Container Orchestration for OT Control System Function Deployment
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Industrial control systems in operational technology (OT) environments lack efficient management and orchestration capabilities similar to those in information technology (IT) systems, limiting the ability to provision, deploy, and maintain OT assets across their lifecycles.
Innovation Solution
Integration of specialized hardware and software control systems within industrial control systems to enable participation in container orchestration operations, using proxy nodes and worker nodes to bridge the gap between IT and OT systems, allowing for container orchestration systems to manage and coordinate OT assets.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If container orchestration systems are integrated into industrial control systems, then management and orchestration capabilities are improved, but device complexity increases
Solution Approach 1:
The patent introduces a gateway component as an intermediary between the container orchestration system and industrial control systems. This gateway translates orchestration commands into native industrial control protocols, enabling IT-based management capabilities to operate OT assets without requiring direct integration. The gateway acts as a mediator that bridges the two different system domains, providing ease of operation while isolating the complexity of integration behind a standardized interface.
Solution Approach 2:
The container orchestration system is designed to provide universal management capabilities that can handle multiple types of industrial control systems and devices through a common interface. The system can provision, deploy, and manage diverse OT assets using standardized container technologies, eliminating the need for separate management systems for different device types. This multi-functionality improves ease of operation across heterogeneous systems while consolidating complexity into a single universal platform.
2Productivity
If IT-based container orchestration techniques are used to manage OT assets, then productivity and automation are improved, but adaptability to OT-specific requirements decreases
Solution Approach 1:
The system dynamically adjusts operational parameters based on the target OT asset type and requirements. The gateway component modifies command parameters, data formats, and communication protocols according to the specific OT system being controlled. This parameter adaptation allows the standardized container orchestration system to maintain high productivity while becoming adaptable to diverse OT requirements through configurable parameter transformations rather than hard-coded adaptations.
Solution Approach 2:
The orchestration system implements dynamic behavior adaptation where the management approach changes based on the runtime characteristics of the OT assets. The system can switch between different operational modes, communication strategies, and resource allocation schemes depending on the specific OT environment. This dynamic adaptability allows IT-based automation techniques to effectively manage OT assets by adjusting to their specific requirements rather than forcing OT systems to conform to rigid IT patterns.
3Reliability
If control systems participate in container orchestration operations, then resource coordination and health monitoring are improved, but ease of repair and maintenance decreases
Solution Approach 1:
The system creates virtual copies of control systems in the form of containers that replicate the functionality and state of the physical OT assets. These containerized representations allow for health monitoring, testing, and maintenance operations to be performed on the virtual copies without affecting the actual industrial control systems. Operators can debug, update, and validate changes in the container environment before applying them to the production system, thereby improving reliability while maintaining ease of repair through the virtualization layer.
Data Source
AI summary
A method may include receiving, via a first computing node of a cluster of computing nodes in a container orchestration system, a pod from a second computing node in the cluster of computing nodes. The method may also include retrieving an image file comprising one or more containers from a registry, such that the pod may include an indication of a location of the image file in the registry. The one or more containers may include one or more pre-analytic operations for a control system of a plurality of control systems to perform. The method may then involve generating a package based on the one or more containers and storing the package in a filesystem shared with the control system.


