External Security Control for Flexible PLC Access States

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security systems for programmable logic controllers in industrial and domestic processes are costly, time-consuming to implement, and vulnerable to password disclosure or theft, with a lack of flexibility in adjusting security levels based on operating requirements.

Innovation Solution

A security system for programmable logic controllers that includes a command element allowing manual or wireless actuation to switch between high-security and low-security states, requiring direct access and configuration, with a reset option to ensure secure and flexible operation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a human-machine interface with password protection is implemented on each controller module, then security against unauthorized access is improved, but device complexity and implementation time increase

Engineering Contradiction:
ImprovesecurityVSAvoidcomplexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The security system is extracted from the controller modules and placed in a separate, dedicated security device. This external security device communicates with the controller modules via secured communication channels, thereby reducing the complexity and implementation burden on each controller module while maintaining robust security functionality.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

A single external security device serves multiple controller modules simultaneously, providing universal security protection across the entire control system. This multi-functional approach eliminates the need for individual human-machine interfaces on each module, reducing overall system complexity while maintaining security.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If a human-machine interface with password protection is implemented on each controller module, then security against unauthorized access is improved, but implementation time increases

Engineering Contradiction:
ImprovesecurityVSAvoidimplementation time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The security functionality is extracted from individual controller modules and consolidated into a dedicated external security device. This eliminates the need to implement and configure human-machine interfaces on each module, significantly reducing implementation time while maintaining security through centralized management.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The security device is configured and secured before being deployed to protect controller modules. By establishing security infrastructure in advance, the system avoids time-consuming security configurations during system deployment and operation.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If a human-machine interface with password protection is implemented on each controller module, then security against unauthorized access is improved, but power consumption increases

Engineering Contradiction:
ImprovesecurityVSAvoidpower consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The power-intensive human-machine interface functionality is extracted from controller modules and relocated to a dedicated security device. The controller modules communicate with the security device through low-power communication protocols, thereby reducing overall system power consumption while maintaining security functionality.

Inventive Principle:
Principle #2Taking out (Extraction)

4Reliability

If a human-machine interface with password protection is implemented on each controller module, then access control is improved, but vulnerability to password disclosure or theft increases

Engineering Contradiction:
Improveaccess controlVSAvoidvulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

A dedicated security device acts as an intermediary between operators and controller modules. This intermediary handles all authentication and access control operations, eliminating the need for passwords on controller modules themselves. The security device uses secure communication channels and protocols, reducing vulnerability to password disclosure or theft while maintaining strong access control.

Inventive Principle:
Principle #24Intermediary (Mediator)

5Reliability

If a complex security system is implemented on each controller module, then security state is improved, but adaptability to different operating situations decreases

Engineering Contradiction:
Improvesecurity stateVSAvoidadaptability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The security system implements dynamic security states that can be adjusted based on operating requirements. The security device can transition between different security levels (e.g., high-security state with full authentication and low-security state with simplified access), allowing the system to adapt to different operating situations while maintaining robust security when needed.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS11182991B2System for securing a device
Publication Date: 2021.11.23 SCHNEIDER ELECTRIC IND SAS
  • US11182991B2 patent drawing
  • US11182991B2 patent drawing
  • US11182991B2 patent drawing

AI summary

Security system fitted in a device, the security system comprising a command element that is actuatable by an operator at least to a first position and to a second position.