Secure Communication Logging in Factory Control Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current control devices in factory automation only monitor data communicated with instruments connected to a network and store it in a ring buffer, failing to provide a configuration for logging information related to communication security and control of the logging operation.
Innovation Solution
A control device with a storage medium interface for detachable external storage, featuring separate logging units for secure communication and logging operation control, which logs secure communication information on an external storage medium and control logging operation information on a different storage medium, allowing for secure communication logging and logging operation control without interrupting the control process.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If separate logging units are introduced for secure communication and logging operation control, then logging completeness and security are improved, but device complexity increases
Solution Approach 1:
The patent divides the logging function into separate logging units: a first logging unit for secure communication information and a second logging unit for logging operation control information. This segmentation allows each unit to specialize in specific logging tasks, improving logging completeness and security while maintaining manageable complexity through modular design.
Solution Approach 2:
The patent introduces an analysis unit that receives and analyzes logging information from both logging units. This intermediary component coordinates the outputs of the separate logging units, integrating their functions without requiring direct complex interactions between the logging units themselves, thus managing system complexity.
2Quantity of substance
If external storage medium is used for secure communication logging, then logging capacity and flexibility are improved, but reliability depends on external medium availability
Solution Approach 1:
The patent combines internal storage (within the control device) and external storage medium into a unified logging system. The first logging unit stores secure communication information in the external storage medium when available, while the second logging unit stores logging operation control information in internal storage, ensuring continuous operation regardless of external medium availability.
3Measurement precision
If comprehensive logging of secure communication is performed, then security analysis capability is improved, but data privacy and security may be compromised
Solution Approach 1:
The patent extracts only the necessary logging information related to secure communication from the actual communication data. The first logging unit logs information about the secure communication without storing the actual encrypted communication content, thereby maintaining security while enabling sufficient analysis capability.
Solution Approach 2:
The patent applies different logging qualities to different types of information: the first logging unit uses a logging quality suitable for secure communication (logging metadata and status without sensitive content), while the second logging unit uses detailed logging for operation control. This localized quality approach balances analysis needs with security requirements.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A control device performs logging of information related to communication with an instrument and logging of information related to control of the logging operation. The control device (100) includes: a first connector (135)that connects a first network to which a control target belongs; a second connector (145) that connects a second network to which an external instrument belongs; a control arithmetic unit (60) that executes control arithmetic processing using data (70) related to the control target; a communication unit (172, 177) that exchanges the data with the external instrument by secure communication through the second network; a first logging unit (118) that logs information (151) related to the secure communication performed by the communication unit; and a second logging unit (119) that logs information (152) related to control of a logging operation of the first logging section.