Sign In to Follow Application
View All Documents & Correspondence

Control Device Monitoring System And Monitoring Method For Control Device

Abstract: The present invention is a PLC monitoring system (10) which monitors the operational state of a plurality of PLCs (1) which control an object to be controlled (5) in order to monitor the operational state of the PLCs (1) wherein the system is characterized in that a PLC (1b) from a PLC (1a) other than itself acquires a control command which has been output from a user program which is being executed at the PLC (1a) and on the basis of the acquired control command generates verification use data. Then the PLC (1b) using the verification use data verifies whether or not the transmission source PLC (1a) for the control command has been infected by a virus or transmits the verification use data to a PC (2) so that by way of the PC (2) displaying the verification use data upon a display device the user performs verification of the infection of the PLC (1a) with the virus.

Get Free WhatsApp Updates!
Notices, Deadlines & Correspondence

Patent Information

Application #
Filing Date
11 July 2014
Publication Number
20/2015
Publication Type
INA
Invention Field
COMPUTER SCIENCE
Status
Email
Parent Application

Applicants

HITACHI LTD.
6 6 Marunouchi 1 chome Chiyoda ku Tokyo 1008280

Inventors

1. TERAE Hisashi
c/o Information and Control Systems Company HITACHI LTD. 2 1 Omika cho 5 chome Hitachi shi Ibaraki 3191293
2. SHIMIZU Katsuhito
c/o Information and Control Systems Company HITACHI LTD. 2 1 Omika cho 5 chome Hitachi shi Ibaraki 3191293
3. MASHIKO Naoya
c/o Information and Control Systems Company HITACHI LTD. 2 1 Omika cho 5 chome Hitachi shi Ibaraki 3191293

Claims

2. A control device monitoring system according to claim 1, wherein the control device monitoring system discriminates an 20 operational state of said another control device on the basis of the generated data for behavior verification.

3. A control device monitoring system according to claim - 1, wherein the control device monitoring system further comprising 25 a management device, and wherein control unit of the control device sends the generated data for behavior verification to the management device, and the management device has the control unit to displays the received data for behavior verification on the display device. 30

4. A control device monitoring system according to claim 1, wherein the data for behavior verification includes an output value which is included in the information sent from the control device to the object controlled by the control device. 3 5

5. Acontroldevicemonitoring s y s t e m a c c o r d i n g t o c l a i m 1 , wherein the control unit of the control device stores the information in the program unit and generates the data for behavior verification on the basis of the information stored in the program unit. 5 6. A control device monitoring system according to claim 1, wherein the control device monitoring system further comprising at least two or more electronic devices connected to communication pathway between the controlled object and the electronic devices, and 10 wherein the electronic devices detects that each control unit tries to control to the object effectively and differently, and informs each control unit that each control unit tries to control to one object effectively and differently. 15 7. Acontroldevicemonitoringsystemaccordingtoclaim1, wherein the control device monitoring system further comprises the control unit on a sending side that generates synchronized data for sending another control device on the basis of information, sent from the object, of controlling the object by using a program 20 executed by itself, and the control unit on a receiving side that generates comparison data as the data for behavior verification on the basis of the same information as the information, sent fromthe object, of controlling the object by using a program similar to the program executed by 25 itself.

8. A control device monitoring system comprising three or more control devices and a decision device for deciding whether output information is valid or not, 30 the decision device is connected to each control device and an object controlled by the control device, wherein when the system obtains output information from the same kind of programs, 3 5 if output information is not consistent, the decision device decides that majority output information is valid according to decision by majority.

9. A monitoring method of a control device which monitors a plurality of control devices to control an object, 5 not from the control device but from another control device, the control device acquires a control information, wherein the control information includes control data for controlling the object outputted by a program executed by said another control device, and includes information regarding the program used for generating the 10 control data, and generates data for behavior verification on the basis of the acquired control information.

10. A monitoring method according to claim 9, wherein a control unit ofthe control device on the sending side generates 15 synchronized data for sending to another control device on the basis of information of controlling the object by using a program executed by itself., and sends the generated synchronizeddatato saidanother control device, and a control unit of the control device on the receiving side 20 generates comparison data as behavior verification-use data on the basis of the same information as the information of controlling the object by using a user program similar to the user program executed by another control device, andperforms verification of action state of said another control device by comparing the comparison data 25 generated by itself with the synchronized data sent from the control unit of the control device on the sending side. Dated this llth day of July 2014 Of Anand and Anand Advocates Agent for the Applicant

