Machine Controller Cyber-Attack Detection Using Concurrent Simulation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Complex machine controllers are vulnerable to cyber-attacks, which can modify control and feedback data, leading to malfunctions and potential injuries, and existing measures are not sufficient for efficient detection and prevention.

Innovation Solution

A method and system that utilize a concurrent simulation, or digital twin, of the machine to compare actual control and monitoring data with simulated data, triggering an alarm if discrepancies are detected, thereby enhancing the detection of cyber-attacks and preventing machine damage.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If machine controllers are connected to the internet or corporate networks for external access, then operational flexibility and monitoring capability are improved, but vulnerability to cyber-attacks increases

Engineering Contradiction:
Improveexternal access capabilityVSAvoidcyber-attack vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

A digital twin acts as an intermediary between the external network and the machine controller. The digital twin receives and processes data from the controller, providing external access and monitoring capabilities while isolating the actual controller from direct network exposure. This mediator enables operational flexibility without directly connecting the controller to potentially harmful external networks.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system creates a virtual copy (digital twin) of the machine controller that can be accessed externally without exposing the real controller. The digital twin replicates the controller's functionality and data structure, allowing external systems to interact with the copy rather than the original, thereby protecting the actual controller from cyber-attacks while maintaining operational flexibility.

Inventive Principle:
Principle #26Copying

2Reliability

If conventional security measures like network monitoring and intrusion detection systems are implemented, then basic protection is improved, but detection of sophisticated cyber-attacks remains insufficient

Engineering Contradiction:
Improvebasic security protectionVSAvoidcyber-attack detection accuracy
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The system implements continuous feedback by constantly comparing data from the machine controller with corresponding data from the digital twin. This real-time comparison provides precise detection of anomalies and cyber-attacks, as any deviation between the physical system and its virtual model immediately triggers an alert, significantly improving detection accuracy over conventional one-way monitoring systems.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system transforms the approach to detection by changing from monitoring absolute values to detecting parameter deviations between two systems. By comparing operational parameters, state values, and behavioral patterns between the controller and digital twin, the system can detect sophisticated attacks that conventional systems miss, as these attacks typically create subtle inconsistencies rather than obvious failures.

Inventive Principle:
Principle #35Parameter changes

3Object-affected harmful factors

If the machine controller is separated from the internet to protect against cyber-attacks, then security is improved, but operational flexibility and monitoring capability deteriorate

Engineering Contradiction:
Improvecyber-attack protectionVSAvoidexternal access capability
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The digital twin serves as an intermediary that enables external access without direct connection to the controller. External systems can monitor and interact with the digital twin, which maintains synchronization with the physical controller through controlled data exchange. This architecture provides security isolation while preserving operational flexibility, as external users access the virtual model rather than the actual controller.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

By creating a accessible virtual copy of the controller, the system allows external monitoring and control operations to be performed on the copy rather than the original. The digital twin maintains the necessary interface capabilities for external access while the actual controller remains isolated from direct external connections, thus preserving operational flexibility without compromising security.

Inventive Principle:
Principle #26Copying

4Measurement precision

If redundant sensor measurements are incorporated to detect data manipulation, then detection capability is improved, but device complexity and cost increase

Engineering Contradiction:
Improvedata manipulation detectionVSAvoidsensor system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

Instead of adding redundant physical sensors, the system creates a virtual copy (digital twin) that independently calculates expected sensor values based on the machine model and control inputs. This virtual sensor system provides the same redundancy and verification capability as physical redundant sensors would, but without the associated hardware complexity and cost, as the digital twin uses computational modeling rather than additional physical measurement devices.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS12348543B2Method and system for detecting a cyber-attack on a machine controller
Publication Date: 2025.07.01 SIEMENS AG
  • US12348543B2 patent drawing
  • US12348543B2 patent drawing
  • US12348543B2 patent drawing

AI summary

For detecting a cyber-attack on a machine controller, a concurrent simulation of the machine is run in a secured access domain. From the machine controller actual control data are transmitted to the machine and resulting monitoring data are transmitted to a monitoring device. Furthermore, sensor data of the machine are transmitted to the concurrent simulation on a first secured transmission path. Based on the sensor data, the concurrent simulation simulates an operational behavior of the machine, thus inferring simulated monitoring data. The simulated monitoring data are then compared with the resulting monitoring, and an alarm signal is triggered depending on the comparison.