OT Network Update Management for Compatible Automation Devices
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for updating automation devices in an OT network are device-specific, lacking comprehensive and modular management systems that ensure end-to-end security and compatibility, especially as IT and OT networks converge, necessitating a unified solution for cross-component updates.
Innovation Solution
A management and updating system with a device management and update user unit that provides interface selection, read-out, update planning, file retrieval, check and allocation services, ensuring centralized control and compatibility checks for automation devices connected to an OT network.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If device-specific update methods are used for each automation device, then individual device updates can be performed, but comprehensive and modular management is lacking and security cannot be ensured end-to-end
Solution Approach 1:
The system segments the update management process into distinct functional modules: a server component for centralized control, client components for device-specific operations, and protocol layers for secure communication. This segmentation allows comprehensive security management while maintaining modular architecture that can be independently configured for each device type.
Solution Approach 2:
The patent introduces a standardized communication protocol as an intermediary between diverse automation devices and the update management server. This protocol layer abstracts device-specific details while enabling secure, standardized update operations across multiple device types, resolving the contradiction between comprehensive management and device complexity.
2Productivity
If multiple different tools are used for updating many automation devices, then individual device updates are possible, but the process becomes inefficient and lacks centralized control
Solution Approach 1:
The update management server is designed with universal functionality to handle multiple device types through a standardized protocol interface. The server can simultaneously manage updates for different automation devices using the same toolset, eliminating the need for multiple specialized tools while maintaining device-specific update requirements through protocol abstraction.
3Adaptability or versatility
If IT and OT networks are converged, then data exchange and connectivity improve, but security gaps and compatibility issues arise
Solution Approach 1:
The system implements local quality by applying device-specific security protocols and update procedures tailored to each automation device type while operating within the unified IT/OT network. The standardized communication protocol enables network convergence and data exchange, while device-specific security configurations maintain reliability and address security gaps locally.
4Reliability
If centralized update management is implemented, then control and compatibility checks improve, but system complexity increases
Solution Approach 1:
The system performs preliminary compatibility checks and authorization validations before executing updates. The server verifies device compatibility, retrieves appropriate update files, and authorizes updates in advance, ensuring reliability and compatibility while keeping the actual update execution simple and standardized across all devices.
Data Source
AI summary
A management and updating system for automation devices connected to an OT network of an automation plant, includes a device management and updating user unit programmed to provide a service for providing a communications interface for producing a communication link with connected ones of the automation devices, a read-out service for reading-out device-type information stored in each automation device, and for storing read-out device-type information, a service for planning update requests for each automation device having saved read-out device-type information, a service for communicating with at least one memory unit and retrieving update files stored therein, a service for checking each retrieved update file for its release relative to the automation devices in functional dependency on the stored device-type information, and, if the checking of one of the retrieved update files leads to a release for an automation device, for allocating this update file to the device-type information saved for this automation device, and a service for transmitting according to saved device-type information to each automation device of the update file allocated thereto, along with an update command, and functionally dependent on the update requests planned for each automation device.