Specification

Title CONTROL DEVICE MONITORING SYSTEM AND MONITORING METHOD FOR
CONTROL DEVICE
5
Technical Field
[OOOl]
The present invention relates to a control device monitoring
system for monitoring behavior of a control device.
10
Background Art
[0002]
There are threats of malicious software such as computer virus
(hereinafter virus) to a general personal computer (hereinafter PC) .
15 For example, Trojan horse is well known as a famous virus. These
viruses are able to intrude from such various routes as FD (Flexible
Disk), mail, and website so as to steal information or to rewrite
information. As mentioned above, though the threats of malicious
software to the PC have been known in the past, recently some of
20 examples of infections for PLC (hereinafter programmable logic
controller) are reported. For example, a virus such as stuxnet is
able to intrude a PC for development through USB (Universal Serial
Bus) memory so that the virus intrudes PLC when downloading a user
program from the PC for development to PLC. Thus it is necessary for
25 PLC to counter the virus.
[0003]
The PLCis a kindof computers for application specificusage such
as plant control. In a computer such as the PLC, a user generates
30 a user program on the PC for development, and the user program is
downloaded from the PC for development to PLC. Thus, if the PC for
development is infectedbya virus, then it is possiblethatthevirus
on the PC for the development is downloaded to the PLC.
35 [0004]
Many methods for improving reliability of software using
multiplexing technique have been proposed.
[0005]
For example, Patent Document 1 discloses a controller and its
controlling method wherein the controller has a plurality of
5 processors andaprocessor executing communication is different from
a processor executing control for a controlled object.
In addition, Patent Document2 discloses a electric device, amain
control board, a peripheral board, an authentication method, and an
authentication program.
10 [0006]
In addition, Patent Document 3 discloses a device for controlling
a system bus and a dual memory system.
In addition, Patent Document 4 discloses a fault analysis support
system for a process controller.
15
Prior Arts
Patent Documents
[0007]
Patent Document 1 : JP 2004-094473 A
20 Patent Document 2 : JP 2011-030607 A
Patent Document 3 : JP H08-016484 A
Patent Document 4 : JP 2001-014027 A
SUMMARY OF THE INVENTION
25 PROBLEM TO BE SOLVED
[0008]
The virus is able to operate an object such as a plant so as not
to let user notice, and the virus makes an accident of the object.
However, a intrusion passage for the PLC, which is not connected to
30 the external line, is more restrictive than the PC.
[0009]
An object of the present invention is to provide a device for
monitoring operational state of the PLC.
35
MEANS FOR SOLVING THE PROBLEM
[ 0 0 10
To solvetheaboveproblem, thepresent inventionis characterized
by a control device monitoring system comprising a plurality of
control devices to control an object, each control device has a
5 control unit that, from another control device, acquires a control
information for controlling the object outputted froma user program
executed by said another control device and that generates data for
behavior verification on the basis of the acquired control
information.
10
EFFECTS OF THE INVENTION
[OOll]
According to the present invention, it is possible to monitor the
operational state of the PLC.
15
Brief Description of Drawings
[0012]
F I G . 1 is a block diagram illustrating a PLC monitoring system
according to the first embodiment;
20 F I G . 2 is a drawing illustrating an example of a hardware structure
of PLC according to the first embodiment;
F I G . 3 is a drawing illustrating an example of a hardware structure
of PC according to the first embodiment;
F I G . 4 is a drawing illustrating a flow of the information of the
25 PLC monitoring system according to the first embodiment;
F I G . 5 is a timing chart illustrating an example of behavior of the
PLC monitoring system according to the first embodiment;
F I G . 6 is a timing chart illustrating another example of behavior
of the PLC monitoring system according to the first embodiment;
30 F I G . 7 is a drawing illustrating an example of a format of a frame
used by the PLC monitorinq system according to the first embodiment;
F I G . 8 is a flow chart illustrating detail steps of a frame sending
operation of the PLC according to the first embodiment;
F I G . 9 is a flow chart illustrating detail steps of a frame receiving
35 operation of the PLC according to the first embodiment;
F I G . 10 is adrawingillustrating anexamplebygraphingverification
data forthe PLCmonitoring system according to the first embodiment;
FIG. 11is a flow chart illustrating detail steps of modifying a table
of a monitoring program according to the first embodiment;
FIG. 12is adrawingillustratinganexampleofatableofamonitoring
5 program according to the first embodiment;
FIG. 13 is a timing chart illustrating another example of behavior
of the PLC monitoring system according to the second embodiment;
FIG. 14 is a drawing illustrating a flow of the information of the
PLC monitoring system according to the third embodiment;
10
Description of Embodiments
[0013]
Embodiments of the present invention will be described in detail
with reference to the related drawings according to the necessity.
15 [0014]
[First Embodiment]
(Structure)
FIG. 1 is a block diagram illustrating a PLC monitoring system
according to the first embodiment.
20 The PLCmonitoring systemas control devicemonitoring systemhas
PLCs (la, lb) as control devices, a PC for development as a management
device (hereinafter PC2), a HUB (electronic device) 3, PI/O (Process
Input/Output : electronic device) 4 and an object 5.
The PLC 1 and PC2 will be detailed later.
2 5 In the PLCmonitoring system, the PLCs la and lb, which constitute
duplex configuration, are connected to the HUB 3 through a field
network. Here, asmentionedbelow, theHUB3 relays suchas a filtering
and network. The filtering has a function in which the PI/O 4 sent
from a PLC 1 that is one of slaves as mentioned below, may not be
30 passed and the PI/04 sent from a PLC 1 that is one of masters may
be passed.
In addition, a relay of a network means that the HUB 3 sends a
control command received from one PLC 1 not only to PI/O 4 but also
to the other PLC1.
35 [0015]
The HUB 3 is connected to PI/O 4, which is a device such that the
device controls the object, through the field network 8.
Aplurality of electronic devices, which has different functions,
are mounted on the PI/O 4, and each device is managed by specific
device numbers. The PLC 1 is able to access any device by assigning
5 the device number.
Inaddition, each PLClis connectedto PC2, whichis able toupdate
software and has a remote control function, through the network 6.
[0016]
Here, in a main system, one of PLC la and lb has a right (master
10 right), in which the PLC with a master right is able to control the
object. Hereinafter, the PLC in the main system is called
"master." In addition, in a sub system, one of PLC la and lb does
not have a master right, in which the PLC without a master right is
notable to control the object. Hereinafter, the PLCinthe sub system
15 is called "slave."
If the master has malfunction such as inoperative state, it is
possible to switch the master and slave each other.
[0017]
First it is assumed that the PLC la is master and the PLC lb is
20 slave.
The PLC lb obtain the data and state, which the PLC la has on the
memory, by using field network 7 so as to meet a sudden switching
request from the master PLC 1
[0018]
2 5 Here, inthis embodiment, acommunicationmethodof fieldnetworks
7 and 8 is a method in which data are sent by a frame unit. In other
words, in themethod, the PLClb sendsthe datatoadestinationdevice
such as the PI/O 4 in one side and the PLC la in the other side through
the communication line of the network by a frame unit, and the sent
30 frame is received by the destination device.
[0019]
As mentioned above, the HUB 3 relays the field networks 7, 8 and
monitors the frame. Specific addresses are given to the PLC 1 and
PI/O 4, and these addresses are sent such that these addresses are
35 written at the header in the frame. Asmentionedbelow, it is possible
that the frame has a master identifier, which indicates that the PLC
1 in the sending side is the master or the slave, at the header in
the frame or in a data area. To use the master identifier, it is
possible that the HUB 3 may send the PI/O 4 the only frame that is
sent from the master with the control right of the object and that
5 the HUB 3 may not send the PI/O 4 the frame that is sent from the
slave.
[0020]
As shownin Fig. 1, if the PLCs constitutemultiplex configuration,
when one of PLCs stops so as to update software, another PLC is able
10 to continue operations. When the software is updated by downloading
through the field network 6, it is possible to update the software
without some of influences to another PLC 1 continuing operations
by assigning the address of the PLC 1 executing downloading. Thus,
though the virus is able to intrude the PLC 1 stopping in order to
15 download user program 112 (FIG. 3), the virus does not intrude the
PLC 1 continuing operation. At this point, there are two states of
PLC 1. In one state, it is possible that the PLC 1 has been infected
by a virus. In the other state, the PLC 1 is not infected by a virus.
Thus, to compare both PLCs 1, it is possible to decide to be infected
20 by a virus. In the present embodiment, the infection with the virus
