Method for integrating plant components into communication network of technical plant
Through the integrated service interaction between facility components and technical facilities, and the use of automatic discovery and certificate management protocols, the problem of OT devices choosing a suitable access method in the network is solved, automated and secure facility component integration is achieved, and the efficiency and reliability of secure device access to the network for OT devices are improved.
Patent Information
- Application Number
- CN202480013670.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2023-02-20
- Filing Date
- 2024-02-05
- Publication Date
- 2025-09-26
AI Technical Summary
In existing technologies, it is difficult for OT devices to automatically identify and select appropriate secure device access methods when connected to the network, resulting in ineffective and unreliable integration.
Determine the type of integration method supported by the facility components, interact with the integration services of the technical facilities, automatically check whether it can be integrated in the communication network of the technical facilities, use methods such as mDNS, GRASP, DNS for automatic discovery, and combine certificate management protocols and certification authorities to ensure that the authentication and certificate configuration of the facility components meet security requirements.
It achieves the automated and reliable integration of facility components in the technical facility communication network, ensures the security and consistency of certificate configuration, reduces manual intervention, and improves integration efficiency and security.
Smart Images

Figure CN120712801A_ABST
Abstract
Description
Technical Field
[0001] The invention relates to a method for integrating an installation component into a communication network of a technical installation. The invention also relates to a computer-implemented integration service and a computer-implemented tool. Background Art
[0002] So-called "secure device onboarding" methods (such as BRSKI (Bootstrap Remote Secure Key Infrastructure)) are increasingly finding their way into operational technology (OT) environments. This aligns particularly with the fundamental "Zero Trust" principle of "never trust, always verify." On the one hand, these methods implement so-called authentication (Proof of Identity) and / or proof of origin (Proof of Originality, see for example the requirements of IEC 62443, "Providing a Root of Trust for the Product Vendor"). On the other hand, these methods enable the secure provision of application-specific credentials (e.g., certificates with associated cryptographic keys required for application-specific authentication) to OT devices.
[0003] So-called secure zero-touch device onboarding methods have proven particularly advantageous because they enable fully automated authentication / origin verification and the provision of application-specific credentials—that is, without any user input and therefore considered particularly user-friendly. Even the automatic search for an instance in the network for authentication / origin verification (often called a registrar) and the instance responsible for providing this data to the device are fully automated within the framework of secure zero-touch onboarding methods, for example using so-called "autodiscovery mechanisms" (such as mDNS and GRASP).
[0004] In some OT application environments, not only must the device-specific LDevID universal certificate be provided to the OT device connected to the corresponding network within the scope of secure device enrollment or immediately thereafter, but also the applications hosted on the OT device (e.g., in so-called Docker containers) must be provided. These applications accordingly receive the required application-specific LDevID App certificates. This is referred to as enrolling the application-specific certificates.
[0005] This step is not a mandatory component of known specifications such as the aforementioned BRSKI specification. However, this step has proven to be meaningful and / or even necessary in many known OT deployment scenarios.
[0006] Due to dynamic customer requirements and equally dynamic requirements regarding standardization / regulation, OT devices will in the long term support more than one secure device onboarding method (i.e., at least two such methods). OT application environments (e.g., manufacturing plants and process technology facilities) are also expected to have to support multiple methods. This means that, in the long term, for example, a BRSKI registrar and an OPC UA (Open Platform Communications Unified Architecture) registrar may be provided simultaneously in one environment (see "Device Provisioning" in OPC UA Part 21).
[0007] OT devices that support multiple secure device onboarding methods and are used in an OT environment (which also supports multiple secure device onboarding methods by providing different registrars in the environment) currently do not have information about which registrar should be contacted specifically in the respective application environment and which method suitable for the application environment (i.e., supported by the application environment) should be used. If an OT device does not support the secure device onboarding method available in the respective application environment, this should be detected as early as possible so that, in particular, the most appropriate response can be made. This is currently not possible using automated methods.
