Embedded Field Device Identification for Secure Cloud Process Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current industrial control systems face challenges in achieving desired security levels due to the convergence of operation technology (OT) with information technology (IT), leading to complex and insecure networks, especially when integrating cloud-based components, which complicates data transfer and increases latency.
Innovation Solution
A new process control and automation system architecture that implements a shared, virtualized compute fabric, allowing for robust and secure communication between physical devices and IT infrastructure, bypassing traditional Purdue model constraints, using containerized components and virtual private networks for enhanced security and flexibility.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional Purdue model architecture is used for industrial control systems, then security layers are established, but network complexity increases and latency is introduced
Solution Approach 1:
The patent implements device identification and authentication by creating virtual representations (digital twins) of physical devices in the cloud platform. These digital twins copy the essential identification characteristics of physical devices, allowing secure authentication without requiring complex physical network infrastructure. The cloud platform maintains copies of device identities and authentication credentials, eliminating the need for multiple physical security layers.
Solution Approach 2:
The patent introduces a cloud-based communication platform as an intermediary between physical devices and IT systems. This platform mediates authentication and communication, simplifying the network architecture by consolidating security functions in the cloud rather than distributing them across multiple network layers. The intermediary handles device identification, credential verification, and secure message routing.
2Adaptability or versatility
If cloud-based components are integrated into industrial control systems, then computing flexibility is improved, but data transfer complexity and latency increase
Solution Approach 1:
The patent performs preliminary authentication and device identification in the cloud platform before actual control operations. Device credentials are verified and cached in advance, so that during runtime communication, authentication can proceed quickly without adding latency to control loops. The system prepares security credentials and communication pathways beforehand.
Solution Approach 2:
The patent creates digital copies of device identities and authentication credentials in the cloud platform. These copies allow rapid verification without requiring physical device presence or complex real-time authentication protocols. The cloud platform maintains replicated copies of device information for quick access during control operations.
3Reliability
If device identification is implemented in process control devices, then security is enhanced, but device complexity increases
Solution Approach 1:
The patent extracts complex identification and authentication logic from physical process control devices and relocates it to the cloud platform. Physical devices retain only essential identification elements (such as device IDs or simple credentials), while the cloud platform handles the complex verification, validation, and authentication processes. This extraction reduces device complexity while maintaining security.
Solution Approach 2:
The cloud platform serves as an intermediary that handles complex identification and authentication tasks. Instead of embedding complex security logic in each physical device, the cloud intermediary receives simple device identifiers, performs comprehensive verification against stored credentials, and returns authentication results. This mediates the complexity away from physical devices.
Data Source
AI summary
A process control device for use in an industrial process control or automation system of an industrial process plant includes a sensor configured to measure a parameter of a process in the industrial process plant and to output to a controller in the industrial process plant the parameter measured. The process control device also or alternatively includes a control element configured to perform an action in the industrial process plant according to an input received from the controller in the industrial process plant. The process control device also includes an embedded device identifier, unique to the process control field device and associated with one or more of an owner of the process control field device, a plant location of the process control field device, a country or geographical or geopolitical region, and a device tag.


