Plant Security Managing Device for Standby System Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Plant monitoring and controlling systems face increased security risks due to the use of general-purpose hardware and networks, which can lead to delays or termination of operations when antivirus software is run, as it increases CPU load and affects system performance.

Innovation Solution

A plant security managing device that determines which system is standby and performs security processes only on that system, allowing for seamless switching between service and standby systems to maintain operation stability and security without affecting CPU load.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If antivirus software is run to check for virus infection, then security is improved, but CPU load increases and system operation becomes slow

Engineering Contradiction:
ImprovesecurityVSAvoidsystem operation speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system divides the control device into multiple control units (first control unit and second control unit) that can operate independently. Security checks are performed on one control unit while the other continues to handle plant control operations, segmenting the security verification task from the critical control function to avoid slowing down system operation.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs security verification in advance on a standby control unit before it is needed for critical operations. By pre-checking the antivirus status of the second control unit while the first control unit is actively controlling the plant, the system ensures security is established before potential use, preventing security issues from disrupting ongoing operations.

Inventive Principle:
Principle #10Preliminary action

2Ease of manufacture

If general-purpose hardware and network are used to reduce cost and ease installation, then ease of manufacture is improved, but security risk from virus attacks increases

Engineering Contradiction:
Improveinstallation easeVSAvoidvirus attack risk
Core Design Contradiction:
Ease of manufactureVSObject-affected harmful factors

Solution Approach 1:

The system introduces a plant security managing device as an intermediary that specifically monitors and manages antivirus status across control units. This dedicated security management layer mediates between the general-purpose hardware infrastructure and the critical control functions, providing specialized security oversight without requiring specialized hardware.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system dynamically changes the operational status parameter of control units between 'service system' and 'standby system' states. By switching which control unit is active and which is being security-checked, the system adapts its security verification process to maintain both accessibility and protection, allowing general-purpose hardware to be used while managing security risks through parameter management.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS8918880B2Plant security managing device, managing method and managing program
Publication Date: 2014.12.23 KK TOSHIBA
  • US8918880B2 patent drawing
  • US8918880B2 patent drawing
  • US8918880B2 patent drawing

AI summary

A technology is provided which ensures a high security without affecting a plant operation. A plant security managing device includes a determining unit that determines which one of control units multiplexed as a service system and a standby system associated with monitoring and controlling of a plant is the standby system, a security processing unit that performs a security process for detecting the presence/absence of a security abnormality on the control unit that is the standby system, and a change instructing unit that outputs an instruction for changing the control unit that is the standby system and the control unit that is the service system with each other after the completion of the security process by the security processing unit.