Method and apparatus for providing data of an industrial automation device to an external device

By processing and abstracting data through industrial edge devices, the problem of data access and exchange between industrial automation networks and external applications is solved, enabling secure and automated data exchange and access control, and improving the efficiency and security of data exchange.

CN114127708BActive Publication Date: 2025-11-07SIEMENS AG
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202080049169.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2020-06-30
Filing Date
2020-07-01
Publication Date
2025-11-07
Estimated Expiration
2040-07-01

AI Technical Summary

Technical Problem

Existing technologies struggle to enable secure and automated data access and exchange between industrial automation networks and external applications, especially when adhering to data protection guidelines and compliance requirements.

Method used

By using industrial edge devices as gateway components, raw data from industrial automation equipment is processed, and the data is abstracted and anonymized according to work orders from external applications. Virtualized data is then delivered to external applications, while data access permissions and frequencies are automatically negotiated and executed.

Benefits of technology

This enables external applications to securely and automatically access the data they need while complying with data protection rules, reducing labor-intensive management work and improving the efficiency and security of data exchange.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114127708B_ABST
    Figure CN114127708B_ABST
Patent Text Reader

Abstract

The invention relates to a method and an apparatus for providing data of a data source, in particular of an industrial automation device (AA), to an external application program (AW), wherein the external application program (AW) is arranged outside a first data network of the data source, in particular runs in a data cloud, and wherein raw data of the data source are processed by a gateway component (GK), in particular an industrial edge device, and the processed data are provided to the external application program (AW). Here, a work order is first transmitted to the gateway component, wherein the work order comprises at least a specification about the identity and / or the role of a user of the external application program, a specification about raw data of the data source to be processed, a specification of an algorithm for processing, abstracting and / or anonymizing the raw data and a frequency or a rate of data processing, according to which the raw data are detected and processed according to the work order, and the processed, virtualized and / or anonymized data are subsequently provided to the external application program or to a target defined in the work order. Thereby, an automated controlled access for the external application program to the data is implemented, which in turn enables the use of the data without the external application program having to access the underlying raw data. Here, the extent of the data access is automatically negotiated and implemented between the participating components (data source, gateway component) taking into account requirements and rules.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to a method for providing data of a data source to an external device according to the application and to a device for providing data of a data source to an external device according to the application. BACKGROUND

[0002] Machine data, production data and planning data of industrial automation devices and other data sources are usually available in a local, isolated production network from the public network. The data are used for controlling and checking industrial production processes and procedures. Such data often also include confidential information, for example about production processes and production methods, financial data, etc., so that it is not desirable to forward the information available at the so-called automation level completely to external sites. Conversely, direct access from external entities, i.e. devices outside the private automation network, to devices, components, etc. of the private automation network is usually not desired or is risky.

[0003] For this reason, technical measures are common in order to separate the private automation network, i.e. the data source, from the public network, in particular the Internet or the so-called "cloud" ("data cloud") in a suitable manner. Such measures can consist, for example, in setting up so-called "firewalls". It is also possible, therefore, to implement controlled access, for example to be able to establish a so-called "tunnel" between a device of the private automation network and an external server, by means of which private data traffic can be implemented into or via the public data network, for example the Internet, in a secure manner and method.

[0004] It is also known to arrange so-called edge devices or edge instruments within the private automation network or at the "border" between the free automation network and the public network, which serve on the one hand to provide resources for data processing in the automation network and on the other hand to provide data from external entities, for example cloud-based applications or solutions, and, conversely, to receive data and commands from the cloud-based applications and to apply them in the private automation network. With regard to the functionality of data provision and transmission, it is also often a matter of "gateway components"; the gateway components can also be installed on components different from the "edge devices".

[0005] If the operator of the cloud-based external application is identical to the operator of the automation network or the data source, but there is a special trust relationship between each other, the data traffic between the automation components of the industrial automation network or between the industrial automation devices on the one hand and the external application on the other hand can be harmoniously planned and implemented by means of a solution based on such edge devices.

