Diversified Controller Voting Against Malicious Set Points

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Controllers running similar firmware are vulnerable to cyberattacks, which can exploit common vulnerabilities across multiple controllers, compromising the reliability of automated systems by turning a 'loyal' component into a 'traitor' that disrupts the system's operation.

Innovation Solution

A controller computing system with multiple controllers, each with memory diversification, an enhanced time delay buffer, and a cyber security manager module that outputs a nominal or reset signal based on timer signals from the controllers, identifying a majority output to generate a voter output and resetting compromised controllers to maintain system integrity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple controllers with similar firmware are used to control a system, then the system can achieve redundancy and reliability, but the system becomes vulnerable to cyberattacks that can exploit common vulnerabilities across all controllers simultaneously

Engineering Contradiction:
Improvesystem reliabilityVSAvoidcyberattack vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies asymmetry by introducing memory diversification where each controller has differently organized memory structures. This asymmetric memory organization ensures that a malicious set point instruction targeting a specific memory layout in one controller will not affect other controllers with different memory configurations, thereby breaking the symmetry that cyberattacks exploit while maintaining functional redundancy

Inventive Principle:
Principle #4Asymmetry

Solution Approach 2:

The patent segments the control system into multiple independent controller instances, each with its own diversified memory structure. This segmentation isolates the impact of cyberattacks to individual controller segments rather than affecting the entire system, allowing loyal controllers to continue operating independently of compromised ones

Inventive Principle:
Principle #1Segmentation

2Speed

If controllers process set point instructions simultaneously without delay, then the system responds quickly to control commands, but malicious set point instructions can be executed immediately across all controllers

Engineering Contradiction:
Improveresponse speedVSAvoidsystem integrity
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The patent implements preliminary action through the enhanced time delay buffer that delays the processing of set point instructions by a predetermined time period before execution. This preliminary delay allows the system to verify the legitimacy of control instructions and prevents immediate execution of malicious set points while maintaining acceptable response speeds through parallel processing

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The enhanced time delay buffer acts as an intermediary component between the set point input and the controllers. This intermediary introduces a controlled delay that allows the system to filter out malicious instructions while permitting legitimate control commands to pass through to the diversified controller instances

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If the system uses a single controller output, then the system is simple to operate, but the system cannot detect or prevent malicious control signals

Engineering Contradiction:
Improvesystem operation simplicityVSAvoidmalicious signal detection
Core Design Contradiction:
Ease of operationVSDifficulty of detecting and measuring

Solution Approach 1:

The patent implements feedback mechanisms where controller outputs are monitored and compared against expected behavioral patterns. The system uses feedback from multiple diversified controller instances to detect anomalies that indicate malicious control signals, while the enhanced voter module provides a simplified single output that maintains ease of operation

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent merges outputs from multiple diversified controller instances through the enhanced voter module, which combines the results into a single consolidated output. This merging process maintains operational simplicity by presenting a unified control signal while internally leveraging the diversity of multiple controllers to detect and prevent malicious inputs

Inventive Principle:
Principle #5Merging (Combining)

4Adaptability or versatility

If the system processes all controller outputs equally, then the system maintains fairness in decision-making, but the system cannot identify and isolate compromised controllers

Engineering Contradiction:
Improvedecision-making fairnessVSAvoidcompromised controller isolation
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent applies local quality by enabling the enhanced voter module to differentiate between individual controller outputs based on their specific memory diversification characteristics. This allows the system to evaluate each controller's output locally and identify which specific controllers are compromised, rather than treating all outputs uniformly, thereby isolating faulty instances while maintaining overall system fairness

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS11443039B2Controller computing system for preventing malicious control of a controlled machinery system
Publication Date: 2022.09.13 FATHOM5 CORP
  • US11443039B2 patent drawing
  • US11443039B2 patent drawing
  • US11443039B2 patent drawing

AI summary

A controller computing system, including a plurality of controllers, each controller configured to i) calculate a respective output based on a current set point and ii) output a timer signal; a cyber security manager (CSM) computing module configured to: output a nominal signal indicating that the current set point is a non-malicious set point when the CSM computing module receives each of the timer signals from each of the plurality of controllers; and output a reset signal indicating that the current set point is a malicious set point when the CSM computing module receives less than each of the timer signals from the plurality of controllers.