Serverless Container Orchestration for OT Control Systems

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Industrial control systems in OT environments lack efficient management and orchestration capabilities similar to those in IT environments, limiting the ability of container orchestration systems to access and manage OT assets for provisioning, deployment, and lifecycle operations.

Innovation Solution

Integration of specialized hardware and software control systems within OT environments that operate as worker or proxy nodes within the container orchestration system, enabling communication and coordination between IT-based container orchestration systems and OT-based industrial control systems, allowing for the management of OT assets through APIs and bi-directional data sharing.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If container orchestration systems are integrated into OT environments, then management and orchestration capabilities are improved, but device complexity increases

Engineering Contradiction:
Improvemanagement and orchestration capabilitiesVSAvoidsystem complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent introduces control systems as intermediary components that bridge IT-based container orchestration systems and OT-based industrial control systems. These control systems include software containers that can be orchestrated by Kubernetes while maintaining compatibility with OT devices, thus enabling advanced management capabilities without directly complicating the OT environment.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system is segmented into distinct layers: the container orchestration layer (Kubernetes), the control system layer (with software containers), and the OT device layer. This segmentation allows each layer to operate independently with well-defined interfaces, improving manageability while containing complexity within specific layers rather than propagating it throughout the entire system.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If specialized control systems are added to enable communication between IT and OT environments, then adaptability is improved, but device complexity increases

Engineering Contradiction:
Improvecommunication capability between IT and OTVSAvoidnumber of control systems
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The control systems are designed with multi-functionality to perform multiple roles: they act as worker nodes in the Kubernetes cluster, serve as proxies for OT device communication, and provide interfaces for both IT and OT protocols. This universality reduces the need for separate specialized components for each function, thereby improving adaptability while limiting the increase in overall system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Productivity

If container orchestration systems manage OT assets, then productivity is improved, but reliability requirements increase

Engineering Contradiction:
Improveautomation of provisioning and deploymentVSAvoidcontinuous operation requirement
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system implements proactive health monitoring and failover procedures that prepare backup control systems in advance. When a control system managing OT assets fails, pre-configured backup systems can take over automatically, cushioning against the impact of failures and ensuring continuous operation while maintaining high productivity through automated management.

Inventive Principle:
Principle #11Beforehand cushioning (Prior cushioning)

Solution Approach 2:

The container orchestration system implements continuous feedback mechanisms through health monitoring of controlled OT assets. This feedback enables the system to detect issues early, adjust operations accordingly, and trigger failover procedures when necessary, thereby maintaining both high productivity and reliability through closed-loop control.

Inventive Principle:
Principle #23Feedback

Data Source

PatentEP3971717B1Implementing serverless functions using container orchestration systems and operational technology devices
Publication Date: 2024.08.28 ROCKWELL AUTOMATION TECH INC
  • EP3971717B1 patent drawingFigure 1
  • EP3971717B1 patent drawingFigure 2~3
  • EP3971717B1 patent drawingFigure 4

AI summary

A method may include receiving, via a first computing node of a cluster of computing nodes in a container orchestration system, a pod from a second computing node in the cluster of computing nodes. The method may also include retrieving an image file comprising one or more containers from a registry, such that the pod may include an indication of a location of the image file in the registry. The one or more containers may include one or more pre-analytic operations for a control system of a plurality of control systems to perform. The method may then involve generating a package based on the one or more containers and storing the package in a filesystem shared with the control system.