SCADA Update Sequencing by Device Criticality and Maintenance Mode

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current firmware update processes in SCADA systems for critical infrastructure, such as electric power systems, often require human intervention, leading to potential errors, system downtime, and increased cybersecurity risks, and do not adequately consider the criticality and operational status of devices during updates.

Innovation Solution

A method and system where the SCADA system interacts with the FLM system to determine an optimal update sequence for devices based on criticality, operational status, and estimated update durations, ensuring that updates are performed without affecting system safety by placing non-critical devices in maintenance mode first and coordinating control actions to manage primary system components.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If firmware updates are performed manually by human experts, then updates can be controlled and monitored, but system downtime increases and human errors may occur

Engineering Contradiction:
Improveupdate control reliabilityVSAvoidsystem downtime
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs firmware updates automatically without human intervention. The SCADA system receives update information from the FLM system, determines the update sequence based on device criticality and operational status, and executes updates autonomously, eliminating the need for human experts to manually perform updates while reducing system downtime

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system determines the update sequence in advance by analyzing device criticality levels and operational statuses before executing updates. This preliminary planning ensures that critical devices are updated at appropriate times while maintaining system functionality, thereby reducing unplanned downtime

Inventive Principle:
Principle #10Preliminary action

2Productivity

If firmware updates are performed automatically without considering device criticality, then update speed increases, but system safety may be compromised

Engineering Contradiction:
Improveupdate speedVSAvoidsystem safety
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system applies different update strategies to different devices based on their individual criticality levels and operational statuses. Critical devices are updated with higher priority and more careful timing, while non-critical devices can be updated more aggressively, ensuring system safety is maintained for important components while maximizing overall update speed

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The update sequence is dynamically determined based on real-time device operational statuses and criticality assessments. The system continuously monitors device states and adjusts the update schedule accordingly, allowing flexible adaptation to changing system conditions while maintaining safety

Inventive Principle:
Principle #15Dynamics

3Productivity

If all devices are updated simultaneously, then update deployment is efficient, but system functionality may be disrupted

Engineering Contradiction:
Improveupdate deployment efficiencyVSAvoidsystem functionality
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system segments the device fleet into different groups based on criticality levels and operational statuses, creating an ordered update sequence. Devices are updated in batches rather than all at once, with critical devices updated at different times from non-critical devices, maintaining system functionality while achieving efficient deployment

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system implements periodic update cycles where devices are updated in successive batches according to their criticality levels. This periodic approach allows the system to maintain operational devices while progressively updating others, balancing deployment efficiency with functional continuity

Inventive Principle:
Principle #19Periodic action

4Reliability

If firmware updates are delayed to ensure system safety, then system stability is maintained, but cybersecurity risks increase

Engineering Contradiction:
Improvesystem stabilityVSAvoidcybersecurity risks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary assessment of device criticality and operational status to determine the optimal update timing. By planning updates in advance based on system state analysis, the system can schedule updates during appropriate windows without unnecessary delays, reducing cybersecurity exposure while maintaining stability

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system continuously monitors device operational statuses and provides feedback to the update scheduling mechanism. This feedback loop allows the system to identify when devices can be safely updated, enabling timely security patch deployment while maintaining system stability through real-time condition assessment

Inventive Principle:
Principle #23Feedback

Data Source

PatentEP4492224A1Method and systems for determining an update sequence of devices
Publication Date: 2025.01.15 HITACHI ENERGY LTD
  • EP4492224A1 patent drawingFigure 1
  • EP4492224A1 patent drawingFigure 2~3
  • EP4492224A1 patent drawingFigure 4~5

AI summary

To determine an update sequence for updating machine-readable data processed by devices (41-46) communicatively coupled to a Supervisory Control and Data Acquisition system (60), the Supervisory Control and Data Acquisition system (60) is operative to communicatively interface with a fleet management system (80).