IP Library Granted Patent US 12,348,543
Granted Patent B2
US 12,348,543 · App. 18/028,599 · Granted Jul 1, 2025

Method and system for detecting a cyber-attack on a machine controller

Inventors: Rishith Ellath Meethal (Bavaria, DE); Christoph Ernst Ludwig (Munich, DE); Mohamed Khalil (Munich, DE); Christoph Heinrich (Donauwörth, DE); Steffen Fries (Baldham, DE); Uwe Blöcher (Puchheim, DE); Dirk Hartmann (Aßling, DE)
Assignee: SIEMENS AKTIENGESELLSCHAFT
H04L63/1425G05B19/4183G05B19/41885G06F21/50G06F21/53H04L63/1408
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,348,543
App. No.
18/028,599
Granted
Jul 1, 2025
Kind
B2
Abstract

For detecting a cyber-attack on a machine controller, a concurrent simulation of the machine is run in a secured access domain. From the machine controller actual control data are transmitted to the machine and resulting monitoring data are transmitted to a monitoring device. Furthermore, sensor data of the machine are transmitted to the concurrent simulation on a first secured transmission path. Based on the sensor data, the concurrent simulation simulates an operational behavior of the machine, thus inferring simulated monitoring data. The simulated monitoring data are then compared with the resulting monitoring, and an alarm signal is triggered depending on the comparison.

Claims (37)

1. A computer-implemented method for detecting a cyber-attack on a machine controller controlling a machine, the method comprising:

a) running a concurrent simulation of the machine on a computer in a secured access domain;

b) transmitting, from the machine controller, actual control data to the machine and resulting monitoring data to a monitoring device;

c) transmitting sensor data of the machine to the concurrent simulation on a first secured transmission path;

d) simulating, by the concurrent simulation, an operational behavior of the machine based on the sensor data, thus inferring simulated monitoring data;

e) comparing the simulated monitoring data with the resulting monitoring data; and

f) triggering an alarm signal depending on the comparing.

2. The method according to claim 1 , wherein the concurrent simulation is implemented as a digital twin continuously supplied with sensor data of the machine and continuously simulating its operational behavior.

3. The method according to claim 1 , wherein the resulting monitoring data comprise sensor data, actual control data and/or operational data of the machine.

4. The method according to claim 1 , wherein the resulting monitoring data are transmitted on a second secured transmission path from the machine controller and/or from the monitoring device to a comparator, which also receives the simulated monitoring data for the comparison with the resulting monitoring data.

5. The method according to claim 1 , wherein:

the resulting monitoring data comprise the actual control data;

the concurrent simulation evaluates an inverse simulation model of the machine, thus determining simulated control data which are compatible with the sensor data;

the simulated control data are compared with the actual control data; and

the alarm signal is triggered depending on the comparing.

6. The method according to claim 1 , wherein:

the sensor data comprise first measured data from a first sensor internal to the machine and second measured data from a second sensor coupled to the machine,

the second sensor is secured against external influence,

a physical compatibility of the first measured data with the second measured data is tested by the concurrent simulation, and

an alarm signal is triggered depending on the test.

7. The method according to claim 6 , wherein the first measured data and the second measured data are weighted by different weight factors in the concurrent simulation.

8. The method according to claim 1 , wherein:

the simulated monitoring data are transmitted on a third secured transmission path from the concurrent simulation to a condition monitoring system,

the condition monitoring system evaluates the simulated monitoring data to detect an anomalous behavior of the machine, and

an alarm signal is triggered depending on an evaluation.

9. The method according to claim 1 , wherein the secured access domain and/or a secured transmission path is secured:

by an isolation or separation from the internet;

by protecting against an access or data transfer from the machine controller;

by authenticating communication endpoints;

by protecting integrity or confidentiality of communicated data;

by detecting unauthorized alteration of communicated data;

by a unidirectional gateway; and/or

by a data diode.

10. A system for detecting a cyber-attack on a machine controller, the system comprising:

one or more hardware processors configured to perform a method according to claim 1 .

11. A computer program product, comprising a computer readable hardware storage device having computer readable program code stored therein, said program code executable by a processor of a computer system to implement a method for detecting a cyber-attack on a machine controller, according to claim 1 .

12. A non-transient computer readable storage medium storing a computer program product according to claim 11 .

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 28, 2024
From: ELLATH MEETHAL, RISHITH; LUDWIG, CHRISTOPH ERNST; KHALIL, MOHAMED; HEINRICH, CHRISTOPH; FRIES, STEFFEN; BLÖCHER, UWE
To: SIEMENS AKTIENGESELLSCHAFT
Reel/Frame 067540/0600 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 28, 2024
From: HARTMANN, DIRK
To: SIEMENS CORPORATION
Reel/Frame 067540/0936 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 28, 2024
From: SIEMENS CORPORATION
To: SIEMENS AKTIENGESELLSCHAFT
Reel/Frame 067541/0025 →
Priority Claims (1)
EP 20199058 · Sep 29, 2020 · regional
Continuity (1)
Related Publication 20240031388A1 · Jan 25, 2024
References Cited (23)
US 7593837B2 · Nakaya · 2009 [cited by examiner]
US 10261846B1 · Patton · 2019 [cited by examiner]
US 20050096872A1 · Blevins · 2005 [cited by examiner]
US 20070005266A1 · Blevins · 2007 [cited by examiner]
US 20160065603A1 · Dekel · 2016 [cited by examiner]
US 20170264629A1 · Wei et al. · 2017 [cited by applicant]
US 20170289191A1 · Thioux · 2017 [cited by examiner]
US 20180159879A1 · Mestha et al. · 2018 [cited by applicant]
US 20180262525A1 · Yan · 2018 [cited by examiner]
US 20190176862A1 · Kumar · 2019 [cited by examiner]
US 20200185107A1 · Cox · 2020 [cited by examiner]
US 20200233956A1 · Wang · 2020 [cited by examiner]
US 20210273965A1 · Pi · 2021 [cited by examiner]
US 20210287459A1 · Cella · 2021 [cited by examiner]
US 20210326731A1 · Nasle · 2021 [cited by examiner]
US 20210344700A1 · Ueno · 2021 [cited by examiner]
US 20220063689A1 · Kumar · 2022 [cited by examiner]
US 20220100185A1 · Karri · 2022 [cited by examiner]
WO WO2020046371A1 · 2020 [cited by applicant]
Adepu Sridhar et al: “Control Behavior Integrity for Distributed Cyber-Physical Systems”; 2020 ACM/IEEE 11th International Conference on Cyber-Physical Systems (ICCPS), IEEE; Apr. 21, 2020 (Apr. 21, 2020); pp. 30-40, XP… [cited by applicant]
Luchs Mark et al: “Last Line of Defense: A Novel IDS Approach Against Advanced Threats in Industrial Control Systems”; Jun. 4, 2017 (Jun. 4, 2017); Advances in Biometrics : International Conference; ICB 2007, Seoul, Kor… [cited by applicant]
Ouchitachen Hicham et al: “Improved multi-objective weighted clustering algorithm in Wireless Sensor Network”; Egyptian Informatics Journal; Elsevier, Amsterdam, NL; vol. 18, No. 1; Aug. 12, 2016 (Aug. 12, 2016); pp. 45… [cited by applicant]
PCT International Search Report and Written Opinion of International Searching Authority mailed Dec. 20, 2021 corresponding to PCT International Application No. PCT/EP2021 /074905 filed Sep. 10, 2021. [cited by applicant]