Edge gateway system with data classification for secure process plant data transfer

Edge gateway systems solve network security problems in process plants through unidirectional data transmission and data classification, enabling efficient and secure data transmission and access, protecting process plants from cyberattacks, and supporting rapid data consumption and analysis.

CN112540575BActive Publication Date: 2025-11-07FISHER ROSEMOUNT SYST INC
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202010990318.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2019-09-20
Filing Date
2020-09-18
Publication Date
2025-11-07
Estimated Expiration
2040-09-18

AI Technical Summary

Technical Problem

Existing process plants and process control systems are at risk of cyber intrusion and malicious cyberattacks, which can compromise the confidentiality, integrity and availability of information assets and may lead to equipment damage, product loss and loss of human life.

Method used

An edge gateway system is adopted to securely transmit process plant-related data to external systems via data diodes. By utilizing field-oriented and edge-oriented components, one-way data transmission is achieved. Combined with data classification and contextual knowledge mining, highly secure data transmission and access control are provided.

Benefits of technology

It enables secure data transmission from low-security process plants to high-security external systems, protecting process plants from cyberattacks while providing efficient and rapid data access and analysis capabilities.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN112540575B_ABST
    Figure CN112540575B_ABST
Patent Text Reader

Abstract

An edge gateway system securely transports and exposes data generated by and / or related to a process plant for consumption by external systems and includes a field-facing component that sends a set of data types defined based on a configuration of the process plant and represented using a syntax native to one or more external systems to a edge-facing component of the system. The field-facing component streams content data related to the process plant indicated by one or more interest lists to the edge-facing component, where the streamed data is represented using the set of data types. Each interest list can include multiple types of data (e.g., control, I / O, diagnostics, equipment, history, etc.) that collectively represent a particular named entity of the plant. Thus, the streamed data is securely transported and exposed to the external systems via the edge-facing component.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present disclosure relates generally to process plants and process control systems, and in particular, to protecting the transfer of process plant related data from a process plant / process control system to external systems that use or consume the process plant related data. BACKGROUND

[0002] Distributed process control systems, like those used in chemical, oil, pharmaceutical, paper production, or other process plants, typically include one or more process controllers communicatively coupled to one or more field devices via an analog, digital or combined analog / digital bus, or via a wireless communication link or network. The field devices, which can be, for example, valve positioners, switch actuators, and transmitters, are located within the process plant environment and perform process control functions such as opening or closing valves, or measuring process parameters such as pressure, temperature, etc. The field devices normally communicate with the controller using known communication protocols such as Fieldbus, HART®, WirelessHART®, and FOUNDATION® Fieldbus, over wired or wireless communication links. Examples of field devices include, for example, smart field devices having built-in process control function and communicating to the controller using the Fieldbus protocol, HART protocol, WirelessHART protocol, and / or FOUNDATION Fieldbus protocol. and The controller is also typically connected to one or more operator workstations or computers via which human operators or users can access the controller and the devices coupled thereto. Typically, the operator computers are connected to the controller over a digital data link, either directly or via a computer network. The operator computers typically include software that enables an operator to interact with the controller and the devices coupled thereto, to change settings, to change control strategies, to view the state of the process and of the equipment, etc.

[0003] Information from the field devices and controllers is typically made available to one or more other hardware devices, such as operator workstations, personal computers or computing devices, data historians, report generators, centralized databases, or other centralized management computers, through data highways, which are often Ethernet networks. Each of these hardware devices typically is centralized within the process plant. These hardware devices run applications that enable an operator, for example, to control the process, to perform troubleshooting, to modify the process controls, to simulate the operation of the process, to train personnel, to keep and update a configuration database, etc. The data highways used by the hardware devices, controllers, and field devices can comprise wired

[0004] As one example, the DeltaV™ control system, sold by Emerson Automation Solutions TMThe control system includes a number of applications stored in and executed by different devices at various locations in the process plant. A configuration application resident on one or more workstations or computing devices enables a user to create or change process control modules and downloads these process control modules to dedicated distributed controllers over a data highway. Typically, these control modules are composed of function blocks that are objects in an object-oriented programming protocol that perform functions within the control scheme based on their inputs and provide outputs to other function blocks within the control scheme. The configuration application can also allow the configuration designer to create or change operator interfaces that are used by a viewing application to display data to an operator and to enable the operator to change settings, such as set points, within the process control routine. Each dedicated controller, and in some cases one or more field devices, stores and executes a respective controller application that runs the control modules distributed and downloaded thereto to implement the actual process control functionality. A viewing application, which can execute on one or more operator workstations (or on one or more remote computing devices communicatively coupled to the operator workstations and to the data highway), receives data from the controller application(s) over the data highway and displays that data to process control system designers, operators, or users who use user interfaces and can provide any of a number of different views, e.g., operator's view, engineer's view, technician's view, etc. A data historian application, which is typically stored and executed on a data historian device, collects and stores some or all of the data provided over the data highway, and a configuration database application can execute on another computer coupled to the data highway to store current process control routine configurations and data related thereto. Alternatively, the configuration database can be located in the same workstation as the configuration application.

[0005] Generally, process control systems of process plants include field devices, controllers, workstations, and other devices interconnected through a set of hierarchical networks and buses. Process control systems can also be connected with various business and external networks, for example, to reduce manufacturing and operating costs, improve productivity and efficiency, provide timely access to process control and / or process plant information, etc. On the other hand, interconnection of process plants and / or process control systems with enterprise and / or external networks and systems increases the risk of network intrusion and / or malicious cyber-attacks that can be caused by, for example, expected vulnerabilities in business systems and applications used in the enterprise and / or external networks. Network intrusion and malicious cyber-attacks of process plants, networks, and / or control systems can adversely affect the confidentiality, integrity, and / or availability of information assets, generally, in a similar manner as with general-purpose computing networks. However, unlike general-purpose computing networks, network intrusion of process plants, networks, and / or control systems can also result in not only damage, destruction, and / or loss of plant equipment, products, and other physical assets, but also loss of human life. For example, network intrusion can cause a process to become uncontrolled and, in turn, result in explosions, fires, floods, exposure to hazardous materials, etc. Thus, it is of utmost importance to secure communications related to process control plants and systems. SUMMARY

[0006] In an embodiment, a method of securely transferring data related to a process plant from the process plant via an edge gateway system for consumption by one or more external systems is disclosed. The edge gateway system includes a field-facing component and an edge-facing component interconnected by a data diode, and the method includes sending, by the field-facing component to the edge-facing component via the data diode, a set of data types corresponding to data related to an industrial process controlled by the process plant and allowed to be exposed to the one or more external systems. The data diode can be a unidirectional data diode configured to prevent any flow of signaling and payload data from the edge-facing component to the field-facing component, and the set of data types is defined based on one or more configurations of the process plant and represented using a syntax inherent to the one or more external systems. The method also includes streaming, by the field-facing component to the edge-facing component over the data diode, content data generated by the process plant, wherein the content data is indicated by one or more interest lists corresponding to the field-facing component, and the content data is represented within the stream using the set of data types. Thus, by the method, the streamed content data generated by the process plant is made available for consumption by the one or more external systems via the edge-facing component. BRIEF DESCRIPTION OF DRAWINGS

[0007] Figure 1 is a block diagram of an example edge gateway system for an industrial process plant.

[0008] Figure 2 is a block diagram of an example industrial process plant, which illustrates, among other things, various example components of a process plant or process control system, the process control system itself, and interconnections between other example related systems and / or networks at similar security levels as the process plant.

[0009] Figure 3 is a block diagram of an example field-oriented component of an edge gateway system for a process plant or process control system.

[0010] Figures 4A-4C illustrates example data types of an example data type system generated by a field-oriented component of an edge gateway system for a process plant or process control system.

[0011] Figure 5A is a block diagram of a first portion of an edge-oriented component of an edge gateway system for a process plant or process control system.

[0012] Figure 5B is a block diagram of a second portion of the edge-oriented component of Figure 5A . DETAILED DESCRIPTION

[0013] Protecting process plant and process control systems from cyber intrusions and malicious cyber attacks often utilizes a layered or tiered security hierarchy, with at least some tiers or levels being protected by the use of firewalls and other security mechanisms. Using the Purdue Model of control hierarchy logical framework standardized by ISA (International Society of Automation) 95.01-IEC (International Electrotechnical Commission) 62264-1 as an example framework, process control systems typically fall into security levels 0-2 (e.g., OT (operational technology) levels, which have a higher level of trust in the security and validity of messages, packets, and other communications), and manufacturing, company, and enterprise systems typically fall into security levels 3-5 (e.g., IT (information technology) levels, which have a lower level of trust). For example, process plant systems, networks, and devices of security levels 0-3 can be protected from threats from enterprise networks of security levels 4-5 and / or from any external networks above security level 5 that utilize the enterprise networks, e.g., by the use of a demilitarized zone (DMZ) and / or one or more firewalls. However, as more and more services and applications that operate on process plant data are moved to be executed remotely, e.g., on networks and systems outside or external to the process plant (e.g., at security levels 4 and / or 5 within an enterprise or business with which the process plant is associated, owned, and / or operated), and / or even on networks and systems outside the enterprise or business (e.g., above security level 5, via the Internet or other public networks), stronger techniques are needed for preventing process plant systems, networks, and devices from being compromised.

[0014] The innovative systems, components, devices, methods, and techniques described herein address these and other security issues related to process plants and their networks, and are particularly directed to securely communicating process plant related data to one or more external systems that are consumers of the process plant related data.

[0015] To illustrate, Figure 1 is a block diagram of an example edge gateway system 1 that securely communicates process plant related data (e.g., field data) from a process plant 5 to one or more external data consuming applications and / or systems (which can include enterprise applications and / or systems (e.g., at IT security levels, e.g., security levels 3-5), and / or third party applications and / or systems. The edge gateway system 1 includes a field facing component 10 that is communicatively connected to an edge facing component 12 via a data diode 15. The field facing component 10 includes one or more processors 18 and one or more non-transitory memories or data storage devices 20 that store at least one data set and at least one set of computer executable instructions, where the at least one set of computer executable instructions is executable by the one or more processors 18. For example, as Figure 1As shown, the one or more memories 20 of the field-facing component 10 store respective data sets, such as one or more interest lists 22, a showable data type system 24A, and optionally other data sets (not shown). The one or more memories 20 of the field-facing component 10 also store computer-executable instructions for a data typer 25, and can store other sets of computer-executable instructions (not shown). The field-facing component 10 is communicatively connected to one or more process plant communication networks, data networks, and / or links 28, which can include any number of wired and / or wireless communication networks, data networks, and / or links that are communicatively connected to various devices and / or other data sources 30 associated with the process plant 5 and that generate data, e.g., as the process plant 5 operates to control an industrial process. More detailed descriptions of embodiments of the field-facing component 10 of the edge gateway system 1 and its subcomponents are provided elsewhere in the present disclosure.

