Deterministic trusted execution container through managed runtime language metadata
US-2022129542-A1 · Apr 28, 2022 · US
US12578706B2 · US · B2
| Field | Value |
|---|---|
| Publication number | US-12578706-B2 |
| Application number | US-202218053486-A |
| Country | US |
| Kind code | B2 |
| Filing date | Nov 8, 2022 |
| Priority date | Nov 12, 2021 |
| Publication date | Mar 17, 2026 |
| Grant date | Mar 17, 2026 |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
A control system includes multiple industrial devices each belonging to one or more communication domains of multiple communication domains set in the same industrial communication network such that industrial devices belonging to the same communication domain communicate with each other. One or more industrial devices of the industrial devices include processing circuitry that stores domain information indicating whether or not the one or more communication domains to which the one or more industrial devices belong is a secure domain in which secure communication is performed, performs security processing related to the secure communication when the domain information indicates the secure domain, and performs the secure communication based on the security processing.
Opening claim text (preview).
The invention claimed is: 1 . A control system, comprising: a plurality of industrial devices each belonging to at least one communication domain of a plurality of communication domains set in a same industrial communication network such that industrial devices belonging to a same communication domain communicate with each other, wherein a first industrial device of the plurality of industrial devices belongs to both a first communication domain and a second communication domain of the plurality of communication domains, and a second industrial device of the plurality of industrial devices belongs to the first communication domain and does not belong to the second communication domain of the plurality of communication domains, wherein at least one industrial device of the plurality of industrial devices includes processing circuitry configured to store domain information indicating whether or not the at least one communication domain to which the at least one industrial device belongs is a secure domain in which secure communication is performed, perform security processing related to the secure communication when the domain information indicates the secure domain, and perform the secure communication based on the security processing, and wherein the processing circuitry is configured to generate source data of data to be communicated independent of whether the data to be communicated is designated for communication in the secure domain. 2 . The control system according to claim 1 , wherein periodic communication is performed in each of the plurality of communication domains, and the processing circuitry is configured to periodically perform the secure communication. 3 . The control system according to claim 1 , wherein the second industrial device is controlled by the first industrial device, and each industrial device belonging to a secure domain includes the processing circuitry. 4 . The control system according to claim 1 , wherein all of the plurality of communication domains are secure domains. 5 . The control system according to claim 1 , wherein the plurality of communication domains includes a normal domain in which normal communication is performed. 6 . The control system according to claim 5 , wherein the processing circuitry is configured to perform the normal communication by transmitting data that has not been subjected to the security processing, when the domain information indicates the normal domain, and perform the secure communication by transmitting data that has been subjected to the security processing, when the domain information indicates the secure domain. 7 . The control system according to claim 5 , wherein the processing circuitry is configured to generate one set of data including both a first portion for the normal communication and a second portion for the secure communication as payloads, and perform the secure communication by transmitting the one set of data. 8 . The control system according to claim 5 , wherein the processing circuitry is configured to generate one set of data that does not include a portion for the normal communication as a payload and includes a portion for the secure communication as a payload, and perform the secure communication by transmitting the one set of data. 9 . The control system according to claim 1 , wherein the plurality of industrial devices includes a third industrial device belonging to the second communication domain and not to the first communication domain. 10 . The control system according to claim 1 , wherein the at least one industrial device belongs to multiple secure domains of the plurality of communication domains, and the processing circuitry is configured to, when an abnormality has occurred in one of the plurality of secure domains, restrict the secure communication in the secure domain in which the abnormality has occurred, and when the abnormality has occurred, restrict the secure communication in the secure domain in which the abnormality has not occurred. 11 . The control system according to claim 1 , wherein the at least one industrial device belongs to multiple secure domains of the plurality of communication domains, and the processing circuitry is configured to, when an abnormality has occurred in one of the plurality of secure domains, restrict the secure communication in the secure domain in which the abnormality has occurred, and continue the secure communication of the secure domain in which the abnormality has not occurred. 12 . The control system according to claim 1 , wherein the at least one industrial device belongs to multiple secure domains of the plurality of communication domains, and the processing circuitry is configured to receive a selection regarding whether or not to restrict the secure communication of the secure domain in which no abnormality has occurred and which is of the plurality of secure domains, when an abnormality has occurred in one of the plurality of secure domains, restrict the secure communication in the secure domain in which the abnormality has occurred, and when an abnormality has occurred and there is a selection to restrict secure communication in a secure domain in which no abnormality has occurred, restrict the secure communication in the secure domain in which no abnormality has occurred. 13 . The control system according to claim 1 , wherein the processing circuitry is configured to generate one set of data that includes a plurality of portions for secure communication as payloads and in which individual error detection codes are respectively set for the plurality of portions, and perform the secure communication by transmitting the one set of data. 14 . The control system according to claim 1 , wherein the first industrial device of the plurality of industrial devices is configured to communicate in either the first communication domain or the second communication domain of the plurality of communication domains after the processing circuitry generates the source data of data to be communicated. 15 . An industrial device, comprising: processing circuitry configured to perform security processing related to secure communication when domain information indicates a secure domain in which the secure communication is performed, and perform the secure communication based on the security processing, wherein the industrial device is one of a plurality of industrial devices each belonging to at least one communication domain of a plurality of communication domains set in a same industrial communication network such that industrial devices belonging to a same communication domain communicate with each other, a first industrial device of the plurality of industrial devices belongs to both a first communication domain and a second communication domain of the plurality of communication domains, a second industrial device of the plurality of industrial devices belongs to the first communication domain and does not belong to the second communication domain of the plurality of communication domains, and the domain information indicates whether or not the at least one communication domain to which the industrial device belongs is the secure domain, and wherein the processing circuitry is configured to generate source data of data to be communicated independent of whether the data to be communicated is designated for communication in the secure domain. 16 . A method for controlling an industrial device, comprising: generating source data of data to be communicated independent of whether the data to be communicated is designated for communication in a secure
Configure parameters of controlled devices · CPC title
characterised by the network communication · CPC title
for separating internal from external traffic, e.g. firewalls · CPC title
characterised by program execution, i.e. part program or machine function execution, e.g. selection of a program · CPC title
electric · CPC title
Related publications grouped by family.
Answers are generated from the same data shown on this page.