PLC Tag Communication for Secure Bidirectional Node Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network-distributed process control systems face challenges in providing secure, reliable bidirectional communication between nodes while maintaining system security and scalability without relying on additional dedicated security units or complex structures.

Innovation Solution

The system employs a method where source and sink nodes are assigned to tag data, allowing bidirectional communication while controlling data flow, and utilizing a configuration that restricts external access, enabling secure operation and scalability by defining preferred data flow directions without additional systems or services.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If unidirectional communication models (publisher-subscriber or one-way communication) are used, then system security is improved, but bidirectional communication capability deteriorates

Engineering Contradiction:
Improvesystem securityVSAvoidbidirectional communication capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system segments communication into separate unidirectional channels: a first communication channel for data transmission from field devices to the computing cloud, and a second communication channel for command transmission from the computing cloud to field devices. This segmentation allows each channel to be optimized for security while maintaining bidirectional communication capability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a dimensional separation in communication by creating distinct transmission paths for different communication directions. Instead of using a single bidirectional channel that compromises security, the system adds a second dimension (separate channel) for reverse communication, thereby maintaining security in the primary channel while enabling bidirectional functionality.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Reliability

If additional dedicated security units are added to ensure secure communication, then system security is improved, but device complexity increases

Engineering Contradiction:
Improvesystem securityVSAvoidsystem structure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The computing cloud server performs multiple functions: it acts as a data acquisition endpoint, a command distribution center, and a communication management unit. By making the computing cloud multi-functional, the patent eliminates the need for separate dedicated security units, thereby maintaining security without increasing device complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent merges security functions with the existing computing cloud infrastructure. Instead of adding separate security units, the security-related communication control is integrated into the computing cloud's operation, combining data processing and security management in a single system component.

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If restrictive communication control is implemented, then system security is improved, but communication flexibility deteriorates

Engineering Contradiction:
Improvesystem securityVSAvoidcommunication flexibility
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system implements dynamic communication control where the computing cloud can selectively send commands to specific field devices based on operational needs. The communication channels are configured to be restrictive by default for security, but can be dynamically activated for bidirectional communication when required, balancing security and flexibility.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentEP3719646B1Method for communicating in a network-distributed process control system and network-distributed process control system
Publication Date: 2023.11.15 GAMMA DIGITAL KFT
  • EP3719646B1 patent drawingFigure 1
  • EP3719646B1 patent drawingFigure 2
  • EP3719646B1 patent drawingFigure 3~5

AI summary

The invention is a method for communicating between operative nodes (10) constituting a network of a network-distributed process control system comprising a PLC (22), each operative node (10) being configured by a node configuration comprising at least one network role, the method comprising reading out tag data of the PLC (22) by an operative node (10). The method is characterised by making available the tag data to other operative nodes (10) of the system by - applying in the system tags that each have at least one assigned operative node (10) configured as a source node (12) and at least one assigned operative node (10) configured as a sink node (14), and - establishing a bidirectional communication connection between the nodes of each node pair that is assigned to the same tag and consists of a source node (12) and a sink node (14), the bidirectional communication comprising - transferring the tag data from the source node (12) to the sink node (14), and - sending a command (15) to be executed from the sink node (14) to the source node (12), the command (15) relating to the tag data of the assigned tag or to a scheduling of a data transfer. The invention is furthermore a network-distributed process control system. (Fig. 6)