[0016] The edge-facing component 12 of the edge gateway system 1 includes one or more processors 35 and one or more non-transitory memories or data storage devices 38 that store at least one data set and at least one set of computer-executable instructions that are executable by the one or more processors 35. For example, as shown, Figure 1 As shown, the one or more memories 38 of the edge-facing component 12 store at least a partial copy 24B of the showable data type system 24A of the field-facing component 10, respective data sets corresponding to a data lake 40 and a contextual knowledge base 42, and the one or more memories 38 of the edge-facing component 12 store respective computer-executable instructions of a contextual knowledge miner 45 and one or more access mechanisms 48 to the contextual knowledge base 42. Of course, although Figure 1 not shown in FIG. 1, the one or more memories 38 of the edge-facing component 12 can store other data sets and / or other sets of computer-executable instructions. Also as shown, Figure 1 As shown, the edge-facing component 12 of the edge gateway system 1 is communicatively connected to one or more external data-consuming systems 8 via one or more external communication networks, data networks, and / or links 50. The one or more external communication networks, data networks, and / or links 50 can include any number of wired and / or wireless communication networks, data networks, and / or links, and can include any number of private and / or public networks and / or links. The one or more external systems 8 can include any number of public computing systems and / or private computing systems, which can be implemented using any suitable technologies, such as server farms, cloud computing systems, etc., respectively, and various applications (e.g., third-party applications, websites, etc.) can execute thereon. More detailed descriptions of embodiments of the edge-facing component 12 and its subcomponents are provided elsewhere in the present disclosure.

[0017] like Figure 1 As shown, the field-facing component 10 and the edge-facing component 12 are interconnected via a data diode 15 (although in some embodiments of the edge gateway system 1 (not shown), the data diode 15 may be omitted, and the field-facing component 10 and the edge-facing component 12 may be directly connected, or integrated, as a single logical and / or physical component). In any case, as... Figure 1 As shown, the data diode 15 includes one or more transmission media through which data (e.g., electronic data) is transmitted from the field-facing component 10 to the edge-facing component 12, wherein the data diode 15 is the sole communication connection between the field-facing component 10 and the edge-facing component 12. In a preferred embodiment, the data diode 15 is unidirectional, such that any and all types of data (e.g., signaling data, control data, management data, payload data, etc.) flows only from the field-facing component 10 to the edge-facing component 12, and not from the edge-facing component 12 to (and in some embodiments, not physically to) the field-facing component 10. That is, the data diode 15 may be physically and / or logically configured to prevent any and all types of data (e.g., signaling data, control data, management data, payload data, etc.) from the edge-facing component 12 to the field-facing component 10. In one example, the unidirectional data diode 15 is implemented using a fiber optic link or cable, or some other suitable type of high-bandwidth hardware and / or software transmission medium, such as an Ethernet link, a wireless data diode, a software-defined data diode, etc. In another example, the hardware and / or software of the unidirectional data diode 15 can be otherwise configured to prevent any type of data (e.g., signaling data, control data, management data, payload data, etc.) from the edge-facing component 12 to the field-facing component 10, while allowing data to flow from the field-facing component 10 to the edge-facing component 12. For example, physical ports of the edge-facing component 12 that would otherwise receive data from one or more external systems 8 can be blocked, disabled, and / or omitted.

[0018] For additional security, data transmitted from the field-facing component 10 to the edge-facing component 10 through the data diode 15 can be encrypted by the field-facing component 10 and decrypted by the edge-facing component 12. Further, for efficiency, the data diode 15 is configured to support high-throughput data streaming, e.g., at a rate of 100K parameters per second or higher. Indeed, in some embodiments, the data diode 15 can operate at a rate of 1 gigabit per second or higher. For example, the data diode 15 can be implemented using a fiber optic link or cable, or some other suitable type of high-bandwidth hardware and / or software transmission medium (e.g., an Ethernet link, a wireless data diode, a software-defined data diode, etc.) to support the high-throughput data streaming capability. Such high-bandwidth hardware and / or software transmission medium can be implemented to have a one-way transfer capability for the field-facing component 10 and no receiving capability, thereby further implementing a one-way, unidirectional data transmission from the field-facing component 10 to the edge-facing component 12. Further, the data diode 15 can be readily scaled to accommodate system growth. For example, multiple cores and / or multiple threads can be added and / or utilized to support system growth and a corresponding increase in the amount and rate of data transmitted from the field-facing component 10 to the edge-facing component 12.

[0019] Generally speaking, the edge gateway system 1 securely connects and / or bridges lower security level process plant 5 and related systems with one or more higher security level data consuming systems 8. For example, with reference to the Purdue model (or other similar security hierarchy), the network / link 28 via which the data source 30 and the edge gateway system 1 obtain process plant related data can be at a lower security level (e.g., security level 0 through security level 2) and can include, for example, process control systems, safety instrumented systems, configuration systems, analytics systems, communication / network systems, asset management systems, diagnostic and / or test tools and / or systems, commissioning tools and / or systems, user devices and / or operator interfaces, historian systems, batch systems, software defined networks, virtual networks such as virtual private networks, virtual local area networks (VLANs), and / or virtual extensible local area networks (VXLANs), and other systems, networks, applications, and / or devices associated with the process plant 5. Thus, for ease of discussion herein, and not by way of limitation, the term “process plant 5” is used to collectively refer to the physical process plant as well as other systems associated with and communicatively connected to the physical process plant that generate and / or communicate lower security level data.

[0020] In Figure 1The edge gateway system 1, with its field-facing component 10 acquiring and initially processing process plant-related data (e.g., field data) generated by the process plant 5, can be at security level 2 to security level 3, and the data diode 15 and edge-facing component 12 can be at security level 3. One or more external data consuming systems 8 can be at security level 4 or higher, and can include any number of public and / or private systems and various applications running thereon, such as enterprise applications and / or systems, third-party applications and / or systems, publicly available applications and / or systems, websites, etc. Thus, the edge gateway system 1 securely transmits field data generated by the process plant and its related systems, networks, and / or applications 5 at a lower security level to the systems, networks, and / or applications 8 at a higher security level.

[0021] In particular, such as Figure 1 As shown, the field-facing component 10 of the edge gateway system 1 obtains or collects field data from the data source 30 according to one or more interest lists 22 stored at the field-facing component 10. The interest list 22 indicates specific process plant-related or field data generated by the process plant 5 and associated with the operation of the plant 5 to control industrial processes, allowing the indicated process plant-related field data to be displayed (e.g., can be displayed) to external systems, networks, and / or applications 8. Thus, the interest list 22 included in the edge gateway system 1 provides an initial level of field-facing security, preventing protected field data from being unintentionally released from the process plant 5 to external data-consuming systems 8. The interest list 22 can indicate specific field data of interest and / or combinations thereof, such as specific runtime data, event data, historical data, configuration data, and / or any other type of process plant-related data, generated and / or associated with devices, components, and / or systems of the process plant 5 at a lower security level (e.g., security level 0-2). The interest list 22 can be accessed via an interest manager ( Figure 1 (not shown in the document) to configure and / or define, which is described in more detail in other parts of this disclosure.

[0022] Additionally, at the field-facing component 10, a data typer 25 classifies the obtained interest list data content according to a presentable data type system 24A, respectively. Generally, the presentable data type system 24A defines or configures a system of data types (including data definitions, names, values, fields, structures, classes, objects, etc.) that are presented or otherwise available to the external data consuming system 8. Additionally, the presentable data system 24A defines processes the mapping, conversion, grouping, assignment, and / or other arrangement of process plant related or field data types to presentable data types so that the process plant related data content can be utilized and understood by the external data consuming system 8. The terms "process plant related data type" or "field data type" are used interchangeably herein to generally refer to a data type (e.g., data definition, name, value, field, structure, class, object, etc.) that has been defined and / or configured for use by the process plant 5 and its related systems at a lower security level. In embodiments, the presentable data type system 24A can be defined or configured via the interest manager (e.g., in the manner described elsewhere in the present disclosure). Regardless, the presentable data system 24A allows the external system 8 to interpret process plant related / field data generated by the process plant 5 and related lower security level systems without the external system 8 needing to know any internal data definitions and / or configurations of the plant 5 and without the need to query and / or initiate communications with and / or send responses to the process plant 5. In this way, the presentable data type system 24A and data typer 25 of the edge gateway system 1 further protect the process plant 5 from possible security breaches from the external system 8. The presentable data type system 24A and data typer 25 are described in greater detail elsewhere in the present disclosure.

[0023] At least due to the use of the presentable data type system 24A and data typer 25, the data diode 15 can be a truly unidirectional data diode. Currently known data diodes provide unidirectional flow of content data, but allow bidirectional flow of signaling, control, and / or management data by allowing positive acknowledgements and / or error conditions to be communicated from the data receiving end to the data sending end. However, the data diode 15 of the edge gateway system 1 can be truly unidirectional in that no type of data flows from its data receiving end to its data sending end. In fact, in embodiments, the data diode 15 is physically configured to prevent the communication of any type of data (e.g., signaling, control, management, content, etc.) from the edge-facing component 12 to the field-facing component 10, such as in embodiments in which the data diode 15 is implemented via an optical transmission medium. In this way, the data diode 15 of the edge gateway system 1 further protects the process plant 5 from possible security breaches from the external system 8 at least due to the truly unidirectional nature of the data diode 15.

[0024] At the edge-facing component 12 of the edge gateway system 1, the classified field content data received from the field-facing component 10 via the data diode 15 is stored in the data lake 40. The contextual knowledge miner 45 mines the data lake 40 to discover relationships and associations between various field content data stored in the data lake 40 and generates / modifies / updates the contextual knowledge base 48 such that the contextual knowledge base 48 includes the received field content data and indications of the discovered relationships and / or associations (e.g., contexts of the received field content data). In this way, the contextual knowledge base 48 stores process plant related or field content data (e.g., runtime data, event data, historical data, and / or other types of data provided by the process plant 5) and contextual information indicating relationships between the provided process plant related / field content data, conditions corresponding to generation, transmission, and / or receipt of the process plant related / field content data within the process plant 5, and / or other types of contexts of the process plant related / field content data. The knowledge stored in the contextual knowledge base 48 (e.g., content data and associated contextual information, and optionally other data) can be exposed to (e.g., available to) one or more external data consuming systems 8.

