Securing Connections of a Process Control or Automation System
A process plant and industrial control system architecture includes a generalized compute fabric that is agnostic or indifferent to the physical location at which the compute fabric is implemented, includes one or more physical control or field devices located at one or more specific sites at which a product or process is being manufactured and further includes a transport network that securely provides communications between the compute fabric and the pool of physical devices. The compute fabric includes an application layer that includes configured containers or containerized software modules that perform various control, monitoring and configuration activities with respect to one or more devices, control strategies and control loops, sites, plants, or facilities at which control is performed, and includes a physical layer including computer processing and data storage equipment that can be located at any desired location, including at or near a site, plant, or facility at which control is being performed, at a dedicated location away from the location at which control is being performed, in re-assignable computer equipment provided in the cloud, or any combination thereof. This control architecture enables significant amounts of both computer processing and IT infrastructure that is used to support a process plant, an industrial control facility or other automation facility to be implemented in a shared, in an offsite and/or in a virtualized manner that alleviates many of the communications and security issues present in current process and industrial control systems that attempt to implement control with shared or virtualized computing resources set up according to the well-known Purdue model. The industrial control system architecture is protected via more secure and customizable techniques as compared to those used in Purdue model-based control systems. For example, communications between any (and in some cases, all) endpoints of the system may be protected via one or more virtual private networks to which authenticated endpoints must be authorized to access. Endpoints may include, for example, containerized components, physical components, devices, sites or locations, the compute fabric, and the like, and the VPNs may include mutually-exclusive and/or nested VPNs. External applications and services, whether automated or executing under the purview of a person, may access information and services provided by the system via only APIs, and different sets of APIs may be exposed to different users that have been authenticated and authorized to access respective sets of APIs. A configuration system operates within the compute fabric to enable a user to easily make configuration changes to the compute fabric as the user does not generally need to specify the computer hardware within the compute fabric to use to make the configuration changes, making it possible for the user to deploy new configuration elements with simple programming steps, and in some cases with the push of a button.
1 . A method in a process control or automation system, the method comprising:
communicatively connecting, by the process control or automation system and via a secured point-to-point (PTP) or peer-to-peer (P2P) connection, a physical device that performs a physical function utilized in control of an industrial or automation process provided by an enterprise and an instantiated micro-encapsulated execution environment (MEEE); and
delivering, by the process control or automation system and via the secured PTP or P2P connection, information between the physical device and the instantiated MEEE, thereby controlling at least a portion of the industrial or automation process.
2 . The method of claim 1 , wherein the secured PTP or P2P connection is a secured, encrypted PTP or P2P connection.
3 . The method of claim 1 , wherein the secured PTP or P2P connection is a virtual private network (VPN).
4 . The method of claim 1 , wherein the secured PTP or P2P connection is a secured P2P connection.
5 . The method of claim 1 , wherein the secured PTP or P2P connection (i) exclusively services only the instantiated MEEE and the physical device, or (ii) exclusively services only the instantiated MEEE and an intervening device communicatively disposed between the physical device and the instantiated MEEE.
6 . The method of claim 1 , wherein:
communicatively connecting the instantiated MEEE and the physical device via the secured PTP or P2P connection includes communicatively connecting the instantiated MEEE and the physical device via multiple secured connections, the multiple secured connections including the secured PTP or P2P connection and at least one of: another secured PTP or P2P connection, a secured point-to-multipoint (PTM) connection, or a secured multipoint-to-multipoint (MTM) connection.
7 . The method of claim 6 , wherein the multiple secured connections include at least one of:
two or more at least partially nested secured connections;
two or more mutually-exclusive secured connections; or
a plurality of Virtual Private Network (VPNs).
8 . The method of claim 1 , wherein the instantiated MEEE is an endpoint of the secured PTP or P2P connection.
9 . The method of claim 1 , wherein:
communicatively connecting the physical device and the instantiated MEEE via the secured PTP or P2P connection includes communicatively connecting the physical device and the instantiated MEEE via a gateway that is communicatively disposed between the physical device and the instantiated MEEE;
the gateway and the physical device are disposed at a first physical location or site; and
the instantiated MEEE executes on a hardware platform disposed at a second physical location or site.
