Relay Unit Address Mapping for Secure PLC Network Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In control systems with multiple connected units, users face difficulties in accessing target function units without knowing their IP addresses, especially as the number of connected units increases, leading to a need for a technology that enables access without revealing or requiring the IP address of the destination unit.

Innovation Solution

A relay unit connected to a Programmable Logic Controller (PLC) that acquires address information of other units, generates setting information associating this information with an identifier, and creates link information for external devices to access these units, concealing the IP address and preventing direct communication between external devices and internal network units.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If users directly access function units using IP addresses, then communication between external devices and internal units is established, but security risks increase and system complexity increases as the number of units grows

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a relay unit as an intermediary between external devices and internal function units. The relay unit receives access requests from external devices, translates them into internal network requests using address information, and forwards them to the target function units. This mediator approach allows external access without exposing internal IP addresses, thereby improving security while managing system complexity through centralized address management.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the network into distinct zones: an external network where devices use identifiers instead of IP addresses, and an internal network where function units have their own IP addresses. The relay unit acts as the boundary between these segments, translating requests between the two address systems. This segmentation isolates the internal network from external access risks while maintaining functionality.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If the number of connected function units increases, then system functionality improves, but the difficulty of grasping IP addresses increases

Engineering Contradiction:
Improvesystem functionalityVSAvoidaccess difficulty
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The patent creates a simplified copy of the internal network structure in the external network through the relay unit. Instead of requiring external devices to know complex internal IP addressing, the relay unit presents a simplified address space using identifiers. This copying approach maintains the functional structure while simplifying the access interface for external devices.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The relay unit serves as an intermediary that manages the mapping between external identifiers and internal IP addresses. As the number of function units increases, the relay unit automatically handles the complexity of address management, translation, and routing, allowing users to access any function unit using simple identifiers without needing to understand or memorize IP address schemes.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If IP addresses are concealed from external devices, then security is improved, but direct communication capability is reduced

Engineering Contradiction:
ImprovesecurityVSAvoidcommunication limitation
Core Design Contradiction:
ReliabilityVSObject-generated harmful factors

Solution Approach 1:

The relay unit acts as a necessary intermediary that enables communication while maintaining security. It receives requests from external devices using identifiers, translates them to internal IP address-based requests, and forwards them to the appropriate function units. This intermediary approach preserves full communication capability while ensuring that internal IP addresses remain concealed and secure.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent adds an additional dimension to the communication architecture by introducing the relay unit as a translation layer between two different address spaces. External devices communicate in one dimension using identifiers, while internal function units operate in another dimension using IP addresses. The relay unit bridges these dimensions, enabling communication without direct exposure between the two systems.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentEP3951517B1Unit, unit control method, and unit control program
Publication Date: 2024.11.13 OMRON CORP
  • EP3951517B1 patent drawingFigure 1
  • EP3951517B1 patent drawingFigure 2
  • EP3951517B1 patent drawingFigure 3

AI summary

Provided is a technology with which it is possible to access a function unit to be accessed without ascertaining an IP address of the function unit. Provided is a unit (200) comprising: a communication unit for relaying a communication between an external device (500) connected to a first network and another unit (300) connected to a second network; a setting unit (252) for acquiring address information of the other unit (300) in the second network from the other unit (300) and generating setting information (230) in which the address information is associated with an identifier which substitutes for the address information; and a link information generation unit (254) for generating, on the basis of the identifier, link information used to access information on the other unit (300) from the external device (500).