring an automated system (2) according to any one of claims 10 to 12, further comprising an interruption (106) of the data signals exchanged between the controller (10) and at least one physical component (20), when at least one input signal (I) is evaluated as not conforming to the generic rules (R) by at least one junction block (30).
14. Method of monitoring an automated system (2) according to any one of claims 10 to 13, further comprising communication (109) by the head module (40) of at least one alert (A) and at least one input signal (I) collected, in a data format to at least one third-party system (3).
Citation Information
Patent Citations
Threat detection system for industrial controllers
US11378929B2
Machinery Condition Assessment Module
US20070073521A1
Systems and methods for displaying a probe gap value on a sensor system
US20150168181A1