Compute Fabric Architecture for Secure Low-Latency Process Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current industrial control systems face challenges in achieving desired security levels due to complex infrastructure requirements and incompatibilities between operational technology (OT) and information technology (IT) networks, leading to insecure data transfer practices and increased latency when integrating cloud-based components, which complicates security and communication within the Purdue model.

Innovation Solution

A new process control and automation system architecture that implements a shared, virtualized compute fabric, allowing for robust and secure communication between physical devices and cloud-based resources, bypassing traditional Purdue model constraints by using containerized components and virtual private networks to manage and secure data transfer.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional Purdue model architecture is used for industrial control systems, then security infrastructure is established, but device complexity and latency increase when integrating cloud-based components

Engineering Contradiction:
ImprovesecurityVSAvoidinfrastructure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a cloud-based gateway as an intermediary component that mediates between field devices and cloud services. This gateway handles protocol translation, data normalization, and security authentication, allowing field devices to communicate with cloud-based analytics and control services without requiring complex local infrastructure. The gateway abstracts the complexity of cloud integration while maintaining security through controlled access points.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent moves control and analytics functions from the traditional hierarchical Purdue model layers to a cloud-based dimension. Field devices continue to operate at the process level, while advanced analytics, historical data storage, and predictive maintenance functions are migrated to cloud-based virtual machines. This dimensional shift reduces on-premises infrastructure complexity while maintaining security through network segmentation and encrypted communication channels.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Adaptability or versatility

If cloud-based components are integrated into industrial control systems, then computing resources and flexibility improve, but latency increases due to network communication

Engineering Contradiction:
ImproveflexibilityVSAvoidlatency
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The patent segments control functions into two categories: time-critical control functions that remain local at the field device or edge gateway level, and non-time-critical analytics and historical processing functions that are migrated to the cloud. This segmentation ensures that cloud-based components provide flexibility and computing power for non-critical functions without introducing latency into real-time control loops.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements edge computing capabilities at the gateway level that perform preliminary data processing, filtering, and anomaly detection before transmitting data to the cloud. This preliminary action reduces the volume of data requiring cloud communication and enables faster local response to critical events, thereby reducing effective latency while maintaining cloud-based flexibility for non-critical functions.

Inventive Principle:
Principle #10Preliminary action

3Loss of information

If OT and IT networks are integrated for data transfer, then information sharing improves, but security vulnerabilities increase due to protocol incompatibilities

Engineering Contradiction:
Improvedata transfer efficiencyVSAvoidsecurity vulnerabilities
Core Design Contradiction:
Loss of informationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces protocol translation and security gateway functions that act as intermediaries between OT field devices and IT cloud services. These gateways translate proprietary field device protocols into standardized TCP/IP protocols for cloud communication, while simultaneously implementing security functions such as authentication, authorization, and data encryption. This intermediary layer enables efficient information transfer while isolating vulnerable field devices from direct exposure to IT network security risks.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20240027981A1Compute fabric enabled process control
Publication Date: 2024.01.25 FISHER ROSEMOUNT SYST INC
  • US20240027981A1 patent drawing
  • US20240027981A1 patent drawing
  • US20240027981A1 patent drawing

AI summary

An industrial process control system includes a compute fabric having a first portion operating on-premises at an industrial process plant controlled by the industrial process control system and a second portion operating remotely from the industrial process plant controlled by the industrial process control system. The system also includes one or more transmitters in the process plant measuring or sensing physical parameters and includes one or more physical control elements in the process plant, each physical control element responsive to a respective setpoint parameter. The system further includes a plurality of micro-encapsulated execution environments instantiated in the compute fabric, each executing at least a portion of a control module that receives data from the one or more transmitters and transmits at least one setpoint parameter to each of the one or more physical control elements to cause the physical control elements to control a process in the industrial process plant.