[0025] Indeed, the edge-facing component 12 provides one or more access mechanisms 48 via which the external data consuming systems 8 can access at least some of the knowledge stored in the contextual knowledge base 48. Each access mechanism can include a respective level of protection against possible security breaches from the external systems 8. For example, the access mechanisms 48 can be implemented using application programming interfaces (APIs), containers, etc. to help prevent unauthorized access by the external systems to the contextual knowledge base 48 and / or the process plant 5. In embodiments, at least one access mechanism 48 can include a respective server or protected application executing at the edge-facing component 12, such as a search engine, where a particular access mechanism for the server or private application (e.g., a server-specific or application-specific API) is exposed to the external systems 8 for their use. The edge-facing component 12 of the edge gateway system 1 and its subcomponents are discussed in more detail in other parts of this disclosure.

[0026] Generally speaking, the features, components, and architecture of the edge gateway system 1 provide near-unlimited access to process plant related data by external data consuming systems 8 in a highly secure manner without impacting the performance of the process plant 5. Additionally, because the edge gateway system 1 provides process plant related data to external systems 8 according to context, such as providing process plant related content data within the context of the configuration of the process plant 5, the external systems 8 can more quickly and easily find and consume process plant related data. Moreover, the edge gateway system 1 allows a variety of different types of data consuming applications to securely and easily operate on contextual knowledge corresponding to the process plant 5, such as mobile connected applications, advanced analytics applications, open systems technology applications (e.g., Node.JS, Docker, Linux, etc.), custom applications, IoT applications, IIoT applications, business and / or enterprise applications (e.g., Excel, Power BI, etc.), and / or other types of applications. Furthermore, the edge gateway system 1 is readily adaptable to aggregate process plant related data from multiple process plants and discover relevant aggregated knowledge therefrom, as well as aggregate data from external systems of higher security levels (e.g., weather forecasting systems, supply chain systems, financial systems, inventory management systems, etc.) and discover relevant aggregated knowledge therefrom.

[0027] Note that although Figure 1 The edge gateway system 1 is shown as including a single field-facing component 10 that is communicatively connected to the edge-facing component 12 via a unidirectional data diode 15, this is merely one of many possible arrangements. For example, in some embodiments, the field-facing component 10 and the edge-facing component 12 can be implemented as an integrated component within the edge gateway system 1, and the data diode 15 can be omitted. In some embodiments, the field-facing component 10 and the data diode 15 can be implemented as an integrated component of the edge gateway system 1, or the data diode 15 and the edge-facing component 12 can be implemented as an integrated component. In some embodiments, multiple instances of the data diode 15 can be included in the edge gateway system 1, such as when an integrated field-facing component 10 / data diode instance 15 is communicatively connected to an integrated data diode instance 15 / edge-facing component 12. In other embodiments, the edge gateway system 1 can include a single edge-facing component 12 that is communicatively connected to multiple field-facing components 10 via respective data diodes 15. In these embodiments, the edge gateway system 1 can serve an entire process plant site, where field-wide data can be aggregated at the edge-facing component 12 and operated on by various applications, such as monitoring applications, analytics applications, reporting applications, display applications, etc. The configuration of a single edge-facing component 12 and multiple field-facing components 10 can likewise be useful for serving multiple process plant sites, multiple process control systems, and / or other distributed configurations within an entire enterprise.

[0028] Process plant and related data sources

[0029] Figure 2 is a block diagram of an example process plant 100 configured to control an industrial process during online or runtime operation, and from which process plant related data can be securely communicated via embodiments of the edge gateway system 1. For example, Figure 1 The process plant 5 can include Figure 2 at least portions of the process plant 100. As Figure 2 shown, the process plant 100 is communicatively connected to an edge gateway system 102, which can be, for example, Figure 1 an embodiment of the edge gateway system 1.

[0030] The process plant 100 (also referred to herein interchangeably as a process control system 100 or a process control environment 100) includes one or more process controllers that receive signals indicative of process and / or other types of measurements made by field devices, process that information to implement control routines, and generate control signals that are sent over wired or wireless process control communication links or networks to other field devices to control operation of an industrial process in the plant 100. Typically, at least one field device performs a physical function (e.g., opens or closes a valve, raises or lowers a temperature, makes a measurement, senses a condition, etc.) to control operation of the process. Some types of field devices communicate with controllers by using I / O devices and / or I / O electronic encapsulation devices, hubs, servers, or systems. Process controllers, field devices, and I / O devices can be wired or wireless, and any number of wired and wireless process controllers, field devices, and I / O devices, and combinations thereof, can be included in the process plant environment or system 100.

[0031] For example, Figure 2A process controller 111 is shown that is communicatively connected to wired field devices 115-122 via input / output (I / O) cards 126 and 128, and to wireless field devices 140-146 via a wireless gateway 135 and a process control data highway or trunk 110. The process control data highway 110 can comprise one or more wired and / or wireless communication links, and can be implemented using any desired or suitable or communication protocol, such as an Ethernet protocol, an IP or other packet protocol, etc. In some configurations (not shown), the controller 111 can be communicatively connected to the wireless gateway 135 using one or more communication networks other than or in addition to the trunk 110, such as by using any number of other wired or wireless communication links that support one or more communication protocols, data protocols, and / or industrial automation protocols, e.g., a Wi-Fi or other IEEE 802.11 compliant wireless local area network protocol, a mobile communication protocol (e.g., WiMAX, LTE, or other ITU-R compliant protocol), HART-IP, other packet protocols, streaming protocols, Profibus, Fieldbus, etc.

[0032] The controller 111, e.g., a DeltaV TM controller sold by Emerson Automation Solutions, can be operative to implement a batch or continuous process using at least some of the field devices 115-122 and 140-146. In embodiments, the controller 111 is communicatively connected to at least some of the field devices 115-122 and 140-146 using any desired hardware and software associated with, e.g., standard 4-20 mA devices, I / O cards 126, 128, and / or any smart communication protocol (e.g., HART, Fieldbus protocol, protocol, protocol, etc.) in addition to being communicatively connected to the process control data highway 110. In Figure 2 embodiments, the controller 111, field devices 115-122, and I / O cards 126, 128 are wired devices, while the field devices 140-146 are wireless field devices. Of course, the wired field devices 115-122 and wireless field devices 140-146 can conform to any other desired standard or protocol, such as any wired or wireless protocol, including any standard or protocol developed in the future.

[0033] Figure 2The process controller 111 includes a processor 130 that implements or monitors one or more process control routines 138 (e.g., stored in memory 132). The processor 130 is configured to communicate with the field devices 115-122 and 140-146, and with other nodes communicatively coupled to the controller 111. It should be noted that any of the control routines or modules described herein can have portions thereof implemented or performed by different controllers or other devices, if desired. Likewise, the control routines or modules 138 described herein that are to be implemented within the process control system 100 can take any form, including software, firmware, hardware, etc. The control routines can be implemented in any desirable software format, such as using object oriented programming, ladder logic, sequential function charts, function block diagrams, or using any other software programming language or design paradigm. The control routines 138 can be stored in any desirable type of memory 132, such as random access memory (RAM) or read only memory (ROM). Likewise, the control routines 138 can be hard coded into, for example, one or more EPROMs, EEPROMs, application specific integrated circuits (ASICs), or any other hardware or firmware elements. Thus, the controller 111 can be configured to implement control strategies or control routines in any desirable manner.

[0034] The controller 111 implements control strategies using what are commonly referred to as function blocks, where each function block is an object or other portion of an overall control routine (e.g., a sub-routine) and operates together with other function blocks (via communications referred to as links) to implement process control loops within the process control system 100. Based on the control, the function blocks generally perform one of the following: an input function, such as those associated with transmitters, sensors, or other process parameter measurement devices; a control function, such as those associated with control routines that perform PID, fuzzy logic, etc. control; or an output function, controlling operation of some devices such as valves, to perform some physical function within the process control system 100. Of course, there are hybrid and other types of function blocks. Function blocks can be stored in and executed by the controller 111, as is commonly done when these function blocks are used to control or monitor standard 4-20 mA devices and the like, or can be stored in and executed by the field devices themselves, as is commonly done with more intelligent field devices or those associated with Fieldbus devices. Devices. The controller 111 can thus include one or more control routines 138 that can implement one or more control loops that are executed by performing one or more function blocks.

[0035] ​The wired field devices 115-122 can be any type of device such as sensors, valves, transmitters, positioners, etc., and the I / O cards 126 and 128 can be any type of I / O device that conforms to any desired communication or controller protocol. In Figure 2 the field devices 115-118 are standard 4-20 mA devices or devices that communicate with the I / O cards 126 over analog or combined analog and digital lines, and the field devices 119-122 are smart devices such as Fieldbus field devices that communicate with the I / O cards 128 over a digital bus using the Fieldbus communication protocol. However, in some embodiments, at least some of the wired field devices 115, 116, and 118-121 and / or at least some of the I / O cards 126, 128 can additionally or alternatively communicate with the controller 111 using the process control data highway 110 and / or by using other suitable control system protocols (e.g., Profibus, DeviceNet, Foundation Fieldbus, ControlNet, Modbus, HART, etc.).

[0036] In Figure 2 the wireless field devices 140-146 communicate via a wireless process control communication network 170 using a wireless protocol such as . Such wireless field devices 140-146 can communicate directly with one or more other devices or nodes of the wireless network 170 that are also configured to communicate wirelessly (e.g., using the wireless protocol or another wireless protocol). To communicate with one or more other nodes that are not configured to communicate wirelessly, the wireless field devices 140-146 can utilize a wireless gateway 135 that is connected to the process control data highway 110 or to another process control communication network. The wireless gateway 135 provides access to the various wireless devices 140-158 of the wireless communication network 170. In particular, the wireless gateway 135 provides communicative coupling between the wireless devices 140-158, the wired devices 115-128, and / or other nodes or devices of the process control plant 100. For example, the wireless gateway 135 can provide communicative coupling by using the process control data highway 110 and / or by using one or more other communication networks of the process plant 100.

[0037] Similar to wired field devices 115-122, wireless field devices 140-146 of wireless network 170 perform physical control functions within process plant 100, such as opening or closing valves or measuring process parameters. However, wireless field devices 140-146 are configured to communicate using the wireless protocol of network 170. Thus, wireless field devices 140-146, wireless gateway 135, and other wireless nodes 152-158 of wireless network 170 act as producers and consumers of wireless communication packets.