[0008] US Pat. No. 11,272,361 B1 discloses a method for integrating technical components into a network.
[0009] WO 2022 / 028975 A1 discloses a system for verifying components of an industrial system.
[0010] EP 3 258 662 A1 discloses a method for registering an intelligent electrical device with a certification body. Summary of the Invention
[0011] The object of the present invention is to provide a method for integrating an installation component into a communication network of a technical installation, which method avoids the disadvantages listed above and enables a more efficient and reliable integration of the installation components.
[0012] This object is achieved by a method having the features of claim 1. Furthermore, this object is achieved by a method having the features of claim 13. Furthermore, this object is achieved by a computer-implemented integration service according to claim 16. Furthermore, this object is achieved by a computer-implemented tool according to claim 17. Advantageous developments are described in the dependent claims.
[0013] According to the method of the invention for integrating an installation component into a communication network of a technical installation, the technical installation being embodied as a process installation or a production installation, the method comprises the following features:
[0014] a) determine the integration services of the technical facility with the aid of the facility components,
[0015] b) transmitting, by means of the facility component, information about the type of integration method supported by the facility component to the integration service of the technical facility,
[0016] c) checking with the aid of the integration service whether an automated integration of the installation component into the communication network of the technical installation is possible, taking into account the information available to the integration service of the technical installation about the types of integration methods supported by the communication network of the technical installation and the information transmitted by the installation component about the types of integration methods supported by the installation component,
[0017] d) Integrating the installation component into the communication network of the technical installation, if automated integration of the installation component into the communication network of the technical installation is possible.
[0018] Technical facilities are facilities from process industries, such as chemical, pharmaceutical, petrochemical industries, or facilities from the food and genetic material industries, or facilities from production industries, factories, in which, for example, all types of vehicles or goods are produced.
[0019] An installation component of a technical installation can be any device or computer-implemented application that needs to be authenticated by one or more certificates in order to communicate with other components of the technical installation. An installation component of a technical installation can be, for example, a device such as a pump, valve, motor, boiler, etc., but can also be a software program.
[0020] Unlike the integration methods for installation components known from the prior art, not only the types of integration methods available for the installation component are considered, but also the types of integration methods applicable within the context of the communication network of the technical installation. According to the present invention, an automated check is performed to determine whether an automated integration method for a (specific) installation component can be implemented within the context of the (specific) communication network of the technical installation. If successful, i.e., if the installation component can be automatically integrated into the communication network of the technical installation, the integration is automatically performed. Therefore, no interaction with an operator or administrator of the technical installation is required.
[0021] Installation components can use known identification methods, such as those based on mDNS, GRASP, DNS, or DHCP, to determine integrated services. These methods are established in the IT field and can also be used advantageously in the field of communication within technical installations.
[0022] The information transmitted by the facility components to the integration service of the communication network of the technical facility can exist in the form of a JSON file and / or as a security event message.
[0023] Preferably, the information additionally includes one or more certificate management protocols supported by the facility component. This additional information can be used by the integration service for later integration of the facility component, which will be explained further in the specification.
[0024] A certificate is understood to be a digital data set that confirms certain characteristics (in this case, characteristics of a machine, device, application, etc.). The credibility and integrity of the certificate can usually be verified with the help of cryptographic methods. Certificates for use in installation components in technical installations are issued by a certification authority, which is also called a so-called "issuing CA (certification authority)". Such an issuing CA is usually always online and issues certificates for various requesters based on input certificate requests, which requesters sign these certificates with their own issuing CA certificates. The credibility of the issuing CA is ensured in that its own issuing CA certificate is signed by the certificate of a trusted root certification authority (also called "root CA"), which is located in a protected environment. It should be noted that the root CA is mostly offline and is only activated or switched on when it is to issue a certificate for the issuing CA to which it belongs, with the strictest security measures observed. The root CA can be located outside the technical installation.
