Role-Based Variable Publication for Secure External Control Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing development support devices allow unrestricted access to published variables, compromising security in the exchange of data between control devices and external devices.

Innovation Solution

A support device that provides a user interface for specifying roles and settings to control the publication of variables to external devices, allowing users to set read and execute permissions based on roles, and prioritizing settings using instance or function block identification information to enhance security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If publication setting is allowed for all variables in a namespace, then data accessibility is improved, but security is worsened

Engineering Contradiction:
Improvedata accessibilityVSAvoidsecurity risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the namespace into multiple groups, where each group contains a subset of variables. Users can selectively publish specific groups to external devices rather than publishing all variables in the namespace. This segmentation allows fine-grained control over data accessibility while maintaining security by limiting exposure to only necessary variables.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies different publication settings to different groups within the namespace. Each group can have its own publication status and access permissions, allowing local customization of data accessibility. This enables security-sensitive variables to be excluded from publication while allowing other variables to be accessed freely.

Inventive Principle:
Principle #3Local quality

2Object-affected harmful factors

If publication setting is conducted for each variable individually, then security control is improved, but setting complexity is worsened

Engineering Contradiction:
Improvesecurity controlVSAvoidsetting complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent merges multiple variables into groups, allowing users to set publication permissions at the group level rather than individually for each variable. This combining approach significantly reduces the number of setting operations required while maintaining fine-grained security control through selective group publication.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent creates publication setting groups that can serve multiple purposes: they can contain variables with similar security requirements, represent functional modules, or group variables by access priority. This multi-functionality allows a single group setting to control access to multiple variables simultaneously, simplifying the overall configuration process.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP4682653A1Support device, control method, and support program
Publication Date: 2026.01.21 OMRON CORP
  • EP4682653A1 patent drawingFigure 1
  • EP4682653A1 patent drawingFigure 2
  • EP4682653A1 patent drawingFigure 3

AI summary

A support device (100) provides a user interface for allowing a user to conduct a publication setting of a variable to an external device (300), the variable being generated during execution of a user program (230), and generates publication setting information (260) based on the publication setting conducted by the user using the user interface. A control device (200) manages publication of a variable to the external device (300) based on the publication setting information (260), the variable being generated during execution of the user program (230). The publication setting information (260) includes at least one of: information for setting whether or not to permit the external device to read at least one variable according to at least one role; and information for setting whether or not to permit the external device to execute the at least one variable according to the at least one role. The user interface is configured to allow the user to specify one of the at least one role to conduct the publication setting.