Control Unit Cyber-Resilience Using Protected Process Data Recovery
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Industrial control systems are vulnerable to cyberattacks and manipulation due to their connectivity, leading to potential disruptions and physical damage, with existing solutions failing to adequately address the state of the controlled physical processes during recovery.
Innovation Solution
A control unit with an access-protected process data storage and a cyber resilience device that performs measures based on stored process data, including features like flushing fluid lines, moving robots, and reorganizing tool magazines, to limit physical damage and ensure reliable recovery.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If industrial control systems are connected to external networks for remote monitoring and management, then operational flexibility and monitoring capability are improved, but vulnerability to cyberattacks and manipulation increases
Solution Approach 1:
The control system is segmented into multiple security zones with different trust levels. The secure element is isolated from the main processor and external networks, creating a segmented architecture where compromise of the main system does not automatically compromise the security-critical functions. This segmentation allows remote monitoring capabilities while protecting core control functions from cyberattacks.
Solution Approach 2:
A secure element acts as an intermediary between the external network and the control system's critical functions. This intermediary verifies the authenticity of remote monitoring and management commands before allowing them to affect the controlled technical process, thereby enabling remote operations while filtering out malicious cyberattacks.
2Reliability
If firmware or software patches are implemented to address vulnerabilities, then security is improved, but time lag between vulnerability discovery and patching increases exposure risk
Solution Approach 1:
Security-critical code and data are pre-loaded into a secure element during manufacturing before the device is deployed. This preliminary action ensures that the most security-sensitive components are established with known good configurations before any potential vulnerabilities can be exploited, eliminating the need for time-consuming firmware updates for critical security functions.
Solution Approach 2:
The system uses a dedicated secure element that can be independently replaced or updated without affecting the main control system. This allows security patches to be applied to the secure element in isolation, reducing the overall time and complexity of updating security vulnerabilities in the complete system.
3Reliability
If the control unit is restored to a secure state after a cyberattack, then security is improved, but the controlled physical processes may be affected causing damage and downtime
Solution Approach 1:
The system continuously monitors the state of the controlled technical process and maintains a secure reference state. Upon detecting a cyberattack, the system automatically initiates countermeasures to restore the process to its secure reference state, preventing the attack from causing physical damage. The preliminary establishment of secure reference states enables rapid recovery without causing damage to physical processes.
Solution Approach 2:
The system continuously feedbacks the actual state of the controlled technical process and compares it against the secure reference state stored in the secure element. This feedback mechanism enables real-time detection of deviations caused by cyberattacks and triggers automatic restoration actions that reconcile the physical process with its secure reference state, preventing damage while maintaining security.
4Reliability
If comprehensive process data is stored for cyber resilience measures, then recovery reliability is improved, but data protection requirements and storage security increase
Solution Approach 1:
The system extracts and isolates the most critical process data and security parameters into a separate secure element. By taking out only the essential data needed for cyber resilience recovery rather than storing all process data, the system achieves high recovery reliability while minimizing the complexity of data protection and storage security requirements.
Data Source
Figure 1

AI summary
The control unit has an access-protected process data storage that continuously stores process data of a technical process controlled by the control unit, and also includes a cyber resilience device (DRE), whereby the cyber resilience device (DRE) performs at least one cyber resilience measure on the technical process depending on the stored process data of the process data storage.