Virtualized Control Configuration via VPN-Segmented Compute Fabric
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current industrial control systems face challenges in achieving desired security levels due to complex infrastructure requirements and incompatibilities between operational technology (OT) and information technology (IT) networks, leading to insecure data transfer practices and increased latency when integrating cloud-based components, especially when adhering to the Purdue model.
Innovation Solution
A new process control and automation system architecture that implements a shared, virtualized compute fabric, allowing for robust and secure communication between physical devices and IT infrastructure, bypassing traditional Purdue model constraints by using containerized components and virtual private networks (VPNs) for secure data transmission.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional Purdue model architecture is used for industrial control systems, then security infrastructure is established, but system complexity and latency increase when integrating cloud-based components
Solution Approach 1:
The patent introduces a VPN gateway as an intermediary component that enables secure cloud-based access without requiring full Purdue model infrastructure. The VPN gateway acts as a mediator between the control system and cloud services, providing encryption and secure communication channels while simplifying the overall architecture and reducing latency compared to traditional multi-layer security infrastructure.
2Adaptability or versatility
If cloud-based components are integrated into industrial control systems, then system functionality and resource management improve, but security risks and latency increase due to OT-IT network incompatibilities
Solution Approach 1:
The patent segments the network architecture into distinct virtual private networks (VPNs) that separate control traffic from data traffic. This segmentation allows cloud-based components to access non-critical data and management functions while maintaining strict security boundaries around critical control operations. The segmented approach enables flexible resource management for cloud services without compromising the security and reliability of the core control system.
3Adaptability or versatility
If data is transferred between OT and IT networks, then system integration and data sharing improve, but security vulnerabilities and latency increase
Solution Approach 1:
The patent employs VPN gateways as intermediary devices that establish encrypted tunnels for data transfer between OT and IT networks. These gateways process and route data packets through secure channels, enabling comprehensive data sharing between operational technology and information technology systems while maintaining security protocols and minimizing latency through optimized routing and encryption handling.
Data Source
AI summary
A process plant and industrial control system architecture includes a generalized compute fabric that is agnostic or indifferent to the physical location at which the compute fabric is implemented, includes one or more physical control or field devices located at one or more specific sites at which a product or process is being manufactured and further includes a transport network that securely provides communications between the compute fabric and the pool of physical devices. A configuration system operates within the compute fabric to enable a user to easily make configuration changes to the software executing in the compute fabric by accessing and downloading new components for execution in the compute fabric from a centralized registry. The configuration system may provide feedback regarding the operation of the new component to a component developer to enable the developer to test and alter the component. The configuration system makes it possible for a user to deploy new configuration elements with simple programming steps, and in some cases with the push of a button.