is decidedbyperformingbehavior verification immediately after the
PLC 1 continuing operations downloads.
[0021] (configuration of the PLC)
FIG. 2 is the drawing illustrating the example of the hardware
25 structure of PLC according to the first embodiment;
The PLC 1 has a main memory 110, a CPU (Central Processing Unit)
120, an input device 130, an output device 140 and storage device
150.
On the main memory 110, a control program (control unit, control
30 unit on a sending side, control unit on a receiving side) 111, a user
program 112, a PI/O driver 113, a master right control proqram 114,
a d a t a g e n e r a t i o n p r o g r a m a n d a v e r i f i c a t i o n p r o g r a m 1 1 6 a r e e x p a n d e d .
These programs are executed by the CPU 120.
The control program 111 may generally control each of programs
35 112 to 116 and may update a monitoring program table. Thus each of
the programs 112 to 116 is executed on the control program 111 such
as an operating system.
[0022]
The user program 112 is a program for controlling the object 5,
which is developed by a user, and is downloaded to the PLC 1.
5 The PI/O driver 113 is a driver for controlling the PI/O 4. The
PI/O driver 113 may generate transmission frames for PI/O 4 and may
send the frames. In addition, the PI/O driver 113 may receive the
frames from the PI/O.
The PLC 1 constituted duplex configuration may operate not only
10 the transmission frames fromthe PI/O 4to PLC 1butalsotransmission
frames from another PLCl to PI/O 4 and transmission frames from
another PLCl to the PLC 1.
The master right control program 114 may switch the master right .,
In addition, when the PC 2 controls the master right, or when the
15 user switches the master right by hand, the master right control
program 114 is optional.
[0023]
The data generation program115 generates data (verification-use
data 251) forperformingverificationoftheinfectionwiththevirus
20 (hereinafter verification) .
The verification program 116 may perform the verification of the
infection with the virus or not, on the basis of the verification-use
data 251 generated by the data generation program 115.
In addition, when the PC 2 performs the verification, the
25 verification program 116 is optional.
Inaddition, the storage device 150 storesthemonitoringprogram
table, as mentioned below.
When the verification is performed on the PLC 1, the
verification-use data 251 shown in the FIG. 3 are generated, and it
30 is stored in the storage device.
In addition, in the present embodiment, though the main memory
110 is separated from the storage device 150, the information stored
in the storage device 150 is able to exist on the main memory 110.
[0024] (PC structure)
35 FIG. 3is adrawingillustratinganexampleofahardware structure
of PC according to the first embodiment
The PC 2 has a main memory 210, a CPU 220, an input device 230,
a display device 240 and the storage device 250.
On the main memory 210, a control program (control unit) 211, a
download program 212 and a verification program 213 are expanded.
5 These programs are executed by the CPU 220.
The control program 211 may generally control each of programs
212 and 213. Thus each of the programs 212 and 213 is executed on
the control program 211 such as an operating system.
The download program 212 downloads the user program 112 stored
10 in the storage device 250 to the PLC 1 (FIG. 1).
The verification program 213
The verification program213 may perform the verification ofthe
infection with the virus or not, on the basis of the verification-use
data 251 sent from the PLC 1.
15 In addition, when the PLC 1 performs the verification, the
verification program 213 is optional.
In addition, the storage device 250 stores the user program
developed by the user and the verification-use data 251 sent from
the PLC1.
20 The verification-use data 251 are data which records information
of behavior according to the user program 112 suspected of the virus
infection. As mentioned below, the verification-use data 251 are
generatedby extracting specific information such as an output value
to the P I / O 4 from the monitoring program table, which is a result
25 of monitoring the behavior of the user program 112 at the PLC 1. An
example of the verification-use data 251 is shown in the FIG. 10.
[0025] (Flow of the information)
FIG. 4 is a drawing illustrating a flow of the information of the
PLC monitoring system according to the first embodiment.
30 Here, it is assumed that the user program 112 stored in the PC2
is infected by the virus. In addition, in the FIG. 4, the electronic
device infected by the virus is marked with dots.
First, the PLC la is temporarily stopped before downloading the
user program 112, and the master right control program 114 executed
35 by the control program 111 of the PLCs la and lb transfers the master
right from the PLC la to the PLC lb.
After transferring the master right, the control program 111 of
the PLC 1 downloads the user program 112 from the PC 2 to PLC la
associated with the download program 212 of the PC 2 (S101). At this
point, the user program 112 infected by the virus is downloaded to
5 the PLC la so that the PLC la is infected by the virus.
[0026]
Here, as mentioned above, the HUB 3 sends the PI/O 4 the frame
sent from the master (PLC lb) (S102, S103), however does not send the
PI/O 4 the frame sent from the slave (S104). In other words, though
10 the HUB 3 may receive frames from both the master and the slave, the
HUB3maysendtheonlyframes fromthemastertothe PI/O4byreferring
the master identifier in the received frames.
In addition, the HUB 3 forwards the frames sent form each PLC 1
to another PLC 1 (S105, S106) . This operation is executed
15 independently of the master identifier so that the received frames
from PLC la is sent to PLC lb and the received frames from PLC lb
is sent to PLC la.
[0027]
After forwarding frames from the HUB 3, each PLC 1 generates the
20 verification-use data 251byusingthe forwardedframes, andperforms
the verification of the infection with the virus by using the
verification-use data 251. Further each PLC 1 sends the PC 2 the
verification-use data 251 and a result of the verification (S107,
S108).
2 5 In addition, an electronic device having a filtering function or
network relay functionmaybe substituted forthe HUB 3. For example,
the PLC 1 decides the master or the slave, and the frames are sent
to PI/O 4 and another PLC 1 if the decision is the master. If the
decision is the slave, the frames are sent to only another PLC 1.
30 The PLC 1 may execute the program for the network relay or filtering
by substituting the HUB 3 for the PLC 1.
[0028]
FIG. 5 is a timing chart illustrating a example of behavior of
the PLC monitoring system according to the first embodiment. This
35 chart starts atapointdenoting state ofthe infectionwith thevirus.
In addition, the operations of the PLC 1 shown in FIG. 5 are
executed by the control program 111 as the control unit of the PLC
1.
[0029]
While the PLC la is temporarily stopped, the master right is
5 transferred to the PLC lb so that the PLC lb becomes the master and
the PLC la becomes the slave.
Further, the PC 2 sends the PLC la the user program 112 (S201),
the PLC la receives the sent user program 112 (S202).
At this point, in this embodiment, it is assumed that the PLC la
10 is infected by the virus from the PC2. On the other hand, the PLC
lb is not infected by the virus because the PCL lb fails to download.
Hereinafter the PLC la is called "infected PLC (IF PLC)" and the PLC
lb is called "normal PLC (NM PLC) ."
[0030]
15 As mentioned above, when the PLC la updates software, the PLC la
is temporarily stopped and the master right is transferred to the
PLC lb so that the PLC lb becomes the master and the PLC la becomes
the slave.
After finishingthe downloading fromthe PC 1, the PLCla restarts
20 such that the PLC lb is the master and the PLC la is the slave until
finishing operations of the verification.
When the PLC 1 is infected by the virus, though destruction of
the inner memory of the PLC 1 (main memory 110 in FIG. 2), the storage
device (storage device 150 in FIG. 2), or infections of another
25 control device became a threat, behavior becoming the worst threat
is fraudulent operations to the object 5 (FIG. 1).
As the object 5 controlledby the PLC lmayinclude such as a power
plant, which is greatlyinfluencedbythemalfunction, the fraudulent
operations to the object 5 must be protected as the first priority.
30 It is necessary that the PLC 1 operate the PI/O 4 so as to operate
the object 5. Thus, in this embodiment, it is necessary that the PLC
la infected by the virus issues illicit control commands to the PI/O
4 so that the PI/O 4 prevents the object 5 from being issued illicit
outputs by executing these control commands.
35 [0031]
As mentioned above, since the PLC la is the slave, the PLC la is
not able to control the PI/O 4 when the user program 112 of the PLC
la issues the control commands.
On the other hand, since the PLC lb is themaster, the user program
112 of the PLC lb sends the control commands A for controlling the
5 object 5 by a frame through the HUB 3 (S203).
The HUB 3 forwards the sent control commands A to the PI/O 4 and
the PLC la (5204).
The PI/O 4 controls the object 5 (FIG. 1) by executing the sent
control commands A (S205) .
10 [0032]
On the other hand, when the PLC la receives the control commands
A from the HUB 3 (S206), the data generation program 115 of the PLC
la generates the verification-use data 251onthebasis ofthe control
commands A, and the verification program 116 performs verification
15 whether the PLC lb, which sends the control commands A, is infected