[0006] Problems can arise when specific production-related data, so-called raw data, i.e. data of the private automation network, should not be available outside the production environment (automation plant), but on the other hand there is a requirement in terms of external applications that data be available to implement business models, optimizations, etc. In this context, also pre-processed local data of the data source, business figures, performance indicators (so-called "KPI" - Key Performance Indicators), etc. that should be protected belong to the raw data.

[0007] Data exchange between the private sphere and external applications is of great importance for a large number of applications, especially when cloud-based applications are used. Furthermore, data is increasingly a commodity today. While in the case of a purely bilateral relationship between the data source and the external application it is possible to simply regulate access to the data and any remuneration, in the case of complex plants the checking of data access is no longer trivial, since further data protection guidelines have to be observed depending on the external application.

[0008] In one example, a tax authority can be authorized to access all financial transactions of a company broadly and of course free of charge. However, an advertising company can also obtain the addresses of customers from the same database stock of the company for advertising purposes, but has to pay a remuneration for this; however, in this case sales to the customers etc. are not part of the data to be provided. This means that the data access of the tax authority has a different scope of rights than the advertising business partner. All rules applicable to data access, access authorization and restrictions have to be managed manually, respectively, which requires a labor-intensive management work. SUMMARY

[0009] It is therefore an object of the present application to manage data access of external applications to data sources in an automated manner.

[0010] According to the application, this object is achieved by a method according to the application and by an apparatus (component) according to the application.

[0011] Here, a method for providing data of a data source, in particular of an industrial automation device, to an external application program is proposed, wherein the external application program is arranged outside a first data network of the data source, in particular runs in a data cloud and / or a second data network, and wherein raw data of the data source are processed by a gateway component, in particular an industrial edge device, and the processed data are provided to the external application program. Here, in a first step, a work order is transmitted by the external application program to the gateway component, wherein the work order comprises at least a specification about an identity and / or a role of a user of the external application program, a specification about raw data of the data source to be processed, an algorithm for abstracting and / or anonymizing the raw data and a specification of a frequency or a frequency of data processing. In a second step, the work order is checked by the gateway component, after which, in a third step, the raw data are detected and processed according to the work order. Finally, in a fourth step, the virtualized and / or anonymized data are provided to the external application program or to a target defined in the work order. By this, an automatically controlled access and thus a use of the data can be realized for the external application program, without the external application program having to access the raw data underlying. Here, the extent of the data access is automatically negotiated and realized between the participating components (data source, gateway component) taking into account requirements and rules.

[0012] The invention is also realized by a device for providing data of a data source, in particular of an industrial automation device, to an external application program, wherein the external application program is arranged outside a first data network of the data source, in particular runs in a data cloud and / or a second data network, and wherein a gateway component, in particular an industrial edge device, is arranged for processing raw data of the data source and for providing the processed data to the external application program. Here, the gateway component is arranged for receiving a work order from the external application program in a first step, wherein the work order comprises at least a specification about an identity and / or a role of a user of the external application program, a specification about raw data of the data source to be processed, an algorithm for abstracting and / or anonymizing the raw data and a specification of a frequency or a frequency of data processing. In a second step, the work order is checked. In a third step, the raw data are detected and processed according to the work order, and in a fourth step, the virtualized and / or anonymized data are provided to the external application program or to a target defined in the work order. By the component, the advantages already discussed according to the method can be realized.

[0013] According to the invention, in a second step, in the case of a negative checking result, a reply message with replacement conditions of the work order is transmitted to the external application program, wherein the external application program confirms or rejects the replacement conditions or uses the replacement conditions for defining a new work order. Thus, a suitable extent of data processing for both trading partners can be dynamically and automatically agreed.

[0014] Advantageous design solutions are described in the various embodiments. The features described there and their advantages can be realized both individually and in a meaningful combination with one another.