[0025] Certificates have specific certificate profiles. These profiles include the certificate type. Examples of these types include TLS server certificates, TLS client certificates, OPC UA server certificates, and OPC UA client certificates. Depending on the assigned certificate type and any additional requirements, the certificate profile can include certificate attributes and their values in accordance with the ITU-T X.509 standard. During verification according to this certificate profile, any certificate request that does not include all specified attributes and values is rejected. The more attributes and / or values specified in the certificate profile, the stricter and more accurate the verification.
[0026] In addition to secure communication, maintaining a secure device configuration that complies with various security requirements, such as "secure by default" and "minimum functionality," is crucial for optimal protection of technical installations. In accordance with the security concept of the technical installation, installation components can verify their origin using so-called manufacturer device certificates (IDevID certificates, according to IEEE 802.1AR).
[0027] Components of technical installations often communicate with more than one communication partner and use more than one secure communication protocol. For example, an industrial automation system (AS) can often provide users with access to its web-based user interface via HTTPS (using an associated TLS server certificate) and simultaneously communicate with associated OPC UA clients (in the role of OPC UA server) via OPC UA. Therefore, installation components often require multiple certificates (LDevID certificates), and from a security perspective, it is recommended to request or use a dedicated certificate for each application.
[0028] Because each certificate issued for a specific purpose should generally be not only initially requested during its lifecycle but also renewed and / or revoked, the aforementioned CMP protocol, for example, provides various so-called CMP messages, which can be used to identify the respective type of certificate request (or the respective underlying application instance). If, for example, a registrar receives a so-called IR message ("Initial Request") from an infrastructure component, it can be informed that this is the initial (first) request for a specific certificate. In a KUR or RR message, the registrar identifies a request to renew or revoke an existing certificate.
[0029] Even though all certificate types, such as TLS server, TLS client, OPC UA server, or OPC UA client, can be issued from a purely technical perspective by the same certification authority (also known as a certification authority (CA)), for security reasons it is recommended to differentiate for each purpose or for each communication protocol (TLS, OPC UA) and therefore use a dedicated certification authority. The reason for this is that if a device uses several different certificates for different purposes or uses several communication protocols used by the device (which are issued by the same certification authority) and this certification authority is compromised, the device can no longer communicate using the secure communication protocol because its (unique) certificate, issued and verified by the compromised certification authority, is no longer considered trustworthy.
[0030] Likewise, if different certification authorities are used to issue certificates for different purposes / communication protocols according to the above recommendations, certificate requests can usually be made through a (central) registration authority (RA). The registration authority can identify the purpose of the target certificate based on, for example, the content of the certificate request or the http / https path from which it received the certificate request.
[0031] If configured accordingly, the registration authority can usually forward different certificate requests to different responsible certification authorities. It should be mentioned that when using the CMP protocol, it is generally possible for the installation component to specify the certification authority to be addressed in the "Recipient" field.
[0032] However, this assumes that the infrastructure components are "aware" of the different certification authorities and their assignment to different certificate profiles, which is rarely the case in practice. Typically, the infrastructure components only know the registration authority (or, in the case of segmented networks, the responsible local registration authority (LRA)) as the respondent for certificate requests.
[0033] Particularly preferably, the integration service checks the identity of the installation component when contact is initiated by the installation component, in particular using identification information stored on the installation component by its manufacturer or integrator in accordance with the IEEE 802.1AR-2018 standard. This ensures that unauthorized integration of the installation component into the communication network of the technical installation is prevented.
[0034] Within the scope of the automation planning of the technical installation, information about the types of integration methods supported by the communication network of the technical installation can be provided to the integration service in advance. However, this information can also be provided to the integration service during the operation of the technical installation, for example by the administrator of the communication network.
[0035] If the system component cannot be automatically integrated into the communication network of the technical system, the operator of the technical system is preferably informed of this, in particular by generating a corresponding message. The operator can then take appropriate measures and implement, for example, modified firmware on the system component.
[0036] Within the scope of an advantageous development of the invention, the integration service can check whether the automation integration has been carried out correctly and, if the check is successful, release the installation component for communication in the communication network of the technical installation. This ensures that the integration has also been carried out in accordance with regulations.
