Cloud Service Failover Control for Secure Plant Operations

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cloud services used in plant control systems face availability and security challenges, particularly due to network failures, which can disrupt operations and safety, and shifting to cloud systems is hindered by risks and budget constraints, requiring a solution that ensures high availability and information security while allowing for flexible and rapid system transitions.

Innovation Solution

A cloud service control device and system that includes a communicator for managing communication with cloud service providers and users, a verifier to assess the operation state of cloud services, a selector to choose suitable cloud services based on verification results, and an information transferor to manage data transfer, ensuring high availability and security by enabling redundancy and secure information handling.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If cloud services are used in plant control systems, then system flexibility and cost efficiency are improved, but availability and security deteriorate due to network failures and external risks

Engineering Contradiction:
Improvesystem flexibilityVSAvoidavailability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent segments the cloud service system into multiple independent virtual machine instances distributed across different physical hosts. Each instance can operate independently, and if one instance fails due to network or security issues, others continue to provide control functions, thereby maintaining system availability while preserving cloud-based flexibility.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements prior cushioning by pre-configuring redundant virtual machine instances and establishing failover mechanisms before failures occur. When network failures or security incidents affect cloud service availability, the pre-prepared backup instances can immediately take over, cushioning the impact on plant control operations.

Inventive Principle:
Principle #11Beforehand cushioning (Prior cushioning)

2Ease of manufacture

If cloud services are used in plant control systems, then budget constraints are relaxed and system modernization is enabled, but information security deteriorates due to external access risks

Engineering Contradiction:
Improvesystem modernizationVSAvoidinformation security
Core Design Contradiction:
Ease of manufactureVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a gateway device as an intermediary between the cloud service platform and the plant control system. This gateway acts as a security mediator that filters, validates, and controls all communications between external cloud services and internal control devices, enabling modernization while mitigating information security risks from external access.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates a secure isolated environment for running cloud-based control applications using virtualized containers with restricted network access and hardened operating systems. This inert computational environment allows modern cloud services to operate while protecting the core control system from external security threats.

Inventive Principle:
Principle #39Inert atmosphere (Inert environment)

3Reliability

If cloud service instances are distributed across multiple hosts, then availability is improved through redundancy, but device complexity increases

Engineering Contradiction:
ImproveavailabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent employs universal virtual machine images and standardized deployment configurations that can run identically across different physical hosts. This multi-functionality approach allows the same control application to be distributed across multiple devices without increasing operational complexity, as each instance follows the same template and management protocol.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent implements self-service automation through orchestration software that automatically provisions, monitors, and manages distributed virtual machine instances. The system self-configures failover rules, automatically detects failures, and redistributes workloads across hosts without requiring manual intervention, thereby improving availability while keeping complexity manageable through automation.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP3346381B1Cloud service control device, cloud service control system, cloud service control method, program and storage medium
Publication Date: 2021.06.16 YOKOGAWA ELECTRIC CORP
  • EP3346381B1 patent drawingFigure 1
  • EP3346381B1 patent drawingFigure 2
  • EP3346381B1 patent drawingFigure 3

AI summary

A cloud service control device includes a first communicator configured to control communication with a cloud service providing a plant control function of controlling a plant, a second communicator configured to control communication with a first device using service information related to the cloud service, a verifier configured to verify an operation state of the cloud service, a selector configured to select the cloud service on the basis of the verified operation state, and an information transferor configured to transfer the service information between the selected cloud service and the first device.