PLC Security Failover for Malicious Function Block Revisions

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional security solutions for industrial control systems are inadequate in addressing cyberattacks, particularly in open and dynamic production environments with increased connectivity from mobile devices and IoT paradigms, as they rely on perimeter protection mechanisms that fail to mitigate risks within the control systems themselves.

Innovation Solution

Implementing security failover procedures within Programmable Logic Controllers (PLCs) that detect malicious revisions by using digital signatures and failover computing devices, allowing for the execution of revised replicas of function blocks or data blocks to maintain control system resilience and minimize adverse impacts from cyberattacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If perimeter protection mechanisms (firewalls, VPN concentrators) are used to protect control systems, then security against external attacks is improved, but security against internal attacks in open production environments deteriorates

Engineering Contradiction:
Improvesecurity protectionVSAvoidopen production environment compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent divides the control system into multiple independent segments: primary control system, backup control system, and failover management system. Each segment operates independently with its own control programs and data, allowing the system to isolate and contain cyberattacks within specific segments while maintaining overall system security and functionality in open production environments

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent changes the security parameter from perimeter-based protection to internal redundancy-based protection. By implementing hot-standby failover mechanisms with real-time monitoring and automatic switching capabilities, the system adapts to open production environments while maintaining security through architectural redundancy rather than perimeter defenses

Inventive Principle:
Principle #35Parameter changes

2Ease of operation

If control systems and security systems run independently with separate design and operation teams, then operational simplicity is improved, but integrated security response to cyberattacks deteriorates

Engineering Contradiction:
Improveindependent operationVSAvoidsecurity response effectiveness
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent merges control system operations with security system operations by implementing a unified failover management mechanism. The failover management system monitors both control functionality and security status simultaneously, enabling coordinated response to cyberattacks that integrates operational simplicity with effective security response through a single management framework

Inventive Principle:
Principle #5Merging (Combining)

3Adaptability or versatility

If production cell networks become open and dynamic with mobile devices and wireless sensors, then data collection and diagnostics capabilities are improved, but security risks to automation devices increase

Engineering Contradiction:
Improveconnectivity capabilityVSAvoidsecurity risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements prior cushioning by pre-configuring backup control systems with identical control programs and data before cyberattacks occur. The failover management system continuously monitors for security threats and maintains readiness to switch to the pre-prepared backup system, providing a safety buffer that protects automation devices from open network risks while maintaining enhanced connectivity capabilities

Inventive Principle:
Principle #11Beforehand cushioning (Prior cushioning)

Data Source

PatentUS11099951B2Cyberattack-resilient control system design
Publication Date: 2021.08.24 SIEMENS AG
  • US11099951B2 patent drawing
  • US11099951B2 patent drawing
  • US11099951B2 patent drawing

AI summary

A method for performing security failover in an industrial production environment includes a programmable logic controller (PLC) receiving notification that a function block (FB) or a function (FC) on the programmable logic controller has been maliciously revised. The PLC next determines whether the function block or the function is also maliciously revised on a failover computing device. If the failover computing device is not maliciously revised, a failover operation is performed by the PLC. This operation includes sending a data block comprising one or more input parameters to the function block or the function and receiving an output data resulting from executing the function block or the function with the data block on the failover computing device.