External Security Monitoring for Unauthorized Control Device Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional control devices lack protection against threats arising from the advancement of networking and incorporation of intelligence, as they only detect abnormalities in facilities or apparatuses but not potential security events related to network access or intelligence integration.

Innovation Solution

A security monitoring device is externally attached to control devices, featuring a communication port, detection portion, and notification portion to identify and alert against security events such as unauthorized access, network address discrepancies, and program modifications, thereby providing real-time threat detection and notification.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional control devices are used without external security monitoring, then device simplicity and ease of operation are maintained, but protection against network-based threats and security events is insufficient

Engineering Contradiction:
Improveprotection against security threatsVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The security monitoring function is segmented from the control device into a separate external security monitoring device. This allows the control device to remain simple while security monitoring capabilities are provided by a dedicated external component that analyzes communication content independently.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The security monitoring device acts as an intermediary between the control device and the network environment. It monitors communication content passing through it, detecting security events without requiring modifications to the control device itself, thus providing protection while maintaining system simplicity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If the control device monitors all communication content for security events, then detection accuracy improves, but processing time and energy consumption increase

Engineering Contradiction:
Improvesecurity event detection accuracyVSAvoidprocessing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The security event detection function is extracted from the control device's main processing tasks and performed by a separate security monitoring device. This extraction allows comprehensive monitoring of communication content without burdening the control device's processing resources, maintaining detection accuracy while minimizing time loss.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If comprehensive security monitoring is implemented, then coverage of security events improves, but false positive rates and notification overhead increase

Engineering Contradiction:
Improvesecurity event coverageVSAvoidnotification overhead
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The security monitoring device provides feedback by notifying relevant parties only when actual security events are detected, rather than generating notifications for all monitored communications. This feedback mechanism ensures comprehensive security coverage while minimizing unnecessary notification overhead through intelligent event filtering and validation.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11397806B2Security monitoring device
Publication Date: 2022.07.26 OMRON CORP
  • US11397806B2 patent drawing
  • US11397806B2 patent drawing
  • US11397806B2 patent drawing

AI summary

A control device is protected from a threat which may occur with the advance of networking or incorporation of intelligence. A security monitoring device that can be externally attached to the control device having a program execution portion that executes a program produced in accordance with a control target includes a communication port for connection with the control device. When it is detected from a content of communication that a security event is generated in access from outside to the control device, a notification is provided to a notification destination corresponding to the generated security event. The security event includes an event that does not conform to a predetermined rule.