[0037] The following steps can be carried out particularly advantageously within the scope of carrying out the integration of the installation components:
[0038] i) transferring an integration plan from the integration service to the facility component, wherein the integration plan includes information about which integration method type or types of integration methods are to be applied, if applicable, in what sequence in at least one integration step and which integration partner of the technical facility is to be used in each case, ii) automating the execution of one or more integration steps.
[0039] The integration service creates an integration plan for the facility component based on the information provided to it. The integration plan includes at least information about the type of integration method to be applied and the integration partner for the technical facility. For situations where multiple integration method types are considered (i.e., the intersection between the integration method types supported by the facility component and those used by the communication network is greater than one), the integration plan can include a prioritization of the integration method types. The integration plan can include multiple individual integration steps, each of which defines the type of integration method for the communication network and the associated integration partner. The integration partner can be, for example, a provisioning server, a secure device access server, or a registrar, such as the integration service.
[0040] Preferably, the integration service checks for at least one, preferably each, integration step whether this integration step has been correctly executed. The integration service thereby receives detailed feedback on whether the respective integration step has been successfully completed and can, if necessary, initiate appropriate measures without further delay (e.g., generate a corresponding notification to the operator of the technical installation).
[0041] The integration service checks a log based on the executed integration method, wherein the log is generated by the system component within the scope of at least one, preferably each, integration step and transmitted to the integration service of the technical system or stored so that it can be retrieved by the integration service. The integration service can transmit the log directly to the integration service or store it in a memory (e.g., on the system component itself) so that the integration service can directly retrieve the log after executing the corresponding integration step.
[0042] The integration plan can include information regarding certificate profiles and / or key usage purposes that are considered when requesting certificates for facility components for communications in the communication network.
[0043] Furthermore, the task as expressed above is solved by a method for virtually integrating a facility component that is designed to be integrated into a communication network of a technical facility within the scope of automated planning of a technical facility by means of a planning tool, wherein, taking into account information about the types of integration methods supported by the communication network of the technical facility and information about the types of integration methods supported by the facility component, a check is made by means of the planning tool or a service commissioned by the planning tool whether the facility component can be automatically integrated into the communication network of the technical facility.
[0044] Within the scope of this method, it is first checked whether the facility components can be automatically integrated into the communication network of the technical installation. This check is performed using a digital twin of the facility components. This digital twin behaves identically to the real, physical facility components and is provided by the planning tool or a service commissioned by it. In other words, the facility components are simulated. This simulated facility component can interact with the (actually implemented or simulated) integration service of the communication network. The advantage of this method is that it can first check whether the facility components can be automatically integrated into the communication network of the technical installation.
[0045] In the case of an automated integration of an installation component into a communication network of a technical installation, the installation component can be physically arranged in the technical installation and the above-described method carries out the integration of the installation component into the communication network of the technical installation.
[0046] If the automated integration of the installation component into the communication network of the technical installation is not possible, the installation component provided for integration can first be virtually modified, in particular the modified firmware being virtually implemented on the installation component. After the virtual modification of the installation component, the above-described method is repeated. If the automated integration of the installation component into the communication network of the technical installation is currently possible, the installation component is also physically modified and arranged in the technical installation, and the integration of the installation component into the communication network of the technical installation is performed according to the above-described method. Multiple iterations are also possible to achieve compatibility for the automated integration of the installation component.
[0047] Furthermore, the object expressed above is achieved by a computer-implemented registration service for a technical installation which is designed to carry out the method as explained above.
[0048] Furthermore, the object expressed above is solved by a computer-implemented tool which is designed to perform the method as described above. BRIEF DESCRIPTION OF THE DRAWINGS
[0049] The above-mentioned characteristics, features and advantages of the present invention and the ways and methods to achieve these characteristics, features and advantages will become clearer and more clearly understood with reference to the following description of an embodiment, which is explained in more detail with reference to the accompanying drawings. DETAILED DESCRIPTION
[0050] The drawing schematically shows an installation component 1 which is to be integrated into a communication network of a technical installation designed as a process installation. The goal here is that the installation component 1 can or allows communication with other components of the technical installation via the communication network.