by the virus or not, by using the verification-use data 251 (S207).
Further, the PLC la sends a result of the verification (S208),
and the PC 2 receiving the result of the verification displays the
result on the display device 240 (S209) .
20 In addition, according to the result of the verification, it is
possible that the PLC la sends the PLC lb warning which means that
the PLC lb is infected by the virus, only if the PLC la decides that
the PLC lb is infected by the virus.
[0033]
25 In addition, it is assumed that the infected PLC la continues
sending the PI/O 4 another control commands B by a frame (SS210).
At this point, the HUB 3 does not send the PI/O 4 the frame by
deciding that the frame is sent from the slave.
On the other hand, the HUB 3 forward the frame sent from the PLC
30 la to the PLC 1b (S211).
[ 0 0 3 4 ]
The following are three examples of methods that prevent the
system from controlling the PI/O when the slave issues control
commands :
35 (1) Software of the slave fails to issue control commands to PI/O
4 by recognizing the slave by itself.
(2) The master only executes control commands when the P I / O 4
receives control commands from both the master and the slave;
(3) The frame including control commands has a master identifier,
and the HUB 3 may send the only frame having the master identifier
to the P I / O 4.
[0035]
This embodiment is explained according above (3), however it is
possible to configure according to above (1) or (2).
In addition, the method identifying the master is not restricted
to above method using the master identifier.
For example, the system may has a function by which the HUB 3 or
the P I / O 4 stores an address or a node number or checks sending side
devices on receiving the frame.
In this case, the HUB 3 or P I / O 4 sends or receives the only frame
received fromthemaster by deciding a device sending the frame. When
switching the master and the slave, the PLC 1 may send the HUB 3 or
P I / O 4 a frame that informs switching the master and the slave so
that the address or the node number stored in the HUB 3 or P I / O 4
is changed.
[0036]
When the PLC lb receives the control commands B form the HUB 3
(S212), the data generation program 115 of the PLC lb generates the
verification-use data 251 on the basis of the control commands b,
and the verification program 116 performs verification whether the
PLC lb, which sends the control commands B, is infected by the virus
or not, by using the verification-use data 251 (5213). Further, the
P L C l a sends aresultoftheverification (S214), andthe P C 2 receiving
the result of the verification displays the result on the display
device 240 (S215).
In addition, according to the result of the verification, it is
possible that the PLC lb sends the PC 2 warning which means that the
PLC la is infected by the virus, only if the PLC lb decides that the
PLC la is infected by the virus.
[0037]
There is not a plurality of the masters but only one master PLC
1 on the PLC monitoring system 10. Thus the restarted PLC la waits
for the PLC lb to abandon the master right so as to obtain the master
right and become the master after updating the software.
In this case, though the PLC lb is the master, when the virus
infecting the PLC la makes the PLC la become the master, the PLC lb
5 is not able to issue effective control commands without the master
right.
Though there are some of the management methods, in this
embodiment, the master right control program 114 executed on the
control program 111 of the PLC 1 manages the master right. Further,
10 in this embodiment, as mentioned above, the HUB 3 recognizes the
master or slave by using the master identifier with a frame.
[0038]
When the PLC la obtains the master right and there are two masters
PLC la and lb (Both PLC masters state), the HUB 3 or PI/O 4 detects
15 the Both PLCs masters state. Further the HUB 3 or PI/O 4 sends the
PCL la and lb a frame that informs the Both PLCs masters state so
as to make the PLC la and lb stop executing.
In other words, when the HUB 3 or PI/O 4 detects that each of PLCs
la and lb (control devices) tries to effectively control the object
20 5 simultaneously and respectively, the HUB 3 or PI/O 4 informs each
of PLCs la and lb that each of PLCs la and lb tries to effectively
control the object 5 respectively.
Thus, it is possible to reduce influences of the fraudulent
operations by the virus.
25 [0039]
In regard to the switching method, there is measured switching
byinstructingthe PLC 1to switch themaster except forthe switching
at the point of failure.
Further, there is intentional switching in which the user
30 intentionally switches the master. In this case, it is possible that
theviruspretendinqtheusermakesthe P C 2 i s s u e t h e m a s t e r s w i t c h i n g
commands to the PLC 1.
In this case, the usermaymake the PLC lhave a specific password,
the PLC 1 executes themaster switching commands onlyifthe password
35 is authenticated.
[0040]
The function mentioned above by the HUB 3, which does not send
the control commands of the slave (PLC lb), is implemented by the
PI/O4. Whenthe P I / O 4 p e r f o r m o u t p u t c o n t r o l o f t h e controlcommands,
the PI/O 4 control the output tothe object 5 by using amethod similar
5 to the method for the HUB 3 as mentioned above (See the third
embodiment) .
[0041]
FIG. 6 is atiming chart illustrating another example of behavior
of the PLC monitoring system according to the first embodiment.
10 In addition, operations of the PLC 1 shown in FIG. 6 is executed
by the control programas a controlunitona sending side ora control
unit on a receiving side.
The steps S301 to S306 shown in FIG. 6 are similar to the steps
S201 to S206 shown in FIG. 5.
15 The PLC la receiving the control commands A through the HUB 3
generates the verif ication-use data 251, by which user decides
whether there is failure or not, on the basis of the control commands
A (S307). Further, the PLC la sends the verification-use data 251
(S308), and the PC 2 receivingthe verification-use data 251 displays
20 the verification-use data 251 on the display device 240 (S309).
The user may decide whether the PLC lb is infected by the virus
by visual judgment by using a graph of the verification-use data 251
on the window displayed by the display device 240.
25 [0042]
The steps S310 to S312 are similar to the steps S210 to S212 shown
in FIG. 5.
The PLC lb receiving the control commands B (generated by the PLC
la) from the HUB 3 generates the verification-use data 251 on the
30 basis of the control commands b (5313). Further, the PLC lb sends
the verification-use data 251 (S314), and the PC 2 receiving the
verification-use data 251 displays the verification-use data 251 on
the display device 240 (S315).
The user may decide whether the PLC la is infected by the virus
35 by visual judgment by using a graph of the verification-use data 251
on the window displayed by the display device 240.
[0043]
In addition, it is possible to perform the verification by
comparing the verification-use data 251 obtained by the step S309
with the verification-use data 251 obtained by the step S315.
5 [0044] (Frame format)
FIG. 7 is a drawing illustrating an example of a format of a frame
used by the PLC monitoring system according to the first embodiment.
The frame construction is as follows.
A frame starting flag denotes a start point of the frame by using
10 a unique pattern, whichdoes not appear in other portion in the frame.
A destination address denotes a physical address of the destination
ofthe frame. Asenderaddress denotes aphysicaladdress ofthe sender
of the frame. The master identifier denotes that the PLC 1 as the
frame sender is master or not.
15 When the frame is sent from the master, the HUB 3 sends PI/O 4
the frame. A frame length denotes a length of the frame. A body of
sending data includes information such as the control commands. A
frame check sequence is error detecting codes by which unexpected
failure occurs or not, for example inverted bits occurring from the
20 starting frame to finishing sending a body of the sending data.
[0045]
The construction of the body of sending data is as follows.
The frame issuing time denotes the time of generating and issuing
the frame in order to calculate arrival time of the frame. The device
25 number denotes the number of PI/O 4 as the destination of the frame.
Though there is one PI/O 4 shown in FIG. 1, when there are a
plurality of PI/Os or the system is connected to another electronic
device except forthe PI/Os, these device aremanagedbythe specific
device number. A command is a command to operate the PI/O such as
30 reading the input data and writing the output data. A data size is
a size of control data, which is used by the command. The control
data stores a value outputted to the object 5 from PI/O 4 on issuing
an output command to PI/O 4.
On the other hand, when the input command is sent from the PLC
35 1 to the PI/O 4, there is no data in the control data. In this case,
when the PI/O 4 returns the PLC 1 the input value obtained by the
object 5, the input value is stored in the control data. A program
flagdenotes whether there is theprograminformationor not. If there
is the programinformation, the program flag is set 14effective."T he
program information stores information according to user program112
5 of the device generating the frame.
[0046]
The construction of the program information is as follows.
A program number stores the number uniquely given to each
executing unit (process) of the user programs 112.
10 The program updating time stores the time at updating the user
