Embedded Industrial Control Platform for Secure Real-Time Cloud Integration
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing industrial control systems face challenges in securely integrating real-time control processes with cloud infrastructure, particularly in ensuring data security and managing complex industrial assets, which hampers efficient operation and maintenance.
Innovation Solution
A local embedded control device with a multi-core hypervisor platform that executes real-time control processes in parallel with a field agent, providing secure connectivity to the cloud, secure data exchange, and secure updates, while ensuring deterministic real-time performance and cyber-hardened security measures.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of information
If cloud infrastructure is integrated with real-time control processes, then data exchange and analytics capabilities are improved, but data security and system vulnerability to cyber intrusions deteriorate
Solution Approach 1:
The control device is divided into multiple isolated execution environments (containers) that segment different control processes and data flows. This segmentation allows secure cloud integration for specific non-critical functions while protecting critical real-time control processes from cyber intrusions, resolving the contradiction between data exchange capability and data security.
Solution Approach 2:
A containerized architecture acts as an intermediary layer between the cloud infrastructure and the real-time control processes. This intermediary enables controlled data exchange while implementing security policies, authentication, and isolation mechanisms that protect the core control system from direct cloud exposure, thus maintaining both data exchange capability and security.
2Device complexity
If multiple control processes are executed on a single platform, then device complexity is reduced, but real-time performance and system stability deteriorate
Solution Approach 1:
The system segments control processes into isolated containers that run independently on a shared hardware platform. Each container gets guaranteed computational resources and isolated execution environments, ensuring that multiple control processes can coexist without interfering with each other's real-time performance, thus reducing device complexity while maintaining reliability.
Solution Approach 2:
A single control device is designed to host multiple containerized control processes simultaneously, making the hardware platform universal and multi-functional. The containerization technology enables diverse control applications to run on one device while maintaining deterministic real-time performance through resource isolation and management, resolving the contradiction between device complexity and real-time performance.
3Reliability
If secure connectivity measures are implemented, then data security is improved, but communication overhead and processing time increase
Solution Approach 1:
Security credentials, certificates, and authentication mechanisms are pre-configured and established before cloud communication begins. Container security contexts and encryption keys are initialized in advance, allowing secure data exchange to proceed with minimal real-time overhead, thus maintaining high cybersecurity while reducing communication latency.
Data Source
AI summary
An apparatus is provided. The apparatus including a plurality of network interfaces, including a first network interface and a second network interface. The apparatus also includes a processor with two or more independent processing units, including a first independent processing unit and a second independent processing unit. The apparatus further includes a memory having first instructions and second instructions stored thereon. Execution of the first instructions, cause the first independent processing unit to execute operations associated with a first operating system and communicate, via the first network interface, over a bi-direction communication, with one or more platform computing devices. Execution of the second instructions, cause the second independent processing unit to execute real-time operations associated with a second operating system and communicate, via the second network interface, with one or more computing devices each having one or more sensors thereon.