10 . The method of claim 9 , wherein the instantiated MEEE is a first endpoint of the secured PTP or P2P connection, and the gateway is a second endpoint of the secured PTP or P2P connection.
11 . The method of claim 9 , wherein:
the process control or automation system further comprises I/O hardware that is disposed at the first physical location and that communicatively connects the physical device and the instantiated MEEE;
the physical device is physically connected to a physical I/O interface included in the I/O hardware;
a combination of the physical device and the physical I/O interface is a physical component that is uniquely identified in the process control or automation system;
the instantiated MEEE is a first endpoint of the secured PTP or P2P connection; and
the physical component is a second endpoint of the secured PTP or P2P connection.
12 . The method of claim 1 ,
further comprising:
first authenticating and/or authorizing, by the process control or automation system, an identity of the physical device or an identity of an intervening device communicatively disposed between the physical device and the instantiated MEEE to communicate via the secured PTP or P2P connection; and
second authenticating and/or authorizing, by the process control or automation system, an identity of the instantiated MEEE to communicate via the secured PTP or P2P connection, and
wherein communicatively connecting the instantiated EE and the physical device via the secured PTP or P2P connection is based on the first authenticating and/or authorizing and the second authenticating and/or authorizing.
13 . The method of claim 1 , wherein:
communicatively connecting the physical device and the instantiated MEEE via the secured PTP or P2P connection includes establishing a session between the physical device and the instantiated MEEE over the secured PTP or P2P connection; and
delivering the information includes delivering the information over the established session.
14 . The method of claim 1 , wherein:
the physical device is a field device configured to perform a physical function responsive to control signals generated by the instantiated MEEE or by another instantiated MEEE; and
the instantiated MEEE is a virtual process controller or a virtual safety controller that (i) operates on received data to generate a first control signal to which the physical device is operably responsive, or (ii) operates on the information received from the physical device to thereby generate a second control signal to which the physical device or another physical device is operably responsive.
15 . The method of claim 1 , wherein:
the instantiated MEEE is included in a plurality of instantiated MEEEs of the process control or automation system and the physical device is included in a plurality of physical devices of the process control or automation system; and
the method further comprises communicatively connecting, by the process control or automation system and via a respective secured PTP or P2P connection, each instantiated MEEE of the plurality of instantiated MEEEs with at least one of: a respective physical device, a respective intervening device communicatively disposed between the respective physical device and the each instantiated MEEE, or another instantiated MEEE.
16 . The method of claim 15 , wherein the respective secured PTP or P2P connection exclusively services only the each instantiated MEEE and the at least one of the respective physical device, the respective intervening device, or the another instantiated MEEE.
17 . The method of claim 15 , wherein a first portion of the plurality of physical devices is disposed at a first physical location or site, a second portion of the plurality of physical devices is disposed at a second physical location or site, and the instantiated MEEE is included in a plurality of instantiated MEEEs that execute on a hardware platform disposed at one or more other physical location or sites.
18 . The method of claim 15 , wherein:
the plurality of instantiated MEEEs includes at least one of: a virtual process controller, a virtual safety controller; a virtual safety logic solver; a virtual I/O card, device, or node; a virtual wireless device; a virtual Ethernet device; a virtual operator workstation; a virtual user interface device; a virtual tool; a virtual gateway; a virtual electronic marshalling cabinet or system; a virtualization of another type of physical device or component disposed within a physical environment of the industrial process plant; a control service; a service providing a subsystem of the process control or automation system; or a service providing business logic of the process control or automation system; and
the business logic of the process control or automation system includes at least one of: a monitoring application or service, an operational application or service, a diagnostic application or service, a dashboard application or service, a user interface application or service, an analytics application or service, a safety routine application or service, a reporting application or service, a historization application or service, a configuration application or service, a simulation application or service, a process control resource and/or resource management service, an automation resource and/or resource management service, an external communications application or service, an alarm application or service, a licensing application or service, or a third-party application or service.
19 . The method of claim 18 , wherein the instantiated MEEE is included in a plurality of instantiated MEEEs, and the plurality of instantiated MEEEs includes a packet router or switch service.
20 . The method of claim 19 , wherein the instantiated MEEE is included in a plurality of instantiated MEEEs, and the plurality of instantiated MEEEs includes at least one of: a software defined compute service, a software defined storage service, or a software defined networking service.