Control Apparatus Security State Assessment for Software Continuity
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional control apparatuses fail to consider the security and control states of target control units when overwriting software, leading to potential security attacks and incorrect operations during abnormal conditions.
Innovation Solution
A control apparatus with communication, detection, management, determination, and switching processing sections that assess and manage the security and control states of connected control units to determine the suitability of another unit to continue the operation of a unit with an abnormality, ensuring secure and correct operation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If software is overwritten in another control unit without considering its security state, then the abnormal control unit can be replaced, but the system becomes vulnerable to security attacks
Solution Approach 1:
The management section performs preliminary assessment of the security state and control state of the target control unit before software overwriting occurs. This preliminary check prevents selecting vulnerable control units for software replacement, thereby maintaining security while enabling operation continuity.
Solution Approach 2:
The management section acts as an intermediary between the detection section and the switching processing section. It evaluates both security state (vulnerability to attacks) and control state (operational capability) before allowing software to be transferred, thus mediating between security concerns and operational requirements.
2Reliability
If software is overwritten in a control unit without considering its control state, then the abnormal control unit can be replaced, but the software may not perform predetermined operations
Solution Approach 1:
The management section performs preliminary verification of the control state (operational requirements) of the target control unit before software overwriting. This ensures that the selected control unit has the necessary control capabilities to execute the transferred software correctly, preventing operational failures.
Solution Approach 2:
The management section serves as an intermediary that verifies both the control state and security state before allowing software transfer. This mediation ensures that only control units meeting both operational and security requirements are selected, guaranteeing both execution accuracy and security.
3Ease of operation
If any control unit is selected for software overwriting without state assessment, then the switching process is simple, but incorrect operation may occur
Solution Approach 1:
Each control unit autonomously manages its own security state and control state information through its management section. When an abnormality is detected, the system automatically evaluates candidate control units and performs software transfer without manual intervention, maintaining both simplicity and reliability.
Solution Approach 2:
The management section continuously monitors and maintains up-to-date information about the security state and control state of each control unit. This feedback mechanism enables the system to make informed decisions about software transfer, ensuring operational correctness while maintaining automated simplicity.
Data Source
AI summary
There is provided a control apparatus having two or more control units that are connected with one another through a communication path; each of the control units has a switching processing section that selects the control unit that is made to continue the operation of software for the control unit in which an abnormality has been detected, based on an operational requirement for software in which an abnormality has been detected and the security state and control state of the control unit other than the control unit in which the abnormality has been detected.


