Fleet Management Compute Fabric for Secure OT-IT Integration
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current industrial control systems face challenges in achieving desired security levels due to complex infrastructure requirements and incompatibilities between operational technology (OT) and information technology (IT) networks, leading to insecure data transfer practices and increased latency when integrating cloud-based components, especially when adhering to the Purdue model.
Innovation Solution
A next-generation process control and automation system architecture that implements a shared, virtualized compute fabric, allowing for robust and secure communication between physical devices and IT infrastructure, bypassing traditional Purdue model constraints by using containerized components and virtual private networks to manage and secure industrial processes across multiple locations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional Purdue model architecture is used to integrate cloud-based components with OT networks, then security infrastructure is established, but latency increases and security levels are insufficient
Solution Approach 1:
The patent introduces a network translator as an intermediary device between OT networks and IT networks. This translator enables secure communication by translating protocols and managing data exchange, thereby maintaining security requirements while reducing the latency associated with traditional multi-layer Purdue model architectures.
Solution Approach 2:
The patent segments the network architecture into distinct OT and IT domains with controlled interaction points. By dividing the system into separate network zones with specific translation layers, it achieves security through segmentation while minimizing latency through direct translation paths rather than traversing multiple traditional security layers.
2Reliability
If traditional Purdue model architecture is used to integrate cloud-based components, then security infrastructure is established, but device complexity increases
Solution Approach 1:
The network translator serves as a simplified intermediary that consolidates multiple security and protocol translation functions into a single device. This reduces infrastructure complexity by eliminating the need for multiple separate security appliances, firewalls, and protocol converters that would otherwise be required in a traditional Purdue model implementation.
Solution Approach 2:
The network translator is designed as a multi-functional device that simultaneously handles protocol translation, security enforcement, and data routing between OT and IT networks. This universal approach reduces overall system complexity by replacing multiple specialized devices with a single platform that performs all necessary functions.
3Adaptability or versatility
If cloud-based components are integrated into industrial control systems, then scalability is improved, but security incompatibilities between OT and IT networks arise
Solution Approach 1:
The network translator acts as a security-compliant intermediary that enables cloud-based components to integrate with OT networks. It translates and secures communications between the cloud (IT domain) and industrial control systems (OT domain), allowing scalability while maintaining security compatibility through protocol translation and secure data exchange mechanisms.
Data Source
AI summary
A process plant and industrial control system architecture includes a generalized compute fabric that is agnostic or indifferent to the physical location at which the compute fabric is implemented. One or more applications, executing via the location-agnostic compute fabric, provide for access, management, and/or reconfiguration of various aspects of one or more process control systems across one or more physical sites operated by an enterprise. The one or more applications may, for example, provide for viewing of operational parameters and/or health statuses based upon information accessed from one, two, three four or more physical sites.


