SCADA-Coordinated Firmware Updates Based on Device Criticality
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for updating machine-readable data in SCADA systems, such as firmware, often require human intervention, leading to potential errors, incomplete updates, and increased cybersecurity risks, especially when considering the criticality and operational status of devices in infrastructure systems like electric power systems.
Innovation Solution
A method and system where a Fleet Management (FLM) system communicatively interfaces with a SCADA system to determine an update sequence for devices, taking into account criticality and operational status, allowing for automated updates that minimize downtime and ensure system safety by coordinating with the SCADA system to manage device maintenance and update processes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If firmware updates are performed manually by human experts, then updates can be controlled and verified, but the process is time-consuming, prone to human error, and increases cybersecurity risks
Solution Approach 1:
The system enables automated firmware updates where the FLM system automatically determines update sequences, coordinates with SCADA systems, and triggers update processes without human intervention. The system self-manages the entire update workflow including device selection, sequencing, and execution, eliminating dependency on human experts while maintaining reliability through automated coordination protocols
Solution Approach 2:
The manual mechanical process of human experts physically updating firmware is replaced by an automated electronic system. The FLM system uses electronic communication interfaces to automatically select devices, determine update sequences based on device criticality, coordinate with SCADA systems, and trigger updates, substituting human manual operations with automated electronic control mechanisms
2Productivity
If automated update processes are implemented without considering device criticality and operational status, then update speed increases, but system safety and operational reliability deteriorate
Solution Approach 1:
The system applies different update priorities and sequences to different devices based on their individual criticality levels and operational statuses. Rather than treating all devices uniformly, the FLM system evaluates each device's specific characteristics and assigns appropriate update timing, ensuring that critical devices are updated at safe moments while non-critical devices can be updated more aggressively
Solution Approach 2:
The system performs preliminary evaluation of device criticality and operational status before initiating updates. The FLM system proactively identifies suitable devices for updates by assessing their current state and criticality level, and pre-determines safe update sequences that maintain system safety while enabling automated high-speed updates
3Device complexity
If updates are performed without coordinating with SCADA system, then update process simplification is achieved, but operational awareness and safety monitoring are lost
Solution Approach 1:
The FLM system acts as an intermediary between the automated update process and the SCADA system. It receives operational status information from SCADA, processes this information to determine safe update sequences, and triggers updates while maintaining awareness of system state. This intermediary role enables automated updates without requiring direct complex integration between update mechanisms and SCADA
4Reliability
If frequent firmware updates are deployed to address cybersecurity challenges, then security posture improves, but risk of disrupting device functionality increases
Solution Approach 1:
The system performs preliminary assessment of device criticality and operational status before deploying security updates. By proactively identifying devices that are safe to update based on their current state and redundancy availability, the system enables frequent security patches to be deployed without causing functional disruptions to critical infrastructure
Solution Approach 2:
The system prepares for potential update failures by considering device redundancy and operational status beforehand. It selects devices for updates only when appropriate cushions or redundancies exist, such as when backup devices are available or when the device is in a non-critical state, thereby protecting against functional disruptions even as update frequency increases
Data Source
Figure 1
Figure 2~3
Figure 4~5
AI summary
To control an update of machine-readable data processed by devices communicatively coupled to a Supervisory Control and Data Acquisition system (60), a fleet management system (80) communicatively interfaces with the Supervisory Control and Data Acquisition system (60).