Secure Controller Failover for High-Availability Industrial I/O

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

High availability industrial control systems face security vulnerabilities due to the lack of secure data transmission between input devices and controllers, particularly with multi-cast data packets that are susceptible to snooping and spoofing, limiting secure connections in complex industrial environments.

Innovation Solution

Establishing a secure connection between a primary and secondary industrial controller and input devices using authentication, data integrity verification, and encryption protocols, such as those under the Common Industrial Protocol (CIP) for EtherNet/IP devices, ensuring secure data transmission and seamless transfer of control in case of faults.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If multi-cast data packets are used for input signal transmission over the industrial network, then the amount of wiring is reduced and network communication is simplified, but security is compromised making data susceptible to snooping and spoofing

Engineering Contradiction:
Improvewiring complexityVSAvoiddata security
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent applies preliminary action by establishing secure connections between the primary controller and input devices before the failover occurs. The connection data including security parameters is pre-configured and transmitted to the secondary controller in advance, so that when failover is needed, the secondary controller can immediately assume the secure connection without security degradation.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses connection data as an intermediary that carries security parameters between controllers and input devices. This connection data structure includes security parameters that enable the secondary controller to authenticate and establish secure connections with input devices, acting as a mediator that transfers security context during failover.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If redundant wiring is provided from input devices to each controller for high availability, then secure direct connections are maintained, but the amount of wiring and system complexity increases significantly

Engineering Contradiction:
Improveconnection availabilityVSAvoidwiring complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies copying by transmitting connection data from the primary controller to the secondary controller. Instead of physical redundant wiring, the connection information including security parameters is copied and stored in the secondary controller, allowing it to assume the connection role digitally without duplicating physical wiring infrastructure.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent makes the industrial network connection universal by enabling a single network connection to serve both primary and secondary controllers. The connection data structure is designed to be reusable, allowing the same connection parameters to be applied by either controller, eliminating the need for separate dedicated wiring for each controller.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Productivity

If the secondary controller assumes control rapidly during failover, then system availability is maintained, but secure connection establishment may be compromised without proper authentication

Engineering Contradiction:
Improvefailover speedVSAvoidconnection security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent applies preliminary action by pre-transmitting connection data including security parameters to the secondary controller before failover occurs. This allows the secondary controller to have authentication credentials ready in advance, enabling rapid assumption of control without sacrificing security during the failover process.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements dynamic connection assumption where the secondary controller can transition from standby to active role with pre-configured security parameters. The connection data structure allows dynamic updating of controller identity while maintaining security, enabling the system to adapt quickly to failover conditions without re-establishing secure connections from scratch.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentEP3979078B1System and method for secure connections in a high availability industrial controller
Publication Date: 2024.01.17 ROCKWELL AUTOMATION TECH INC
  • EP3979078B1 patent drawingFigure 1
  • EP3979078B1 patent drawingFigure 2
  • EP3979078B1 patent drawingFigure 3

AI summary

Secure data transmission between an input device and both industrial controllers in a high-availability system utilizes a secure connection established between the primary industrial controller and the input device. Data required to establish the secure connection is stored on the primary controller as part of the connection data corresponding to the secure connection. The input device transmits data to the primary controller over the secure connection according to the desired level of security. The primary controller transmits the connection data defining the secure connection to the secondary controller. If a failure occurs in the primary controller, the secondary controller establishes a connection to the input device using the connection data for the secure connection, such that the secondary controller may assume responsibility for the controller end of the secure connection. The primary controller transmits the input signals to the secondary controller via the dedicated connection between controllers.