SCADA-Coordinated Firmware Updates Based on Device Criticality

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for updating machine-readable data in SCADA systems, such as firmware, often require human intervention, leading to potential errors, incomplete updates, and increased cybersecurity risks, especially when considering the criticality and operational status of devices in infrastructure systems like electric power systems.

Innovation Solution

A method and system where a Fleet Management (FLM) system communicatively interfaces with a SCADA system to determine an update sequence for devices, taking into account criticality and operational status, allowing for automated updates that minimize downtime and ensure system safety by coordinating with the SCADA system to manage device maintenance and update processes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If firmware updates are performed manually by human experts, then updates can be controlled and verified, but the process is time-consuming, prone to human error, and increases cybersecurity risks

Engineering Contradiction:
Improveupdate reliabilityVSAvoidupdate time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system enables automated firmware updates where the FLM system automatically determines update sequences, coordinates with SCADA systems, and triggers update processes without human intervention. The system self-manages the entire update workflow including device selection, sequencing, and execution, eliminating dependency on human experts while maintaining reliability through automated coordination protocols

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The manual mechanical process of human experts physically updating firmware is replaced by an automated electronic system. The FLM system uses electronic communication interfaces to automatically select devices, determine update sequences based on device criticality, coordinate with SCADA systems, and trigger updates, substituting human manual operations with automated electronic control mechanisms

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Productivity

If automated update processes are implemented without considering device criticality and operational status, then update speed increases, but system safety and operational reliability deteriorate

Engineering Contradiction:
Improveupdate speedVSAvoidsystem safety
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system applies different update priorities and sequences to different devices based on their individual criticality levels and operational statuses. Rather than treating all devices uniformly, the FLM system evaluates each device's specific characteristics and assigns appropriate update timing, ensuring that critical devices are updated at safe moments while non-critical devices can be updated more aggressively

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system performs preliminary evaluation of device criticality and operational status before initiating updates. The FLM system proactively identifies suitable devices for updates by assessing their current state and criticality level, and pre-determines safe update sequences that maintain system safety while enabling automated high-speed updates

Inventive Principle:
Principle #10Preliminary action

3Device complexity

If updates are performed without coordinating with SCADA system, then update process simplification is achieved, but operational awareness and safety monitoring are lost

Engineering Contradiction:
Improveupdate process complexityVSAvoidoperational awareness
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The FLM system acts as an intermediary between the automated update process and the SCADA system. It receives operational status information from SCADA, processes this information to determine safe update sequences, and triggers updates while maintaining awareness of system state. This intermediary role enables automated updates without requiring direct complex integration between update mechanisms and SCADA

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If frequent firmware updates are deployed to address cybersecurity challenges, then security posture improves, but risk of disrupting device functionality increases

Engineering Contradiction:
Improvecybersecurity postureVSAvoidfunctional disruption risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary assessment of device criticality and operational status before deploying security updates. By proactively identifying devices that are safe to update based on their current state and redundancy availability, the system enables frequent security patches to be deployed without causing functional disruptions to critical infrastructure

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system prepares for potential update failures by considering device redundancy and operational status beforehand. It selects devices for updates only when appropriate cushions or redundancies exist, such as when backup devices are available or when the device is in a non-critical state, thereby protecting against functional disruptions even as update frequency increases

Inventive Principle:
Principle #11Beforehand cushioning (Prior cushioning)

Data Source

PatentEP4492225A1Method and systems for controlling an update of devices
Publication Date: 2025.01.15 HITACHI ENERGY LTD
  • EP4492225A1 patent drawingFigure 1
  • EP4492225A1 patent drawingFigure 2~3
  • EP4492225A1 patent drawingFigure 4~5

AI summary

To control an update of machine-readable data processed by devices communicatively coupled to a Supervisory Control and Data Acquisition system (60), a fleet management system (80) communicatively interfaces with the Supervisory Control and Data Acquisition system (60).