Gateway Node Synchronizing Security Settings Between Control Systems

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Industrial plant control systems (IPCS) face compatibility issues when integrating additional control systems, leading to hardware intensity and loss of customized security settings, which can hinder user access to process parameters during emergency situations.

Innovation Solution

A gateway node is used to modify and synchronize customized security settings from a first control system to a second control system by converting the data into a compatible format, allowing or blocking user requests based on access levels, ensuring seamless communication and maintaining security protocols.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a second control system is connected to expand capabilities, then functionality and adaptability are improved, but device complexity and hardware intensity increase

Engineering Contradiction:
Improvesystem capabilityVSAvoidhardware intensity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

A gateway node is introduced as an intermediary component between the first control system and the second control system. The gateway node handles protocol conversion, data formatting, and communication coordination, enabling the second control system to access the first control system's resources without requiring direct integration. This mediator approach reduces the complexity of direct system integration while maintaining expanded functionality.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If default security settings are used in the second control system, then ease of operation is improved, but loss of customized security settings occurs

Engineering Contradiction:
Improveaccess to process parametersVSAvoidcustomized security settings
Core Design Contradiction:
Ease of operationVSLoss of information

Solution Approach 1:

The gateway node automatically retrieves and applies customized security settings from the first control system before the second control system operates. This preliminary action ensures that when users log into the second control system, they inherit the appropriate security permissions and access levels without manual configuration. The customized security settings are pre-synchronized, eliminating the need for users to manually configure access rights while preserving the tailored security framework.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If customized security settings are synchronized between control systems, then reliability of security protocols is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity protocolsVSAvoidsynchronization mechanism
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The gateway node serves as a dedicated intermediary that manages security setting synchronization between control systems. It automatically retrieves customized security settings from the first control system, converts them to the appropriate format for the second control system, and applies them without requiring complex manual configuration. This mediator approach simplifies the synchronization process while maintaining reliable security protocol enforcement across both systems.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS8276186B2System and method for synchronizing security settings of control systems
Publication Date: 2012.09.25 HONEYWELL INTERNATIONAL INC
  • US8276186B2 patent drawing
  • US8276186B2 patent drawing
  • US8276186B2 patent drawing

AI summary

A method for communicating data between a first and second control system (FCS and SCS). FCS (202) controls a first process (FP) having first security data (FSD) in a first data security format (FDSF). The method involves modifying the FSD (214) from being in the FDSF into modified security data (MSD) in a modified security format (MSDF) compatible with SCS (226). Subsequent to the modifying, a request is received from an SCS user. The request includes a user type, process parameter (PP) associated with the FP, and request for information regarding the PP or a request to change a PP value. The method also involves referencing the user type and PP to the MSD. The method further involves blocking or allowing the request based on results of the referencing. If results indicate that the request is allowed, then an access level can be impersonated for changing the PP value in FCS.