Virtual Machine Management Layer for Heterogeneous Field Devices
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current industrial control systems fail to meet high isolation, security, and reliability requirements due to vulnerabilities in mainstream operating systems, leading to service interruptions and susceptibility to hacker attacks.
Innovation Solution
A heterogeneous field devices control management system based on an industrial internet operating system, featuring a virtual machine management layer with real-time and non-real-time virtual machines, which separates services by real-time requirements, provides customized operating environments, and includes security measures like blacklisting instructions to enhance isolation and security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If services are integrated into a mainstream operating system, then ease of operation and adaptability are improved, but security and reliability deteriorate due to vulnerability to attacks and lack of isolation
Solution Approach 1:
The patent divides the operating system into multiple isolated virtual machine environments (real-time VM and non-real-time VM) that run on the mainstream operating system. This segmentation allows services to benefit from the ease of operation of the mainstream OS while maintaining isolation boundaries that prevent attacks or failures in one VM from affecting others, thus resolving the contradiction between ease of operation and reliability.
2Adaptability or versatility
If services are integrated into a mainstream operating system, then adaptability is improved, but security deteriorates due to susceptibility to hacker attacks
Solution Approach 1:
The patent introduces virtual machine environments as intermediary layers between the mainstream operating system and the control services. These VMs act as isolated execution environments that maintain security boundaries, allowing services to adapt to the mainstream OS ecosystem while preventing direct exposure to security threats, thus resolving the contradiction between adaptability and security.
3Adaptability or versatility
If system upgrades or service modifications are performed, then functionality is improved, but reliability deteriorates due to potential system-wide interruptions
Solution Approach 1:
The patent segments services into isolated virtual machine environments, allowing upgrades and modifications to be performed in one VM without affecting other VMs. This segmentation enables functional improvements while maintaining system reliability, as failures or interruptions in one isolated environment do not propagate to the entire system.
4Reliability
If virtualization is implemented to improve isolation and security, then reliability is improved, but device complexity increases
Solution Approach 1:
The patent implements a virtualization platform that provides multiple functions (isolation, security, resource management, scheduling) through a unified virtual machine infrastructure. This universal approach improves reliability while managing complexity by consolidating multiple protective and management functions into a single virtualization layer rather than requiring separate complex systems for each function.
Data Source
AI summary
Disclosed is a heterogeneous field devices control management system based on an industrial internet operating system. In order to solve the problems that it is difficult to add new heterogeneous field devices to an existing system, as well as that the system has low security and a real-time performance, on one hand, according to embodiments of the present disclosure, on the basis of the differences of real-time requirements of services operated by heterogeneous field devices, a real-time virtual machine processes a real-time service and a non-real-time virtual machine processes a non-real-time service, thus different operating environments could be customized for a real-time service and a non-real-time service, avoiding the situation that when a system upgrade is made for a non-real-time service or a non-real-time virtual service fails, a real-time service is also affected, service isolation is realized, and, stability and reliability of industrial field control are enhanced.

