Field Device Digital Twins on Compute Fabric for Secure Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing industrial control systems face challenges in integrating cloud-based components with the Purdue model, leading to complex, disorganized, and insecure data transfer practices, with issues such as latency, incompatibility with IT security protocols, and difficulty in integrating third-party software, resulting in compromised security and inflexible virtualized control systems.

Innovation Solution

A new control system architecture utilizing a compute fabric that abstracts from the Purdue model, implementing a shared, virtualized computing environment with containerized applications and services, enabling secure, flexible, and redundant communication through a transport network using VPNs and point-to-point connections, abstracting higher-level business logic from specific hardware.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If cloud-based components are integrated with the Purdue model, then computing resources and scalability are improved, but system complexity and security vulnerabilities increase

Engineering Contradiction:
Improvecloud integration capabilityVSAvoidsystem architecture complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces a cloud gateway as an intermediary component that mediates between cloud-based services and the Purdue model architecture. This gateway handles protocol translation, authentication, and data formatting, thereby enabling cloud integration without directly complicating the core control system architecture.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system architecture is segmented into distinct layers: the Purdue model layers (Levels 0-5) remain separate from cloud infrastructure, with clear interfaces defined at Level 3/4 boundaries. This segmentation allows cloud components to be integrated at higher levels without affecting lower-level control functions, managing overall system complexity.

Inventive Principle:
Principle #1Segmentation

2Productivity

If data transfer is implemented across Purdue model layers, then control functionality is improved, but latency and security risks worsen

Engineering Contradiction:
Improvecontrol response speedVSAvoiddata transfer latency
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The system pre-loads and caches frequently accessed process data at higher Purdue levels (Levels 3-5) before it is actually needed for decision-making. This preliminary action reduces the time required for data retrieval during critical control operations, thereby reducing latency without compromising security protocols.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements parallel data transfer paths: a fast path for non-critical data that can tolerate higher latency, and a dedicated low-latency path for critical control data. This dimensional separation of data streams allows the system to optimize for speed where needed while maintaining security for other data types.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Reliability

If traditional Purdue model architecture is used, then security protocols are maintained, but flexibility and virtualization capability are reduced

Engineering Contradiction:
Improvesecurity protocol complianceVSAvoidvirtualization flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces dynamic configuration capabilities at Levels 3 and 4 of the Purdue model, allowing the system to adapt its architecture in real-time. Virtual machines and containers can be dynamically instantiated, migrated, and configured without violating security boundaries, providing flexibility while maintaining the static security model of the Purdue architecture.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system employs universal virtualization layers that can host multiple different applications and services (IT, OT, analytics, AI) within the same Purdue model framework. This multi-functionality allows diverse workloads to run on standardized infrastructure while adhering to the same security protocols, enhancing versatility without compromising reliability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12554236B2Field device digital twins in process control and automation systems
Publication Date: 2026.02.17 FISHER ROSEMOUNT SYST INC
  • US12554236B2 patent drawing
  • US12554236B2 patent drawing
  • US12554236B2 patent drawing

AI summary

A process control or automation system configured to control a plurality of process control or automation field devices in a process, includes a compute fabric executing a plurality of instantiated micro-encapsulated execution environments (MEEEs) that cooperate to control the process. Each of the plurality of field devices operates to sense a parameter of the process and output the sensed parameter of the process to an input of the compute fabric and/or to affect a parameter of the process according to an input received from the compute fabric. The system also includes a plurality of digital twin services, each instantiated as one or more of the plurality of instantiated MEEEs, each having an associated one or group of field devices, and each operable to mimic non-physical operation of the one or group of field devices.