Industrial Network Policy Derivation from Control Logic

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Industrial automation networks face inefficiencies in deriving full knowledge of network setup, traffic models, and operation from control data configuration and control logic, leading to challenges in managing network policies and ensuring predictable performance and security.

Innovation Solution

A device receives control logic programmed within industrial network controllers and determines the network topology to derive a network policy based on control logic and topology, automating network setup and configuration, and ensuring safety and security by inferring traffic patterns, bandwidth requirements, and latency constraints.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of information

If manual network configuration methods are used in industrial automation networks, then network setup and configuration can be performed with existing processes, but the ability to derive full knowledge of network setup, traffic models, and operation from control data configuration and control logic is insufficient

Engineering Contradiction:
Improveknowledge of network setup, traffic models, and operationVSAvoidautomation of network setup and configuration
Core Design Contradiction:
Loss of informationVSExtent of automation

Solution Approach 1:

The system automatically derives network policies, traffic models, and operational knowledge from control data configuration and control logic without requiring manual intervention. The network controller autonomously analyzes the control application requirements and generates the necessary network configuration information, enabling the system to serve itself in terms of network management and policy derivation.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces manual mechanical configuration processes with automated electronic derivation. Instead of manually configuring network parameters and policies based on control applications, the system uses electronic analysis of control data configuration and control logic to automatically generate network setup information, traffic models, and operational knowledge, substituting human-operated mechanical processes with automated computational methods.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If traditional network management approaches are used, then existing network structures can be maintained, but managing network policies and ensuring predictable performance and security becomes challenging

Engineering Contradiction:
Improvepredictable performance and securityVSAvoidcomplexity of managing network policies
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system introduces an intermediary automated derivation process between control data configuration and network policy management. This intermediary automatically analyzes control application requirements and translates them into network policies, traffic models, and configuration parameters, simplifying the management complexity while ensuring reliable and secure network operation through consistent, rule-based derivation.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system establishes feedback loops where network performance and security outcomes are continuously monitored and fed back into the automated derivation process. This allows the system to adjust and refine network policies based on actual operational data, ensuring predictable performance and security while managing complexity through adaptive, data-driven adjustments rather than manual intervention.

Inventive Principle:
Principle #23Feedback

3Ease of operation

If automated derivation of network policies is implemented, then network management is simplified and IT/OT operations converge, but more advanced analysis of control logic and topology is required

Engineering Contradiction:
Improvenetwork managementVSAvoidanalysis of control logic and topology
Core Design Contradiction:
Ease of operationVSDifficulty of detecting and measuring

Solution Approach 1:

The system implements a universal automated derivation engine that performs multiple functions: analyzing control logic, determining network topology, deriving traffic models, generating network policies, and ensuring security requirements. This multi-functional approach simplifies network management by consolidating previously separate tasks into a single automated process, even though it requires sophisticated analysis capabilities.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system performs preliminary analysis of control logic and network topology automatically during the network setup phase, before actual network operation begins. By pre-deriving traffic models, performance requirements, and security policies based on control application specifications, the system simplifies ongoing network management while requiring advanced analytical capabilities to be executed upfront during the configuration stage.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10447540B2Deriving a network policy for an industrial automation network
Publication Date: 2019.10.15 CISCO TECHNOLOGY INC
  • US10447540B2 patent drawing
  • US10447540B2 patent drawing
  • US10447540B2 patent drawing

AI summary

In one embodiment, a device receives control logic programmed within at least one controller included within an industrial network. The device also determines a network topology of the industrial network, and derives a network policy for the industrial network based upon, at least in part, the control logic and the network topology.