[0015] In an advantageous design solution, a work order is utilized for the provision of a reward for providing processed, abstracted and / or anonymized data. This reward can be negotiated repeatedly as a function of the extent of data processing. Although the reward can be realized in money (or "points", etc.). It is also possible, however, for new data (e.g. results, statistics) to be derived from the transmitted data, which are provided as a reward to the data source.

[0016] Before or during the second step, the algorithm is checked by an authentication authority with respect to compliance with data protection standards. At the same time, it is also possible to check independently whether the algorithm processes and provides data in the desired manner. A certificate issued here can be associated in a tamper-proof manner with the algorithm or a standardized work order, a so-called work order template. The data protection standards are advantageously named or transmitted by a gateway component of the authentication authority, so that the data source retains full control over its data or raw data. Depending on the role and / or identity of the user of the transaction partner, i.e. of the external application, the user can also predefine criteria. For example, the tax authorities mentioned above can thus limit the raw data to be accessed and the data processing to be set by means of it, if necessary.

[0017] Advantageously, in the second step, the identity or role of the user of the external application is taken into account in the check. It is also possible to associate a data access right, a so-called trust level, with the identity or role. The identity, role or trust level can also be attested by a certificate.

[0018] The work order should be formulated in a machine-readable manner; this applies in particular to the algorithm. For example, a data format based on XML or JSON or the like is supplied, which can contain keywords that can also be read by humans. In particular, the work order (template) can thus be prepared, designed and checked manually.

[0019] Advantageously, the algorithm is stored in the form of an abstraction of data for defining at least one industrial automation component. This has the advantage that it is possible to abstract the data by means of a semantic model that is independent of the machine. In particular, such a model can be determined by personnel who do not master any programming language. Furthermore, such a model can be universal and transferable.

[0020] Advantageously, a machine-readable description is associated with the algorithm or the model contained therein, wherein the description comprises information about the data (variables, data points, files, etc.) to be processed on the data source (e.g. automation component) and about the degree or type of abstraction of the data by the algorithm or by the model implemented therein or loaded, wherein the description is checked against a policy before the algorithm or the model is executed, wherein the policy prescribes rules about the access to the data of the data source or automation component allowed or prohibited and / or about the successful abstraction of the data by the algorithm and wherein the algorithm and, if necessary, the model contained therein for the abstraction of the data are only allowed to be executed if they are in line with the policy.

[0021] The algorithm or the model implemented therein can be checked by means of this meta-information, which can also be done automatically or partially automatically in advantageous variants. Advantageously, the meta-information, i.e. the machine-readable description which can exist, for example, in the form of an XML file, is inseparably added to the algorithm, the work order or the underlying model for defining the abstraction of the data and is provided by the provider of the work order (or "template"). Thus, in particular, it is possible to prescribe to what extent the original data must be abstracted at least. Thus, for example, it is possible to define for a specific input value, for example the operating time of a machine, that the data is only passed on in the form of an average value or a cumulative value for one month. It is thus advantageous here that the machine-readable description of the algorithm and the machine-readable description of the policy are syntax-compatible in order to simplify the comparison in a manual and in a machine-readable manner.

[0022] Advantageously, the work order or its generic template or at least one model for the abstraction of the data or the algorithm to be embedded in the work order or to be referred to can be provided by means of a service for providing industrial applications, in particular an industrial application store. In an advantageous variant, this is a similar or even the same application store which also provides applications for industrial edge devices. This is particularly suitable in the case where the work order or even the data processing module for executing the work order is designed as an application (app) for an industrial edge device. In this case, the advantage also arises that the industrial edge device can in any case access the automation data of the subordinate automation component (data source) and can thus provide the raw data for processing by the work order or the algorithm. In particular, the industrial edge device usually also has a communication channel to the "outside", i.e. to the outside environment, to the "cloud" or to the Internet. BRIEF DESCRIPTION OF DRAWINGS

[0023] In the following, embodiments of the method according to the application and furthermore also of the component according to the application are explained with reference to the drawings.

