Cyber Security System for Physical Control Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increasing use of computers and processors in controlling equipment has led to vulnerabilities and susceptibilities to hacking and unauthorized access, necessitating effective detection and correction of unwanted operating conditions to minimize disruptions and maintain system effectiveness in the presence of cyber security threats.

Innovation Solution

A cyber security system comprising local security devices and control devices that monitor operational aspects of protected systems, detect potential cyber attacks by analyzing operational information, and output commands to restore a normal operating state, utilizing encryption and auto-registration for secure communication, with a hierarchical approach to system security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If computers and processors are used to control equipment and systems, then system functionality and control precision are improved, but vulnerability to hacking and unauthorized access increases

Engineering Contradiction:
Improvecontrol precisionVSAvoidvulnerability to hacking
Core Design Contradiction:
Measurement precisionVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a cyber security system as an intermediary layer between control systems and external networks. This intermediary monitors operational aspects, detects anomalies indicating potential attacks, and prevents unauthorized access while allowing legitimate control operations to proceed, thus maintaining control precision while reducing vulnerability to hacking.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If security monitoring and detection systems are implemented, then system security is improved, but system complexity increases

Engineering Contradiction:
Improvesystem securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements control devices that perform multiple functions: they serve as both control elements for equipment operation and as security monitoring devices. By making control devices universal and multi-functional, the system achieves enhanced security without adding separate dedicated security hardware, thus limiting the increase in overall system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If real-time detection and correction of security threats is implemented, then system resilience is improved, but processing requirements and system complexity increase

Engineering Contradiction:
Improvesystem resilienceVSAvoidprocessing requirements
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a self-service security system where control devices autonomously monitor their own operational aspects and automatically detect security threats without requiring external security devices. The system performs self-diagnosis and self-protection, eliminating the need for separate security hardware and reducing overall system complexity while maintaining real-time threat detection and correction capabilities.

Inventive Principle:
Principle #25Self-service

4Reliability

If hierarchical security architecture with multiple devices is implemented, then security coverage is improved, but device complexity and communication overhead increase

Engineering Contradiction:
Improvesecurity coverageVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the functions of control devices and security monitoring devices into a single integrated system. By combining these previously separate functions, the hierarchical security architecture achieves comprehensive security coverage without the communication overhead and complexity of multiple separate devices, as the control devices themselves perform security monitoring functions.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS9697355B1Cyber security for physical systems
Publication Date: 2017.07.04 SERVICENOW INC
  • US9697355B1 patent drawing
  • US9697355B1 patent drawing
  • US9697355B1 patent drawing

AI summary

A cyber security system and method that includes one or more devices configured to determine a cyber security threat or breach event based on analysis of operational information of a protected system.