Control Security Setting via Automated Threat and Countermeasure Scenarios

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increasing sophistication of control devices due to advancements in information and communication technology has led to a rise in security threats, requiring specialized knowledge for threat analysis, which is costly and burdensome for production engineers and equipment manufacturers.

Innovation Solution

A control system with a support device that includes a system-configuration input part, threat analysis database, threat-scenario creating part, countermeasure database, countermeasure creating part, and security setting part, which acquires device configuration and protected assets, analyzes threats, creates threat and countermeasure scenarios, and outputs security function settings to the security unit.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If control devices are connected to external devices via network and processing becomes more sophisticated, then functionality and intelligence of the control system are improved, but security threats increase and require specialized knowledge for analysis

Engineering Contradiction:
ImprovefunctionalityVSAvoidsecurity threats
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a support device as an intermediary between the control device and security analysis. This support device includes a threat-scenario creating part that automatically generates threat scenarios based on device configuration information, and a countermeasure creating part that formulates security countermeasures. This intermediary automates the security analysis process that would otherwise require specialized human expertise.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The control device performs self-security analysis by utilizing the support device to automatically create threat scenarios and countermeasures based on its own configuration information. The system enables producers to independently analyze security threats and generate countermeasures without requiring external security specialists, thus achieving self-service security analysis.

Inventive Principle:
Principle #25Self-service

2Measurement precision

If specialized knowledge is required for threat analysis, then security analysis accuracy is improved, but labor cost and education time increase

Engineering Contradiction:
Improvesecurity analysis accuracyVSAvoidlabor cost
Core Design Contradiction:
Measurement precisionVSQuantity of substance

Solution Approach 1:

The patent replaces the mechanical system of human security specialists performing manual threat analysis with an automated information processing system. The support device's threat-scenario creating part and countermeasure creating part automatically generate security analyses based on device configuration, substituting human expertise with algorithmic processing that maintains accuracy while eliminating labor costs and education requirements.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system changes the parameter of security analysis from requiring human expert judgment to using automated parameter-based analysis. By inputting device configuration parameters into the support device, the system automatically generates threat scenarios and countermeasures, transforming security analysis from a knowledge-intensive human task to a parameter-driven automated process.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If threat analysis is performed manually by specialists, then comprehensive security assessment is achieved, but processing time and complexity increase

Engineering Contradiction:
Improvesecurity assessmentVSAvoidanalysis complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the security analysis process into distinct functional modules: the threat-scenario creating part that generates threat scenarios, and the countermeasure creating part that formulates countermeasures. This segmentation allows each module to handle specific aspects of security analysis independently, simplifying the overall complex process while maintaining comprehensive security assessment through the coordinated operation of these modular components.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS12025967B2Control system and setting method
Publication Date: 2024.07.02 OMRON CORP
  • US12025967B2 patent drawing
  • US12025967B2 patent drawing
  • US12025967B2 patent drawing

AI summary

A control system including a controller system and a support device is provided. The controller system controls a control target. The support device supports setting of the controller system. The support device includes a system-configuration input part, a threat analysis database, a threat-scenario creating part, a countermeasure database, a countermeasure creating part, and a security setting part. The countermeasure creating part creates a countermeasure scenario containing a countermeasure for each of protected assets of the controller system according to a threat scenario and countermeasures of the countermeasure database.