[0051] In the installation component 1, an integration wizard 2, a CMP (Certificate Management Protocol) client 3 based on the Certificate Management Protocol, a BRSKI commitment 4 based on the Remote Secure Key Infrastructure Bootstrapping protocol of the IETF ANIMA (Internet Engineering Task Force - Autonomous Network Integration Simulation and Methodology) working group, and a configuration client 5 based on the OPC UA (Open Platform Communications Unified Architecture) standard are computer-implemented. Furthermore, the installation component 1 includes a memory 6.
[0052] The following describes the integration method sequence: In a first step, the integration wizard 2 of the installation component 1 performs an automatic discovery method. This can be based, for example, on the mDNS (Multicast Domain Name System) protocol or the GRASP (General Autonomous Signaling Protocol) protocol. This discovery method enables the integration wizard 2 of the installation component 1 to identify the integrated services 7 of the technical installation.
[0053] The integration service 7 then first checks the identity of the installation component 1, in particular using identification information stored in the memory 6 of the installation component 1 by the manufacturer or integrator of the installation component 1 in accordance with the IEEE 802.1AR-2018 standard. Once the integration service has determined the identity of the installation component 1, it allows data exchange between the installation component 1 and the integration service 7. This can be done, for example, using network access control in accordance with IEEE 802.1X, WLAN device authentication in accordance with IEEE 802.11, or 5G network access authentication in accordance with 3GPP TS 23.501 and TS 33.501. The installation component 1 can authenticate its identity using identification information in accordance with the IEEE 802.1AR-2018 standard, in particular using an IDevID device certificate. However, the installation component 1 can also select a Network Access Identifier (NAI) based on a serial number, a MAC address, or an IMEI identifier. In one variant, the authenticity of the determined identification information can be checked before data exchange between the installation component 1 and the integration service 7 is permitted. The integration wizard 2 of the installation component 1 transmits information about the integration method types and certificate management protocols supported by the installation component 1 to the integration service 7 of the technical installation, for example in the form of a JSON object. Further examples are XML objects, CBOR objects or ASN.1 objects.
[0054] Taking into account the information provided by the technical installation integration service 7 about the types of integration methods supported by the technical installation's communication network and the information transmitted by the installation component 1 about the types of integration methods supported by the installation component 1, the integration service 7 checks whether automated integration of the installation component 1 into the technical installation's communication network is possible. Automated integration is also known as "secure device onboarding."
[0055] The integration service 7 receives information about the type of integration method supported by the communication network of the technical installation from a computer-implemented tool 8, which is used in particular for creating a plan for the automation of the technical installation. The computer-implemented tool 8 has a memory 8a in which the corresponding information is stored.
[0056] If the check proves that the system component 1 does not support any of the integration method types (safety device onboarding) available in the corresponding application environment of the technical system, the automated integration (safety device onboarding) is prohibited. In addition, the operator of the technical system is informed in a suitable manner (e.g., by a corresponding message) so that he or she needs to manually check the system component 1 and provide it with the necessary data.
[0057] When the automated integration of the facility component 1 into the communication network of the technical facility is possible, the integration service 7 creates an integration plan 9 and transmits it to the integration wizard 2 of the facility component 1. The integration plan 9 includes information about which integration method type or types of integration methods are to be applied in at least one integration step, in what order if applicable, and which integration partner of the technical facility is to be used in each case. Furthermore, the integration plan includes information about certificate profiles and / or key usage purposes, which are taken into account when requesting a certificate for the facility component 1 for communication in the communication network. A certificate profile describes the essential content / components of a particular certificate type and can, for example, take the form of a machine-readable XML file. An example of such a certificate profile (which can, for example, take the form of an XML file) is:
[0058] -Device-specific Local Significant Device Identifier Universal Certificate (sometimes also called Customer Device Certificate)
[0059] - Various application-specific (also called operational) certificates, such as TLS client certificate, TLS server certificate, signing certificate, OPC UA client certificate, OPC UA server certificate.
