IP Library Granted Patent US 12682051
Granted Patent B2
US 12682051 · App. 18/034,179 · Granted Jul 14, 2026

Control system having isolated user computing unit and control method therefor

Inventors: Deok Woo Kim (Seoul, KR); Jung Woo Park (Seoul, KR)
Assignees: WOORI TECHNOLOGIES CORPORATION; Deok Woo Kim
G06F21/554G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12682051
App. No.
18/034,179
Granted
Jul 14, 2026
Kind
B2
Abstract

A control system for monitoring and taking action on security, abnormal situations, abnormal operations, and the like in various fields is disclosed. The present control system includes a user computing unit and a secure computing unit. The user computing unit includes its own CPU and generates control information by executing a user program. The secure computing unit includes its own CPU and again checks input information inputted from a device to be controlled and the control information generated by the user computing unit to generate system check information. The system check information is compared with system state determination standard information preset by a user, and when the system state is within a normal range, the control information is outputted as it is, and when the system state is not within the normal range, the user takes a preset appropriate security action.

Claims (24)

1 . A control system having an isolated user computing unit, comprising:

a user computing unit including a first central processing unit (CPU) and peripheral circuits, and configured to execute a control program for controlling a device to be controlled using input information, which is input from the device to be controlled, to generate preliminary control information, the user computing unit being isolated from the device to be controlled;

a security computing unit including a second CPU and peripheral circuits, and configured to generate system check information using the input information received from the device to be controlled, the control program, system state information, and the preliminary control information provided from the user computing unit, compare the system check information with system state determination standard information preset by a user, directly output the preliminary control information as a final control information when it is determined that an operation state of the device to be controlled is within a normal range, and take a security action preset by the user when it is determined that the operation state of the device to be controlled is out of the normal range; and

a control input/output unit connected between the device to be controlled and the security computing unit and not connected to the user computing unit, and configured to receive the input information from the device to be controlled and to provide the input information to the user computing unit through the security computing unit, and further configured to provide the final control information outputted by the security computing unit to the device to be controlled,

wherein the input information includes at least one of a state signal of the device to be controlled and a sensor detection signal; and the preliminary control information and the final control information include a control signal for controlling the device to be controlled, and wherein the security computing unit is configured to generate the system check information by, prior to receiving the preliminary control information provided from the user computing unit, performing calculation using the input information, the control program, and the system state information, and performing remaining calculation using the preliminary control information after the user computing unit provides the preliminary control information.

2 . The control system of claim 1 , wherein the security computing unit is configured to perform the remaining calculation, after the preliminary control information generated and provided by the user computing unit is compared with preliminary control information generated by the security computing unit and a result of the comparison is verified.

3 . The control system of claim 1 , wherein the security action is to restore or reset an operating system or application program of the user computing unit to an initial state.

4 . The control system of claim 1 , wherein an alarm is output when the security action is taken.

5 . The control system of claim 1 , further comprising a security input/output unit configured to report a state of the control system to an entity outside the control system or receive a command or computer program to be executed by the security computing unit from the entity outside the control system.

6 . A control method performed in the control system having the isolated user computing unit according to claim 1 , comprising:

an input information providing operation in which the input information is provided to the user computing unit through the security computing unit;

a preliminary control information receiving operation in which the security computing unit receives the preliminary control information from the user computing unit;

a system check information deriving operation in which the security computing unit derives system check information using the preliminary control information and the input information;

a system state determining operation in which the derived system check information is compared with preset system state determination information;

a final control information providing operation in which when it is determined that a system state is within a normal range in the system state determining operation, the preliminary control information is output; and

a security action executing operation in which when it is determined that the system state is not within the normal range in the system state determining operation, a security control program is executed,

wherein the input information includes at least one of a state signal of the device to be controlled and a sensor detection signal; and the preliminary control information and the final control information include a control signal for controlling the device to be controlled, and

wherein in the system check information deriving operation, the system check information is derived by, prior to receiving the preliminary control information provided from the user computing unit, performing calculation using the input information, the control program, and the system state information, and performing remaining calculation using the preliminary control information after the user computing unit provides the preliminary control information.

7 . The control method of claim 6 , wherein, in the system check information deriving operation, the remaining calculation is performed using the preliminary control information, after the preliminary control information generated and provided by the user computing unit is compared with preliminary control information generated by the security computing unit and a result of the comparison is verified.

8 . The control method of claim 6 , wherein the security action executing operation includes:

a security information providing operation in which at least one of the system check information, the system state information, the input information, and the final control information is provided to an entity outside the control system; and

a security command applying operation in which a security command is issued to the security computing unit on the basis of information provided from the entity outside the control system.

9 . The control method of claim 6 , wherein, the preliminary control information receiving operation, the system check information deriving operation, the system state determining operation, the final control information providing operation, and the security action executing operation are performed whenever the input information is provided to the user computing unit through the security computing unit in the input information providing operation.

10 . The control method of claim 6 , wherein the preliminary control information receiving operation, the system check information deriving operation, the system state determining operation, the final control information providing operation, and the security action executing operation are performed after the input information is provided to the user computing unit through the security computing unit a predetermined number of times in the input information providing operation.