SCADA Update Sequencing by Device Criticality and Maintenance Mode
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current firmware update processes in SCADA systems for critical infrastructure, such as electric power systems, often require human intervention, leading to potential errors, system downtime, and increased cybersecurity risks, and do not adequately consider the criticality and operational status of devices during updates.
Innovation Solution
A method and system where the SCADA system interacts with the FLM system to determine an optimal update sequence for devices based on criticality, operational status, and estimated update durations, ensuring that updates are performed without affecting system safety by placing non-critical devices in maintenance mode first and coordinating control actions to manage primary system components.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If firmware updates are performed manually by human experts, then updates can be controlled and monitored, but system downtime increases and human errors may occur
Solution Approach 1:
The system performs firmware updates automatically without human intervention. The SCADA system receives update information from the FLM system, determines the update sequence based on device criticality and operational status, and executes updates autonomously, eliminating the need for human experts to manually perform updates while reducing system downtime
Solution Approach 2:
The system determines the update sequence in advance by analyzing device criticality levels and operational statuses before executing updates. This preliminary planning ensures that critical devices are updated at appropriate times while maintaining system functionality, thereby reducing unplanned downtime
2Productivity
If firmware updates are performed automatically without considering device criticality, then update speed increases, but system safety may be compromised
Solution Approach 1:
The system applies different update strategies to different devices based on their individual criticality levels and operational statuses. Critical devices are updated with higher priority and more careful timing, while non-critical devices can be updated more aggressively, ensuring system safety is maintained for important components while maximizing overall update speed
Solution Approach 2:
The update sequence is dynamically determined based on real-time device operational statuses and criticality assessments. The system continuously monitors device states and adjusts the update schedule accordingly, allowing flexible adaptation to changing system conditions while maintaining safety
3Productivity
If all devices are updated simultaneously, then update deployment is efficient, but system functionality may be disrupted
Solution Approach 1:
The system segments the device fleet into different groups based on criticality levels and operational statuses, creating an ordered update sequence. Devices are updated in batches rather than all at once, with critical devices updated at different times from non-critical devices, maintaining system functionality while achieving efficient deployment
Solution Approach 2:
The system implements periodic update cycles where devices are updated in successive batches according to their criticality levels. This periodic approach allows the system to maintain operational devices while progressively updating others, balancing deployment efficiency with functional continuity
4Reliability
If firmware updates are delayed to ensure system safety, then system stability is maintained, but cybersecurity risks increase
Solution Approach 1:
The system performs preliminary assessment of device criticality and operational status to determine the optimal update timing. By planning updates in advance based on system state analysis, the system can schedule updates during appropriate windows without unnecessary delays, reducing cybersecurity exposure while maintaining stability
Solution Approach 2:
The system continuously monitors device operational statuses and provides feedback to the update scheduling mechanism. This feedback loop allows the system to identify when devices can be safely updated, enabling timely security patch deployment while maintaining system stability through real-time condition assessment
Data Source
Figure 1
Figure 2~3
Figure 4~5
AI summary
To determine an update sequence for updating machine-readable data processed by devices (41-46) communicatively coupled to a Supervisory Control and Data Acquisition system (60), the Supervisory Control and Data Acquisition system (60) is operative to communicatively interface with a fleet management system (80).