Secure Remote Maintenance for Safety Control Systems

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current maintenance methods for safety control systems require on-site presence, limiting efficiency and productivity due to the need for direct access and identification of the safety controller, which complicates remote maintenance and increases the risk of errors or unauthorized access.

Innovation Solution

A safety system configuration that includes a process execution unit for safety control, a communication unit for secure external access, and a support device connected via a network, using cryptographic keys and certificates for secure data exchange and authentication to enable remote maintenance while ensuring the integrity and authenticity of the safety program updates.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If maintenance is performed on-site at the controller location, then direct access and identification are ensured, but maintenance efficiency and productivity are reduced

Engineering Contradiction:
Improvemaintenance efficiencyVSAvoidremote access capability
Core Design Contradiction:
ProductivityVSEase of operation

Solution Approach 1:

A communication unit is introduced as an intermediary between the support device and the process execution unit. This mediator enables secure remote maintenance by exchanging identification information and cryptographic keys, allowing the support device to access and maintain the safety program without requiring on-site presence while ensuring authentication and data security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If remote maintenance is implemented, then maintenance efficiency is improved, but security risks and unauthorized access increase

Engineering Contradiction:
Improvemaintenance efficiencyVSAvoidsecurity and authentication
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system performs preliminary actions by exchanging identification information and cryptographic keys before maintenance operations. The communication unit stores keys and certificates in advance, and the support device verifies authentication information beforehand, ensuring that only authorized devices can perform maintenance while enabling secure remote access.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The communication unit serves as a security intermediary that handles all authentication and data exchange between the support device and process execution unit. It verifies cryptographic signatures, manages key pairs, and controls access rights, thereby preventing unauthorized access while facilitating efficient remote maintenance operations.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If identification information is exchanged in advance, then authentication reliability is improved, but system complexity increases

Engineering Contradiction:
Improveauthentication accuracyVSAvoidcommunication and key management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system uses cryptographic key pairs (public/private keys) and digital certificates as copies of identification information. Instead of transmitting complex authentication data, the communication unit stores encrypted copies of identification information and keys, allowing verification without exposing the actual authentication credentials, thus simplifying the communication protocol while maintaining high authentication reliability.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS12155758B2Safety system and maintenance method
Publication Date: 2024.11.26 OMRON CORP
  • US12155758B2 patent drawing
  • US12155758B2 patent drawing
  • US12155758B2 patent drawing

AI summary

A safe system is able to execute remote maintenance reliably with respect to a process execution unit for executing a safety control in accordance with a safety program. This safety system includes: a process execution unit for executing a safety control in accordance with a safety program; a communication unit that is directly connected to the process execution unit and mediates external access to a safety program held in the process execution unit; and a support device that is connected via a network to the communication unit and, in accordance with a user operation, executes maintenance, including an addition or a change, with respect to the safety program. The support device and the communication unit identify each other by means of information that has been exchanged in advance, and exchange data required for maintenance.