OT Container Orchestration via Proxy Nodes for Asset Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Industrial control systems in operational technology (OT) environments lack efficient management tools for coordinating operations across multiple OT devices, as existing container orchestration systems are not capable of accessing and managing OT assets in the same way they manage IT assets, leading to limitations in provisioning, deploying, and maintaining OT assets throughout their lifecycles.
Innovation Solution
Integration of specialized hardware and software control systems within industrial control systems to enable participation in container orchestration operations, using worker nodes and proxy nodes that support communication with container orchestration systems, allowing for bi-directional coordination and management of OT assets, including automatic updates, health monitoring, and failover procedures.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Extent of automation
If container orchestration systems are used to manage IT assets, then automation and coordination efficiency are improved, but the ability to access and manage OT assets is lost
Solution Approach 1:
The patent introduces a gateway component that acts as an intermediary between container orchestration systems and OT assets. This gateway translates OT device data into formats compatible with container orchestration systems, enabling automated management of OT assets without requiring direct integration. The gateway mediates communication protocols and data structures, allowing the orchestration system to manage diverse OT assets through a standardized interface.
2Adaptability or versatility
If specialized control systems are integrated into OT environments to enable container orchestration participation, then coordination capability is improved, but system complexity increases
Solution Approach 1:
The patent segments the integration architecture into distinct functional components: edge computing devices that collect OT data, a gateway that translates and routes data, and container orchestration systems that coordinate operations. This segmentation allows each component to have a specific, simplified function while the overall system achieves high coordination capability. The modular structure reduces complexity by isolating integration logic in the gateway layer.
Solution Approach 2:
The gateway serves as an intermediary that handles the complexity of protocol translation and data format conversion between OT systems and container orchestration systems. By concentrating integration complexity in this single intermediary component, the patent allows both the OT control systems and the container orchestration system to remain relatively simple while achieving sophisticated coordination through the gateway's mediation.
3Ease of operation
If worker nodes and proxy nodes are deployed to support bi-directional coordination, then management capability is improved, but infrastructure requirements increase
Solution Approach 1:
The patent designs worker nodes and proxy nodes with multi-functional capabilities that allow them to perform multiple roles within the integrated system. These nodes can simultaneously handle data collection, local processing, communication with OT devices, and participation in container orchestration. This universality reduces the total number of specialized components needed, as each node performs multiple functions that would otherwise require separate dedicated systems.
Data Source
AI summary
A method may include receiving, via a first computing node of a cluster of computing nodes in a container orchestration system, a pod from a second computing node in the cluster of computing nodes. The method may also include retrieving an image file comprising one or more containers from a registry, such that the pod may include an indication of a location of the image file in the registry. The one or more containers may include one or more pre-analytic operations for a control system of a plurality of control systems to perform. The method may then involve generating a package based on the one or more containers and storing the package in a filesystem shared with the control system.


