NCS Configuration Monitoring for Tamper Detection and Failover

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Networked Control Systems (NCSs) face malfunctions due to discrepancies in configuration information between sensors, actuators, and controllers, which can lead to system failures, especially in critical environments like autonomous systems and manufacturing plants.

Innovation Solution

A configuration management device and method that automatically detect discrepancies in configuration data and characteristics of network components by comparing them with reference data stored in a database, sending tamper detection signals to switch communication from a compromised component to a redundant one, ensuring system integrity and safety.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual monitoring of configuration information is performed, then system reliability can be maintained, but labor intensity and time consumption increase

Engineering Contradiction:
Improvesystem reliabilityVSAvoidtime consumption
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs self-diagnosis by automatically comparing its own configuration information against stored reference data, eliminating the need for external manual monitoring. The control manager autonomously detects discrepancies and initiates switching operations, making the system self-sufficient in maintaining its own reliability.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system continuously monitors configuration information from sensors and actuators, compares it with reference data, and provides feedback through tamper detection signals when discrepancies are found. This closed-loop feedback mechanism automatically maintains system reliability without requiring continuous manual intervention.

Inventive Principle:
Principle #23Feedback

2Measurement precision

If configuration information is frequently monitored and compared, then tampering detection accuracy improves, but system complexity and computational load increase

Engineering Contradiction:
Improvetampering detection accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

Reference configuration data is pre-stored in the control manager's database before any tampering can occur. This preliminary preparation allows for immediate and accurate comparison when configuration information is received, achieving high detection accuracy without requiring complex real-time analysis algorithms.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent extracts only the essential configuration information from sensors and actuators for comparison, rather than monitoring all system parameters. This selective extraction approach maintains high tampering detection accuracy while minimizing system complexity and computational requirements.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If redundant network components are prepared for switching, then system availability improves, but device complexity and cost increase

Engineering Contradiction:
Improvesystem availabilityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Redundant network components are pre-configured and prepared in advance, ready to immediately take over if a tampering incident occurs. This beforehand preparation ensures high system availability by eliminating switching delays, while the redundancy architecture follows standard engineering practices that balance complexity with reliability benefits.

Inventive Principle:
Principle #11Beforehand cushioning (Prior cushioning)

Solution Approach 2:

The control manager acts as an intermediary that manages both the primary and redundant network components. It receives configuration information, performs comparisons, and controls the switching operation, thereby coordinating the redundancy system without requiring complex direct communication between multiple redundant components.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If automatic tamper detection and switching is implemented, then operational safety improves, but loss of information and communication overhead increase

Engineering Contradiction:
Improveoperational safetyVSAvoidcommunication overhead
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The system extracts only the essential configuration information needed for tamper detection from the data transmitted by sensors and actuators. By focusing on critical parameters rather than processing all communication data, the system achieves high operational safety while minimizing communication overhead and information loss.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent applies partial monitoring by selectively comparing configuration information against reference data only when necessary, rather than continuously analyzing all system communications. This approach ensures operational safety through targeted detection while reducing the communication overhead associated with constant full-system monitoring.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentEP3514638B1Automatic tampering detection in networked control systems
Publication Date: 2021.04.21 THE BOEING CO
  • EP3514638B1 patent drawingFigure 1
  • EP3514638B1 patent drawingFigure 2
  • EP3514638B1 patent drawingFigure 3A

AI summary

A configuration manager (20) is associated with a Networked Control System (NCS) (10) comprising a plurality of sensors (12) and actuators (16). The configuration manager automatically discovers the hardware and/or software configurations of the sensors and actuators, and analyzes that information in order to detect whether any of the sensors and actuators have been tampered with. Provided the configuration manager detects such tampering, the configuration manager indicates the tampering to a control manager (14) of the NCS, which then functions to minimize potential damage to the NCS.