program 112. A program size stores a size of the user program 112.
In regard to the program information, there is a message digest
value (hash value) on the basis of the program object.
When the program is updated, the program updating time, the
15 program size and message digest value are updated.
[0047] (Frame sending operation)
FIG. 8 is a flowchartillustratingdetailsteps ofa frame sending
operation of the PLC according to the first embodiment.
In addition, to refer to FIG. 1 timely, these operations are
20 executed at the steps S203 and S210 shown in FIG. 5 and the steps
S303 and 310 shown in FIG. 6.
The frame sent to the field network 7 is generated and sent on
issuing the control command to operate the PI/O 4.
The control command to operate the PI/O may be prepared as system
25 calls of the software (control program 111) installed in the PLC 1.
In this case, as mentioned below, when the user program calls the
control command, the user program 112 is evacuated to the storage
device 150 by context switch. In the state, the software (control
program 111) installed in the PLC 1 is able to obtain information
30 of the evacuated context. On the PLC 1, when the PI/O driver, which
executes the control command, is activated, and the program
informationobtainedfromthe context, whichis information regarding
the user program 112 calling the driver, is sent to the PI/O driver,
it is possible that the PI/O driver stores the program information
35 in the frame and sends the frame. Thus the PLC 1 received the frame
is able to decide which user program 112 issues this control command
by using the received program information so as to monitor the PLC
1 received the frame by a user program 112 unit.
[0048]
When the userprogram112 on the PLClexecutes the control command
5 (S351), the control program 111 as system calls is executed.
Next, the control program 111 evacuates the haven executed user
program 112 to the storage device 150 by context switch (S352).
Further, the control program 111 on the PLC 1 obtains information
of the evacuated context (S353), and the program information is
10 generated (S354) .
The information of the evacuated context includes such as memory
address on the executed user program 112. Thus, for example, the
controlprogramdecidestheprogramnumberbyusingthememoryaddress
on the executeduserprogram112 such that the programnumber is equal
15 to the memory address.
Further, if the user program 112 stores information such as the
time of the downloading the user program 112 from the PC2 to the PLCl
on another main memory 110, the control program is able to obtain
these information by searching the program number.
20 [0049]
Next, the control program 111 stores the generated program
information to the storage device 150 (S355), activates the PI/O
driver 113 (S356), and sends the program information to the PI/O
driver.
2 5 The PI/O driver 113 obtains the sent program information and the
executed control command and generates the frame on the basis of the
obtained control command and program information (S357) , the
generated frame is sent to the field network 7 (S358).
As mentioned above, it is possible to send the user program 112
30 to another PLC 1.
[0050]
On the other hand, the control program 111 recovers the evacuated
context in the context switch (S359) so that the control program 111
recovers and returns the user program 112 (S360).
3 5 So the user program 112 continues the control operations.
[0051] (Operations after receiving the frame)
FIG. 9 is a flow chart illustrating detail steps of a frame
receiving operation of the PLC according to the first embodiment.
In addition, to refer to FIG. 1 timely, these operations are
executed at the steps 5206, S207 S212 and S213 shown in FIG. 5 and
5 the steps S306, S307, S312 and 310 shown in FIG. 6.
First, the PI/O drover 113 receives the frame from another PLC
1 (S401).
Next, the control program 111 of the PLC 1 starts to update the
monitoring program table 151 (S402), interrupts to the user program
10 112, and temporarily stops executed operations (S403).
Next, the control program of the PLC 1 obtains the program
information of the frame (S404), and updates the monitoring program
table151byusingtheobtainedprograminformation (S404). Thedetail
of the S405 is shown in FIG. 11.
15 When the updating monitoring program table 151 is finished, the
control program 111 finishes the operation of updating (S406), and
restarts executing the user program 112 (S407).
[0052]
Then the control program 111 start to perform the verification
20 for checking the program behavior (S408), interrupts to the user
program 112, and temporarily stops executed operations (5403)
Then, the control program 111 refers to the record of the
monitoring program table 151 (S410). Further, the control program
111 generates the verification-use data 251 of the monitored user
25 program on the basis of the data stored in the record referred by
the data generation program 115 (S411). Further, the verification
program 116 performs the verification on the basis of the
verification-use data (S412) .
When the PC 2 performs the verification as shown in FIG. 6, it
30 is possible that the verification program 116 fails to perform the
verification. In this case, the verification program 116 generates
the verification-use data 251 at the step S411, and sends the sends
the verification-use data 251 to the PC2.
When the operationofthe verificationat the steps412 is finished,
35 the control program 111 sends a result of the verification, and
finishesthe operationoftheverification (S413), restarts executing
the user program 112 (S414) .
In addition, the steps of S408 to S414 are periodically executed
by regular time intervals.
[0053] (an example of the verification-use data)
5 The detail of the verification-use data is as follows.
There are some of verification methods. For example, it is
possible to perform the verification on the PLC 1 by setting the
pattern fortheverificationortodecidevalidityoftheuserprogram
by user own self by using the application software with a function
10 by which the PC 2 makes a graph showing behavior of the user program.
[0054]
There are some of methods by which,the virus hides in the PLC 1.
For example, it is possible to rewrite the user program 112 or to
generate the new user program 112. Thus it is necessary to update
15 the user program so as to infect the user program with the virus.
In this embodiment, the PLC la updates the software (user program
112). Thus the user is not able to decide whether the virus hides
in the PLC la and updates the program or not.
[0055]
20 Thus, in this embodiment, when there is a mark of updating the
user program 112 of the PLC 1, another PLC 1 monitors the user program
112 and decides that there is manipulation by deciding that behavior
of the user program 112 is abnormal. The verification-use data 251
includes data of behavior of the program in which there is a mark
25 of updating on themonitored PLC land is storedinthe storage device
150or250. Thusitispossibletodecidewhetherthereismanipulation
by the virus or not.
[0056]
FIG. 10 is a drawing illustrating an example by graphing
30 verificationdata forthe PLCmonitoringsystemaccordingtothe first
embodiment. T h e v e r i f i c a t i o n - ~ s e d a t a a r e d a t a ~ s t o r e d p a r a m e t e rfsr om
the monitoring program table 151 on performing specific actions by
the user program 112. An example shown in FIG. 1 shows an example
inwhich the data generation programobtains sequence of numbers (CSV
35 file etc.) of the verification-use data 251 and display it as a graph
on the display device 240 of the PC2.
In addition, in the FIG. 10, an output value is denoted on the
vertical axis and the number of executing the commands of the user
program 112 is denoted on the horizontal axis.
Inthe steps S207 andS213 shownin FIG. 5, theverificationprogram
5 116 of PLC 1 may decide whether another PLC 1 is infected by the virus
or not, on the basis of behavior of the output of the user program
112 on another PLC 1.
In addition, in operations shown in FIG. 6, it is possible to urge
the user to verify whether the PLC 1 is infected by the virus or not,
10 by displaying a graph as shown in FIG. 10 on the display device 240
by the PC2 at the step S315.
[0057]
Dot lines 1011 and 1012 denote upper and lower limits in a range
of the output value predetermined by the user. In addition, plots
15 1001 to 1009 denote first to ninth output values of the user program
112. In this example, plots 1001 to 1004 are within the range between
the upper limit 1011 and lower limit 1012. However plots 1005 to 1009
are not within the range but higher than the upper limit 1011. Thus
it is possible to decide that the user program is infected by the
20 virus sothat theoutput values arenot within the range predetermined
by the user.
[0058]
On the other hand, the plot 1007 is smaller than neighbor plots.
Thus it is possible to decide that the user program is infected by
25 the virus so that the virus make the object given an excess load by
changing the output value up and down.
[0059]
Thus the user or the verification program is able to check the
virus' hiding by displaying the graph of the behavior of the user
30 program 112 registered in the monitoring program table 151.
In addition, it is possible that the verification program 116
performs the verification on the basis ofthe predetermined standard
on the PLC 1, as mentioned above. Thus the verification program 116
of the PLC 1 or the verification program 213 of the PC 2 is able to
35 check above output values and display the warning if the behavior
is abnormal.