[0060] Key usage purpose (Key Usage in English), such as "digital signature," "key encryption," or "key agreement." These are standardized names according to RFC 5280 for the purposes for which the associated key (or associated key pair, where the public key is contained in the certificate and the private key is securely stored) can be used.
[0061] In the presently described embodiment, the “common feature” of the installation components 1 and the communication network is the integration method based on the BRSKI protocol.
[0062] As part of the integration method, the BRSKI commitment 4 carries out an automatic discovery method (AutomaticDiscovery) based on the mDNS protocol in order to determine the BRSKI registry 10 of the communication network. Alternatively, for example, it is also possible to contact the BRSKI registry 10 directly based on the contact data contained in the integration plan 9. The BRSKI extension BRSKI-AE is then used with the cooperation of the CMP client 3 in conjunction with the certification authority 11 for the technical installation of the installation component 1 to grant a universal LDevID certificate. Application-specific LDevID certificates are then granted with the cooperation of the CMP client 3 in conjunction with the certification authority 11 for the technical installation of the installation component 1. These application-specific certificates are used by individual services / applications of the installation component 1, such as an mTLS client (bidirectional transport layer security), for communication with partners within the communication network of the technical installation.
[0063] Integration service 7 monitors each integration step of the integration method using log data, which integration wizard 2 stores in memory 6 of installation component 1. To this end, integration service 7 obtains corresponding access to memory 6 of installation component 1. Alternatively or additionally, integration wizard 2 of installation component 1 can generate notifications to log the corresponding integration steps, which are transmitted to integration service 7 of the technical installation.
[0064] Alternatively or additionally, the generated notifications can be transmitted (e.g. via system logs) to a central entity (e.g. a system log server or a so-called Security Information Event Management (SIEM) system), which can evaluate the notifications as needed and / or provide them to other entities, such as integration services and / or users, and can be archived for a specific duration (e.g. 90 days) for audit / traceability / forensic purposes.
[0065] By means of the above-described evaluation of individual or multiple messages using specific (possibly dynamic and / or configurable based on the KI) rules, specific actions can optionally be initiated automatically or the user can be notified accordingly or asked to take specific actions.
[0066] After successful execution of the integration plan, the installation component 1 is released for operational use in the communication network of the technical installation.
[0067] The described integration method can be used, for example, when a system component 1 is first put into operation in a technical installation. However, the method can also be used when replacing an existing system component with a current system component 1. In this case, the information of the existing system component 1 is transferred using the integration service 7. In other words, the integration plan created for the new, current system component 1 is based on the information of the existing system component 1 and the original integration plan (which is stored, for example, in an archive accessible to the integration service 7).
[0068] Although the present invention has been shown and described in more detail by means of preferred embodiments, the present invention is not restricted to the disclosed examples and a person skilled in the art can derive other variations therefrom without departing from the scope of protection of the present invention.
Claims
1. A method for integrating a facility component (1) into a communication network of a technical facility, the technical facility being embodied as a process facility or a production facility, the method comprising: a) determining an integrated service (7) of the technical installation using the installation components (1), b) transmitting, by means of the installation component (1), information about the type of integration method supported by the installation component (1) to the integration service (7) of the technical installation, c) checking with the aid of the integration service (7) whether the installation component (1) can be automatically integrated into the communication network of the technical installation, taking into account the information available to the integration service (7) of the technical installation about the types of integration methods supported by the communication network of the technical installation and the information transmitted by the installation component (1) about the types of integration methods supported by the installation component (1), d) Integrating the installation component (1) into the communication network of the technical installation, if the installation component (1) can be automatically integrated into the communication network of the technical installation.
2. The method according to claim 1, wherein The facility component (1) uses an automatic discovery method, in particular a method based on mDNS, GRASP, DNS or DHCP, to determine the integrated service (7).