[0038] In some configurations of process plant 100, wireless network 170 includes non-wireless devices. For example, in Figure 2 middle, Figure 2 Field device 148 is a legacy 4-20mA device, while field device 150 is a wired device. Devices. For communication within network 170, field devices 148 and 150 can connect to wireless communication network 170 via corresponding wireless adapters 152A and 152B. Wireless adapters 152A and 152B support wireless protocols such as WirelessHART, and can also support other wireless protocols such as… Fieldbus, PROFIBUS, DeviceNet, and one or more other communication protocols. Furthermore, in some configurations, the wireless network 170 may include one or more network access points 155A, 155B, which may be separate physical devices communicating with the wireless gateway 135 via wired connections, or may be provided as an integrated device along with the wireless gateway 135. The wireless network 170 may also include one or more routers 158 to forward packets from one wireless device to another wireless device within the wireless communication network 170. Figure 2 In this context, wireless devices 140-146 and 152-158 communicate with each other and with wireless gateway 135 via wireless link 160 of wireless communication network 170 and / or via process control data high-speed channel 110.

[0039] exist Figure 2 In this process control system 100, one or more operator workstations 171 are communicatively connected to a high-speed data channel 110. Using the operator workstations 171, operators can view and monitor the operational status of the process plant 100, and can take any diagnostic, corrective, maintenance, and / or other necessary actions. At least some of the operator workstations 171 may be located in or near various protected areas of the plant 100, such as in the back-end environment of the plant 100, and in some cases, at least some of the operator workstations 171 may be located remotely but still communicatively connected to the plant 100. The operator workstations 171 can be wired or wireless computing devices.

[0040] The example process control system 100 is also shown to include a configuration application 172A and a configuration database 172B, each of which is also communicatively connected to the data highway 110. Various instances of the configuration application 172A can execute on one or more computing devices (not shown) to enable users to create or change process control modules and / or other types of modules, and to download these modules to the controllers 111 and / or other devices of the process control system 100 via the data highway 110, as well as to create or change operator interfaces via which operators can view data and change data settings within process control routines. The configuration database 172B stores the created (e.g., configured) modules and / or operator interfaces. Typically, the configuration application 172A and the configuration database 172B are centralized and have a single logical appearance to the process control system 100, although multiple instances of the configuration application 72a can execute concurrently within the process control system 5, and the configuration database 172B can be implemented on multiple physical data storage devices. Thus, the configuration application 172A, the configuration database 172B, and the user interface thereto (not shown) comprise a configuration or development system 172 for the control and / or display modules. Typically, but not necessarily, the user interface of the configuration system 172 is different from the operator workstations 171, as configuration and development engineers utilize the user interface of the configuration system 172, whether or not the plant 100 is operating in real-time, while operators utilize the operator workstations 171 during real-time operation of the process plant 100 (also referred to herein interchangeably as "runtime" operation of the process plant 100).

[0041] The example process control system 100 includes a data historian application 173A and a data historian database 173B, each of which is also communicatively connected to the data highway 110. The data historian application 173A operates to collect some or all of the data provided over the data highway 110 and to historize or store the data in the historian database 173B for long-term storage. Like the configuration application 172A and the configuration database 172B, the data historian application 173A and the historian database 173B are centralized and have a single logical appearance to the process control system 100, although multiple instances of the data historian application 173A can execute concurrently within the process control system 100, and the data historian 173B can be implemented on multiple physical data storage devices.

[0042] In some configurations, process control system 100 includes one or more other wireless access points 174 that communicate with other devices using other wireless protocols, such as Wi-Fi or other IEEE 802.11 compliant wireless local area network protocols, mobile communication protocols (such as WiMAX (Worldwide Interoperability for Microwave Access), LTE (Long Term Evolution), or other ITU-R (International Telecommunication Union - Radio) compliant protocols), short wavelength radio communications (such as near field communications (NFC) and Bluetooth), or other wireless communication protocols. Typically, such wireless access points 174 allow handheld or other portable computing devices (such as user interface devices 175) to communicate over a corresponding wireless process control communication network that is distinct from wireless network 170 and supports a different wireless protocol than wireless network 170. For example, wireless or portable user interface devices 175 can be mobile workstations or diagnostic test devices used by operators in process plant 100 (such as an instance of one of operator workstations 171). In some cases, in addition to portable computing devices, one or more process control devices (such as controllers 111, field devices 115-122, or wireless devices 135, 140-158) also communicate using the wireless protocol supported by access points 174.

[0043] In some configurations, process control system 100 includes one or more gateways 176, 178 to systems external to current process control system 100. Typically, such systems are consumers or providers of information generated or manipulated by process control system 100. For example, process control plant 100 can include gateway node 176 to communicatively couple current process plant 100 with another process plant. Additionally or alternatively, process control plant 100 can include gateway node 178 to communicatively couple current process plant 100 with an external public or private system, such as a laboratory system (e.g., a laboratory information management system or LIMS), an operator tour database, a material handling system, a maintenance management system, a product inventory control system, a production scheduling system, a weather data system, a shipping and handling system, a packaging system, the Internet, another provider's process control system, or other external system.

[0044] Note that although Figure 2Only a single controller 111 included in the example process plant 100 is shown, along with a limited number of field devices 115-122 and 140-146, a wireless gateway 35, a wireless adapter 152, an access point 155, a router 1158, and a wireless process control communication network 170. This is merely an exemplary and non-limiting embodiment. Any number of controllers 111 may be included in the process control plant or system 100, and any controller 111 can communicate with any number of wired or wireless devices and networks 115-122, 140-146, 135, 152, 155, 158, and 170 to control the processes in plant 100.

[0045] like Figure 2 As shown, and for purposes of clarity rather than limitation, see references. Figure 1 The process plant 100 is communicatively connected to the edge gateway system 102, which can be Figure 1 An embodiment of the edge gateway system 1. For example, process plant 100 can be communicatively connected to the field-facing component 10 of the edge gateway system 1 via one or more process plant communication networks, data networks and / or links, directly and / or via a corresponding gateway of process plant 100. For example, the field-facing component 10 of the edge gateway system 1 can be communicatively connected to process plant 100 via networks 110, 170, via gateways 135, 176, 178 and / or via other networks, links and / or gateways associated with the process plant, and the field-facing component 10 receives or obtains data generated by various data sources 30 associated with process plant 100 via the above networks, links and / or gateways.

[0046] Generally, the network / link 28 through which the data source 30 and the edge gateway system 1 obtain process plant-related data can be at a lower level of the Purdue model or a similar security level (e.g., level 0 to level 2), and can include controllers, field devices, I / O cards, and other types of process control devices. Furthermore, it should be understood that the set of data sources 30 associated with the process plant is not limited to process control devices that directly generate first-order process data, but may additionally or alternatively include any devices or components within and / or associated with the process plant 100 that generate process data and / or other types of data as a result of the process plant 100 controlling online processes. For example, the set of data sources 30 may include modules, alarms, event history records, batch systems and / or history records, diagnostic devices or components that generate diagnostic data, network routing devices or components that transmit information between various components and / or devices in the process plant 100, asset management systems, configuration systems, analysis systems, mobile devices, software-defined networks, virtual networks such as virtual private networks, VLANs, and / or VXLANs, etc. In practice, Figure 2Any one or more components shown (e.g., components 111, 115-122, 126, 128, 135, 140-146, 152, 155, 158, 160, 170, 171-176, 178) and Figure 2 Other components not shown may be data source 30, which generates process plant related data that can be provided via edge gateway systems 1, 102 for consumption by one or more external systems 8.

[0047] Field-facing components

[0048] Figure 3 This is a block diagram of a field-oriented component 300 that can be included in an edge gateway system (e.g., edge gateway system 1 or edge gateway system 102). For example, the field-oriented component 300 could be... Figure 1 The field-facing component 10 shown, and / or may be connected with Figure 2 The process plant 100 communication connection. For illustrative purposes, and not for limitation, please refer to [reference needed]. Figure 1 and 2 To describe Figure 3 However, it should be understood that the field-oriented component 300 may be included in an edge gateway system other than edge gateway system 1 or 102, and may communicate with process plants other than process plant 5 or process plant 100.

[0049] like Figure 3 As shown, the field data receiver 302 of the field-oriented component 300 can communicate with a process plant, such as process plant 5 or 102, and optionally with other systems, devices, and / or applications that support and / or are associated with the process plant during its operation, such as process control systems, safety instrumentation systems, configuration systems, analysis systems, communication / network systems, asset management systems, diagnostic and / or testing tools and / or systems, commissioning tools and / or systems, user equipment and / or operator interfaces, historical database systems, batch systems, software-defined networks, virtual networks such as virtual private networks, VLANs, and / or VXLANs, and other systems, networks, applications, and / or devices associated with the process plant. Generally, the process plant and its supporting systems to which the field-oriented component 300 communicates operate at security levels 0-2 of the Purdue model (or a similar security hierarchy). For ease of discussion and not for limitation, the term “process plant 5” is used in common to refer to the physical process plant with which the field-facing component 300 communicates, as well as other systems associated with and communicatively connected to the physical process plant that generate and / or transmit data at a lower security level.

[0050] The field data receiver 302 is communicatively connected to the process plant 5 via one or more links, communication networks, and / or data networks 305 of the process plant 5 (which are collectively referred to herein as “process plant networks 305”). The process plant networks 305 can include any number of wired and / or wireless links and / or networks that support one or more communication protocols, data protocols, and / or industrial automation protocols, such as Ethernet, IP or other types of packet protocols, Wi-Fi or other IEEE 802.11 compliant wireless local area network protocols, mobile communication protocols (such as WiMAX, LTE, or other ITU-R compliant protocols), other standardized communication and / or data protocols, such as those managed by the Internet Engineering Task Force (IETF), the Institute of Electrical and Electronics Engineers (IEEE), or the International Organization for Standardization (ISO), HART-IP, Profibus, Fieldbus, Field Device Integration (FDI), OPC (Object Linking and Embedding for Process Control) UA (Unified Architecture), other types of industrial automation protocols, and the like. For example, the process plant networks 305 can include the process plant networks 28, the wireless network 170, the trunk 110, and any other wired and / or wireless networks and / or links used in the process plant 5 and its related systems, such as asset management networks, historian networks, data analytics networks, software defined networks, virtual networks such as virtual private networks, VLANs, and / or VXLANs, diagnostic and / or test networks, configuration networks, and / or other types of networks corresponding to the operation, maintenance, and / or configuration of the process plant 5.

