Networked Control Security Monitoring for External Access Threats

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional control devices lack protection against threats arising from the advancement of networking and incorporation of intelligence, as they only detect abnormalities in facilities or apparatuses but not potential security events related to external access or network threats.

Innovation Solution

A control device equipped with a detection module to identify security events such as unauthorized access, program modifications, and network anomalies, and a notification module to alert administrators of such events, ensuring proactive protection against potential threats.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If networking and intelligence are incorporated into control devices to enhance functionality, then processing capability and connectivity are improved, but vulnerability to security threats increases

Engineering Contradiction:
Improvenetworking capabilityVSAvoidsecurity threat
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements preliminary security measures by establishing predetermined rules for data communication before threats occur. The control device proactively defines permitted communication patterns, addresses, and ports, then automatically detects and blocks deviations from these rules. This preventive approach addresses security threats before they can exploit the networking capabilities.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary security monitoring function that mediates between the networking module and external communications. This intermediary layer intercepts communication requests, validates them against predetermined security rules, and blocks unauthorized access attempts. The intermediary protects the control device's intelligence and processing capabilities from external threats while maintaining legitimate networking functionality.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If security monitoring functions are added to detect external threats, then protection capability is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity protectionVSAvoidsystem structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent makes the control device's existing communication processing module perform multiple functions: both normal data communication and security event detection. By utilizing the same hardware resources for dual purposes, the patent achieves comprehensive security monitoring without adding separate dedicated security hardware, thus avoiding significant increases in device complexity while maintaining high reliability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The control device performs self-monitoring and self-protection by automatically detecting security events and generating notifications without requiring external security systems. The device uses its own processing capabilities to analyze communication patterns, identify threats, and alert users, reducing the need for additional complex external security infrastructure.

Inventive Principle:
Principle #25Self-service

3Measurement precision

If comprehensive security event detection is implemented, then threat identification capability is improved, but processing overhead increases

Engineering Contradiction:
Improvesecurity event detectionVSAvoidprocessing load
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The patent implements partial monitoring by focusing detection efforts on specific security-critical parameters such as communication addresses, ports, and predetermined patterns, rather than analyzing all data traffic comprehensively. This selective approach achieves sufficient threat identification capability while minimizing processing overhead and energy consumption by avoiding excessive analysis of non-critical data.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS11516229B2Control device and control system
Publication Date: 2022.11.29 OMRON CORP
  • US11516229B2 patent drawing
  • US11516229B2 patent drawing
  • US11516229B2 patent drawing

AI summary

A control device includes: a program execution module that executes a program created depending on a control target; a detection module that determines whether a security event occurs in access from outside to the control device; and a notification module that provides a notification, upon detection of occurrence of the security event, to a notification destination corresponding to the occurred security event. The security event includes an event that does not conform to a predetermined rule.