admission mechanism
By using hardware-based non-transient memory devices and controllers, and leveraging a dynamic rule system to manage the interaction between projects and computing devices, the problem of automatic recovery and flexible management of computing devices in complex or hazardous environments in existing technologies is solved, achieving automated and secure access control.
Patent Information
- Application Number
- CN202111273205.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2020-11-03
- Filing Date
- 2021-10-29
- Publication Date
- 2025-10-28
- Estimated Expiration
- 2041-10-29
AI Technical Summary
Existing technologies struggle to automatically restore the normal operation of computing devices in complex or hazardous environments in industrial applications, and the access mechanisms lack flexibility and dynamism, failing to effectively manage the interaction between projects and computing devices.
It employs hardware-based non-transitory storage devices and controllers, and manages the interaction between projects and computing devices through a dynamic rule system. It uses admission and rule filtering mechanisms to determine whether a project meets multiple rules, thereby controlling access and interaction.
It enables automated recovery of computing devices in complex or dangerous environments and flexible project management, improving the system's dynamism and security, and ensuring that interactions meet preset standards.
Smart Images

Figure CN114444066B_ABST
Abstract
Description
[0001] Cross-references to related applications
[0002] The entire contents of this patent application are incorporated herein by reference in patent application serial number 16 / 377,237 (hereinafter referred to as the "HIVE Patent"), filed on April 7, 2019, entitled "CONTROLHIVE ARCHITECTURE ENGINEERING EFFICIENCY FOR AN INDUSTRIAL AUTOMATION SYSTEM". Background Technology
[0003] The admission mechanism uses a set of rules to govern the admission of "projects" to "project holders." A project can be anything. An example of a project is a computer program that can be placed into a computer. The rules allow projects to be correctly placed into project holders without violating a set of placement criteria.
[0004] In industrial applications, software projects are used to perform control functions on computing devices (project owners). This can occur, for example, in oil refineries, paper mills, or power plants. Furthermore, some industrial installations are difficult or costly to access, and these installations may also be hazardous and / or their operation critical. Computers controlling gas distribution facilities or power plants are two examples. In systems like these, failures are expected over time, and computers may malfunction, interrupt, and / or require regular maintenance. In these scenarios, access control mechanisms can be used, for example, to restore normal operation of the computer without human intervention. Attached Figure Description
[0005] Figure 1 This is a schematic diagram of a system that can adopt an access mechanism.
[0006] Figure 2 This is a schematic diagram of another system that can employ an access mechanism.
[0007] Figure 3 This is a flowchart illustrating the rule application performed by the admission mechanism.
[0008] Figure 4 This is a flowchart illustrating another rule application performed by the admission mechanism.
[0009] Figure 5 This is a flowchart illustrating another rule application performed by the admission mechanism. Summary of the Invention
[0010] One implementation includes: a first computing system configured to control a second computing system; a software module configured to attempt to interact with the second computing system once the first computing system causes the second computing system to enter a first state; and an admission mechanism configured to determine whether the interaction is permitted.
[0011] Another implementation includes one or more hardware-based nontransitory memory devices storing computer-readable instructions that, when executed by one or more processors disposed in a computing device, cause the computing device to: put an item holding module into a first state by a controller; receive an access request from an item module to the item holding module; and determine whether the item module can access the item holding module using an admission mechanism by applying multiple rules in a dynamic rule-based system, wherein if the item module violates one of the multiple rules, the access is not allowed.
[0012] Another embodiment includes a device comprising: a controller configured to control a computing device and bring the computing device to an initial state in a computing system; an application configured to interact with the controller to attempt to access the computing device; and an admission device configured to use a plurality of rules associated with the computing system to determine whether the access between the application and the computing device is permissible, wherein if the application violates one of the plurality of rules, the interaction is not permitted. Detailed Implementation
[0013] Figure 1 This is a schematic diagram of a system that can employ an admission mechanism. The system includes a project module 120, a project retention module 100, and a controller 110 operating within a dynamic rules-based system 150. An example of such a system 150 is described in more detail with respect to the HIVE patent. In this system, rules can be added and removed as needed, for example, by using tags associated with the rules. An HIVE coordinator or other controllers, such as controller 110, can be used. Controller 110 can apply rules to determine whether interaction between devices, systems, software, etc., can occur at the current time.
[0014] Controller 110 has an admission mechanism 130 and multiple rules 140. Controller 110 is coupled to a dynamic rule-based system 150, and each controller has access to the rules 140. Item retention module 100 includes a state machine 170 representing the state of item retention module 100. For example, this may include states indicating that item retention module 100 is rebooted or enters an initial state. Controller 110 is connected to item retention module 100 and can perform actions to change the state of item retention module 100, which is then reflected by state machine 170.
[0015] Figure 2 This is a schematic diagram of a system that may employ an admission mechanism. The system includes software applications 220, 221, and 222 operating within an HIVE-based system 250, a computing device 200, and an HIVE coordinator 210. See, for example, HIVE patents for further details. The HIVE coordinator 210 may apply multiple rules 240 to determine whether interaction between devices, systems, software, etc., can occur at the current time.
[0016] The HIVE coordinator 210 has an admission mechanism 230 coupled to multiple rules 240. The HIVE coordinator 210 is coupled to a dynamic rule-based system 250, and each can access the rules 240. The computing device 200 includes a state machine 270 representing the state of the computing device 200. In this example, the state machine 270 has a reboot state 290 and an initial configuration state 295, but multiple other states are possible. The HIVE coordinator 210 is connected to the state machine 270 and can perform actions to change the state of the computing device 200, including returning the computing device to its initial configuration or rebooting the computing device 200.
