Relay-Based Access Control for Legacy Factory Automation Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing factory automation systems face security vulnerabilities in communications between control devices and external devices due to the use of legacy applications, making it impractical to implement new security technologies without significant cost or operational disruption.

Innovation Solution

A control system with a relay unit that authenticates request sources and manages access restrictions, allowing secure communication without altering legacy applications by using methods like password, biometric, or certificate authentication, and maintaining access logs.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If new security technology is implemented in legacy FA systems, then security is improved, but system complexity and cost increase significantly

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a relay device as an intermediary component between external devices and the control device. This relay device handles authentication and access control functions, allowing legacy FA systems to benefit from security improvements without modifying the core control system or external devices. The relay device mediates communications, performing authentication requests and managing access rights while the legacy systems continue to operate unchanged.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If new security technology is implemented in legacy FA systems, then security is improved, but implementation cost increases significantly

Engineering Contradiction:
ImprovesecurityVSAvoidimplementation cost
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent segments the security function from the legacy FA systems by introducing a separate relay device. This segmentation allows the security enhancement to be implemented as an independent component rather than requiring modification of existing expensive control devices or external equipment. The relay device can be added to the network without replacing existing systems, thereby reducing implementation costs while still providing improved security.

Inventive Principle:
Principle #1Segmentation

3Reliability

If new security technology is implemented in legacy FA systems, then security is improved, but operational disruption occurs

Engineering Contradiction:
ImprovesecurityVSAvoidoperational continuity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The relay device performs authentication requests in advance before allowing communications between external devices and the control device. By pre-establishing authentication credentials and access rights through the relay device, the system ensures security is already in place before operational communications begin, avoiding the need to interrupt production for security setup or verification.

Inventive Principle:
Principle #10Preliminary action

4Reliability

If authentication and access control are implemented, then security is improved, but communication overhead increases

Engineering Contradiction:
ImprovesecurityVSAvoidcommunication overhead
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The relay device performs authentication requests in advance before allowing communications between external devices and the control device. By pre-establishing authentication credentials and access rights through the relay device, the system ensures security is already in place before operational communications begin, avoiding the need to interrupt production for security setup or verification.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12422811B2Control system, relay device, and access management program
Publication Date: 2025.09.23 OMRON CORP
  • US12422811B2 patent drawing
  • US12422811B2 patent drawing
  • US12422811B2 patent drawing

AI summary

A control system includes a control unit configured to control a control object and communicate with an external device, and a relay unit configured to relay access from the external device to the control unit. The relay unit includes a reception unit configured to receive an authentication request from a request source, an authentication unit configured to authenticate validity of the request source upon receipt of the authentication request by the reception unit, and an access management unit configured to control a restriction level of access from the external device to the control unit when the validity of the request source is authenticated by the authentication unit.