SCU Patch Auditing for ICS Connectivity and Performance Deviations

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Industrial control systems face challenges in determining the success of firmware or software patches on supervisory control units (SCUs), as existing methods lack automation for checking connectivity and performance issues post-patch, leading to potential unintended consequences and manual verification limitations.

Innovation Solution

A system and method that captures pre-patch status information for SCUs and equipment, applies the patch, and then compares post-patch status information to generate an audit report, identifying any deviations and potentially taking corrective actions based on the comparison.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If manual checking methods are used to verify patch success, then the verification process can be performed, but the process is cumbersome and time-consuming with limited coverage

Engineering Contradiction:
Improvepatch verification accuracyVSAvoidverification time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs self-verification by automatically capturing pre-patch status information, applying the patch, capturing post-patch status information, and comparing the two states to detect any deviations. This automated self-service approach eliminates the need for manual verification while comprehensively checking all connected devices and system parameters.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system implements feedback by automatically comparing post-patch status information with pre-patch baseline data, generating verification results that provide feedback on patch success or failure. This feedback mechanism enables continuous monitoring and automatic detection of any unintended consequences from the patch.

Inventive Principle:
Principle #23Feedback

2Reliability

If comprehensive manual checking of all connected devices is performed, then complete system verification is achieved, but the complexity and time required increases significantly

Engineering Contradiction:
Improvesystem reliability after patchVSAvoidverification process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system automatically performs comprehensive verification by capturing status information from all connected devices before and after the patch, comparing the states, and generating verification reports without requiring manual intervention. This self-service approach achieves complete system verification while keeping the process simple and automated.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The verification system is designed to universally check all types of connected devices and system parameters through a single automated process. The system can verify connectivity, operational status, and performance metrics across diverse device types without requiring different verification procedures for each device category.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If firmware patches are applied to update software, then software bugs are fixed and performance is improved, but unintended consequences such as connectivity issues may occur

Engineering Contradiction:
Improvesoftware reliabilityVSAvoidunintended consequences from patch
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system takes preliminary anti-action by capturing the baseline status information of all connected devices before applying the patch. This pre-patch documentation serves as a reference to quickly identify and reverse any unintended consequences that may occur after the patch is applied, such as connectivity issues or device failures.

Inventive Principle:
Principle #9Preliminary anti-action

Solution Approach 2:

The system implements continuous feedback by monitoring system status after patch application and automatically comparing it with pre-patch baseline data. This feedback mechanism enables rapid detection of unintended consequences and triggers appropriate responses, such as generating alerts or rolling back the patch if critical issues are detected.

Inventive Principle:
Principle #23Feedback

4Productivity

If automated patch verification is implemented, then verification efficiency is improved and time is reduced, but system complexity increases

Engineering Contradiction:
Improvepatch verification efficiencyVSAvoidverification system complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The verification system achieves high productivity by implementing self-service automation that independently captures pre-patch and post-patch status information, performs comparisons, and generates verification reports without manual intervention. This automated approach dramatically improves verification efficiency while the modular design keeps system complexity manageable.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary actions by pre-configuring the status capture mechanisms and establishing baseline data before the patch is applied. This preliminary preparation enables the automated verification process to efficiently compare pre and post-patch states without requiring complex real-time analysis, thereby improving productivity while maintaining reasonable system complexity.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP4187372A1Method and apparatus for maintaining software of a control unit for an industrial control system
Publication Date: 2023.05.31 TRANE INTERNATIONAL INC
  • EP4187372A1 patent drawingFigure 1
  • EP4187372A1 patent drawingFigure 2
  • EP4187372A1 patent drawingFigure 3

AI summary

The present disclosure provides a method and apparatus for maintaining computer software of a supervisory control unit (SCU) of an industrial control system (ICS) configured to control equipment of a facility. The method includes capturing status information for the SCU and equipment that indicates at least performance of the SCU and the equipment, and connectivity of the SCU with the equipment. The method includes patching the computer software automatically to update, change, fix, or improve the computer software. The method includes capturing corresponding status information for the SCU and equipment and performing an audit of the ICS after the patch in which the status information and the corresponding status information are compared to identify any deviations in the performance or the connectivity of the equipment resulting from the patch. The method includes generating an audit report of the ICS that indicates any of the deviations that satisfy a reporting threshold.