Intrusion-Tolerant SCADA Architecture with Byzantine Replication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current SCADA systems are vulnerable to malicious attacks and network partitions, leading to potential system downtime at critical times and incorrect command issuance, as they fail to account for broader fault models including both benign and malicious failures.

Innovation Solution

A network-attack-resilient, intrusion-tolerant SCADA system architecture with at least three centers, including two control centers and one data center, situated at different geographic locations, utilizing a Byzantine replication protocol to ensure consensus among operational servers for system updates and command issuance, even in the presence of server disconnections or compromises, with proactive recovery mechanisms to maintain safety and performance.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a cold-backup approach is used with a backup control center in a different geographic location, then system availability is improved after complete control center failure, but system downtime occurs at critical times when attackers target the primary control center

Engineering Contradiction:
Improvesystem availabilityVSAvoidsystem downtime
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements a warm-backup control center that is pre-initialized and maintains a ready state with pre-loaded system data and configurations, allowing immediate takeover within seconds rather than minutes or hours. This preliminary preparation eliminates the activation delay inherent in cold-backup systems while maintaining geographic separation for disaster recovery.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system dynamically transitions between operational states, with the warm-backup control center maintaining a partially active state that can quickly escalate to full operation. The backup center continuously synchronizes with the primary center and can immediately assume control when needed, creating a flexible, adaptive recovery mechanism.

Inventive Principle:
Principle #15Dynamics

2Reliability

If a hot-backup approach is used with an always-active backup control center, then system availability is improved for immediate takeover, but network partitions cause a split-brain problem where both control centers believe they are primary and issue conflicting commands

Engineering Contradiction:
Improvesystem availabilityVSAvoidsplit-brain problem and incorrect commands
Core Design Contradiction:
ReliabilityVSObject-generated harmful factors

Solution Approach 1:

The patent implements a centralized coordinator that continuously monitors the operational status of both primary and backup control centers. This coordinator receives heartbeats and status reports from both centers, determines which one should be active, and provides authoritative feedback to prevent the split-brain problem. The coordinator acts as an arbiter that resolves conflicts and ensures only one center issues commands at any given time.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The coordinator serves as an intermediary between the primary and backup control centers, managing their interactions and preventing direct conflicts. It mediates the failover process by validating takeover requests and ensuring proper state transitions, thereby eliminating the possibility of both centers operating as primary simultaneously.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If traditional fault-tolerance techniques are used in SCADA systems, then benign failures are handled adequately, but malicious attacks and network partitions cannot be effectively addressed

Engineering Contradiction:
Improvefault toleranceVSAvoidresilience to malicious attacks
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments the control system into multiple geographically distributed control centers (primary, warm-backup, and cold-backup) rather than relying on a single centralized system. This segmentation isolates malicious attacks to specific locations, preventing system-wide compromise and enabling localized failure containment while maintaining overall system functionality.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The warm-backup control center is pre-initialized with system data and configurations before failures occur, allowing immediate assumption of control without requiring data reconstruction or system reinitialization. This preliminary preparation significantly reduces recovery time and prevents attackers from exploiting the activation window present in cold-backup systems.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11140221B2Network-attack-resilient intrusion-tolerant SCADA architecture
Publication Date: 2021.10.05 JOHNS HOPKINS UNIVERSITY
  • US11140221B2 patent drawing
  • US11140221B2 patent drawing
  • US11140221B2 patent drawing

AI summary

The present invention generally relates to network-attack-resilient intrusion-tolerant Supervisory Control and Data Acquisition (SCADA) systems. Some implementations utilize redundant, proactively-recovery-configured servers at multiple centers communally executing a replication protocol. Some implementations, in addition to control centers, include data centers, which participate in the replication protocol, except that they may not be capable of controlling remote units such as Remote Terminal Units (RTUs).