[0051] The field data receiver 302 obtains one or more field configurations of the process plant 5 from the process plant 5 via the process plant networks 305. For example, when the process plant 5 includes a DeltaV process control system provided by Emerson Automation Solutions, the field data receiver 302 obtains one or more FHX files in which the configuration of the process control system and its components (e.g., physical, logical, and data components) are defined, for example, via the configuration application 172A. The interest manager 308 defines, creates, generates, and updates the presentable data type system or collection 310 based on the obtained field configurations of the process plant 5. As described in greater detail in other portions of this disclosure, the field-facing component 300 communicates the presentable data type system or collection 310 to its respective edge-facing component (e.g., the edge-facing component 12). In example embodiments, the presentable data type system or collection 310 is Figure 1 the presentable data type system 24A.

[0052] In general, to define, create, generate and update the presentable data type system 310, the interest manager 308 extracts information from the obtained live data configuration, where the extracted information is allowed to be presented (e.g., presentable) to external data consuming systems 8. Whether or not a particular piece of information included in the obtained live configuration is allowed to be presented to external systems 8 can be predefined, e.g., by the edge gateway system, the live-oriented component 300 and / or by a user via one or more interest lists 315, and / or can be indicated online during the extraction process, e.g., by the edge gateway system, the live-oriented component 300 and / or by a user. Regardless, the interest manager 308 defines, names, maps, transforms, groups, assigns and / or otherwise arranges the extracted information into respective data types and configurations of the presentable data type system 310, e.g., by using a generally understood syntax, such as a standard or open source syntax. Thus, the presentable data type system 310 provides a common understanding of the types of presentable process plant related data included in the live content data (e.g., which can include process plant related data types, parameter types, block types, module types, event types, historical data types, device and device component types, display and display component types, and other types of process plant related data generated by the process plant) by using a syntax that is inherently understood by external data consuming systems 8.

[0053] For example, the presentable data type system 310 can include basic data types such as floating point, floating point with status, signed integer, unsigned integer, and the like, as well as other basic data types that are inherently understood by external data consuming systems 8. In addition, the presentable data type system 310 can include more complex data configuration type definitions that are defined and structured based at least in part on the basic data types, examples of which are shown in Figures 4A-4C Some data types of the presentable data type system 310 can include multiple fields, as shown by example schema type 312a that has been defined to include four fields of type ENUM in Figure 4A Indeed, the presentable data type system 310 can include types based on multiple enumerations, which can be user-defined or system-defined. For example, as shown in Figure 4C part 312b of an example set of enumerations included in the presentable data type system 310 is named and defined to indicate discrete HART status used in the process plant 5. Figure 4B part 312c, which shows an even more complex example, where a Causal Element Matrix (CEM) function block of the process plant 5 is defined within the presentable data type system 310 by using block types. Of course, the presentable data type system 310 can include more presentable data type definitions and / or configurations than the examples shown in Figures 4A-4C ​

[0054] Generally, the system or collection of presentable data types 310 generated or defined by the interest manager 308 need not conform to the data types, configurations, hierarchies, and architectures already defined in the process plant 5 (although some presentable data types 310 can be defined to conform at least in part to the defined process plant data architectures and configurations, if desired). Additionally, it will be appreciated that the generation or definition of the system or collection of presentable data types 310 is generally not a one-to-one conversion or mapping of the defined process plant data types to corresponding presentable data types. Rather, only the process plant data types that are allowed to be presented to the external data consuming systems 8 are included in the collection / system 310, and such presentable process plant data types are reconfigured, rearranged, regrouped, merged, distributed, abstracted, defined, and / or otherwise expressed in the comprehensive data type system 310 that is not only more useful syntactically, but also more useful and / or easier to utilize by the external systems 8 in terms of the structure and arrangement of the content.

[0055] In particular, as noted above, in certain embodiments the interest manager 308 extracts the presentable data type system 310 from the obtained live configuration of the process plant 5 based at least in part on one or more interest lists 315. The interest lists 315 indicate which types of process plant related data can be presented by the field-facing component 300 to the external data consuming systems 8, and the interest lists 315 can be defined by a user, the field-facing component 300, the edge gateway system 1, and / or by some other computing system, such as via an interest list configuration application provided by the field-facing component 300. For example, the field-facing component 300 can provide a web-based user interface via which a user can manually define one or more interest lists 315, such as by using JSON (JavaScript Object Notation) or some other type of scripting or notation. Additionally or alternatively, the field-facing component 300, the edge gateway system 1, and / or some other computing system can automatically determine or define one or more interest lists 315, such as by using templates and best practices, by including commonly written and / or read data points (e.g., via mining and / or analysis of operator interface data, process history data, event history data, etc.), and / or by using some other suitable automated technique. In embodiments, the collection of interest lists 315 at the field-facing component 300 define the only data from the totality of data obtained by the field-facing component from the process plant that is allowed to be presented by the field-facing component to one or more external systems for consumption. If desired, different field-facing components 300 of the process plant 5 can store different collections of interest lists 315, indicating particular types of process plant related data that are respectively allowed to be presented by the hosting field-facing component to the data consuming systems 8.

[0056] The interest lists can indicate, for example, names and corresponding groupings or arrangements of related modules, nodes, diagnostics, alarms, events, and / or other field data information that can be configured across multiple configurations, sometimes entirely different configurations, within the process plant 5. In practice, the interest lists 315 are not required to conform to the defined configuration hierarchy and / or configuration content of the process plant 5 (although some interest lists 315 can be defined to at least partially conform to the defined process plant configuration hierarchy and / or configuration content, if desired). Generally speaking, the interest lists 315 can be defined in any manner (e.g., organizationally, hierarchically, and / or content-wise) that is useful and / or readily utilized by the external systems 8 as consumers of the exposed process plant related data. For example, at least some of the interest lists 315 can be named to reflect particular plant equipment and / or devices (e.g., "Diesel Hydroprocessor 1," "Alkylation Unit 3," etc.) and can be defined using parameters from several different modules, nodes, diagnostics, alarms, etc. that are defined from the process plant 5 and that are relevant to the particular plant equipment / device from multiple different configurations. For example, the field data content ingestor 320 can utilize a particular interest list 315 to extract particular field content data (e.g., control data, I / O data, diagnostic data, equipment data, etc.) that is collectively identified by the particular interest list 315 as being representative of a particular named entity (e.g., "Diesel Hydroprocessor 1," "Alkylation Unit 3," etc.) and can store the extracted data corresponding to the particular named entity in the cache 322, for example, as-is and / or in reorganized fashion (such as by using the exposeable data type system 310A), such that the extracted data corresponding to the particular named entity of the particular interest list 315 is exposed to the external systems 8 via the edge-oriented component 12.

[0057] For example, the "Spray Tower 2" interest list can be defined to refer to a particular spray tower in the process plant 5 and can include all parameters related to "Spray Tower 2" that are included in the asset management system, the process control system, the safety instrumented system, the diagnostic tool, the historian system, the software defined network, the on-premise configuration of virtual networks such as virtual private networks, VLANs, and / or VXLANs, etc. For example, the "Spray Tower 2" interest list can include parameters indicative of the area in which the spray tower 2 is located; parameters indicative of pipes, pumps, and other container, line, and other physical component devices included in the spray tower 2 (e.g., which can be referenced within the on-premise configuration by device tags and other types of physical component tags or identifiers); parameters indicative of logical process elements such as control loops and modules, control parameters and / or variables (e.g., set points, measurements, control signals, other signals, etc.), alarms, events, operational states or conditions, device or equipment states or conditions, timestamps, and other logical and / or data components included in and / or utilized by the spray tower 2 (e.g., which can be referenced within the on-premise configuration by control tags, device signal tags, or other types of logical component tags or identifiers), etc. Further, the "Spray Tower 2" interest list can be indicative of other characteristics and / or aspects of the parameters such as respective units of measurement, respective ranges, respective target values or set points, respective control routines or other applications that utilize the parameters; respective usage, respective diagnostic parameters, and / or other respective characteristics and / or associated information.

[0058] In some embodiments, based on generating the interest list 315, the interest manager 308 can determine one or more changes to one or more on-premise configurations stored in the process plant 5 and can communicate the determined changes to the configuration application 172A or other process plant related configuration application via the process plant network 305, as indicated by reference numeral 318.

[0059] Returning now to the field data receiver 302, in addition to the field configuration, the field data receiver 302 also obtains field content data from the process plant 5 via the process plant network 305, including data generated by the process plant 5 in operating to control the industrial process, as well as other data related to the process plant 5 operating to control the industrial process. In general, the field content data can include any type of data generated by the process plant 5, such as data generated by process control systems, configuration systems, analytics systems, communication / network systems, asset management systems, diagnostic and / or test tools and / or systems, commissioning tools and / or systems, user devices and / or operator interfaces, historian systems, batch systems, software defined networks, virtual networks such as virtual private networks, VLANs, and / or VXLANs, and other systems, networks, applications, and / or devices associated with the process plant. For example, the field content data can include runtime process data, continuous process data, batch process data, batch history data, event data, alarm data, analytics data, diagnostic data, environmental data, user interface data, performance data, and / or other types of payload data generated by the data sources 30. The field data receiver 302 can receive the field content data via the process plant network 305 in any protocol used by the process plant network 305, such as Ethernet, WirelessHART, HART-IP, and / or other packet protocols, streaming protocols, etc.

[0060] The live content data ingestor 320 ingests the obtained live data content based on the interest list 315, can perform processing on at least a portion of the ingested live data content, and stores the ingested live data content in a cache or other type of memory 322 of the live-facing component 300 for eventual transfer to its respective edge-facing component (e.g., edge-facing component 12). The live content data ingestor 320, together with the live data receiver 302, can obtain live content data for ingestion in one or more different ways. For example, for live content data published by respective sources 30 and included on the interest list 315, the live content data ingestor 320 can cause the live data receiver 302 to subscribe to publication of such live content data, e.g., on behalf of the live-facing component 300. In another example, for some live content data included on the interest list 315, the live content data ingestor 320 can initiate querying of live content data by respective data sources 30, e.g., in accordance with at least some of the configured or defined interest list 312, e.g., via polling and / or via a request / response mechanism. In yet another example, for some live content data included on the interest list 315, the live content data ingestor 320 can discard or filter out any live content data obtained at the live-facing component 300 via the live data receiver 302 and not indicated on the interest list 302. In yet another embodiment, some interest lists 315 can define or indicate which types of live content data are to be excluded from presentation to external sources 8, rather than defining or indicating live content data to be presented to external sources 8. If and when such non-presentable live content data is received at the live-facing component 300, the live content data ingestor 320 can discard or filter out such live content data so that the excluded live content data is not stored into the cache 322 and prevented from being transferred to the edge-facing component.

