Plant Control User Authentication Switching Between Local and Domain Modes
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing user authentication systems in plant control systems face a trade-off between security and availability, where high security measures, such as using a domain controller, can lower system availability due to the potential unreliability of the domain controller and information network, while local authentication maintains availability but compromises security.
Innovation Solution
A user authentication system that includes both a local user authentication unit in the manipulation monitoring terminal and a domain controller, with a user authentication alarm unit that generates security alarms and switches between local and domain authentication based on the domain controller's operational status, ensuring security when available and maintaining system operation through local authentication in emergencies.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If domain controller is used for user authentication, then security is improved, but system availability deteriorates
Solution Approach 1:
The system dynamically switches between domain authentication and local authentication modes based on the operational status of the domain controller. When the domain controller is available, the system uses domain authentication for high security. When the domain controller fails, the system automatically transitions to local authentication to maintain availability, thus resolving the contradiction between security and system availability.
Solution Approach 2:
The system changes the authentication parameter from domain-based to local-based authentication depending on the domain controller's operational status. This parameter change allows the system to adapt between security-oriented and availability-oriented authentication modes, effectively balancing the two competing requirements.
2Productivity
If local user authentication unit is used, then system availability is maintained, but security deteriorates
Solution Approach 1:
The system dynamically adjusts the authentication method based on operational conditions. Local authentication is not used as a default but only when the domain controller is unavailable, as detected by the alarm unit. This dynamic adjustment ensures that security is maintained when possible while allowing availability to be preserved when necessary.
Solution Approach 2:
The domain controller acts as an intermediary that mediates between security requirements and availability requirements. When the intermediary is functional, it enforces security through domain authentication. When the intermediary fails, the system bypasses it to maintain availability through local authentication, thus resolving the contradiction.
3Reliability
If user authentication alarm unit generates security alarm, then security monitoring is improved, but system complexity increases
Solution Approach 1:
The alarm unit provides feedback about the domain controller's operational status and authentication mode transitions. This feedback mechanism enables security monitoring without requiring complex additional systems, as the alarm unit leverages existing authentication infrastructure to generate security alerts when local authentication is used instead of domain authentication.
Data Source
AI summary
A plant control system may include a manipulation monitoring terminal that includes a local user authentication unit configured to authenticate a user who logs in the manipulation monitoring terminal and a domain controller that includes a domain user authentication unit and communicates with the manipulation monitoring terminal. The manipulation monitoring terminal may include a user authentication alarm unit configured to generate a security alarm when the local user authentication unit performs user authentication on the user in a state in which the domain controller is in normal operation.


