Diversified Controller Voting Against Malicious Set Points
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Controllers running similar firmware are vulnerable to cyberattacks, which can exploit common vulnerabilities across multiple controllers, compromising the reliability of automated systems by turning a 'loyal' component into a 'traitor' that disrupts the system's operation.
Innovation Solution
A controller computing system with multiple controllers, each with memory diversification, an enhanced time delay buffer, and a cyber security manager module that outputs a nominal or reset signal based on timer signals from the controllers, identifying a majority output to generate a voter output and resetting compromised controllers to maintain system integrity.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If multiple controllers with similar firmware are used to control a system, then the system can achieve redundancy and reliability, but the system becomes vulnerable to cyberattacks that can exploit common vulnerabilities across all controllers simultaneously
Solution Approach 1:
The patent applies asymmetry by introducing memory diversification where each controller has differently organized memory structures. This asymmetric memory organization ensures that a malicious set point instruction targeting a specific memory layout in one controller will not affect other controllers with different memory configurations, thereby breaking the symmetry that cyberattacks exploit while maintaining functional redundancy
Solution Approach 2:
The patent segments the control system into multiple independent controller instances, each with its own diversified memory structure. This segmentation isolates the impact of cyberattacks to individual controller segments rather than affecting the entire system, allowing loyal controllers to continue operating independently of compromised ones
2Speed
If controllers process set point instructions simultaneously without delay, then the system responds quickly to control commands, but malicious set point instructions can be executed immediately across all controllers
Solution Approach 1:
The patent implements preliminary action through the enhanced time delay buffer that delays the processing of set point instructions by a predetermined time period before execution. This preliminary delay allows the system to verify the legitimacy of control instructions and prevents immediate execution of malicious set points while maintaining acceptable response speeds through parallel processing
Solution Approach 2:
The enhanced time delay buffer acts as an intermediary component between the set point input and the controllers. This intermediary introduces a controlled delay that allows the system to filter out malicious instructions while permitting legitimate control commands to pass through to the diversified controller instances
3Ease of operation
If the system uses a single controller output, then the system is simple to operate, but the system cannot detect or prevent malicious control signals
Solution Approach 1:
The patent implements feedback mechanisms where controller outputs are monitored and compared against expected behavioral patterns. The system uses feedback from multiple diversified controller instances to detect anomalies that indicate malicious control signals, while the enhanced voter module provides a simplified single output that maintains ease of operation
Solution Approach 2:
The patent merges outputs from multiple diversified controller instances through the enhanced voter module, which combines the results into a single consolidated output. This merging process maintains operational simplicity by presenting a unified control signal while internally leveraging the diversity of multiple controllers to detect and prevent malicious inputs
4Adaptability or versatility
If the system processes all controller outputs equally, then the system maintains fairness in decision-making, but the system cannot identify and isolate compromised controllers
Solution Approach 1:
The patent applies local quality by enabling the enhanced voter module to differentiate between individual controller outputs based on their specific memory diversification characteristics. This allows the system to evaluate each controller's output locally and identify which specific controllers are compromised, rather than treating all outputs uniformly, thereby isolating faulty instances while maintaining overall system fairness
Data Source
AI summary
A controller computing system, including a plurality of controllers, each controller configured to i) calculate a respective output based on a current set point and ii) output a timer signal; a cyber security manager (CSM) computing module configured to: output a nominal signal indicating that the current set point is a non-malicious set point when the CSM computing module receives each of the timer signals from each of the plurality of controllers; and output a reset signal indicating that the current set point is a malicious set point when the CSM computing module receives less than each of the timer signals from the plurality of controllers.