[0024] Herein is shown:

[0025] Figure 1 Fig. 1 shows a schematic diagram of an automation device linked via a gateway component according to the application with an external application, and

[0026] Figure 2 Fig. 2 shows a schematic flow chart during processing of a work order. DETAILED DESCRIPTION

[0027] The embodiments explained below have in common that a requestor needs data and for this (in an advantageous variant) provides a return (e.g. data driver service, money, return of data,...). In the case that the data has a commercial value or can be evaluated, the components that supply and sell data can also be described as "data market". Since commercial secrets and legal interests are hidden behind the commercial data, any misuse or undesired opening of knowledge must be prevented. Therefore, it must be ensured that the data provided is converted (processed, abstracted, anonymized) from the raw data (initial data) before transmission to the data user, so that it is not important for the data producer to pass on the data commercially.

[0028] According to the application, measures are provided that enable the separation of data user and data producer, so that on the one hand no conclusions about the data causality can be drawn for the data user and on the other hand a data user is provided with data of sufficient quality. In the case of direct use of the data, the producer of the data benefits directly from the results based on the data. In the case of indirect use of the data, the data user can further process or convert the data (for example by including more data sources), which in turn promotes it to a different value chain, which is then utilized or further sold.

[0029] The core of the automation data market is the ability to automatically negotiate contracts and monitor contract fulfillment, which requires controlled and monitored data supply. The core component is the "electronic contract", the core of which is a machine-readable work order. The work order contains precise instructions about how the parties are to handle the negotiation subject data. For this purpose, the technical work order is subdivided into three sub-aspects in addition to the basic data (identity, role):

[0030] 1) Description of which data sources of the data producer are required to be able to derive the desired result.

[0031] 2) Description of how the data provided by the data source should be processed and in which format the processed result should be provided to the data user.

[0032] 3) Specification of how often the data should be called from the data source of the data producer and how often the processed result should be transferred to the data user independently thereof.

[0033] Other explanations and conditions can of course also be part of the electronic contract and thus of the work order, for example, in which time period the data should be provided.

[0034] The method enables the data user to provide a work order and its description at the time of requesting data, so that the data producer (the owner of the raw data) can consciously decide before processing the work order whether the desired data source and the requested result (e.g. processed or abstracted raw data) are provided at the stored frequency and wishes to install the work order locally for this purpose. After permission by the data producer, the work order is stored in an audit-secure manner. In addition, the platform executing the work order also records the activities of the locally running work order, for example, which data or raw data are received and which data are provided to the user. Here, it is ensured that it is always unambiguously and tamper-proof identified which work order is responsible for the data retrieval, processing, frequency and output. Thus, for the data user as well as for the data producer it is always possible to check the activities of the work order and thus the compliance of the contract, to timely detect tampering or to make it as difficult as possible.

[0035] The degree of automation of the contract negotiation is an absolute factor for how far a data-driven business model is successful in expanding the business. Therefore, it is advantageous to have further mechanisms in order to further increase the automation in a reliable manner. Belonging to the mechanisms are, for example, the feasibility that a third neutral supervisory authority must check the same machine-readable and by the data producer defined policy ("policy") against the work order or the algorithm defined therein in order to allow the processing of the data.

[0036] The type of result to be transmitted is combined in an audit-secure manner with the role and rights of the requesting data user (e.g. tax authority, internal customer, external customer, contracted service provider), so that it is possible to limit one or the same work order in the output of the result. The same mechanism can also be used to enable the data producer to sell or exchange work orders that are certified by the supervisory authority and thus safe from their point of view, for example via a machine-readable trading platform.

