Industrial Control Connections via Virtualized Compute Fabric Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current industrial control systems face challenges in achieving desired security levels due to the convergence of operation technology (OT) with information technology (IT), leading to complex and insecure networks, especially when integrating cloud-based components, which complicates data transfer and increases latency.

Innovation Solution

A new process control and automation system architecture that implements a shared, virtualized compute fabric, allowing for robust and secure communication between physical devices and IT infrastructure, bypassing the traditional Purdue model, and utilizing containerized components for enhanced security and flexibility.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional Purdue model architecture is used for industrial control systems, then security layers are established, but network complexity increases and latency is introduced

Engineering Contradiction:
ImprovesecurityVSAvoidnetwork complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the security function from the complex multi-layer Purdue architecture and consolidates it into a single dedicated security appliance positioned at the network boundary. This security appliance performs authentication, authorization, and encryption functions that were previously distributed across multiple layers, thereby maintaining security requirements while eliminating the complexity of multiple security zones and demilitarized zones.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent merges multiple security functions (authentication, authorization, encryption, intrusion detection) into a single integrated security appliance. This consolidation maintains comprehensive security coverage while reducing network complexity by eliminating the need for separate security mechanisms at each Purdue layer, thereby resolving the contradiction between security reliability and network complexity.

Inventive Principle:
Principle #5Merging (Combining)

2Productivity

If cloud-based components are integrated into industrial control systems, then computing resources are enhanced, but data transfer complexity and latency increase

Engineering Contradiction:
Improvecomputing resourcesVSAvoidlatency
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The patent introduces an edge computing device as an intermediary between cloud-based components and industrial control devices. This edge device pre-processes data locally before cloud transmission and rapidly delivers cloud-generated control commands to field devices, thereby maintaining enhanced computing resources while minimizing data transfer latency through local caching and priority routing.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements preliminary data processing and caching at the edge computing device before cloud interaction is required. Frequently accessed data and control parameters are pre-loaded into local memory, and data is pre-processed into cloud-ready formats, thereby reducing the time required for cloud data transfer and processing while maintaining access to enhanced cloud computing resources.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If conventional security measures are applied in industrial control systems, then security protection is provided, but ease of operation deteriorates

Engineering Contradiction:
Improvesecurity protectionVSAvoidease of operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements automatic authentication and authorization mechanisms where the security appliance autonomously verifies device identities, validates communication permissions, and enforces security policies without requiring manual intervention from operators. This self-service security approach maintains robust security protection while eliminating the operational burden of manual security configuration and management.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The security appliance acts as an intelligent intermediary that transparently handles security protocols between control devices and operators. It automatically manages authentication credentials, encrypts/decrypts communications, and filters traffic based on security policies, thereby providing comprehensive security protection while making security operations transparent and easy for end users.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20240028005A1Securing Connections of a Process Control or Automation System
Publication Date: 2024.01.25 FISHER ROSEMOUNT SYST INC
  • US20240028005A1 patent drawing
  • US20240028005A1 patent drawing
  • US20240028005A1 patent drawing

AI summary

A process plant and industrial control system architecture includes a generalized compute fabric that is agnostic or indifferent to the physical location at which the compute fabric is implemented, includes one or more physical control or field devices located at one or more specific sites at which a product or process is being manufactured and further includes a transport network that securely provides communications between the compute fabric and the pool of physical devices. The compute fabric includes an application layer that includes configured containers or containerized software modules that perform various control, monitoring and configuration activities with respect to one or more devices, control strategies and control loops, sites, plants, or facilities at which control is performed, and includes a physical layer including computer processing and data storage equipment that can be located at any desired location, including at or near a site, plant, or facility at which control is being performed, at a dedicated location away from the location at which control is being performed, in re-assignable computer equipment provided in the cloud, or any combination thereof. This control architecture enables significant amounts of both computer processing and IT infrastructure that is used to support a process plant, an industrial control facility or other automation facility to be implemented in a shared, in an offsite and/or in a virtualized manner that alleviates many of the communications and security issues present in current process and industrial control systems that attempt to implement control with shared or virtualized computing resources set up according to the well-known Purdue model.The industrial control system architecture is protected via more secure and customizable techniques as compared to those used in Purdue model-based control systems. For example, communications between any (and in some cases, all) endpoints of the system may be protected via one or more virtual private networks to which authenticated endpoints must be authorized to access. Endpoints may include, for example, containerized components, physical components, devices, sites or locations, the compute fabric, and the like, and the VPNs may include mutually-exclusive and/or nested VPNs. External applications and services, whether automated or executing under the purview of a person, may access information and services provided by the system via only APIs, and different sets of APIs may be exposed to different users that have been authenticated and authorized to access respective sets of APIs.A configuration system operates within the compute fabric to enable a user to easily make configuration changes to the compute fabric as the user does not generally need to specify the computer hardware within the compute fabric to use to make the configuration changes, making it possible for the user to deploy new configuration elements with simple programming steps, and in some cases with the push of a button.