In this embodiment, an example of the output values of the PI/O
4 as checking parameter is shown. However there are some of examples
of checkingparameter. For example, it is possibleto check frequency
of issuing a specific commandandtowarn the infectionwith the virus
5 if the command issues at abnormal frequency.
[0060]
In addition, if the monitoring program table 151 is given the PC
2 as log information, it is possible to analyze behavior of the virus
by using the log information.
10 Further, the PLClmay fail to stop the systemin order to increase
degree of availability, and only warn, because it is possible to
misjudge.
Further, it is possible to stop only program or PI/O 4 infected
bythevirus. Inthis case, the controlprogram111receivesthenumber
15 of the user program 112 infected by the virus and stops a process
of the user program 112.
[0061] (Operations of updating the monitoring program table)
FIG. 11 is a flow chart illustrating detail steps of modifying
a table of a monitoring program according to the first embodiment.
20 These operations are executed at the step S405 shown in FIG. 9.
The generation and updating of the monitoring program table is
as follows.
The control program compares information obtained from the
received frame fromanother P L C l w i t h i n f o r m a t i o n o f i t s userprogram
25 112. When there is difference between these information, the program
information is registered in the monitoring program table 151. The
monitoring program table 151 updates this registration by receiving
information of the user program 112 registered in the monitoring
program table 151. Thus the system continues to record information
30 of behavior of the user program 112 at the monitoring program table
151.
The control program 111 receives the frame from another PLC 1
(S501), obtains information of the frame and search the same program
number as the program number stored in the frame (S502).
35 [0062]
Further the control program 111 decide whether the corresponding
program number is registered or not by using a result of the step
S502 (S502).
On the basis of a result of the step S502, if the program number
is registered (S503 -> Yes), the control program 111 executes the
5 step S510.
If the program number is not registered (S503 -> No), the control
program 111 searches whether the same program number as the program
number stored in the frame exists in the PLC 1 (finishes downloading)
or not (S504).
10 [0063]
It is possible to use a program list with information of the
downloading user program 112 sorted by the program number. The
downloading information is stored in the storage device 150 in order
to search the user program 112 in the PLC 1.
15 As a result of the step S504, the control program 111 decides
whether the user program corresponding to the program number or not
(S505).
[0064]
As a result of the step 505, if there is no user program
20 corresponding to the program number in the PLC 1 (S505 -> NO), the
control program 111 executes the step 509.
If there is a user program corresponding to the program number
in the PLCl (S505 ->Yes), the control program111 obtains the update
time (update time of another PLC 1) and the program size in order
25 to check modification of the user program 112 (S506)
Next, the control program 111 compares the obtained update time
and program size with the update time and program size searched of
the PLC 1 at the step S504 (S507)
[0065]
30 As a result of the step 5507, the control program 111 decides
whether the obtained update time and program size are equal to the
update time and program size searched of the PLC 1 (S508).
As a result of the step S508, if the obtained update time and
programsize arenot equal totheupdate timeandprogramsize searched
35 ofthe PLCl (S508 ->NO), the control programwrite theprogramnumber
stored in the frame in the monitoring program table 151 (S509).
On the other hand, if the obtained update time and program size
are equal to the update time and program size searched of the PLC
1 (S508 -> Yes), the control program finishes operations of updating
monitoring program table.
5 Next, the control program 111 obtains the command stored in the
frame (S510), decides whether the command is a command that executes
to output to the object 5 (output command) or not (S511).
[0066]
As a result of the step S511, if it is not the output command (S511
10 -> NO), the control program finishes operations of updating the
monitoring program table.
If it is the output command (S511 -> Yes), the control program
write the command, the number of the PI/O 4 and the corresponding
program number in the monitoring program table 151 (S512).
15 [0067]
In this embodiment, decision of updating program (S508) is used
by the updating time and program size. Further, it is possible to
use such as message digest value if obtained. However, when decision
is used by one program information, it is possible to fail to detect
20 modification of the program. Thus the decision is preferably used
by a plurality of the program information.
In this embodiment, the output command is only registered in the
monitoring program table 151 because the virus does not act on
commands except for the output command in order to control the object
25 5. However, it is possible to register another command such as
master-slave switching command, device stopping command for PI/O 4
on duty, reset command, and restart command of the PI/O 4 off duty,
in the monitoring program table 151.
[0068] (monitoring program table)
30 FIG. 12 is a drawing illustrating an example of a table of a
monitorinq proqram accordinq to the first embodiment.
The monitoring program table 151 manages the user program 112,
since the PLC 1 or the PC 2 monitors the user program 112 in order
to perform verification.
3 5 As shownin FIG. 12, aprogramnumberoftheuserprogram112, program
updating time, a program size, commands, device number and control
data are stored in the monitoring program table 151.
[0069]
The c o n t r o l p r o g r a m 1 1 1 r e g i s t e r s information such as the command
and device number by receiving the frame. The control program 111
5 monitors such as the user program which only exists another PLC 1.
The PLC 1 or PC 2 monitors behavior of the user program 112 because
it is possible that the virus modifies the user program 112.
[0070]
History of the output command of the user program 112 with risk
10 of infection is recorded in the monitoring program table 151 by
executing operation shown in FIG. 11.
In an example shown in FIG. 12, fist line denotes that the program
number of the user program is 0x0005, update time of this program
is 14: 40: 10 on August 1, 2011, a size of this program is 428 bytes.
15 Further, regarding commands, first command is write command by which
OxFFFFllll (longword) is written inanalog device withdevice number
OxBOOOOB80, and second command is also write command by which
0x00001860 (short word) is written in digital output (DO) device with
device number OxB0000140. Though both program numbers are equal, it
20 is possibleto differ both outputcommands, whenboth output commands
denote different operations respectively.
[0071]
TheexampleshowninFIG. 1 2 , t h o u g h a p a r t o f i n f o r m a t i o n i s shown,
the monitoring program table 151 is able to include such as frame
25 issue time and address of used data in order to further monitor
behavior of the user program 112.
When the monitoring program table is generated, the data
generation program 115 generates the verification-use data 251 by
usingtrigger such as user' s requestortimerataprescribedperiod.
30 The data obtained by the data generation program 115 is able to be
customized. For example, as shown in FIG. 10, the program 115 obtains
an output value (control data) when the specific user program 112
issues the PI/O 4 an output command.
[0072] (Conclusion of the first embodiment)
35 According to the first embodiment, one of PLCs 1 of the duplex
configuration is able to check the other PLC 1 with possibility of
the virus infection by performing the verification or by generating
the verification-use data.
As mentioned above, according to the present embodiment, if one
of PLCs 1 of the duplex configuration is infected by the virus, the
5 other PLC is able to check the infection. Thus it is possible to
increase security.
In addition, it is possible to counter the virus fundamentally,
since behavior of the user programs 112 with a downloaded program
is compared with behavior of the user programs 112 without a
10 downloaded program.
[0073]
In this embodiment, it is assumed that program information such
as the update time and size information is able to be obtained by
the PLC 1 and the information is able to be sent to another PLC 1,
15 which performs the verification.
In this case, there is no problem if area infected by the virus
is in program area (user program 112) used by the user. However, if
area infected by the virus is in system program area (control program
111, PI/O driver 113, master right control program 114, data
20 generation program 115, verification program 116), it is possible
that thevirus rewrites information suchas the update time orprogram
size. Thus, when updating software, it is necessary to prohibit that
the downloading program is written in the system program area.
[0074]
25 In addition, when the virus infection is not detected after
performing the verification according to the present embodiment, it
is possible to recover the state before updating the software such
that the PLC la, which has been temporally stopped, is the master
and the PLC lb, which has temporally been the master, is the slave
30 by switching the master and the slave. 9
