FA Control Security Monitoring for Incident Detection and Notification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional control devices for factory automation (FA) lack a scheme to notify managers of security incidents arising from networking and intelligentization, potentially leading to system shutdowns without appropriate incident addressing.

Innovation Solution

A control system comprising a control unit and a security unit that collects state information, senses incidents, and provides notification on the type, seriousness, and risk of incidents, allowing for tailored responses based on configuration and network settings.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional control devices merely sense failures in the control device itself, then the control device can monitor its own unusual states, but no scheme is provided for notifying managers of security incidents that may occur with networking or intelligentization

Engineering Contradiction:
Improvesecurity incident detection capabilityVSAvoidsecurity monitoring system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The control system is divided into distinct functional modules: a collection module that gathers state information, a sensing module that detects security incidents, and a notification module that alerts managers. This segmentation allows each module to perform its specific function independently, improving security detection capability while keeping the overall system manageable through clear division of responsibilities.

Inventive Principle:
Principle #1Segmentation

2Loss of information

If the sensing module senses multiple types of incidents with different degrees of seriousness, then actionable information for addressing incidents is provided, but the complexity of incident classification and notification increases

Engineering Contradiction:
Improveinformation completeness for incident addressingVSAvoidincident classification complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The notification module provides tailored notifications based on the specific type and degree of seriousness of each incident. Different incidents trigger different notification contents and methods, ensuring that managers receive precisely the information needed for each situation without being overwhelmed by uniform generic alerts. This local quality approach optimizes information delivery while managing classification complexity.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system establishes a feedback loop where state information is continuously collected, analyzed for security incidents, and then used to generate notifications that provide actionable information to managers. This feedback mechanism ensures that the system adapts to different incident types and seriousness levels, providing appropriate responses while maintaining systematic operation.

Inventive Principle:
Principle #23Feedback

3Adaptability or versatility

If the control system networks with various external apparatuses and performs sophisticated processing, then the control system becomes more intelligent and capable, but types of security incidents that may occur increase

Engineering Contradiction:
Improvenetworking and intelligentization capabilityVSAvoidsecurity incident types
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The sensing module is configured with pre-defined conditions for multiple types of security incidents. By establishing these detection conditions in advance, the system is prepared to recognize and respond to various security threats that may arise from networking and intelligentization, without needing to react to each new threat type as it emerges.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The security unit is designed as a multi-functional component that can detect multiple types of security incidents across different incident types and seriousness levels. This universal approach allows a single security unit to handle diverse security threats resulting from networking and intelligentization, rather than requiring separate specialized systems for each threat type.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12111639B2Control system
Publication Date: 2024.10.08 OMRON CORP
  • US12111639B2 patent drawing
  • US12111639B2 patent drawing
  • US12111639B2 patent drawing

AI summary

Information for addressing an incident depending on the incident is given. A control system includes a controller that performs a control operation for controlling an object to be controlled and a security component connected to the controller, the security component being responsible for a security function of the control system. The security component includes a collection module configured to collect state information indicating an operating state of the control system, a sensing module configured to sense an incident in the control system based on the collected state information, and a notification module configured to give information for addressing the sensed incident.