Plant Control Zoning for Cyberattack Damage Containment

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional plant control systems are vulnerable to cyberattacks due to the use of low-cost general-purpose devices, which can propagate damage across interconnected components, making it essential to develop technology that suppresses damage when a plant is subjected to a cyberattack.

Innovation Solution

A plant management method and device that acquire correlation information between components and zone them based on this information to isolate affected components, prevent the spread of damage, and prioritize critical components to maintain plant operation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If low-cost general-purpose devices are used in plants, then device cost is reduced, but vulnerability to cyberattacks increases

Engineering Contradiction:
Improvecybersecurity resilienceVSAvoidcyberattack vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent divides the plant control system into multiple isolated zones (control zones) based on correlation information between components. This segmentation allows the system to contain cyberattacks within specific zones, preventing propagation to other parts of the plant while using general-purpose devices.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a plant management device as an intermediary that acquires correlation information between components and determines appropriate control actions. This intermediary layer provides security management without requiring changes to the general-purpose devices themselves.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If components are isolated to prevent cyberattack propagation, then damage suppression is improved, but system complexity increases

Engineering Contradiction:
Improvedamage suppression capabilityVSAvoidnetwork structure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent performs preliminary acquisition of correlation information between components before cyberattacks occur. This advance preparation enables the system to quickly determine appropriate isolation actions during attacks without complex real-time analysis, reducing operational complexity.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The plant management device automatically acquires correlation information and determines control actions based on predefined criteria. This self-service approach reduces the need for manual intervention and complex human decision-making during cyberattacks.

Inventive Principle:
Principle #25Self-service

3Reliability

If correlation information is acquired and components are zoned, then cyberattack damage is suppressed, but information processing requirements increase

Engineering Contradiction:
Improvecyberattack response effectivenessVSAvoidinformation processing load
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent extracts only the necessary correlation information between components that is relevant to cyberattack propagation. This selective extraction reduces information processing requirements compared to analyzing all possible component interactions in the plant.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentEP4030251B1Method for managing plant, plant design device, and plant management device
Publication Date: 2024.06.05 CHIYODA CORP
  • EP4030251B1 patent drawingFigure 1
  • EP4030251B1 patent drawingFigure 2
  • EP4030251B1 patent drawingFigure 3A~3B

AI summary

A plant management method includes: a step (S12) of acquiring correlation information indicating a correlation between a component subjected to a cyberattack and a component to be possibly affected by the cyberattack when a plant including a plurality of components is subjected to the cyberattack; and a step (S14) of zoning the plurality of components on the basis of the correlation information.