Visual Data Bridge for Secure Cogen-DCS Integration
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The integration of Cogeneration (Cogen) systems and Manufacturing Operations Management (MOM) systems with Distributed Controls Systems (DCS) faces challenges in secure data transfer and cybersecurity, particularly due to the need for legacy network connections and potential vulnerabilities to hacking and malware spread.
Innovation Solution
A method and system that utilize a multi-port risk calculation engine to dynamically assess risk levels, controlling data transfer through visual recognition on an image display and capturing device, ensuring secure integration by powering off data transfer when risk levels are high and maintaining a 100% physical air gap between systems, thus enhancing security, reliability, and availability.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If legacy network connections are used to integrate Cogen and MOM systems with DCS, then data transfer capability is improved, but cybersecurity vulnerability increases
Solution Approach 1:
The patent introduces an image display and capturing device as an intermediary component between the DCS and third-party systems. Data is transmitted from the DCS to the image display device, captured via imaging, and then processed by the receiving system. This intermediary physical layer breaks direct network connections while enabling data transfer, thus resolving the contradiction between connectivity and security.
Solution Approach 2:
The patent replaces traditional electronic/network data transmission mechanisms with a physical imaging and optical recognition system. Instead of direct digital communication through vulnerable network connections, data is converted to visual display, captured through imaging devices, and reconstructed digitally on the receiving end. This substitution eliminates network-based attack vectors while maintaining data transfer functionality.
2Adaptability or versatility
If direct network integration is implemented between Cogen/MOM systems and DCS, then system interoperability is improved, but risk of hacking and malware spread increases
Solution Approach 1:
The image display and capturing device serves as a security intermediary that physically isolates the DCS from third-party systems while enabling controlled data exchange. The device allows necessary data transfer for interoperability (process values, blending recipes) while blocking malicious communications, thus achieving both adaptability and reliability.
Solution Approach 2:
The patent segments the data transfer process into distinct physical and logical layers: (1) DCS outputs data to image display, (2) imaging device captures display, (3) receiving system processes captured images. This segmentation creates security boundaries that maintain interoperability while preventing direct exposure of the DCS to external threats.
3Speed
If session-based network connections are used for data transfer, then real-time data exchange is improved, but cybersecurity attack surface increases
Solution Approach 1:
The patent replaces session-based network protocols with a display-capture-reconstruct workflow. Data flows from DCS display through optical imaging to receiving system reconstruction, eliminating the need for persistent network sessions, authentication handshakes, and protocol negotiations that create attack surfaces. The physical imaging process inherently provides session isolation.
Solution Approach 2:
The system creates visual copies of data for transmission instead of transmitting digital data directly. The DCS displays data that is then optically copied by the imaging device, and the receiving system reconstructs the data from these visual copies. This copying mechanism enables real-time data exchange without establishing vulnerable digital communication channels.
Data Source
AI summary
The present disclosure describes methods and systems for integrating third party automation systems. One computer-implemented method includes calculating, by at least one of a first device and a second device, a risk level, and controlling, by the at least one of the first device and the second device, a switch based on the risk level. If the risk level is less than a predetermined value, the switch is controlled to power on an image display and capturing device. Data is displayed by the first device and received by the second device through visual recognition on the image display and capturing device. If the risk level is not less than the predetermined value, the switch is controlled to power off the image display and capturing device. Data transfer from the first device to the second device through visual recognition on the image display and capturing device is stopped.