In addition, another PLC 1 does not obtain the information when
the user program 112 infected by the virus is not activate. Thus,
if the user program 112 infected by the virus has not been activate
until switching the master and the slave, the PLC 1 infected by the
35 virus is able to be the master so that the PLC 1 is able to control
the object 5. To avoid above case, after downloading, the registered
user program 112 is forced t o execute these programs so as t o perform
the v e r i f i c a t i o n t o a l l user programs 112.
[0075]
When it is p o s s i b l e t o i n f e c t with the v i r u s according t o content
5 r e g i s t e r e d i n the monitoring program t a b l e 151, as mentioned above,
the PLC 1 performing the v e r i f i c a t i o n i s s u e s warning and gives log
information t o the PC 2.
In regard t o behavior of the system i n f e c t e d by the v i r u s , it is
considered t h a t the update time of the user program 112 is d i f f e r e n t
10 from one o f a n o t h e r user program 112, t h a t the value of the c o n t r o l
data i s abnormally smaller or higher, t h a t data w r i t e s by abnormal
period, and t h a t an i n v a l i d command is issued.
[0076] [Second embodiment]
In f i r s t embodiment, it is assume t h a t the s l a v e is i n f e c t e d by
15 t h e v i r u s . Next, it is assume t h a t the master on duty is i n f e c t e d
by t h e v i r u s .
In f i r s t embodiment, it is assume t h a t the slave is i n f e c t e d by
t h e v i r u s . However, i f t h e r e is a method of communicating between
the PC 2 and the PLC 1 on duty, it is p o s s i b l e t h a t the PLCs of the
20 master a n d t h e slave a r e i n f e c t e d b y t h e v i r u s through the PC2 without
updating software.
In t h i s case, s i n c e both the master and the slave have means
p e r f o r m i n g v e r i f i c a t i o n , the PLCmonitoringsystem1is able t o d e t e c t
the f a i l u r e by comparing information o f t h e user program112 executed
25 by the PLC 1 w i t h i n f o r m a t i o n of the user program 112 executed by
another PLC 1.
[0077]
When the master is i n f e c t e d by t h e v i r u s , t h e s l a v e may perform
t h e v e r i f i c a t i o n a n d d e t e c t t h e i n f e c t i o n w i t h the v i r u s on t h e m a s t e r .
30 However, it is undesirable t h a t the master i n f e c t e d by the v i r u s is
able t o c o n t r o l the o b j e c t 5. Thus it is necessary t h a t the slave
o b t a i n s t h e c o n t r o l command f r o m m a s t e r t h r o u g h t h e HUB 3 andperforms
the v e r i f i c a t i o n by analyzing it immediately.
I n a d d i t i o n , the user must avoid influence of t h e v i r u s by means
35 of immediately stopping the PLC 1, when the user receives warning
which means t h a t the master is or may be i n f e c t e d by the v i r u s .
[0078]
When the master is infectedbythe virus, there is another problem
except above problem in which the slave is infected by the virus.
As generally the hot standby state is retained by using the duplex
5 configuration, data are synchronized by copying the data from the
master to the slave.
Thus, when the normal slave copies data from the master infected
by the virus, it is hard to detect the virus by means of the first
embodiment, because it is possible to lose normal data by rewriting
10 data of the PLC 1 performing the verification.
Thus, in the second embodiment, the slave analyzes validity of
the synchronized data received from the master. In this case, the
synchronized data is obtained if the data has validity, and warning
is issued to the PC 2 if the data does not have validity.
15 [0079]
FIG. 13 is atiming chartillustratinganotherexample ofbehavior
of the PLC monitoring system according to the second embodiment.
In addition, operations shown in FIG. 13 are executed when the
master right returns from the PLC lb to the PLC la and the PLC la
20 controls the object 5. FIG. 13 shows operations if the PLC la is
infected by the virus at this point.
The timing of synchronizing data between the master and the slave
is given by the timing of executing control calculation and storing
aresultofthe calculationinthedataarea. The triggerofthe control
25 calculation is given by issuing an input request to PI/O 4 for the
PLC 1 in order to obtain physical information from the object 5.
[0080]
The PLC la (master) sends an input request for controlling the
object 5 as the frame to the PI/O 4 (S601).
30 When the HUB 3 receives the input request A, the HUB 3 forwards
the input request A to the PI/O 4 and the PLC lb (slave) (S602), and
the PLC 1b receives the input request A (S603)
P I / O e x e c u t e s t h e o b j e c t 5 a c c o r d i n g t o t h e inputrequestA (S604),
the response corresponding to the request (input response A) is sent
35 to HUB 3 (S605).
[0081]
The HUB 3 forward the input response A to the PLC la (master) and
the PLC lb (slave) (S606).
[0082]
Generally both PLCs 1 (the master and the slave) must calculate
5 the same results, since both PLCs 1 must execute by the same user
programs stored by the master and slave. However it is possible to
outputdifferentresultswhenoneofthe P L C s i s i n f e c t e d b y t h e v i r u s ,
because both PLCs 1 execute by the different user programs.
[0083]
10 T h u s , w h e n t h e P L C l b r e c e i v e s t h e i n p u t r e s p o n s e A f r o m P I / O (S607),
the PLC lb generates data for comparing with synchronized data sent
from the PLC la by using the same user program as the user program
112 on the PLC la and by using the received input response A (S608).
On the other hand, when the PLC la receives the input response
15 A (S609), the PLC la generates the synchronized data by using the
user program 112 so as to send the synchronized data to the PLC lb
(S610)
[0084]
Further the PLC la sends the synchronized data sends the
20 synchronized data to the PLC lb (S611), and the HUB 3 forwards the
received synchronized data to the PLC lb (S512).
The PLC lb compares the synchronized data sent from the PLC la
with the comparison data generated at the step S608.
Further, the PLC lb sends a result of the comparison to the PC
25 2 (S614), the PC2 displaysthe result ofthe comparisononthedisplay
device 240 (S615).
[0085]
The PI/O driver of the PLC lb is able to receive the input request
A for the PI/O 4 issued by the PLC la through the field network 7
30 by using a network relay function of the HUB 3. The PLC lb receive
the frame of which destination is the PLC lb own self, as the
destination of the transmission frame is PI/O 4 regarding a
communication from the PLC la to the PLC lb. It is possible to share
information between the PLCs la and lb by using field network 7 and
35 PI/O driver 113.
[0086]
In addition, the bus used by the synchronized data is used for
existencemonitoring except for data copy fromthe PLC lofthemaster
to the slave. If the PLC 1 of the slave is not able to receive the
data synchronizedframe, it is consideredthat themasterhas stopped,
5 The PLC 1 obtains the master right and confirms the existence of the
master. The PLC 1 may execute the comparison operation at the S611
by using information of the existence confirmation as the
synchronized data.
[0087]
10 In addition, in FIG. 13, though the result of the compassion is
sent to the PC2, the slave may send warning to the PC 2 if a result
of the comparison data is not consistent.
In addition, in FIG. 13, though the slave executes the comparison
operation, themasterinfectedbythevirusmayexecutethe comparison
15 operation.
Inaddition, operation shownin FIG. 13 executes at every constant
time.
[0088]
Here, a used format on sending the synchronized data is the same
20 as the format shown in FIG. 7. Regarding the synchronized frame, the
device number is set to the number of the slave corresponding to
synchronizing data.
In addition, it is possible to obtain a start address of the main
memory 110 from which data synchronizing starts, because the device
25 number includes not only the number of the device but also address
of the main memory on executing the user program 112.
In addition, the command for synchronizing data is stored. It is
different from the command of the PI/O 4. The control data in the
synchronized frame is data (synchronized data) for copying from the
30 master to the slave and for synchronizing.
[0089]
In addition, the input request is issued from the PLC 1 to the
PI/O 4. Further, the frame of the input response sent from the PI/O
has the program number.
3 5 Thus, the slave obtains informationwhichuser programmaybeused
for calculating. In other words, the slave is able to generate data
(comparison data) for comparing with the synchronized data by using
the same as the user program 112 of the synchronized data, on the
basis of the program number and input request.
In addition, in one user program, a plurality of input requests
5 maybe issued. Inthis case, itispossibletomanagetheinputrequests
such that each of the input requests is given sub-numbers so as to
specify the corresponding command in the user program 112.
[0090] (Conclusion of the second embodiment)
According to the second embodiment, it is possible to perform the
10 verification of the virus infection by using synchronized data sent
from the master to the slave when the master infected by the virus
controls the object 5. Further, special provision such as a patch
for the virus
is unnecessary.
15 [0091] [Third embodiment]
In examples as mentioned above, it is assumed that two PLCs 1
(duplex configuration) are connected to the HUB 3. However, there
are some of examples for the PLC 1 to perform the verification.
