Secure Controller Failover for High-Availability Industrial I/O
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
High availability industrial control systems face security vulnerabilities due to the lack of secure data transmission between input devices and controllers, particularly with multi-cast data packets that are susceptible to snooping and spoofing, limiting secure connections in complex industrial environments.
Innovation Solution
Establishing a secure connection between a primary and secondary industrial controller and input devices using authentication, data integrity verification, and encryption protocols, such as those under the Common Industrial Protocol (CIP) for EtherNet/IP devices, ensuring secure data transmission and seamless transfer of control in case of faults.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If multi-cast data packets are used for input signal transmission over the industrial network, then the amount of wiring is reduced and network communication is simplified, but security is compromised making data susceptible to snooping and spoofing
Solution Approach 1:
The patent applies preliminary action by establishing secure connections between the primary controller and input devices before the failover occurs. The connection data including security parameters is pre-configured and transmitted to the secondary controller in advance, so that when failover is needed, the secondary controller can immediately assume the secure connection without security degradation.
Solution Approach 2:
The patent uses connection data as an intermediary that carries security parameters between controllers and input devices. This connection data structure includes security parameters that enable the secondary controller to authenticate and establish secure connections with input devices, acting as a mediator that transfers security context during failover.
2Reliability
If redundant wiring is provided from input devices to each controller for high availability, then secure direct connections are maintained, but the amount of wiring and system complexity increases significantly
Solution Approach 1:
The patent applies copying by transmitting connection data from the primary controller to the secondary controller. Instead of physical redundant wiring, the connection information including security parameters is copied and stored in the secondary controller, allowing it to assume the connection role digitally without duplicating physical wiring infrastructure.
Solution Approach 2:
The patent makes the industrial network connection universal by enabling a single network connection to serve both primary and secondary controllers. The connection data structure is designed to be reusable, allowing the same connection parameters to be applied by either controller, eliminating the need for separate dedicated wiring for each controller.
3Productivity
If the secondary controller assumes control rapidly during failover, then system availability is maintained, but secure connection establishment may be compromised without proper authentication
Solution Approach 1:
The patent applies preliminary action by pre-transmitting connection data including security parameters to the secondary controller before failover occurs. This allows the secondary controller to have authentication credentials ready in advance, enabling rapid assumption of control without sacrificing security during the failover process.
Solution Approach 2:
The patent implements dynamic connection assumption where the secondary controller can transition from standby to active role with pre-configured security parameters. The connection data structure allows dynamic updating of controller identity while maintaining security, enabling the system to adapt quickly to failover conditions without re-establishing secure connections from scratch.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Secure data transmission between an input device and both industrial controllers in a high-availability system utilizes a secure connection established between the primary industrial controller and the input device. Data required to establish the secure connection is stored on the primary controller as part of the connection data corresponding to the secure connection. The input device transmits data to the primary controller over the secure connection according to the desired level of security. The primary controller transmits the connection data defining the secure connection to the secondary controller. If a failure occurs in the primary controller, the secondary controller establishes a connection to the input device using the connection data for the secure connection, such that the secondary controller may assume responsibility for the controller end of the secure connection. The primary controller transmits the input signals to the secondary controller via the dedicated connection between controllers.