Security Services for Software-Defined Process Control Containers
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current industrial process control systems are inflexible and hardware-centric, leading to high initial engineering costs, change management complexity, and supply-chain delays due to dependence on purpose-built hardware, and lack the flexibility seen in modern IT systems.
Innovation Solution
A software-defined process control system (SDCS) decouples software and hardware, utilizing a hyper-converged infrastructure with a software-defined networking, application, and storage layer to dynamically manage resources and support dynamic process control demands, employing containers and orchestrators for load balancing and fault tolerance, and includes security and discovery services for secure and efficient operation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If purpose-built hardware is used in traditional process control systems, then system reliability is improved, but device complexity and initial engineering costs increase
Solution Approach 1:
The patent segments the process control system into virtualized functional modules (process control functions, I/O functions, networking functions) that can be independently deployed and managed as separate software components on standardized hardware platforms, reducing overall system complexity while maintaining reliability through modular design
Solution Approach 2:
The patent implements universal standardized hardware platforms that can host multiple different process control functions and applications through software virtualization, allowing a single hardware infrastructure to serve multiple control purposes and reducing the need for dedicated purpose-built hardware for each function
2Stability of the object's composition
If purpose-built hardware is used in traditional process control systems, then system stability is improved, but adaptability and flexibility worsen
Solution Approach 1:
The patent introduces dynamic software-defined configurations that allow process control systems to be reconfigured and adapted to different process requirements through software updates and virtual machine migration, enabling the system to dynamically adjust its behavior and functionality without changing the underlying hardware infrastructure
Solution Approach 2:
The patent uses virtualization to create software copies of control functions and processes that can be replicated, migrated, and distributed across multiple physical hosts, allowing flexible deployment and easy adaptation while maintaining consistent system behavior through virtualized abstractions
3Reliability
If traditional hardware-centric architecture is used, then system reliability is improved, but ease of manufacture and deployment worsens
Solution Approach 1:
The patent replaces traditional mechanical and hardware-based control architectures with software-defined virtualized systems, substituting physical hardware configurations with software-based virtual machines and virtual networks, thereby simplifying manufacturing and deployment while maintaining system reliability through virtualized abstractions
4Reliability
If dedicated hardware is used for each control function, then system reliability is improved, but productivity and response time worsen
Solution Approach 1:
The patent merges multiple dedicated hardware control functions into shared virtualized infrastructure, combining process control, I/O handling, and networking functions into integrated software modules that run on common hardware platforms, improving resource utilization and productivity while maintaining reliability through virtualization isolation
Data Source
AI summary
A software defined (SD) process control system (SDCS) includes a control container having contents which are executable during run-time of the process plant to control at least a portion of an industrial process. The SDCS also includes a security service associated with the control container and including contents which define one or more security conditions. The security service executes via a container on a compute node of the SDCS to control access to and/or data flow from the control container based on the contents of the security container.


