Distributed Ledger Control Architecture for Process Plant Cybersecurity

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Process control systems in industrial plants face vulnerabilities to cyber intrusions, which can lead to equipment damage, product loss, and even human safety risks due to the lack of secure and immutable data recording and transaction verification.

Innovation Solution

The implementation of a distributed ledger system, such as a blockchain, within process control systems to record transactions and execute smart contracts, providing a secure, immutable, and trustless record of process parameters, product quality, and regulatory data, while enabling secure automation of transactions between entities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a distributed ledger system is implemented in process control systems, then data security and integrity are improved, but device complexity increases

Engineering Contradiction:
Improvedata securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The distributed ledger system segments the control architecture into autonomous nodes (field devices, gateways, controllers) that each maintain copies of the ledger. This segmentation distributes the security function across multiple independent units, improving overall data security while allowing each node to operate with relatively simple local logic for generating and verifying cryptographic signatures.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces cryptographic intermediaries (digital signatures, hash functions, and consensus protocols) that mediate between nodes. These cryptographic mechanisms serve as trusted intermediaries that verify data integrity without requiring complex trust relationships between individual nodes, thus enhancing security while keeping node-to-node interactions relatively simple.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If distributed ledger technology is used for immutable data recording, then data integrity is improved, but processing speed decreases

Engineering Contradiction:
Improvedata integrityVSAvoidprocessing speed
Core Design Contradiction:
ReliabilityVSSpeed

Solution Approach 1:

The system performs preliminary cryptographic hashing of data before it is added to the blockchain. By pre-computing hash values and preparing transaction data in advance, the system reduces the processing burden during the critical consensus and immutability phases, thereby maintaining data integrity while improving overall processing throughput.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements partial validation where not all nodes need to perform full verification of every transaction. Instead, a subset of nodes (validators or consensus participants) perform the intensive verification work, while other nodes can proceed with lighter validation. This partial action approach maintains data integrity through distributed consensus while significantly improving processing speed by avoiding redundant full verifications across all nodes.

Inventive Principle:
Principle #16Partial or excessive action

3Object-affected harmful factors

If blockchain technology is implemented for secure transaction verification, then cybersecurity is improved, but device complexity increases

Engineering Contradiction:
ImprovecybersecurityVSAvoidarchitecture complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The distributed ledger serves multiple functions simultaneously: it acts as a secure transaction verification system, a decentralized database, a consensus mechanism, and an immutable audit trail. By consolidating these multiple security and data management functions into a single universal infrastructure, the system improves cybersecurity comprehensively while avoiding the need for separate complex systems for each function.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The blockchain system implements self-service security through automated cryptographic verification and consensus protocols. Nodes automatically verify transactions, validate blocks, and maintain security without requiring external security management infrastructure. This self-service approach enhances cybersecurity while reducing the complexity of external security management systems.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11405180B2Blockchain-based automation architecture cybersecurity
Publication Date: 2022.08.02 FISHER ROSEMOUNT SYST INC
  • US11405180B2 patent drawing
  • US11405180B2 patent drawing
  • US11405180B2 patent drawing

AI summary

To provide a trusted, secure, and immutable record of transactions within a process plant, techniques are described for utilizing a distributed ledger in process control systems. The distributed ledger may be maintained by nodes which receive transactions broadcasted from field devices, controllers, operator workstations, or other devices operating within the process plant. The transactions may include process plant data, such as process parameter data, product parameter data, configuration data, user interaction data, maintenance data, commissioning data, plant network data, and product tracking data. The distributed ledgers may also be utilized to execute smart contracts to allow machines such as field devices to transact by themselves without human intervention. In this manner, recorded process parameter values and product parameter values may be retrieved to verify the quality of products. Moreover, regulatory data may be recorded in response to triggering events so that regulatory agencies can review the data.