PLC Tag Communication for Secure Bidirectional Node Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network-distributed process control systems face challenges in providing secure, reliable bidirectional communication between nodes while maintaining system security and scalability without relying on additional dedicated security units or complex structures.
Innovation Solution
The system employs a method where source and sink nodes are assigned to tag data, allowing bidirectional communication while controlling data flow, and utilizing a configuration that restricts external access, enabling secure operation and scalability by defining preferred data flow directions without additional systems or services.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If unidirectional communication models (publisher-subscriber or one-way communication) are used, then system security is improved, but bidirectional communication capability deteriorates
Solution Approach 1:
The system segments communication into separate unidirectional channels: a first communication channel for data transmission from field devices to the computing cloud, and a second communication channel for command transmission from the computing cloud to field devices. This segmentation allows each channel to be optimized for security while maintaining bidirectional communication capability.
Solution Approach 2:
The patent introduces a dimensional separation in communication by creating distinct transmission paths for different communication directions. Instead of using a single bidirectional channel that compromises security, the system adds a second dimension (separate channel) for reverse communication, thereby maintaining security in the primary channel while enabling bidirectional functionality.
2Reliability
If additional dedicated security units are added to ensure secure communication, then system security is improved, but device complexity increases
Solution Approach 1:
The computing cloud server performs multiple functions: it acts as a data acquisition endpoint, a command distribution center, and a communication management unit. By making the computing cloud multi-functional, the patent eliminates the need for separate dedicated security units, thereby maintaining security without increasing device complexity.
Solution Approach 2:
The patent merges security functions with the existing computing cloud infrastructure. Instead of adding separate security units, the security-related communication control is integrated into the computing cloud's operation, combining data processing and security management in a single system component.
3Reliability
If restrictive communication control is implemented, then system security is improved, but communication flexibility deteriorates
Solution Approach 1:
The system implements dynamic communication control where the computing cloud can selectively send commands to specific field devices based on operational needs. The communication channels are configured to be restrictive by default for security, but can be dynamically activated for bidirectional communication when required, balancing security and flexibility.
Data Source
Figure 1
Figure 2
Figure 3~5
AI summary
The invention is a method for communicating between operative nodes (10) constituting a network of a network-distributed process control system comprising a PLC (22), each operative node (10) being configured by a node configuration comprising at least one network role, the method comprising reading out tag data of the PLC (22) by an operative node (10). The method is characterised by making available the tag data to other operative nodes (10) of the system by - applying in the system tags that each have at least one assigned operative node (10) configured as a source node (12) and at least one assigned operative node (10) configured as a sink node (14), and - establishing a bidirectional communication connection between the nodes of each node pair that is assigned to the same tag and consists of a source node (12) and a sink node (14), the bidirectional communication comprising - transferring the tag data from the source node (12) to the sink node (14), and - sending a command (15) to be executed from the sink node (14) to the source node (12), the command (15) relating to the tag data of the assigned tag or to a scheduling of a data transfer. The invention is furthermore a network-distributed process control system. (Fig. 6)