Containerized Control Architecture for Secure OT-IT Integration
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current industrial control systems face challenges in achieving desired security levels due to the convergence of operation technology (OT) with information technology (IT), leading to complex and insecure networks, especially when integrating cloud-based components, which complicates data transfer and increases latency.
Innovation Solution
A new process control and automation system architecture that implements a shared, virtualized compute fabric, allowing for robust and secure communication between physical devices and IT infrastructure, bypassing traditional Purdue model constraints by using containerized components and virtual private networks for enhanced security and flexibility.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional Purdue model security architecture is used to integrate OT and IT systems, then security is improved, but system complexity and latency increase
Solution Approach 1:
The patent extracts the security function from the complex Purdue model architecture and implements it at the application layer within the compute fabric. Containerized security modules provide authentication, authorization, and encryption services directly to applications, eliminating the need for multiple network security layers and reducing overall system complexity while maintaining security.
Solution Approach 2:
The compute fabric acts as an intermediary layer between OT and IT systems, providing virtualized computing resources and integrated security services. This mediator consolidates security functions that previously required separate infrastructure at multiple Purdue levels, reducing complexity while maintaining security boundaries.
2Adaptability or versatility
If cloud-based components are integrated into industrial control systems, then computing flexibility is improved, but data transfer latency and security complexity increase
Solution Approach 1:
The compute fabric segments computing resources into virtualized containers that can be dynamically allocated and distributed. This segmentation allows cloud-based components to be integrated flexibly while maintaining low-latency communication through direct container-to-container data paths, avoiding the latency of traditional network architectures.
Solution Approach 2:
The compute fabric provides universal computing services that support both OT and IT workloads on the same infrastructure. By consolidating computing resources and providing multi-functional support for different protocol stacks and applications, the system achieves computing flexibility without the latency overhead of separate cloud infrastructure.
3Reliability
If dedicated process controllers are used in plant environment, then control reliability is improved, but system adaptability and remote management capability deteriorate
Solution Approach 1:
The patent creates virtual copies of control functions through containerized applications that run on the compute fabric. These virtualized controller instances can be replicated, migrated, and managed remotely while maintaining the reliability of control functions. The containerized architecture allows control logic to be copied and distributed across multiple physical locations without sacrificing reliability.
Solution Approach 2:
The system transitions from physical control controllers in the plant environment to a virtualized dimension where control functions run as software containers. This dimensional shift enables remote management and enhanced adaptability while maintaining control reliability through the virtualized architecture's ability to replicate and migrate control instances.
Data Source
AI summary
A process plant and industrial control system architecture includes a generalized compute fabric that is agnostic or indifferent to the physical location at which the compute fabric is implemented, includes one or more physical control or field devices located at one or more specific sites at which a product or process is being manufactured and further includes a transport network that securely provides communications between the compute fabric and the pool of physical devices. The compute fabric includes an application layer that includes configured containers or containerized software modules that perform various control, monitoring and configuration activities with respect to one or more devices, control strategies and control loops, sites, plants, or facilities at which control is performed, and includes a physical layer including computer processing and data storage equipment that can be located at any desired location, including at or near a site, plant, or facility at which control is being performed, at a dedicated location away from the location at which control is being performed, in re-assignable computer equipment provided in the cloud, or any combination thereof. This control architecture enables significant amounts of both computer processing and IT infrastructure that is used to support a process plant, an industrial control facility or other automation facility to be implemented in a shared, in an offsite and/or in a virtualized manner that alleviates many of the communications and security issues present in current process and industrial control systems that attempt to implement control with shared or virtualized computing resources set up according to the well-known Purdue model.The industrial control system architecture is protected via more secure and customizable techniques as compared to those used in Purdue model-based control systems. For example, communications between any (and in some cases, all) endpoints of the system may be protected via one or more virtual private networks to which authenticated endpoints must be authorized to access. Endpoints may include, for example, containerized components, physical components, devices, sites or locations, the compute fabric, and the like, and the VPNs may include mutually-exclusive and/or nested VPNs. External applications and services, whether automated or executing under the purview of a person, may access information and services provided by the system via only APIs, and different sets of APIs may be exposed to different users that have been authenticated and authorized to access respective sets of APIs.A configuration system operates within the compute fabric to enable a user to easily make configuration changes to the compute fabric as the user does not generally need to specify the computer hardware within the compute fabric to use to make the configuration changes, making it possible for the user to deploy new configuration elements with simple programming steps, and in some cases with the push of a button.