[0061] In some embodiments, the interest list 315 can indicate showable live content data of interest that is not generated by the process plant related data sources 30, but is derived or generated from live content data generated by the process plant related data sources 30. Such second order live content data can be determined or generated by one or more computational engines 325 invoked by the live content data ingestor 320. Generally, the computational engines 325 operate on first order live content data obtained via the process plant network 308 to generate one or more outputs, where the outputs of the computational engines 325 are defined as showable live content data on one or more interest lists 315. The outputs of the computational engines 325 can be stored in the cache 322 along with other first order live content data for eventual transfer to the edge facing components. The computational engines 325 can perform computational functions such as input stream data aggregation and / or processing (e.g., mean, maximum, minimum, etc.). The computational engines 325 can perform more complex computations or algorithms such as principal component analysis (PCA), partial least squares (PLS) prediction, and / or other types of statistical computations or analysis. The computational engines 325 can perform process control specific computations such as function blocks, shadow blocks, and / or control module operations. At least some of the computational engines 325 can be defined and / or configured by scripts and / or a web-based user interface or other type of computational engine configuration application provided via the live facing component 300, at least some of the computational engines 325 can be defined and / or configured by using containers (such as Docker containers and / or other suitable types of containers) that are accessible by and / or installed at the live facing component 300.

[0062] In addition to the computational engines 325, the live content data ingestor 320 can invoke a data classifier 328 to transform at least a portion of the obtained showable live content data into respective showable data types according to the showable data type system 310. That is, the data classifier 328 represents the showable live content data using the names, structures, groupings, values, arrangements, etc. defined by the showable data type system 310. The live content data ingestor 320 stores the classified live content data into the data cache 322 as showable live content data related to the process plant 5 for transfer to the edge facing components.

[0063] The presentation data provider 330 of the field-facing component 300 provides presentable data configuration and presentation data content to the edge-facing component corresponding to the field-facing component 300, e.g., via the data diode 15 or via some other suitable data transfer mechanism. For example, the presentation data provider 330 can send the presentable data configuration of the presentable data type system 310 to the edge-facing component, e.g., on behalf of the field-facing component 300, to enable the edge-facing component to interpret the presentation data content sent by the field-facing component 300. Subsequently, the presentation data provider 330 can retrieve the stored presentation field data content stored in the cache 322 and send the retrieved data to the edge-facing component. The presentation data provider 330 can send the presentable data configuration and presentation data content using a streaming protocol and / or a common or popular data exchange format, such as JSON or some other standardized and / or open source data exchange format. For example, the field-facing component 300 can provide a streaming service that the presentation data provider 330 utilizes to stream data to its corresponding edge-facing component, e.g., via the respective unidirectional data diode 15. In embodiments, the presentation data provider 330 wraps the presentable data configuration and presentation data content with a streaming protocol implemented using a common or popular data exchange format. In some embodiments, the presentation data provider 330 sends the presentable data configuration and presentation data content to the edge-facing component using a proprietary or private protocol that can be a proprietary or private streaming protocol. In some embodiments, the presentation data provider 330 encrypts the presentation data configuration and presentation data content before transmitting it to the edge-facing component.

[0064] In embodiments, the presentation data provider 330 publishes the presentable data configuration and presentation data content, e.g., over the data diode 15. The edge-facing component subscribes to the information published by the presentation data provider 330 of the field-facing component 300, thereby obtaining the presentable data configuration and presentation data content, which can make the presentable data configuration and presentation data content available to external data consumption systems 8 at the edge-facing component, as described in greater detail elsewhere in this disclosure.

[0065] Note that, in Figure 3 , although the field data receiver 302, the interest manager 308, the field content data ingester 320, the data classifier 328, and the presentation data provider 330 are shown as distinct components of the field-facing component 300, this is for clarity of discussion only and not for limitation. In practice, any two or more of the components 302, 308, 320, 328, and 330 can be implemented as an integral component of the field-facing component 300, if desired.

[0066] Edge-facing components

[0067] Figures 5A-5B A block diagram of an edge-facing component 400 that can be included in an edge gateway system, such as the edge gateway system 1 of Figure 1 or the edge gateway system 102 of Figure 2 is shown. For example, the edge-facing component 400 can be the edge-facing component 12 shown in Figure 1 and / or can be communicatively connected with a field-facing component 10 or 300, e.g., via a data diode 15 or another connection link, network, or medium. For ease of illustration, and not by way of limitation, the edge-facing component 400 is described with simultaneous reference to Figures 1-3 and Figure 5A and 5B but it is understood that the edge-facing component 400 can be included in an edge gateway system other than the edge gateway system 1 or 102 and can be in communicative connection with a field-facing component other than the field-facing component 10 or 300.

[0068] As shown in Figure 5A , the presentation data receiver 402 of the edge-facing component 400 can be communicatively connected with a field-facing component that is, in turn, communicatively connected with a process plant, such as the process plant 5 or 102, and optionally other systems, devices, and / or applications that support the process plant and / or are associated with the process plant in its runtime operation, such as a process control system, a safety instrumented system, a configuration system, an analytics system, a communication / network system, an asset management system, a diagnostic and / or test tool and / or system, a commissioning tool and / or system, a user device and / or operator interface, a historian system, a batch system, a software-defined network, a virtual network such as a virtual private network, VLAN, and / or VXLAN, and other systems, networks, applications, and / or devices associated with the process plant. Generally speaking, the process plant and its supporting systems to which the field-facing component corresponding to the edge-facing component 400 is communicatively connected operate at security levels 0-2 of the Purdue model (or similar security hierarchy).

[0069] The presentation data receiver 402 of the edge-facing component 400 is communicatively connected with the edge-facing component 400 and the corresponding field-facing component via one or more links, communication networks, and / or data networks. In preferred embodiments, the presentation data receiver 402 is communicatively connected with the edge-facing component 400 and the corresponding field-facing component via a data diode, e.g., Figure 1The edge-facing components 400 are communicatively connected to the corresponding field-facing components via unidirectional data diodes 15, as shown in FIG. 1. For ease of discussion, but not by way of limitation, the edge-facing components 400 are described below as being communicatively connected to the field-facing components via the data diodes 15, but it should be understood that other communicative connections in addition to the data diodes 15 can interconnect the edge-facing components 400 and the field-facing components. For example, in some embodiments, the edge-facing components 400 and the field-facing components can be included in an integrated system or device.

[0070] The presentation data receiver 402 can receive presentation data configuration and presentation data content from the field-facing components. The presentable data configuration and the presentation data content can be received via a streaming protocol and / or via a common or commonly used data exchange format, such as JSON or some other standardized and / or open source data exchange format. In some embodiments, the presentation data configuration and the presentation data content can already be packaged in a streaming protocol at the field-facing component end, and the presentation data receiver 402 unpacks or extracts the presentation data configuration and the presentation data content from the data stream. In some embodiments, the presentation data configuration and the presentation data content can have been encrypted at the field-facing component end, and the presentation data receiver 402 decrypts the information received via the data stream. In some embodiments, the field-facing components publish the presentable data configuration and the presentation data content, e.g., through the data diodes 15. The edge-facing components 400 subscribe to the information published by the field-facing components, thereby obtaining the presentable data configuration and the presentation data content from the field-facing components.

[0071] The presentable data configuration received at the presentation data receiver 402 collectively defines a presentable data type system (e.g., the presentable data type system 24A or 310) that has been generated by the field-facing components based on process plant related configuration (e.g., in the manner described above). The presentation data receiver 402 locally stores the received presentable data configuration as a local copy 24B of at least a portion of the presentable data type system 24A of the field-facing components in one or more memories.

[0072] The presentation data content received at the presentation data receiver 402 is represented using the respective data types included in the presentable data type system 24B. The received presentation data content can include live content data generated by the process plant 5, such as data generated by process control systems, configuration systems, analytics systems, communication / network systems, asset management systems, diagnostic and / or test tools and / or systems, commissioning tools and / or systems, user devices and / or operator interfaces, historian systems, batch systems, software defined networks, virtual networks such as virtual private networks, VLANs, VXLANs, and other systems, networks, applications, and / or devices associated with the process plant. For example, the live content data can include runtime process data, continuous process data, batch process data, batch history data, event data, alarm data, analytics data, diagnostic data, environmental data, user interface data, performance data, and / or other types of payload data generated by the data sources 30. Additionally, the received presentation data content can include data that has been derived or generated from the live content data by the live-facing components corresponding to the edge-facing component 400, such as derived or generated by one or more compute engines 325 of the live-facing components. The presentation data receiver 402 provides the received presentation data content to the presentation data ingester 405 of the edge-facing component 400 for interpretation, possible additional processing, and storage, such that the presentation data content (and possible additional content) is available for use by data consuming applications and / or systems, as represented by block 422 in Figure 5B

[0073] In particular, the presentation data ingester 405 utilizes a local copy of the presentable data type system 24B to interpret the presentation data content received from the live-facing components. In this way, the presentation data ingester 405 and the edge-facing component 400 do not need to (and in fact do not) know any internal or local data definitions and / or configurations of the process plant 5. That is, the edge-facing component 400 interprets the received presentation data content based on the received presentable data configuration that has been stored in the presentable data type system 24A corresponding to the live-facing components, and the edge-facing component 400 does not need to send any communications to the live-facing components to obtain and / or reconcile the data configuration. This technique protects the process plant 5 from possible security breaches, as no administrative and / or control messages need to be sent from the edge-facing component to the live-facing components that are communicatively connected to the process plant 5, thereby eliminating a possible point of entry for malicious actors. Moreover, this technique allows configuration changes in the process plant 5 to be communicated to the edge-facing component 400 online, in real-time, and incrementally, if desired. Still further, this technique allows a single edge-facing component 400 to serve multiple different live-facing components that utilize different presentable data type systems.

[0074] ​In some embodiments, the edge-facing component 400’s exhibit data ingestor 405 can derive and / or generate additional data from the received exhibit data content. For example, the exhibit data receiver 402 can invoke one or more compute engines 408 to operate on at least some of the received exhibit data content, thereby generating additional data content that can be used by the data consumption applications and / or systems 422. The compute engines 408 can be stored at the edge-facing component 400 and can perform computational functions on the payload values of the data, such as instruction stream data aggregation and / or processing (e.g., mean, maximum, minimum, etc.). Some compute engines 408 can be configured to perform more complex computations or algorithms, such as principal component analysis (PCA), partial least squares (PLS) prediction, and / or other types of statistical computations or analysis, compute key performance indicators (KPIs), etc., and some compute engines 408 can be configured to drive events. At least some compute engines 408 can be defined and / or configured by scripts and / or via web-based user interfaces or other types of compute engine configuration applications provided by the edge-facing component 400, and / or at least some compute engines 400 can be defined and / or configured by using containers that are accessible to and / or installed at the edge-facing component 400. Indeed, some compute engines 408 can be made available for use by the data consumption applications and / or systems 422, such as in the manner described elsewhere within this disclosure.

