Securing SCADA network access from a remote terminal unit

US10134207B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-10134207-B2
Application numberUS-201715492744-A
CountryUS
Kind codeB2
Filing dateApr 20, 2017
Priority dateApr 20, 2017
Publication dateNov 20, 2018
Grant dateNov 20, 2018

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

A first message from a remote terminal unit (RTU) is received, where the first message indicates that a motion has been detected. In response to receiving the first message, a timer is started at a supervisory control and data acquisition (SCADA) server. Whether a personal identification number (PIN) verification and a radio-frequency identification (RFID) verification have succeeded is determined before the timer expires. In response to determining that at least one of the PIN verification or the RFID verification fails, a communication port connecting the RTU with the SCADA server is disabled.

First claim

Opening claim text (preview).

What is claimed is: 1. A computer-implemented method, comprising: receiving, a first message from a remote terminal unit (RTU), wherein the first message indicates that a motion has been detected; in response to receiving the first message, starting a timer at a supervisory control and data acquisition (SCADA) server; determining whether a personal identification number (PIN) verification and a radio-frequency identification (RFID) verification with respect to the RTU have succeeded before the timer expires; and in response to determining that at least one of the PIN verification or the RFID verification fails, disabling a communication port connecting the RTU with the SCADA server. 2. The method of claim 1 , further comprising, in response to determining that at least one of the PIN verification or the RFID verification fails, transmitting a second message to the RTU, wherein the second message initiates a recording of video images by a camera. 3. The method of claim 2 , wherein the camera includes infra-red (IR) night vision capabilities. 4. The method of claim 1 , wherein the RTU performs a control operation of a field instrument while the communication port is disabled, and the control operation includes at least one of a valve control operation, an instrument reading operation, an abnormal operating condition detection operation, a data processing operation, or an operating condition control operation. 5. The method of claim 2 , further comprising: receiving, a third message from a remote terminal unit (RTU), wherein the third message indicates that another motion has been detected; in response to receiving the third message, starting a second timer; determining whether a second personal identification number (PIN) verification and a second radio-frequency identification (RFID) verification with respect to the RTU have succeeded before the second timer expires; and in response to determining that the second PIN verification and the second RFID verification have succeeded, initiating a logging procedure at the SCADA server. 6. The method of claim 1 , wherein the first message is formatted according to an 802.1x standard. 7. The method of claim 1 , wherein the first message is encrypted by the RTU. 8. A supervisory control and data acquisition (SCADA) server, comprising: a memory; and at least one hardware processor communicatively coupled with the memory and configured to: receive, a first message from a remote terminal unit (RTU), wherein the first message indicates that a motion has been detected; in response to receive the first message, start a timer at the supervisory control and data acquisition (SCADA) server; determine whether a personal identification number (PIN) verification and a radio-frequency identification (RFID) verification have succeeded before the timer expires; and in response to determining that at least one of the PIN verification or the RFID verification fails, disable a communication port connecting the RTU with the SCADA server. 9. The SCADA server of claim 8 , further comprising: an interface configured to receive RFID information and a PIN input from the RTU, wherein the at least one hardware processor is configured to: determine whether the PIN verification has succeeded based on PIN input; and determine whether the RFID verification has succeeded based on the RFID information. 10. The SCADA server of claim 8 , wherein the at least one hardware processor is further configured, in response to determining that at least one of the PIN verification or the RFID verification fails, to transmit a second message to the RTU, wherein the second message initiates a recording of video images by a camera. 11. The SCADA server of claim 10 , wherein the camera includes infra-red (IR) night vision capabilities. 12. The SCADA server of claim 8 , wherein the RTU performs a control operation of a field instrument while the communication port is disabled, and the control operation includes at least one of a valve control operation, an instrument reading operation, an abnormal operating condition detection operation, a data processing operation, or an operating condition control operation. 13. The SCADA server of claim 10 , wherein the at least one hardware processor is further configured to: receive, a third message from a remote terminal unit (RTU), wherein the third message indicates that another motion has been detected; in response to receiving the third message, start a second timer; determine whether a second personal identification number (PIN) verification and a second radio-frequency identification (RFID) verification have succeeded before the second timer expires; and in response to determining that the second PIN verification and the second RFID verification have succeeded, initiate a logging procedure at the SCADA server. 14. The SCADA server of claim 8 , wherein the first message is formatted according to an 802.1x standard. 15. The SCADA server of claim 8 , wherein the first message is encrypted by the RTU. 16. A non-transitory, computer-readable medium storing one or more instructions executable by a computer system to perform operations comprising: receiving, a first message from a remote terminal unit (RTU), wherein the first message indicates that a motion has been detected; in response to receiving the first message, starting a timer at a supervisory control and data acquisition (SCADA) server; determining whether a personal identification number (PIN) verification and a radio-frequency identification (RFID) verification with respect to the RTU have succeeded before the timer expires; and in response to determining that at least one of the PIN verification or the RFID verification fails, disabling a communication port connecting the RTU with the SCADA server. 17. The non-transitory, computer-readable medium of claim 16 , the operations further comprising, in response to determining that at least one of the PIN verification or the RFID verification fails, transmitting a second message to the RTU, wherein the second message initiates a recording of video images by a camera. 18. The non-transitory, computer-readable medium of claim 16 , wherein the RTU performs a control operation of a field instrument while the communication port is disabled, and the control operation includes at least one of a valve control operation, an instrument reading operation, an abnormal operating condition detection operation, a data processing operation, or an operating condition control operation. 19. The non-transitory, computer-readable medium of claim 17 , the operations further comprising: receiving, a third message from a remote terminal unit (RTU), wherein the third message indicates that another motion has been detected; in response to receiving the third message, starting a second timer; determining whether a second personal identification number (PIN) verification and a second radio-frequency identification (RFID) verification have succeeded before the second timer expires; and in response to determining that the second PIN verification and the second RFID verification have succeeded, initiating a logging procedure at the SCADA server. 20. The non-transitory, computer-readable medium of claim 16 , wherein the first message is formatted according to an 802.1x standard.

Assignees

Inventors

Classifications

  • using communication transmission lines {(G08B13/19658, G08B21/0286, G08B25/016 take precedence)} · CPC title

  • G06F21/34Primary

    involving the use of external additional devices, e.g. dongles or smart cards · CPC title

  • Self-organising networks, e.g. ad-hoc networks or sensor networks · CPC title

  • with motion detection · CPC title

  • Scada supervisory control and data acquisition · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US10134207B2 cover?
A first message from a remote terminal unit (RTU) is received, where the first message indicates that a motion has been detected. In response to receiving the first message, a timer is started at a supervisory control and data acquisition (SCADA) server. Whether a personal identification number (PIN) verification and a radio-frequency identification (RFID) verification have succeeded is determi…
Who is the assignee on this patent?
Saudi Arabian Oil Co
What technology area does this patent fall under?
Primary CPC classification G06F21/34. Mapped technology areas include Physics.
When was this patent published?
Publication date Tue Nov 20 2018 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 2 related publications on this page (citations in our corpus or others sharing the same primary CPC).