OT Device Updates via Container Orchestration Gateway Nodes

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Industrial control systems in operational technology (OT) environments lack efficient methods for managing and coordinating operations of OT devices, as existing container orchestration systems are not compatible with OT assets and cannot access remote-control nodes via OT networks.

Innovation Solution

Integration of specialized hardware and/or software control systems into industrial control systems, enabling them to participate in orchestration operations by acting as worker nodes or proxy nodes within a container orchestration system, thereby bridging the gap between IT and OT systems.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If container orchestration systems are used to manage IT assets, then operational efficiency and automation are improved, but compatibility with OT assets and access to remote-control nodes via OT networks deteriorate

Engineering Contradiction:
Improveoperational efficiencyVSAvoidcompatibility with OT assets
Core Design Contradiction:
ProductivityVSAdaptability or versatility

Solution Approach 1:

The patent introduces a gateway device as an intermediary between the container orchestration system (IT environment) and OT assets. The gateway translates orchestration commands into OT-compatible protocols and communicates with remote-control nodes via OT networks, enabling IT-based automation tools to effectively manage OT assets without direct compatibility requirements

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If traditional industrial control systems are used to manage OT devices, then compatibility and direct access are maintained, but operational efficiency and management capabilities deteriorate

Engineering Contradiction:
Improvecompatibility with OT devicesVSAvoidmanagement efficiency
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The gateway device serves as a bridge that allows traditional OT control systems to work with modern container orchestration platforms. The gateway translates high-level orchestration intents into device-specific commands that OT controllers can execute, thereby enhancing management efficiency without sacrificing compatibility

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system architecture segments functionality into distinct layers: the container orchestration system handles high-level automation and coordination, while the gateway device handles protocol translation and device-specific communication. This segmentation allows each component to be optimized independently for its specific function

Inventive Principle:
Principle #1Segmentation

3Extent of automation

If container orchestration systems are implemented in OT environments, then automation and resource coordination are improved, but system complexity and integration requirements worsen

Engineering Contradiction:
Improveautomation capabilityVSAvoidsystem integration complexity
Core Design Contradiction:
Extent of automationVSDevice complexity

Solution Approach 1:

The gateway device absorbs the complexity of protocol translation and device integration, presenting a simplified interface to the container orchestration system. This shields the automation platform from OT-specific complexities while maintaining high automation capabilities

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP3998529B1Updating operational technology devices using container orchestration systems
Publication Date: 2025.03.05 ROCKWELL AUTOMATION TECH INC
  • EP3998529B1 patent drawingFigure 1
  • EP3998529B1 patent drawingFigure 2~3
  • EP3998529B1 patent drawingFigure 4

AI summary

A method may include receiving, via a first computing node, a first pod from a second computing node. The method may also include retrieving a first image file that may include a first set of containers from a registry based on the first pod. The first set of containers may cause a control system to halt operations. The method may then involve generating a first package based on the first set of containers and storing the first package in a filesystem, receiving a second pod from the second computing node, and retrieving a second image file having a second set of containers from the registry. The second pod may include the second set of containers may cause the control system to update software components. The method may also involve generating a second package based on the second set of containers and storing the second package in the filesystem.