OT Container Orchestration via Worker and Proxy Nodes

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Industrial control systems in OT environments lack efficient management and orchestration capabilities similar to those in IT environments, limiting the ability to coordinate operations, provision, deploy, and maintain OT assets across their lifecycles.

Innovation Solution

Integration of specialized hardware and software control systems within industrial control systems to enable participation in container orchestration operations, using worker nodes and proxy nodes to bridge the gap between IT and OT systems, allowing for bi-directional communication and coordination with container orchestration systems.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If container orchestration systems are integrated into OT environments, then management and orchestration capabilities are improved, but device complexity increases

Engineering Contradiction:
Improvemanagement and orchestration capabilitiesVSAvoidsystem complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent introduces worker nodes and proxy nodes as intermediary components that bridge IT container orchestration systems and OT control systems. These intermediaries translate and coordinate operations between the two environments, enabling sophisticated management capabilities without directly complicating the core OT devices. The worker nodes manage container lifecycles while proxy nodes handle communication protocols, isolating complexity from the OT control systems.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system is divided into distinct functional modules: master nodes for orchestration coordination, worker nodes for container management on OT devices, and proxy nodes for protocol translation. This segmentation allows each component to handle specific tasks independently, improving overall manageability while distributing complexity across multiple specialized units rather than concentrating it in a single system.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If worker nodes and proxy nodes are added to bridge IT and OT systems, then coordination capability is improved, but device complexity increases

Engineering Contradiction:
Improvecoordination capabilityVSAvoidnode architecture complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

Worker nodes are designed to perform multiple functions including container deployment, health monitoring, log collection, and coordinate with both master nodes and proxy nodes. This multi-functionality reduces the need for separate specialized components, thereby improving coordination capability while limiting the increase in overall system complexity through consolidated design.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If automatic updates and health monitoring are implemented, then reliability is improved, but use of energy increases

Engineering Contradiction:
Improvesystem reliabilityVSAvoidenergy consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

Worker nodes continuously monitor the health status of containers and OT devices, providing feedback to master nodes. This feedback mechanism enables automatic updates and failover procedures only when necessary, rather than continuous operations. The system adjusts its monitoring and update activities based on actual system state, improving reliability while minimizing unnecessary energy consumption from constant operations.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11513877B2Updating operational technology devices using container orchestration systems
Publication Date: 2022.11.29 ROCKWELL AUTOMATION TECH INC
  • US11513877B2 patent drawing
  • US11513877B2 patent drawing
  • US11513877B2 patent drawing

AI summary

A method may include receiving, via a first computing node, a first pod from a second computing node. The method may also include retrieving a first image file that may include a first set of containers from a registry based on the first pod. The first set of containers may cause a control system to halt operations. The method may then involve generating a first package based on the first set of containers and storing the first package in a filesystem, receiving a second pod from the second computing node, and retrieving a second image file having a second set of containers from the registry. The second pod may include the second set of containers may cause the control system to update software components. The method may also involve generating a second package based on the second set of containers and storing the second package in the filesystem.