Industrial Independence Alliance

Autosuffisance
industrielle.

Industrial Independence Architecture est un patron architectural. Exploiter independamment. Ne dependre de rien d'externe. S'il existe des consommateurs externes, les servir en toute securite et sur ses propres conditions. Les systemes de controle fonctionnent sur la Securite, la Fiabilite, la Performance — pas sur la CIA. Quand cette distinction disparait, les processus physiques tombent en panne.

Nouveau dans l’automatisation industrielle, les ICS ou les technologies operationnelles ? Commencez ici →

§ Le fractal

Le meme patron a chaque zone d'un reseau industriel - cellule, ligne, aire, usine, region, corporate. Chaque zone exploite independamment, partage ce qu'elle choisit de partager en toute securite, et ne depend de rien d'externe. A l'interieur : ce que l'exploitant a herite, a n'importe quel niveau de securite. Seule l'echelle change.

The Fractal - a box at the head of every zone, the secure edge gateway Two-pane diagram. Left pane shows the internal anatomy of one secure edge gateway: inbound, internal DMZ, outbound, and management partitions, with a local lake - the decentralized historian - as source of truth. Right pane shows the deployment rule: every zone has a gateway at its head. Inside the zone are pools of data (process, device telemetry, network, asset inventory, event streams, topology) fed by the gateway's active poll. Devices contributing to those pools can be any security level; the security boundary lives at the gateway, not at every device. The gateway publishes information governed by CIA outbound through a secure conduit (with a hardware data diode in the SL4 ideal realization) to whatever the zone's consumers are. The gateway is identical at every zone; the operator defines what counts as a zone. The Fractal the unit is the same · scope varies · a gateway at the head of every zone The Unit · anatomy identical at every scope INBOUND · ACS-facing active poll · classify whatever the operator needs on the ACS side INTERNAL DMZ in-flight bus · transient no durable state here OUTBOUND · IT-facing secure publish · structured query API the only external access into the zone MANAGEMENT local ops UI · signed-artifact ingress only LOCAL LAKE · HISTORIAN source of truth on the box · decentralized historian The Deployment · where a box at the head of every zone · the secure edge gateway CONSUMERS internet · plant · partner · regulator · whoever secure conduit SL4: hw diode, one-way box secure edge gateway poll · historian · publish ACS data (SRP) active poll ZONE · OPERATOR-DEFINED production · plant · site · corp · any boundary POOLS OF DATA process data device telemetry network data asset inventory event streams topology any SL device contributes · gateway is the security boundary active poll feeds every pool into the historian FRACTAL same pattern at every zone · operator decides what counts as a zone
The Fractal - a secure edge gateway at the head of every zone. Inside the zone are pools of data fed by the gateway's active poll; devices contributing can be any security level. The gateway publishes information securely outbound through a conduit (with a hardware data diode in the SL4 ideal realization) to whatever the zone's consumers are. The gateway is identical at every zone; the operator defines what counts as a zone.

L'essentiel

88 000 $/h — cout moyen d'un arret de production

Qui controle l'infrastructure d'automatisation controle l'usine. Si ce n'est pas vous, c'est quelqu'un d'autre.