SCADA Data Abstraction for Secure Cloud-Based Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current SCADA systems face challenges in maintaining security and confidentiality when transitioning to cloud-based settings, as sensitive information may be compromised due to malicious attacks or unauthorized access, leading to potential devastating effects on system operations.

Innovation Solution

Implementing an abstraction representation for SCADA data, allowing only logical addresses to be shared with cloud-based systems, which are then translated back to physical addresses by the client's control systems, thereby securing sensitive information and preventing its disclosure to cloud providers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If SCADA systems transition to cloud-based settings to obtain cost and scalability benefits, then productivity and ease of operation are improved, but security and confidentiality of sensitive information deteriorate due to potential malicious attacks and unauthorized access

Engineering Contradiction:
Improveprocessing power and efficiencyVSAvoiddata security and confidentiality
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an abstraction layer as an intermediary between the cloud-based SCADA system and the actual physical infrastructure. This abstraction representation hides sensitive information (physical addresses, locations, IP addresses of field sites and RTUs) while allowing the cloud system to operate using abstract identifiers. The intermediary translates between abstract representations and actual physical details, enabling cloud-based processing without exposing confidential data to potential security breaches.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If cloud-based systems are used to reduce costs and simplify management, then ease of operation is improved, but the risk of malicious attacks and unauthorized access increases

Engineering Contradiction:
Improvemanagement simplicityVSAvoidunauthorized access and malicious attacks
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent extracts sensitive information from the cloud-based SCADA system by removing physical addresses, locations, and direct access details from the data transmitted to the cloud. Only abstract representations are sent to the cloud provider, while the actual sensitive data remains isolated in the client's control system. This extraction eliminates the attack surface for unauthorized access while preserving the operational benefits of cloud-based management.

Inventive Principle:
Principle #2Taking out (Extraction)

3Object-affected harmful factors

If abstraction representation is implemented to secure sensitive information, then data security is improved, but device complexity increases due to the need for translation between abstract and physical addresses

Engineering Contradiction:
Improvedata securityVSAvoidsystem architecture complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent changes the parameter representation from physical details (addresses, locations, IP addresses) to abstract identifiers. By transforming the data format and representation rather than adding complex security protocols, the system achieves enhanced security through parameter transformation. The abstraction layer modifies how data is structured and transmitted, using parameter changes to inherently protect sensitive information without requiring additional complex security infrastructure.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS10990083B2Systems and methods for cloud-based control and data acquisition with abstract state
Publication Date: 2021.04.27 JOHNS HOPKINS UNIVERSITY
  • US10990083B2 patent drawing
  • US10990083B2 patent drawing
  • US10990083B2 patent drawing

AI summary

Systems, computer readable media, and method concern assigning an abstraction representation to data associated with a system of the SCADA environment. The method also includes providing the abstraction representation to a control system associated with the system of the SCADA environment. The control system is implemented in a computer system. Further, the method includes receiving actual data from the system of the SCADA environment. Additionally, the method includes generating abstract data from the actual data using the abstraction representation. The method, also includes forwarding the abstract data to the control system.