Inline Controller Monitoring for Cybersecure Network Connectivity

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Network connected controllers in industrial applications are prone to technical malfunctions leading to downtime and financial losses, and are vulnerable to unauthorized modifications and cybersecurity threats, especially as they become more connected to the internet, with existing diagnostic methods being subjective and potentially late in detection.

Innovation Solution

A data acquisition device is interposed between the controller and the network to monitor and secure data communication, enabling real-time, non-intrusive, and protocol-independent monitoring and protection, using techniques like data extraction, decryption, and AI for anomaly detection, and allowing for process control and integrity verification.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If traditional diagnostic methods are used by trained personnel, then errors can be localized, but the diagnosis is subjective and may be too late for timely restoration

Engineering Contradiction:
Improveerror detection accuracyVSAvoiddowntime for restoration
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The monitoring system enables the controller to monitor itself automatically without requiring human intervention. The data acquisition device continuously extracts and analyzes controller data, detecting errors and generating alerts autonomously, thus eliminating the subjectivity and time delays associated with manual diagnostics by trained personnel.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system implements continuous feedback by constantly monitoring controller data and comparing it against expected parameters. When deviations are detected, the system immediately generates alerts, creating a closed-loop feedback mechanism that enables timely detection and response to errors, preventing the delays inherent in periodic manual checks.

Inventive Principle:
Principle #23Feedback

2Adaptability or versatility

If the controller is connected to the network for data sharing, then operational flexibility is improved, but vulnerability to cyber attacks and unauthorized modifications increases

Engineering Contradiction:
Improvenetwork connectivity flexibilityVSAvoidcybersecurity threats
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The data acquisition device serves as an intermediary between the controller and the network. It monitors all data communications passing through it, detecting and alerting on potential cyber threats, unauthorized modifications, or malicious activities. This intermediary position enables the system to maintain network connectivity while providing a protective layer that can identify and respond to security threats before they compromise the controller.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If firewalls and antivirus software are deployed, then cybersecurity protection is improved, but system complexity and vulnerability to advanced attacks remain

Engineering Contradiction:
Improvecybersecurity protectionVSAvoidsecurity infrastructure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The monitoring function is extracted from the controller itself and placed in a separate data acquisition device. This separation allows the controller to remain simple and unchanged while the monitoring system provides comprehensive security and diagnostic capabilities independently. The extraction of monitoring functions reduces the complexity burden on the controller and creates a specialized monitoring infrastructure.

Inventive Principle:
Principle #2Taking out (Extraction)

4Reliability

If software modifications are made to enhance security, then protection capabilities are improved, but the risk of introducing new vulnerabilities and operational disruptions increases

Engineering Contradiction:
Improvesecurity protection capabilityVSAvoidnew vulnerabilities and disruptions
Core Design Contradiction:
ReliabilityVSObject-generated harmful factors

Solution Approach 1:

The data acquisition device acts as an intermediary monitoring layer that provides security and diagnostic capabilities without requiring any software modifications to the controller. By positioning the monitoring function externally, the system gains enhanced protection and detection capabilities while avoiding the risk of introducing new vulnerabilities through controller software changes.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20240220657A1A method, a monitoring system and a computer program product for monitoring and securing a network connected controller
Publication Date: 2024.07.04 AXITE INTELLIGENCE SERVICES BV
  • US20240220657A1 patent drawing
  • US20240220657A1 patent drawing

AI summary

The invention relates to a method for monitoring and securing a network connected controller. The method includes a step of providing a data acquisition device interconnected between the controller and the network. Further, the method includes a step of extracting data from the controller, using the data acquisition device. The invention also relates to a data acquisition device.