Controller Security Mode Switching During Cyber Incidents

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increasing networking and intelligence in control devices and systems have enhanced the potential for threats, necessitating improved protection mechanisms to ensure reliability against these threats.

Innovation Solution

A controller system with a control unit and a security unit that transitions between normal and degeneration modes based on detected security incidents, maintaining the degeneration mode until the incident is canceled, and restricting operations in the degeneration mode to prevent unauthorized access and maintain system integrity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If the control device is network-connected and intelligence is advanced, then the processing capability and functionality are improved, but the vulnerability to security threats increases

Engineering Contradiction:
Improveprocessing capabilityVSAvoidsecurity threats
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The control device is divided into functionally independent units: a control unit for normal operations and a security unit for security monitoring. This segmentation allows the security unit to independently detect and respond to threats without affecting the control unit's processing capabilities, thereby maintaining high adaptability while addressing security vulnerabilities.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A security unit acts as an intermediary between the control unit and external networks. This intermediary monitors security incidents and controls mode transitions, providing a buffer that protects the control device from direct exposure to security threats while maintaining network connectivity and processing capabilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If the control unit operates in normal mode continuously, then the productivity is maintained, but the system becomes vulnerable to unauthorized operations during security incidents

Engineering Contradiction:
Improveoperation continuityVSAvoidprotection reliability
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The control unit dynamically transitions between normal mode and degeneration mode based on security incident detection. This dynamic adaptability allows the system to maintain high productivity during normal operations while automatically reducing operations to essential functions only when security threats are detected, thereby ensuring both productivity and protection reliability.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system prepares a degeneration mode in advance that limits operations to essential functions only. When a security incident is detected, this pre-prepared mode is activated immediately, preventing unauthorized operations before they can cause harm while maintaining essential productivity through limited operations.

Inventive Principle:
Principle #9Preliminary anti-action

3Loss of time

If the control unit restarts processing after an security incident, then the system recovery is accelerated, but the incident may not be canceled leading to repeated security issues

Engineering Contradiction:
Improverecovery timeVSAvoidsecurity incident cancellation
Core Design Contradiction:
Loss of timeVSReliability

Solution Approach 1:

The security unit continuously monitors whether security incidents are canceled and provides feedback to the control unit. This feedback mechanism ensures that the control unit only returns to normal mode when the security incident is confirmed to be canceled, preventing premature recovery and repeated security issues while maintaining efficient system recovery.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system checks for incident cancellation as a preliminary condition before allowing mode transition from degeneration to normal mode. This preliminary check ensures that recovery only occurs when it is safe to do so, preventing repeated security incidents while maintaining efficient recovery timing.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12019743B2Controller system
Publication Date: 2024.06.25 OMRON CORP
  • US12019743B2 patent drawing
  • US12019743B2 patent drawing
  • US12019743B2 patent drawing

AI summary

A controller system includes a controller that executes a control operation in order to control a control target, and a security unit that is in charge of a security function for the controller system. The security unit includes a detector that detects a presence or absence of an incident regarding security in the controller system. The controller transitions a control mode to a degeneration mode when the detector detects the incident, and the controller maintains the control mode in the degeneration mode until cancellation of the incident is detected by the detector.