PLC Logic Transducer Modeling for Cyberattack Risk Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Industrial systems face increased vulnerability due to the convergence of operational and information technologies, necessitating a unified approach to ensure both safety and security, particularly in identifying and mitigating cyberattack risks.

Innovation Solution

A method involving the conversion of programmable logic controller (PLC) logic into minimal finite transducers to identify critical transitions and sensitive states, coupled with risk analysis to assess potential cyberattacks, using tools like Teloco and Quine-McCluskey algorithms to minimize and classify states and transitions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If PLC logic is converted into minimal finite transducers to identify critical transitions and sensitive states, then the ability to detect and mitigate cyberattacks is enhanced, but the device complexity and computational requirements increase

Engineering Contradiction:
Improvecyberattack detection capabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent replaces traditional mechanical cybersecurity defense mechanisms with a mathematical modeling approach using finite transducers. By converting PLC logic into formal mathematical models, the system automatically identifies critical transitions and sensitive states through algorithmic analysis rather than manual security configuration, thereby enhancing detection capability while managing complexity through mathematical abstraction.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent transforms the analysis of PLC logic by changing the parameter representation from traditional programming logic to finite transducer states and transitions. This parameter transformation enables systematic identification of critical transitions and sensitive states, allowing the system to detect cyberattacks through mathematical property analysis rather than conventional security scanning methods.

Inventive Principle:
Principle #35Parameter changes

2Measurement precision

If comprehensive risk analysis is performed on all transitions and states, then the security assessment accuracy is improved, but the analysis time and computational resources increase

Engineering Contradiction:
Improvesecurity assessment accuracyVSAvoidanalysis time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent extracts only the critical elements from the complete PLC logic system by identifying sensitive states and critical transitions within the finite transducer model. Rather than analyzing all possible states and transitions, the method focuses specifically on those elements that pose security risks, thereby maintaining high assessment accuracy while significantly reducing analysis time and computational resource requirements.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent segments the PLC logic system into distinct finite transducer components with clearly defined states and transitions. This segmentation allows the risk analysis to be performed systematically on individual transitions and states, enabling comprehensive security assessment to be broken down into manageable analytical units that can be processed efficiently.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentEP4390584B1Method and apparatus for identifying cyberattack risk
Publication Date: 2026.02.04 COMMISSARIAT A LENERGIE ATOMIQUE ET AUX ENERGIES ALTERNATIVES
  • EP4390584B1 patent drawingFigure 1
  • EP4390584B1 patent drawingFigure 2
  • EP4390584B1 patent drawingFigure 3

AI summary

This description relates to a method for identifying the risks of cyberattacks on a programmable logic controller, the method comprising: - the generation of a digital representation of a minimal finite transducer based on a specification of a logic controller of the programmable logic controller, the minimal finite transducer comprising a set of source states, a set of destination states and a set of transitions going from a source state to a destination state based on an input data value; - the generation of a second computer file, based on a first computer file identifying a subset of sensitive states, the second file comprising a list of critical transitions associated with the sensitive states, and for each transition, a list of input data;and - the generation of a fourth computer file indicating input data to be protected which are associated both with critical transitions and with a risk of corruption.