Virtualized Compute Fabric for Secure Industrial Control Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current industrial control systems face challenges in achieving desired security levels due to complex infrastructure requirements and incompatibilities between operational technology (OT) and information technology (IT) networks, leading to insecure data transfer practices and increased latency when integrating cloud-based components, which complicates security and communication within the Purdue model.

Innovation Solution

A new process control and automation system architecture that implements a shared, virtualized compute fabric, allowing for robust and secure communication between physical devices and IT infrastructure, bypassing traditional Purdue model constraints by using containerized components and virtual private networks to manage and secure data transfer across different levels of the system.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional Purdue model architecture is used to integrate OT and IT networks, then security infrastructure is established, but device complexity and latency increase

Engineering Contradiction:
ImprovesecurityVSAvoidinfrastructure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a cloud-based data highway as an intermediary layer between OT and IT networks. This data highway uses standardized protocols (OPC UA, MQTT, AMQP) to enable secure communication without requiring complex traditional security infrastructure like firewalls and DMZs. The intermediary translates and secures data transfers, reducing overall system complexity while maintaining security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces the mechanical/physical security infrastructure (firewalls, routers, dedicated security devices) with software-based security mechanisms implemented in the cloud. Security functions are virtualized and delivered as services, eliminating the need for cumbersome physical security infrastructure while maintaining or improving security effectiveness.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Adaptability or versatility

If cloud-based components are integrated into traditional control systems, then computing flexibility improves, but security management complexity and latency increase

Engineering Contradiction:
Improvecomputing flexibilityVSAvoidlatency
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The patent pre-configures cloud-based data highways with established communication protocols and security mechanisms before integration. Standardized templates for OPC UA, MQTT, and AMQP connections are prepared in advance, allowing rapid deployment without ad-hoc configuration. This preliminary preparation reduces integration latency and simplifies the connection process between cloud services and control systems.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent changes the fundamental parameters of cloud integration by using lightweight, standardized protocols instead of traditional heavy protocols. This enables faster data transmission and reduces latency. The cloud-based architecture allows dynamic parameter adjustment without physical reconfiguration, improving flexibility while maintaining real-time performance.

Inventive Principle:
Principle #35Parameter changes

3Adaptability or versatility

If cloud-based components are integrated into traditional control systems, then computing flexibility improves, but security infrastructure requirements increase

Engineering Contradiction:
Improvecomputing flexibilityVSAvoidsecurity infrastructure
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent merges security functions with cloud-based data highway services. Instead of separate security infrastructure, security is integrated into the cloud platform itself through identity management, authentication, and encryption services. This consolidation reduces the number of separate security components needed while providing comprehensive security coverage for cloud-integrated systems.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The cloud-based data highway provides universal security mechanisms that work across multiple protocols and platforms. A single security infrastructure in the cloud protects communications regardless of whether OPC UA, MQTT, or AMQP is used. This multi-functional approach eliminates the need for protocol-specific security configurations and reduces overall infrastructure complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20240027980A1Monitoring and Operational Functionalities for an Enterprise Using Process Control or Automation System
Publication Date: 2024.01.25 FISHER ROSEMOUNT SYST INC
  • US20240027980A1 patent drawing
  • US20240027980A1 patent drawing
  • US20240027980A1 patent drawing

AI summary

A process plant and industrial control system architecture includes a generalized compute fabric that is agnostic or indifferent to the physical location at which the compute fabric is implemented, includes one or more physical control or field devices located at one or more specific sites at which a product or process is being manufactured and further includes a transport network that securely provides communications between the compute fabric and the pool of physical devices. The compute fabric includes an application layer that includes configured containers or containerized software modules that perform various control, monitoring and configuration activities with respect to one or more devices, control strategies and control loops, sites, plants, or facilities at which control is performed, and includes a physical layer including computer processing and data storage equipment that can be located at any desired location, including at or near a site, plant, or facility at which control is being performed, at a dedicated location away from the location at which control is being performed, in re-assignable computer equipment provided in the cloud, or any combination thereof. This control architecture enables significant amounts of both computer processing and IT infrastructure that is used to support a process plant, an industrial control facility or other automation facility to be implemented in a shared, in an offsite and/or in a virtualized manner that alleviates many of the communications and security issues present in current process and industrial control systems that attempt to implement control with shared or virtualized computing resources set up according to the well-known Purdue model.The industrial control system architecture is protected via more secure and customizable techniques as compared to those used in Purdue model-based control systems. For example, communications between any (and in some cases, all) endpoints of the system may be protected via one or more virtual private networks to which authenticated endpoints must be authorized to access. Endpoints may include, for example, containerized components, physical components, devices, sites or locations, the compute fabric, and the like, and the VPNs may include mutually-exclusive and/or nested VPNs. External applications and services, whether automated or executing under the purview of a person, may access information and services provided by the system via only APIs, and different sets of APIs may be exposed to different users that have been authenticated and authorized to access respective sets of APIs.A configuration system operates within the compute fabric to enable a user to easily make configuration changes to the compute fabric as the user does not generally need to specify the computer hardware within the compute fabric to use to make the configuration changes, making it possible for the user to deploy new configuration elements with simple programming steps, and in some cases with the push of a button.