3. The method according to claim 1 or 2, wherein The information according to step b is transmitted to the integration service (7) of the facility component (1) as a JSON document and / or as a security event message.
4. The method according to any one of the preceding claims, wherein The information transmitted in step b additionally includes one or more certificate management protocols supported by said infrastructure component (1).
5. The method according to any one of the preceding claims, wherein In particular, the integration service (7) checks the identity of the installation component (1) using identification information according to the IEEE 802.1AR-2018 standard stored on the installation component (1) by the manufacturer or integrator of the installation component (1).
6. A method according to any one of the preceding claims, wherein Within the scope of the planning of the automation of the technical installation, information about the type of integration method supported by the communication network of the technical installation is provided in advance to the integration service.
7. The method according to any one of the preceding claims, wherein If the installation component (1) cannot be automatically integrated into the communication network of the technical installation, this fact is notified to the operator of the technical installation, in particular by generating a corresponding message.
8. A method according to any one of the preceding claims, wherein The integration service (7) checks whether the automation integration has been performed correctly and, if the check is successful, releases the installation component (1) for communication in the communication network of the technical installation.
9. The method according to any one of the preceding claims, wherein The following steps are carried out within the scope of carrying out the integration of the plant components (1): i) transmitting an integration plan from the integration service (7) to the facility component (1), wherein the integration plan includes information about which type of integration method or types of integration methods are to be applied in what order, if applicable, in at least one integration step and which integration partner of the technical facility is to be used in each case, ii) Automating one or more of the integration steps.
10. The method according to claim 9, wherein: The integration plan includes information about certificate profiles and / or key usage purposes, which are taken into account when requesting a certificate for the facility component (1) for communication in the communication network.
11. The method according to any one of claims 8 to 10, wherein The integration service (7) checks for at least one, preferably each, integration step whether the integration step has been performed correctly.
12. The method according to claim 11, wherein The check is performed by the integration service (7) based on a record of the executed integration method, wherein the record is created by the installation component (1) within the scope of at least one, preferably each, integration step and is transmitted to the integration service (7) of the technical installation or is stored so that it can be retrieved by the integration service.
13. A method for the virtual integration of plant components (1) provided for integration into a communication network of a technical plant, which is designed as a process plant or production plant, by means of a planning tool (8) within the scope of automated planning of a technical plant, wherein: Taking into account information about the types of integration methods supported by the communication network of the technical facility and information about the types of integration methods supported by the facility component (1), the planning tool (8) or a service commissioned by the planning tool (8) checks whether the facility component (1) can be automatically integrated into the communication network of the technical facility.
14. The method according to claim 13, wherein In order to enable the automated integration of the facility component (1) into the communication network of the technical facility, the facility component (1) is physically arranged in the technical facility and the integration of the facility component (1) into the communication network of the technical facility is performed according to a method according to any one of claims 1 to 12.
15. The method according to claim 13, wherein In the event that the facility component (1) cannot be automatically integrated into the communication network of the technical facility, the facility component (1) provided for integration is first virtually modified, in particular the modified firmware is virtually implemented on the facility component (1), wherein, after the virtual modification of the facility component (1), the method according to claim 11 is again performed, wherein, in the event that the facility component (1) can now be automatically integrated into the communication network of the technical facility, the facility component (1) is also physically modified and arranged in the technical facility, and the integration of the facility component (1) into the communication network of the technical facility is performed according to the method according to any one of claims 1 to 12.
16. A computer-implemented integration service (7) for a technical installation, the integration service being implemented for carrying out the method according to any one of claims 1 to 12.
17. A computer-implemented tool (8) embodied for performing the method according to any one of claims 13 to 15.
Citation Information
Patent Citations
Secure efficient registration of industrial intelligent electronic devices
EP3258662A1
Zero-touch onboarding in a network
US11272361B2
System and method for verifying components of an industrial monitoring system
WO2022028975A1