[0037] Figure 1 An industrial automation plant AA is shown, which is, for example, a manufacturing site of a producer. Different components are running in the automation system AA, for example programmable logic controllers, human-machine interaction (HMI) devices, manufacturing execution systems (MES), etc., wherein, in the course of the production process, data are generated and stored in the automation system AA. Figure 1An automated component AK (e.g. a machine tool) is merely exemplary. Production data (so-called raw data) of the automated component AK can be accessed via a gateway component GK, which in the present embodiment is an industrial edge device. The gateway component GK can exchange data with an external application AW via a data firewall FW of the automation device AA, wherein the external application AW is arranged in a data network of a service provider OEM. The connection between the gateway component GK and the external application AW can take place, for example, via a data channel in the Internet. The operator of the external application AW, the service provider OEM, is in this embodiment the operator of the automated component AK.

[0038] In this context, the method according to the application serves to realize a business model of the service provider OEM as owner of the automated component AK. The business model provides for a so-called "pay-per-use", i.e. a remuneration model for the machine usage which is related to the runtime and the load. It should be noted that in the present example the service provider OEM is although a machine manufacturer, but in other examples can also be another "non-industrial" service provider OEM (e.g. a bank, an insurance company, a maintenance service provider, etc.) or even an administrative authority. By this, the service provider OEM can (as described in the next paragraph) be the owner of the automated component, but does not necessarily have to be the owner of the automated component.

[0039] The manufacturer or service provider OEM located in the external network needs corresponding information to settle and maintain the machine, the automated component AK. However, according to the wishes of the user, i.e. the operator of the automation device AA, the data should be present in a form which does not allow conclusions to be drawn about production details. Therefore, direct access to the raw data is excluded.

[0040] For this purpose, the service provider OEM defines an algorithm for data preprocessing which pre-processes the raw data from the industrial environment and abstracts it here such that only the information is transmitted to its data processing and accounting device which is necessary for providing the business model or server. For this purpose, the service provider OEM (machine manufacturer) defines a model for abstracting the data, which model exists, for example, in a domain-specific language, a database query language (e.g. SQL) via a conventional computing program (e.g. Matlab from the provider The Mathworks) or the like. Here, it is important that the data access and data processing (abstraction) of the production data (raw data) of the automated component AK can be modeled.

[0041] This querying and pre-processing (abstracting) of the data, i.e. of the model, is advantageously encapsulated, for example in a processing module (container), i.e. together with executable program code. Here, it is important to ensure integrity, authenticity and proprietary protection, which means that the interests of the service provider OEM and of the operator of the automation facility AA can be taken into account in the long term. The processing module, which contains the model for defining the data abstraction and the model for accessing the data, is therefore authenticated and, in a further advantageous variant, also encrypted.

[0042] The algorithm or the processing module encapsulated here is an important component of the new work order sent to the gateway component GK. The work order therefore contains, in addition to the actual algorithm, a machine-readable description, so-called meta-information about what happens with the raw data, and specifications about the frequency of data processing, etc. The algorithm is authenticated in this case, so that a certificate of an independent testing authority is included, which certifies that the algorithm precisely fulfils what is described in the meta-information. In addition, the identity and role of the requestor are recorded.

[0043] The work order is checked on the gateway component GK side.

[0044] Figure 2 A possible flow chart of the checking and processing of the work order is shown. In a first phase (checking phase), the work order is checked in terms of various criteria of the policy. The raw data is acquired and processed in the algorithm processing phase.

[0045] In the current variant, a description in the form of an XML file is attached to the work order as so-called meta-information, which defines both the accessed raw data and the abstraction of the raw data and specifies the output parameters of the data processing or data abstraction accomplished thereby. In the current embodiment, the operator of the automation facility AA defines a policy, which likewise exists in the form of an XML file. In the policy, the data points that can be accessed for acquiring raw data are defined individually for each identity or role of the "data receiver", and it is also specified how the data must be processed, i.e. the minimum degree of abstraction, and with what frequency. In the current case, the policy specifies that the usage time, the maximum torque of the drive of the automation component AK and the access to alarm messages can be accessed by a work order with the identity or role of the operator OEM. The policy also defines that the alarm is only allowed to be forwarded without a time stamp, the usage time is allowed to be delivered cumulatively over a period of one month, and the torque value of the drive is only allowed to be delivered in terms of the frequency of reaching a certain torque ("overload"). The policy and the meta-information of the processing module can be compared with one another automatically, so that the work order can be checked and allowed or rejected or renegotiated automatically.