[0075] The exhibit data ingestor 405 stores the received exhibit data content and any output generated by the compute engines 408 in a data lake 410, which database, for example, can be the data lake 40 of Figure 1 As the data lake 40 stores field content data received from the field-facing components, the data lake 40 reflects at least a portion of the totality of data related to the process plant 5 (e.g., runtime data, configuration data, event data, historical data, and other types of data generated by and related to the process plant 5), where the process plant-related data stored in the data lake 40 can be exhibited to (e.g., made available for use by) external data consumption systems 8. In some process plants, all of the data generated by the process plant 5 is reflected at the edge-facing component 400 and exhibited to the external systems 8, while in other process plants, only a subset of all of the data generated by the process plant 5 is reflected at the edge-facing component 400 and exhibited to the data consumption applications and / or systems 8, where the subset is defined by the collective set of interest lists 22, 315 that reside on the set of field-facing components of the process plant 5.

[0076] As previously mentioned, in some embodiments, in addition to reflecting process plant-related data, data lake 40 also stores relevant computational data generated by computing engine 408 at edge-oriented component 400 based on presentation content data received from process plant 5. Furthermore, in some embodiments, data lake 410 also stores data from other external data providing systems (e.g., systems outside process plant 5 that generate data that can be interpreted and / or analyzed in conjunction with process plant-related data) via one or more external data ingestors 412. Figure 5A (Not shown in the image) The received content data, and the other external data providing systems are typically at a higher security level than process plant 5. Such external data providing systems may include, for example, enterprise-level systems such as email systems, intranet systems, site business planning and logistics systems, scheduling systems, supply chain management systems, financial systems, accounting systems, inventory management systems, other company systems, other IT systems, etc., and / or may include third-party provided systems such as weather forecasting systems, stock market feeds, third-party provided OPC servers, etc. External data ingestor 412 may convert, modify, translate, and / or otherwise transform external data received from external data providing systems into a form consistent with the displayable data type system 24B. Furthermore, in some embodiments, external data ingestor 412 may invoke one or more computing engines 408 to operate on the acquired external data, thereby generating additional data stored in data lake 410. In some embodiments, the external data ingestor 412 may communicate with enterprise and / or third-party systems to obtain and / or coordinate appropriate data configurations, and in some embodiments, the external data ingestor 412 may update the data type display system 24B to include data types corresponding to those utilized by the enterprise and / or third-party systems. However, even though the edge-oriented component 400 may participate in bidirectional communication with the external data providing system, the process plant 5 is still protected from potential security breaches via external systems because the edge-oriented component 400 does not send (and in fact, can be physically prevented from sending) any communication to the field-oriented component communicating with the process plant 5.

[0077] Regardless, data lake 410 stores content data generated and received from the process plant 5 via field-facing components, and in some embodiments, stores content data generated and received from one or more external data providing systems. In some embodiments, data lake 410 may store additional data computed and / or derived from the received content data (whether process plant-related and / or externally generated) by one or more computing engines 408. Data stored in data lake 410 may be configured according to the presentable data type system 24B so that the data content can be easily consumed by applications and / or system 422.

[0078] The edge-facing component 400 includes a contextual knowledge miner 415 that operates on the contents of the data lake 410 to discover relationships and associations between various different data points of the data lake 410. That is, the contextual knowledge miner 415 discovers respective contexts of the data points of the data lake 410. For example, the contextual knowledge miner 415 can discover that a certain type of alarm is generated for a similar set of operating states of various different vendor’s field devices of a given age that are located in the same area of the process plant, or the contextual knowledge miner 415 can discover that a key performance indicator of a particular line within the plant corresponds to a rate of change of a particular valve relative to a rate of change of another particular valve. Regardless, the contextual knowledge miner 415 stores the discovered contexts and relationships along with the contents of the data lake 415 (collectively referred to herein as “knowledge”) in the contextualized plant knowledge base 420, e.g., in a connected domain. The contextualized process plant knowledge base 420 can be implemented, for example, using a graph database or other suitable model in which content data and its respective interconnections are stored. For example, a graph database node can correspond to a name or label included in the data lake 410, attributes stored at the node can include respective parameters, values, states, etc., and connectors between nodes and other nodes can represent interrelationships discovered by the contextual knowledge miner 415. Generally, the information stored in the contextualized process plant knowledge base 420 is made available to (e.g., consumable by) the data consumer applications and / or systems 422.

[0079] Note that, in Figure 5A , while the showcase data receiver 402, the showcase data ingester 405, and the contextual knowledge miner 415 are shown as different components of the edge-facing component 400, this is for clarity of discussion only and not for limitation. Indeed, any two or more of the components 402, 405, and 415 can be implemented as an integral component of the edge-facing component 400, if desired.

[0080] Continuing Figure 5BAs shown in the portion of the edge-facing component 400 shown in FIG. 4, the edge-facing component 400 provides a set of one or more access mechanisms 425 via which various types of data consuming applications and / or systems 422 can access information stored in the contextual knowledge repository 420, either directly or via other applications and access mechanisms. Data consuming applications and / or systems 422 that can utilize the access mechanisms 425 provided by the edge-facing component 400 can include, for example, external applications and / or systems 8, such as enterprise applications and / or systems 422a associated with an enterprise that owns, operates, and / or is otherwise associated with the process plant 5 and that are at a higher security level than the process plant 5 (e.g., email, intranet, site business planning and logistics, scheduling, supply chain management, financial, accounting, inventory management, corporate, and / or other IT applications and / or systems), and such as third party applications and / or systems 422b that consume process plant related knowledge (e.g., cloud computing applications / systems, external OPC servers, IoT applications / systems, IIoT applications / systems, etc.). In some arrangements, the data consuming applications and / or systems 422 can include plant related applications and / or systems 422c, which can be at a similar security level as the process plant 5, or even can be systems within the process plant 5, such as process control systems, analytics systems, etc. For example, at least some of the one or more access mechanisms 425 can be used by one or more applications that are specific to the process plant 5, such as a monitoring application, an analytics application, an optimization application, a virtualized device application, a process control application, an alarm management application, a device management application, a scheduling application, a low cost sensor application, a simulation application, an operator training application, a redundancy or backup application, a recovery application, a safety instrumented system application, a vibration monitoring application, an engineering application, an asset management application, a user interface application, or an application executing on a personal electronic device. As Figure 5B As shown, the data consuming applications and / or systems 422 can be communicatively connected to the edge-facing component 400 via one or more networks 423, which can be public networks, private networks, wired networks, and / or wireless networks. Additionally or alternatively, at least some of the data consuming applications 422, whether plant, enterprise, or third party, can be installed at the edge-facing component 400, as described in more detail below.

[0081] As Figure 5BAs shown, the access mechanisms 425 provided by the edge-facing component 400 include one or more APIs 428 that serve as direct access mechanisms to information stored in the contextual knowledge base 420. The one or more direct access APIs 428 can be implemented in accordance with, for example, a REST (Representational State Transfer) architecture, GraphQL or other suitable query language, and / or other standardized, open-source, interoperable data syntax, format, and / or architecture for APIs. For example, the APIs 428 can interface with C, C++, and / or C# applications, Python applications, Node.JS applications, and / or other types of applications (in languages, protocols, platforms, and frameworks supported or provided by the edge-facing component 400), and thus, the APIs 428 can be accessed using respective bindings. Other higher-level or more removed access mechanisms can leverage the one or more direct access APIs 428 to access knowledge and information stored in the contextual knowledge base 420.

[0082] Other access mechanisms 425 provided by the edge-facing component 400 include, for example, utilities 430, servers 432, services 435, and applications 438, to name a few. In general, the access mechanisms 425 collectively support various types of access to process plant-related knowledge stored in the contextual knowledge base 420, such as request / response, publish / subscribe, event-driven access, and the like. Each access mechanism 425 can leverage one or more direct access APIs 422 to access information stored in the contextual knowledge base 420. Some of the access mechanisms 425 can be exposed to external applications and / or servers 422, some can be exposed only to process plants 5 and associated other systems at a lower security level (e.g., OT level), and / or some can be exposed to the edge-facing component 400 itself. For example, at least one access mechanism 425 can include one or more replication mechanisms via which the data lake 410 and / or the contextual knowledge base 420 can be replicated, for example, for fault-tolerance, backup, and / or redundancy purposes.

[0083] Utilities 430 that can be provided by the edge-facing component 400 include, for example, query and / or search engines, natural language processors, and / or other types of contextual utilities. Additionally or alternatively, the utilities 430 can include computational utilities, such as calculations, resolutions, analyses, scripts, and the like. The utilities 430 can be implemented at the edge-facing component 400 using, for example, functions, algorithms, applications, and the like.

[0084] Servers 432 that can be provided by edge-oriented component 400 include, for example, OPC UA servers that expose process plant related knowledge to data consuming applications / systems 422 via OPC UA data models, e.g., via respective subscriptions; web servers that host one or more websites and / or web applications via which data consuming applications and / or systems 422 can interface with edge-oriented component 400 to access process plant related knowledge stored in contextual knowledge repository 420; and other types of servers. In some embodiments, one or more of servers 432 are not exposed to external applications and systems 422, but are provided for use by process plant 5 and / or lower security level systems associated with process plant 5. For example, edge-oriented component 400 can provide an I / O server that sends data between various components of process plant 5.

[0085] Services 435 that can be provided by edge-oriented component 400 include, for example, AMQP (Advanced Message Queuing Protocol) queuing services (e.g., publishing knowledge in JSON format); MQTT (Message Queuing Telemetry Transport) publish and subscribe services; and / or other similar purpose services, systems, and / or protocols that support the transmission of process plant related information to cloud computing applications and / or systems, IoT and / or IIoT applications and / or systems, event hubs, and / or other data consuming applications and / or systems 422 (e.g., via publish / subscribe mechanisms and / or point-to-point mechanisms). For example, services 435 can include OPC runtime services that can provide respective data sources for each external OPC server (which can be a plant, enterprise, or third party OPC server) that is a consumer of process plant related knowledge. In addition, services 435 can include other types of services such as authentication and / or authorization services for authenticating and / or authorizing data consuming applications and / or systems 422 (e.g., by leveraging OAuth2 or some other suitable standard), services that interact with mobile devices, web services, knowledge or information subscription managers, and / or any other types of services that can be exposed to and / or utilized by at least some of data consuming applications and / or systems 422.

