Control Unit Data Exchange Restriction via Security Intermediary

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The exchange of data between a control unit and an external device in factory automation systems poses a security threat due to potential data leaks and malicious data storage, as existing systems lack adequate security measures to restrict unauthorized data exchange.

Innovation Solution

A controller system is introduced with a security unit that manages data exchange through two interfaces, where a restriction mechanism prevents direct data exchange between the control unit and external devices when connected, and a management mechanism allows secure data transfer via a secondary interface, with an evaluation part ensuring data safety and notification for low-security data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If data exchange between control unit and external device is unrestricted, then ease of operation is improved, but security reliability deteriorates

Engineering Contradiction:
Improvedata exchange capabilityVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a security unit as an intermediary between the control unit and external devices. This security unit mediates all data exchange operations, performing security checks before allowing data transfer. The security unit acts as a buffer that maintains ease of operation for authorized exchanges while blocking malicious data, thus resolving the contradiction between operational convenience and security reliability.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If security unit is connected to control unit, then security reliability is improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidsystem structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the security unit with the control unit into a single integrated system. Rather than adding a completely separate security device, the security functions are combined within the existing control unit architecture. This integration reduces the overall system complexity while maintaining enhanced security capabilities, as the security unit shares resources and communication channels with the control unit.

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If direct data exchange is restricted through first interface, then security reliability is improved, but ease of operation deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoiddata transfer convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The security unit serves as a mediator that provides secure data transfer through the second interface when direct exchange through the first interface is restricted. Users can still perform data transfer operations, but must route them through the security unit which provides automated security validation. This maintains operational ease while ensuring security requirements are met.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The security unit performs preliminary security checks on data before allowing transfer through the second interface. By validating data security attributes in advance, the system prevents malicious data from reaching the control unit while maintaining a user-friendly interface for legitimate data transfer operations.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12093408B2Controller system, control unit, and non-transitory computer readable medium
Publication Date: 2024.09.17 OMRON CORP
  • US12093408B2 patent drawing
  • US12093408B2 patent drawing
  • US12093408B2 patent drawing

AI summary

The present invention makes it possible to reduce threats to the security of a control unit. This controller system is provided with: a control unit that performs a control calculation for controlling a controlled object; and a security unit that is responsible for security. The control unit comprises: a first interface that brokers data exchange with an external device; a communication controller that is responsible for communication with the security unit; and a restriction means that restricts data from being exchanged with the external device via the first interface if a connection between the control unit and the security unit is detected via the communication controller.