[0046] In execution, the gateway component GK or the data processing module (runtime environment) in which the work order is executed accesses the machine data of the automation component AK which are confidential to the main. In the present case, as data to be passed on, the information is ascertained that the user uses the machine within the framework agreed in the contract. As a return for the electronic permission information which is sent to the machine as "reward" for the provision of data, the continued use is enabled. Otherwise the machine would be blocked from continued use.

[0047] For the case that the frequency of the requests in the work order, for example using the transmission of data, violates the internal policy of the gateway component, the work order can be answered with an electronic rejection which includes a specification of the "unallowed access frequency to the runtime data". Then, a new work order with a less frequent requirement can be created and transmitted likewise fully automatically. Thus, the participating systems can negotiate acceptable work orders among each other within certain rules and limits.

[0048] In a variant, any type of planning data or other local data can also be accessed, as far as this is necessary for the execution of the external application AW. This means that data of multiple industrial components can also be combined with each other.

[0049] Instead of the embodiment of the "pay-per-use" application case shown here, the method and components (processing modules) described here can also be used for predictive maintenance, residual value determination (for example for tax depreciation), calculation of insurance risks, etc. Thus, the service provider OEM can also be a bank, an insurance company, a maintenance service company or other "data consumer".

[0050] During the ongoing operation of the industrial automation plant AA, the raw data of the automation component AK which are defined in the abstraction model are now regularly (for example periodically) detected, recorded and processed according to the defined abstraction by the processing modules in the data processing model DVM. The processed data are then provided to the application AW via the data connection.

[0051] It is important that the gateway component GK forms a uniform, versatile access point for the private raw data, by which different work orders can be checked, or renegotiated and executed, role and / or identity-related. It is therefore important that the reliability of the query is checked in advance according to the machine-readable description of the data processing by means of a "handshake method" and the identity and role of the querying party is queried if necessary.

[0052] Another type of work order can involve transmitting sales figures to tax authorities, from which the tax authorities calculate taxes. Such work orders, digitally signed with official certificates, therefore include stipulations regarding the frequency (here: hourly) at which sales or financial data should be transmitted. Here, cumulative sales figures should be calculated based on the type of goods. This is defined in the algorithm of the work order.

[0053] according to Figure 2 The proposed solution first examines the work order. First, it determines that the sales figures are essentially within the allowed raw data. Then, it checks whether the order principal—the person linked to the requesting application or work order—has access rights to the requested data source, and consequently, the raw data to be processed. Permissions can be stored for known order principals; alternatively, certificates can be associated with the work order for this purpose. In a variant, permissions can also be associated alternatively or additionally based on roles. Next, it checks whether the algorithm applied to the raw data, or the entire work order, is certified. If not, alternatively, the work order can be rejected, or it can be sent to a certification body for verification; however, this intermediate step is not included in the process. Figure 2 As shown in the diagram. Finally, check whether the frequency of access to the raw data and / or the loop frequency of the execution of work orders or the included algorithms are acceptable. If one of the checks yields a negative result (in... Figure 2 If the answer is "No", then the work order will be rejected or "upgraded" in the previously specified manner.

[0054] Following the inspection phase, the work orders are processed, accessing the referenced data sources to the necessary extent and processing the raw data obtained therein. Finally, the results are transmitted to the order principal, where, especially in the case of work orders running for longer periods, it is possible to check whether authorization still exists. In the current embodiment, this means: calculating the cumulative sales value for each product group from the sales figures every hour and reporting it to the tax authorities.

[0055] Then, it is possible to make possible pre-agreed rewards or compensation.