FIG. 14 is a drawing illustrating a flow of the information of the
20 PLC monitoring system according to the third embodiment.
The PLCmonitoring systemloahas three PLCs 1 (la, lb, lc) oftriplex
configuration andnoHUB 3. Eachofthe PLCs 1 (la, lb, lc) is directly
connected to the PI/O 4 so as to communicate each other.
As shown in the first embodiment, it is assumed that the PC 2 is
25 infected by the virus, and the PLC 1A is downloaded the program
infected by the virus (the device infected by the virus is shown by
dots).
When the control command is valid, there are following two
decision methods on outputting from the PI/O to the object 5;
30 (a) as shown in above embodiment, the system recognizes that only
the control command or input request of the PLC 1 with the master
right are valid.
(b) the system recognizes that the control command that is the same
command as another command and that the input request is the same
35 request as another request, when all control commands and input
requests from the PLCs 1A to 1C.
In other words, the system recognizes according to decision by
majority. The user makes PLC 1 that issue the command being different
from others stop executing, because there are some of problems (such
as the virus infection).
5 Inaddition, the control commands and the input requests sent from
the three PLC 1A to 1C are issued by the user program of the same
user.
[0092]
In case of above (a) and (b), the PLC 1A sends the control command
10 to the PI/O 4 at the step S701, PI/O 4 forwards the control command
to the PLCs 1B and 1C (S711, S712)
Similarly, the PLCs 1B and 1C send the control command to the PI/O
4 (S702, S703), PI/O 4 forwards the control command to other PLCs
1A to 1C (S711, S712, S721, S722 and S723). In this case, the PI/O
15 4 may send the same as majority commands according to decision by
majority.
Herethe P L C s 1 A t o 1 C i s a b l e t o p e r f o r m t h e v e r i f i c a t i o n a c c o r d i n g
tothe steps shown FIGs. 3, 4 and7 onthebasis ofthe receivedcontrol
command and the program information.
20 In addition, each of the PLCs 1A to 1C executes operation shown
in the first and second embodiments, and sends a result to the PC
2 (S731 to S733).
In addition, at this point, the PLCs 1A to 1C executes the
verification operation shown in the first embodiment (S207, S213
25 shown in FIG. 5), generates the verification-use data (S307, S313
shown in FIG. 6), and the comparison operation (S613 shown in FIG.
13) by using data between three PLCs 1.
[0093] (Conclusion of the third embodiment)
According to the third embodiment, when one of PCLs of multiplex
30 configuration is infected by the virus, another normal PLC is able
to perform the verification.
Especially, it is possible to quickly take measures to the virus
by using the decision by majority.
[0094]
3 5 In addition, in the second and third embodiments, the hardware
structure is similar to the structure shown in FIGs 2 and 3, and each
of programs 111 to 116 and 211 to 213 are expanded on the main memory
110 and 210, and are executed by the CPU 120 and 220.
List of Reference Signs
5 [0095]
1 PLC (control device)
2 PC (management device)
3 HUB (electronic device)
4 PI/O (electronic device)
10 5 object
6, 7, 8 field network
10 PLC monitoring system (control device monitoring system)
110 main memory of PLC
111 control program of PLC (control unit, control unit on a
15 sending side, control unit on a receiving side)
112 user program (program)
113 PI/O driver
114 master right control program
115 data generation program
20 116 verification program of PLC
120 CPUofPLC
130 input device of PLC
140 output device
150 storage device of PLC
2 5 151 monitoring program table (monitoring prog. TBL denoted in
figures)
210 main memory of PC
211 control program of PLC(contro1 unit)
212 download program
30 213 verification program of PC
220 CPUofPLC
230 input device of PC
240 display device
250 storage device of PC
251 verification-use data(behavior verification-use data)
(VU data denoted in figures)
CLAIMS AMENDED UNDER ARTICLE 19
We claim:
5 1. A control device monitoring system comprising a plurality of
control devices to control an object,
the control device has a control unit,
not from the control device but 'from another control device, the
control unit
10 acquires a control information, wherein the control information
includes control data for controlling the object outputted by a
program executed by said another control device, and includes
information regarding the program used for generating the control
data, and
15 generates data for behavior verification on the basis of the
acquired control information.
2. A control device monitoring system according to claim 1,
wherein the control device monitoring system discriminates an
20 operational state of said another control device on the basis of the
generated data for behavior verification.
3. A control device monitoring system according to claim - 1,
wherein the control device monitoring system further comprising
25 a management device, and
wherein control unit of the control device sends the generated
data for behavior verification to the management device, and the
management device has the control unit to displays the received data
for behavior verification on the display device.
30
4. A control device monitoring system according to claim 1,
wherein the data for behavior verification includes an output
value which is included in the information sent from the control
device to the object controlled by the control device.
3 5
5. Acontroldevicemonitoring s y s t e m a c c o r d i n g t o c l a i m 1 , wherein
the control unit of the control device stores the information in the
program unit and generates the data for behavior verification on the
basis of the information stored in the program unit.
5 6. A control device monitoring system according to claim 1,
wherein the control device monitoring system further comprising
at least two or more electronic devices connected to communication
pathway between the controlled object and the electronic devices,
and
10 wherein the electronic devices detects that each control unit
tries to control to the object effectively and differently, and
informs each control unit that each control unit tries to control
to one object effectively and differently.
15 7. Acontroldevicemonitoringsystemaccordingtoclaim1, wherein
the control device monitoring system further comprises
the control unit on a sending side that generates synchronized
data for sending another control device on the basis of information,
sent from the object, of controlling the object by using a program
20 executed by itself, and
the control unit on a receiving side that generates comparison
data as the data for behavior verification on the basis of the same
information as the information, sent fromthe object, of controlling
the object by using a program similar to the program executed by
25 itself.
8. A control device monitoring system comprising three or more
control devices and a decision device for deciding whether output
information is valid or not,
30 the decision device is connected to each control device and an
object controlled by the control device,
wherein
when the system obtains output information from the same kind of
programs,
3 5 if output information is not consistent, the decision device
decides that majority output information is valid according to
decision by majority.
9. A monitoring method of a control device which monitors a
plurality of control devices to control an object,
5 not from the control device but from another control device, the
control device acquires a control information, wherein the control
information includes control data for controlling the object
outputted by a program executed by said another control device, and
includes information regarding the program used for generating the
10 control data, and generates data for behavior verification on the
basis of the acquired control information.
10. A monitoring method according to claim 9, wherein
a control unit ofthe control device on the sending side generates
15 synchronized data for sending to another control device on the basis
of information of controlling the object by using a program executed
by itself., and sends the generated synchronizeddatato saidanother
control device, and
a control unit of the control device on the receiving side
20 generates comparison data as behavior verification-use data on the
basis of the same information as the information of controlling the
object by using a user program similar to the user program executed
by another control device, andperforms verification of action state
of said another control device by comparing the comparison data
25 generated by itself with the synchronized data sent from the control
unit of the control device on the sending side.
Dated this llth day of July 2014
Of Anand and Anand Advocates
Agent for the Applicant

Documents

Application Documents

# Name Date
1 IB304.pdf 2014-07-23
2 FORM-5.pdf 2014-07-23
3 FORM-3.pdf 2014-07-23
4 15682-388-SPECIFICATION.pdf 2014-07-23
5 5825-DELNP-2014.pdf 2014-07-26
6 5825-delnp-2014-Form-3-(09-01-2015).pdf 2015-01-09
7 5825-delnp-2014-Form-1-(09-01-2015).pdf 2015-01-09
8 5825-delnp-2014-Correspondence Others-(09-01-2015).pdf 2015-01-09
9 5825-delnp-2014-Form-1-(28-01-2015).pdf 2015-01-28
10 5825-delnp-2014-Correspondance Others-(28-01-2015).pdf 2015-01-28
11 5825-delnp-2014-GPA-(12-03-2015).pdf 2015-03-12
12 5825-delnp-2014-Correspondence Others-(12-03-2015).pdf 2015-03-12
13 5825-DELNP-2014-FER.pdf 2018-12-31
14 5825-DELNP-2014-AbandonedLetter.pdf 2019-11-05

Search Strategy

1 SearchStrategy_05-12-2018.pdf