[0086] In addition, edge-oriented component 400 can provide one or more applications 438 that access and operate on information stored in contextual knowledge repository 420. For example, some of utilities 430 can be implemented using applications 438, some web services can be implemented using applications 438. At least some of applications 438 can be provided by the enterprise, such as query engines and search engines. Some of applications 438 can be provided by third parties and can be exposed to and / or utilized by at least some of data consuming applications and / or systems 422.

[0087] In practice, the edge-oriented component 400 can support or provide a number of architectural constructs, platforms, and frameworks that enable the edge-oriented component 400 to support or provide utilities 430, servers 432, services 435, and / or applications 438 generated by an enterprise associated with the process plant 5 as well as generated by third parties. In some configurations, both enterprise-provided and third-party-provided utilities 430, services 432, and / or applications 438 can be installed at the edge-oriented component 400. For example, the edge-oriented component can support Docker, Linux, or other types of containers in which OPC UA servers, AMQP gateways, and various enterprise-provided access mechanisms 425 can be implemented at the edge-oriented component 400 and via which third-party-provided applications can be implemented at the edge-oriented component 400. For example, Docker and / or other types of containers can utilize the direct access API 428 to access information stored in the contextual knowledge base 420.

[0088] Additionally or alternatively, the edge-oriented component 400 can provide a Node.JS framework that supports web applications and services provided by the enterprise and / or third parties and installed at the edge-oriented component 400. The Node.JS framework can utilize the direct access API 428 to access information stored in the contextual knowledge base 420 and / or the Node.JS framework can invoke various utilities 430 (e.g., queries, searches, language processing, etc.) to access, obtain, and / or manipulate information stored in the contextual knowledge base 420.

[0089] Accordingly, and in view of the foregoing discussion, embodiments of the edge gateway system 1 securely connect the process plant 5 and associated networks with applications executing on the plant premises and with remotely executed applications, such as those hosted in the cloud and / or remote networks. Applications and / or systems consuming data generated by the process plant 5 and discovered relationships and / or knowledge included therein can securely access and obtain demonstrated contextual process plant knowledge with minimal or even no risk to the process plant 5 itself. Moreover, the edge gateway system 1 can operate continuously in environments with a permanent intranet connection, such as at security levels 3 and 4, and in environments with a public internet connection. The various security mechanisms and features of the edge gateway system 5, such as the physical separation of OT and IT networks and physical blocking of data flows into the process plant 5, secure boot and update, signed firmware and packet execution, encryption, custom demonstrable data type system, etc., protect the process plant 5 and its data and provide protection against data theft and security breaches. Additionally, in embodiments, the edge gateway system 1 and / or components thereof utilize or incorporate one or more security technologies described in commonly-owned U.S. Patent Application No. 15 / 332,622; commonly-owned U.S. Patent Application No. 15 / 332,690; and commonly-owned U.S. Patent Application No. 15 / 332,751, the entire disclosures of which are incorporated by reference herein, to further protect the process plant 5 and its data and provide further protection against data theft and security breaches.

[0090] When implemented in software, any of the applications, services, and engines described herein can be stored in any non-transitory computer-readable medium, such as storage devices including magnetic disks, optical disks, solid state memory devices, molecular memory storage devices or other storage devices, RAM or ROM of a computer or processor, etc. While the example systems disclosed herein are disclosed as including software and / or firmware executed on hardware, it is noted that such systems are merely illustrative and should not be considered limiting. For example, it is contemplated that any of these hardware, software, and firmware components could be implemented in specialized hardware, software, or any combination thereof. Accordingly, although the example systems described herein are described as being implemented in software executed on a processor of one or more computer devices, it is noted that the examples provided are not the only way such systems can be implemented.

[0091] Thus, although the present application has been described with reference to specific examples, it is to be understood that these are only illustrative of the present application and are not to be considered limiting. Various modifications, additions or deletions can be made to the disclosed embodiments by those skilled in the art without departing from the spirit and scope of the present application.

Claims

1. A method of securely transferring data related to a process plant from the process plant for consumption by one or more external systems via an edge gateway system, the edge gateway system comprising field-oriented components and edge-oriented components interconnected by data diodes, the method comprising: sending, by the field-facing component, a set of data types to the edge-facing component via the data diode, the set of data types corresponding to data related to an industrial process controlled by the process plant and allowed to be exposed to the one or more external systems, the data diode being a unidirectional data diode configured to prevent any flow of both signaling and payload data from the edge-facing component to the field-facing component, the set of data types being defined based on one or more configurations of the process plant and represented using a syntax native to the one or more external systems; and streaming, by the field-facing component, content data generated by the process plant to the edge-facing component through the data diode, the content data being indicated by one or more interest lists corresponding to the field-facing component and the content data being represented within the stream using the set of data types, such that the streamed content data generated by the process plant is available for consumption by the one or more external systems via the edge-facing component; wherein: each of the one or more interest lists indicates respective data allowed to be exposed by the field-facing component to the one or more external systems for consumption, the respective exposable data indicated by each interest list corresponding to respective data content generated by a respective one or more devices of the process plant when the process plant operates to control the industrial process; the respective data content including at least one of: a respective operational state, a respective time corresponding to the respective data content, a respective parameter value, a respective source of the respective data content, a respective recipient of the respective data content, or other data corresponding to the respective data content; and the exposable data indicated by the one or more interest lists defining only data of a totality of data obtained by the field-facing component from the process plant that is allowed to be exposed by the field-facing component to the one or more external systems for consumption.

2. The method of claim 1, further comprising defining, by the field-facing component, the set of data types based on the one or more configurations of the process plant and optionally based on the one or more interest lists.

3. The method of claim 2, wherein, Defining the set of data types according to the one or more configurations of the process plant includes extracting the set of data types from the one or more configurations of the process plant.

4. The method of any one of claims 2-3, wherein, The one or more interest lists indicate at least some of the content data allowed to be exposed to the one or more external systems, and defining the set of data types is based on both the one or more configurations of the process plant and the one or more interest lists.

5. The method of any one of claims 1 to 3, wherein, Sending the set of data types includes sending a set of data types including at least one of: a floating point data type, a floating point data type with state, a signed integer type, an unsigned integer type, a pattern data type, an enumeration data type, or a function block data type.

6. The method of any one of claims 1 to 3, wherein, Transmitting the set of data types to the edge-oriented component includes transmitting at least one data type to the edge-oriented component that includes a respective plurality of fields, each field of the respective plurality of fields having a respective data type.

7. The method of any one of claims 1 to 3, wherein, Transmitting the set of data types to the edge-oriented component includes transmitting a definition of the set to the edge-oriented component, the definition of the set indicating a name of the set and a respective name of each of a plurality of values of a particular data type.

8. The method of any one of claims 1 to 3, wherein, Streaming content data generated by the process plant and indicated by the one or more interest lists includes streaming content data generated by and / or corresponding to at least one of: a process parameter, a function block, a module, an event, historical record data, a piece of equipment, a device, a display view, or one or more other physical and / or logical components of the process plant.

9. The method of any one of claims 1 to 3, wherein, Transmitting the set of data types to the edge-oriented component includes transmitting at least one of: a user-defined data type or a system-defined data type to the edge-oriented component.

10. The method of any one of claims 1 to 3, wherein, Transmitting the set of data types to the edge-oriented component via the data diode includes transmitting the set of data types to the edge-oriented component via the data diode using a common data exchange format.

11. The method of claim 10, wherein, Transmitting the set of data types to the edge-oriented component via the data diode using the common data exchange format includes transmitting the set of data types using a JSON (JavaScript Object Notation) format.

12. The method of any of claims 1-3, further comprising providing, by the field-oriented component, one or more interfaces via which the one or more interest lists are configured.

13. The method of any one of claims 1 to 3, wherein, Transmitting the set of data types via the unidirectional data diode configured to prevent any flow of both signaling and payload data from the edge-oriented component to the field-oriented component includes transmitting the set of data types via an optical link, an Ethernet link, a wireless data diode, or a software-defined data diode.

14. The method of any one of claims 1 to 3, wherein, At least one of: (i) the method further comprises encrypting the set of data types, and wherein transmitting the set of data types to the edge-oriented component includes transmitting the encrypted set of data types to the edge-oriented component; or (ii) the method further comprises encrypting content data generated by the process plant, and wherein streaming content data generated by the process plant includes streaming encrypted content data generated by the process plant.

15. The method of any one of claims 1 to 3, wherein: The method further comprises publishing, by the field-oriented component, content data generated by the process plant; the edge-oriented component subscribes to the published content data generated by the process plant; and streaming content data generated by the process plant includes streaming the published content data generated by the process plant.

16. The method of any of claims 1 to 3, further comprising scaling the data diode based on respective sizes of the one or more interest lists.

17. The method of claim 16, wherein, Scaling the data diode comprises adjusting at least one of a number of cores or a number of threads used to stream the content data and respective contexts of the content data generated by the process plant.

18. The method of any one of claims 1 to 3, wherein, Streaming the content data represented using the set of data types comprises packing the content data represented using the set of data types in a streaming protocol.

19. The method of any of claims 1 to 3, further comprising obtaining, at the field-oriented component, the content data generated by the process plant from the process plant via one or more process plant networks supporting one or more digital automation formats and / or protocols selected from the group consisting of: Remote I / O, Fieldbus, HART, WirelessHART, HART-IP, Field Device Integration (FDI), OPC UA, or Profibus.

20. The method of any one of claims 1 to 3, wherein, Streaming the content data through the data diode comprises streaming the content data through a data diode configured to support a streaming rate of at least 100,000 process plant parameters per second.

21. The method of any one of claims 1 to 3, wherein, Streaming the content data through the data diode comprises streaming the content data through a data diode configured to support a data transfer rate of at least 1 gigabit per second.

22. The method of any one of claims 1 to 3, wherein, Streaming content data generated by the process plant comprises streaming at least one of: runtime process data, continuous process data, batch process data, batch history data, historian data, event data, alarm data, analytics data, diagnostic data, environmental data, user interface data, performance data, or another type of data corresponding to operation of one or more devices of the process plant that control an industrial process.

23. A field-oriented component configured to perform the method of any of claims 1 to 22.

24. An edge gateway system comprising the field-oriented component of claim 23, a data diode, and an edge-oriented component.

Citation Information

Patent Citations

  • Secured Process Control Communications

    US20180115517A1

  • Securely Transporting Data Across a Data Diode for Secured Process Control Communications

    US20180115528A1

  • Method and system for interest groups in a content centric network

    US20170373974A1

  • Publishing Data Across a Data Diode for Secured Process Control Communications

    US20180115516A1