Claims

1. Method for providing data of a data source to an external application (AW), the data source being an industrial automation device (AA), wherein the external application (AW) being arranged outside a first data network of the data source, wherein raw data of the data source are processed by a gateway component (GK) and the processed data are provided to the external application (AW), wherein in a first step, a work order is transmitted by the external application to the gateway component, wherein the work order comprises at least a specification about an identity and / or a role of a user of the external application, a specification about the raw data of the data source to be processed, an algorithm for abstracting and / or anonymizing the raw data, and a specification for a frequency of data processing, wherein in a second step, the work order is checked by the gateway component, wherein in a third step, the raw data are detected and processed according to the work order, and wherein in a fourth step, the virtualized and / or anonymized data are provided to the external application or to a target defined in the work order, characterized in that in the second step, in case of a negative check result, a reply message with alternative conditions of the work order is transmitted to the external application, wherein the external application confirms or rejects the alternative conditions or the external application uses the alternative conditions for defining a new work order.

2. The method of claim 1, wherein, the external application is running in a data cloud and / or a second data network.

3. The method of claim 1, wherein, the gateway component is an industrial edge device.

4. Method according to any one of claims 1 to 3, characterized in that a remuneration for providing abstracted and / or anonymized data is supplied with the work order.

5. Method according to any one of claims 1 to 3, characterized in that before or during the second step, the algorithm is checked by an authentication authority in terms of compliance with data protection standards.

6. Method according to claim 5, characterized in that the data protection standards are named or transmitted by the gateway component for the authentication authority.

7. Method according to any one of claims 1 to 3, characterized in that in the second step, the identity or the role of the user of the external application is considered at the check.

8. Method according to any one of claims 1 to 3, characterized in that the work order is provided by means of a service for providing industrial applications or at least the algorithm.

9. The method of claim 8, wherein, the industrial application is an industrial application store.

10. Device for providing data of a data source to an external application (AW), the data source being an industrial automation device (AA), wherein the external application (AW) being arranged outside a first data network of the data source, wherein a gateway component (GK) is arranged for processing raw data of the data source and for providing processed data to the external application (AW), wherein the gateway component is arranged for In a first step, a work order is received from the external application, wherein the work order comprises at least a specification of an identity and / or a role of a user of the external application, a specification of raw data to be processed of the data source, an algorithm for abstracting and / or anonymizing the raw data, and a specification of a frequency for data processing, In a second step, the work order is checked, In a third step, the raw data is detected and processed according to the work order, and In a fourth step, virtualized and / or anonymized data is provided to the external application or to a target defined in the work order, characterized in that the gateway component is provided for: In the second step, a reply message with replacement conditions of the work order is transmitted to the external application in the case of a negative checking result, wherein the external application is provided for confirming or rejecting the replacement conditions or for defining a new work order.

11. The apparatus of claim 10, wherein, The external application is running in a data cloud and / or a second data network.

12. The apparatus of claim 10, wherein, The gateway component is an industrial edge device.

13. The apparatus according to any one of claims 10 to 12, characterized in that the work order comprises a remuneration for providing abstracted and / or anonymized data.

14. The apparatus according to any one of claims 10 to 12, characterized in that an authentication authority is provided, which is provided for checking the algorithm in terms of compliance with data protection standards before or during the second step.

15. The apparatus according to claim 14, characterized in that the gateway component is provided for naming or transmitting the data protection standards for the authentication authority.

16. The apparatus according to any one of claims 10 to 12, characterized in that in the second step, the identity or the role of the user of the external application is considered in the checking.

17. The apparatus according to any one of claims 10 to 12, characterized in that a service for providing industrial applications is provided, wherein the service is provided for providing a plurality of prepared work orders or at least one prepared algorithm for calling.

18. The apparatus of claim 17, wherein, The industrial application is an industrial application store.

Citation Information

Patent Citations

  • Method, device and system for building corresponding relationship between private network label and primary VRF (VPN (virtual private network) routing and forwarding table)

    CN103746914A

  • SCALABLE AND SECURE RESOURCE ISOLATION AND SHARING FOR IoT NETWORKS

    US20190014117A1