Security and safety of an industrial operation using opportunistic sensing

US2023078632A1 · US · A1

Patent metadata
FieldValue
Publication numberUS-2023078632-A1
Application numberUS-202117471783-A
CountryUS
Kind codeA1
Filing dateSep 10, 2021
Priority dateSep 10, 2021
Publication dateMar 16, 2023
Grant date

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

A method for security and safety of an industrial operation includes receiving sensor information from a plurality of sensors of an industrial operation. Sensor information from at least a portion of the plurality sensors is used for functionality of a plurality of components of the industrial operation. The method includes monitoring data traffic of the industrial operation, and deriving a baseline signature from the sensor information. The baseline signature encompasses a range of normal operating conditions. The method includes identifying an abnormal operating condition of the industrial operation based on a comparison between additional sensor information from the plurality of sensors and the baseline signature and identifying an abnormal data traffic condition. The method includes determining that the abnormal operating condition correlates to the abnormal data traffic condition, and sending a security alert in response to determining that the abnormal operating condition correlates to the abnormal data traffic condition.

First claim

Opening claim text (preview).

What is claimed is: 1 . A method comprising: receiving sensor information from a plurality of sensors of an industrial operation, sensor information from at least a portion of the plurality sensors is used for functionality of a plurality of components of the industrial operation; monitoring data traffic of the industrial operation; deriving a baseline signature from the sensor information, the baseline signature encompassing a range of normal operating conditions; identifying an abnormal operating condition of the industrial operation based on a comparison between additional sensor information from the plurality of sensors and the baseline signature; identifying an abnormal data traffic condition; determining that the abnormal operating condition correlates to the abnormal data traffic condition; and sending a security alert in response to determining that the abnormal operating condition correlates to the abnormal data traffic condition. 2 . The method of claim 1 , wherein the abnormal data traffic condition comprises a change in data traffic beyond a data traffic threshold and determining that the abnormal operating condition correlates to the abnormal data traffic condition comprises correlating timing of the abnormal data traffic condition with the abnormal operating condition. 3 . The method of claim 2 , wherein the change in data traffic is from a source external to the industrial operation. 4 . The method of claim 2 , wherein the change in data traffic is from a node added to the industrial operation for data access within a threshold amount of time prior to the abnormal operating condition. 5 . The method of claim 1 , wherein identifying the abnormal data traffic condition and determining that the abnormal operating condition correlates to the abnormal data traffic condition comprises determining that one or more firmware updates to one or more components of the industrial operation occurred prior to the abnormal operating condition and the one or more firmware updates are correlated in time with the abnormal operating condition. 6 . The method of claim 5 , wherein the one or more firmware updates were installed from an external node accessing equipment of the industrial operation. 7 . The method of claim 1 , further comprising receiving commands used to control the industrial operation, wherein the baseline signature comprises sensor information from the plurality of sensors for a normal operating condition correlated with commands related to the normal operating condition. 8 . The method of claim 7 , wherein monitoring the data traffic further comprises monitoring data sent to a display of operating parameters of the industrial operation and wherein identifying the abnormal data traffic condition and determining that the abnormal operating condition correlates to the abnormal data traffic condition comprise determining that the data sent to the display conflicts with sensor information of the identified abnormal operating condition. 9 . The method of claim 1 , wherein deriving the baseline signature comprises using a machine learning algorithm to derive the baseline signature. 10 . The method of claim 1 , wherein portions of the baseline signature are distributed among a plurality of devices in the industrial operation in a blockchain format and updates to the baseline signature are stored using a blockchain. 11 . The method of claim 1 , wherein the plurality of sensors are spread across a majority of the components of the industrial operation. 12 . A component comprising: a sensor module configured to receive sensor information from a plurality of sensors of an industrial operation, sensor information from at least a portion of the plurality sensors is used for functionality of a plurality of components of the industrial operation; a data monitor module configured to monitor data traffic of the industrial operation; a baseline module configured to derive a baseline signature from the sensor information, the baseline signature encompassing a range of normal operating conditions; an abnormal operation module configured to identify an abnormal operating condition of the industrial operation based on a comparison between additional sensor information from the plurality of sensors and the baseline signature; an abnormal data module configured to identify an abnormal data traffic condition; a correlation module configured to determine that the abnormal operating condition correlates to the abnormal data traffic condition; and an alert module sending an alert in response to determining that the abnormal operating condition correlates to the abnormal data traffic condition, wherein at least a portion of said modules comprise one or more of hardware circuits, a programmable hardware device and program code, the program code stored on one or more computer readable storage media. 13 . The component of claim 12 , wherein: the abnormal data traffic condition comprises a change in data traffic beyond a data traffic threshold and determining that the abnormal operating condition correlates to the abnormal data traffic condition comprises correlating timing of the abnormal data traffic condition with the abnormal operating condition; and/or identifying the abnormal data traffic condition and determining that the abnormal operating condition correlates to the abnormal data traffic condition comprises determining that one or more firmware updates to one or more components of the industrial operation occurred prior to the abnormal operating condition and the one or more firmware updates are correlated in time with the abnormal operating condition. 14 . The component of claim 13 , wherein: the change in data traffic is from a source external to the industrial operation; and/or the change in data traffic is from a node added to the industrial operation for data access within a threshold amount of time prior to the abnormal operating condition. 15 . The component of claim 13 , wherein the one or more firmware updates were installed from an external node accessing equipment of the industrial operation. 16 . The component of claim 12 , further comprising a command module configured to receive commands used to control the industrial operation, wherein the baseline signature comprises sensor information from the plurality of sensors for a normal operating condition correlated with commands related to the normal operating condition. 17 . The component of claim 16 , wherein the data monitor module monitoring the data traffic further comprises a display traffic module configured to monitor data sent to a display of operating parameters of the industrial operation and wherein the abnormal data module identifying the abnormal data traffic condition and the correlation module determining that the abnormal operating condition correlates to the abnormal data traffic condition comprise determining that the data sent to the display conflicts with sensor information of the identified abnormal operating condition. 18 . The component of claim 12 , wherein portions of the baseline signature are distributed among a plurality of devices in the industrial operation in a blockchain format and updates to the baseline signature are stored using a blockchain. 19 . A computer program product comprising a computer readable storage medium having program code embodied therein, the program code executable by a processor to: receive sensor information from a plurality of sensors of an industrial operation, sensor information f

Assignees

Inventors

Classifications

  • Distributed file systems · CPC title

  • involving long-term monitoring or reporting · CPC title

  • characterised by program execution · CPC title

  • Updates (security arrangements therefor G06F21/57) · CPC title

  • Monitor workflow, to optimize business, industrial processes · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US2023078632A1 cover?
A method for security and safety of an industrial operation includes receiving sensor information from a plurality of sensors of an industrial operation. Sensor information from at least a portion of the plurality sensors is used for functionality of a plurality of components of the industrial operation. The method includes monitoring data traffic of the industrial operation, and deriving a bas…
Who is the assignee on this patent?
Rockwell Automation Tech Inc
What technology area does this patent fall under?
Primary CPC classification H04L63/1416. Mapped technology areas include Electricity.
When was this patent published?
Publication date Thu Mar 16 2023 00:00:00 GMT+0000 (Coordinated Universal Time) (A1). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 12 related publications on this page (citations in our corpus or others sharing the same primary CPC).