[0017] The HIVE coordinator 210 is also capable of determining where items (such as those provided by applications 220 to 222) should be placed. Rule 240 includes multiple tags 280. The HIVE coordinator 210 can add or remove tags 280 associated with each rule in rule 240. This allows rules to be dynamically activated, deactivated, or modified as needed by the system, and the HIVE coordinator 210 can determine at any given time whether an item can be placed in an item holder (such as computing device 200). In one implementation, the admission mechanism 230 sequentially receives proposed items for insertion. Regarding Figure 2 This includes receiving requests from software applications 220, 221, and 222 to place items on computing device 200. It should be understood that other implementations include a single application making multiple requests to computing device 200 and applications requesting that items be placed on other computing devices (not shown).
[0018] In operation, the admission mechanism 230 has a rule screen 260. The rule screen 260 sequentially receives proposed insertion items and determines whether an item can be placed into a item holder. An example of how this determination is made includes: 1) each proposed item (e.g., from software applications 220, 221, and 222) and each item holder (computing device 200) is reviewed by each rule 240; 2) if the proposed item and item holder combination violates even one of the rules, admission is denied; and 3) if the proposed admission does not violate any of the rules, admission is granted.
[0019] Rule 240 may include any type of rule that can be used in the computing environment. Reference Table 1 shows some examples of Rule 240 that can be used by the HIVE coordinator 210:
[0020] Table 1
[0021]
[0022] Table 1 is a partial list of possible rules according to one implementation scheme. Additional rules can be added to rule 240 as needed.
[0023] Figure 3 This is a flowchart illustrating the rule application process using an access control mechanism. At step 300, each rule is reviewed until no rules remain; at this point, the process ends at box 320. When a rule exists to be processed, at step 310, the system determines whether the rule applies to the current project and the project holder. If not, the process is repeated at step 300, and the next rule (if any) is reviewed. If the rule applies to the current project and the project holder at step 310, at step 330, the system determines whether the rule's criteria are met. For example, the rule could be APART, and if a specific other project is already in the project holder, it might require the current project not to be included in that project holder. (See Table 1 for more examples). If the rule criteria are not met at step 330, access to the project holder is blocked, and the process is repeated at step 300, while the next rule is analyzed. If the rule criteria are met, at step 340, the project's access to the project holder is granted.
[0024] Figure 4This is a flowchart illustrating the rule application performed by the admission mechanism. At step 400, the controller puts the item holder into a first state. The first state can be, for example, the result of the controller rebooting the item holder. Alternatively, the first state can be the result of the controller putting the item holder in an initial configuration. Thereafter, at step 410, the controller waits for an access request from an item retention module. In practice, any multiple item retention modules can communicate with the controller to place items therein; however, for clarity, this example depicts a single request.
[0025] If no request is received at step 410, the process ends at step 420. When a request occurs, the admission mechanism receives the request at step 430. At step 440, the admission mechanism determines whether a rule exists to be applied to the current access request. If so, the rule is applied to the rule filter at step 450. This process is then repeated at step 440. If no further rules exist, at step 460, the system determines whether any of the rules has been violated. If any rule has been violated at step 460, the request is rejected at step 480. Alternatively, if no rule has been violated at step 460, the request may be granted at step 470.
[0026] Figure 5 This is a flowchart illustrating the application of rules by the admission mechanism. At step 500, the HIVE coordinator puts the computing device into a first state. The first state can be, for example, a reboot state or an initial configuration. In many applications, including industrial applications, controllers such as the HIVE coordinator routinely put the computing device into this state as part of the device's lifecycle for repair, maintenance, or in other words, into the first state.
[0027] Once the device enters the first state, at step 510, the system determines whether an application is requesting access to the computing device. If not, the system waits until such a request is made (if any). Once the application is requesting access to the computing device (e.g., to place items there), at step 520, a rule filter is applied to the request. Thereafter, at step 530, the system determines whether any of the rules in the rules have been violated. If any rule is violated at step 530, the request is rejected at step 550. Alternatively, if no rule is violated at step 530, the request may be granted at step 570.
[0028] Although the subject matter has been described in language specific to structural features and / or methodological actions, it should be understood that the subject matter defined in the appended claims is not necessarily limited to the specific features or actions described above. Rather, the specific features and actions described above are disclosed as exemplary forms for implementing the claims.
Claims
1. A system comprising: Second computing device; A first computing device, configured to control a second computing device to at least configure the second computing device to a first state; A software module configured to send a request to the first computing device to attempt to interact with the second computing device after the first computing device causes the second computing device to enter a first state; and Admission mechanism (130), the admission mechanism being configured as follows: Multiple rules (140) are used in a dynamic rule-based system (150) to determine whether an interaction between the software module and the second computing device can occur, wherein if the software module violates at least one of the multiple rules (140), the interaction is not allowed to occur, wherein each of the multiple rules is associated with a label; as well as Add or remove tags associated with the plurality of rules for at least one of the activation, deactivation, and modification of the plurality of rules.
2. The system of claim 1, wherein the first state is an initial configuration or a configuration after a reboot.
3. The system of claim 1, wherein the first computing device includes a HIVE coordinator (210).
4. One or more hardware-based non-transitory memory devices, the one or more hardware-based non-transitory memory devices storing computer-readable instructions, which, when executed by a controller disposed in a first computing device, cause the first computing device to: The controller causes the second computing device to enter the first state; After the second computing device enters the first state, the application for the second computing device receives a request to access the second computing device; The access mechanism (130) is used to determine in the controller whether the application can access the second computing device by applying multiple rules (140) in a dynamic rule-based system (150), wherein if the application violates one of the multiple rules (140), the access is not allowed, wherein each of the multiple rules is associated with a tag; as well as Add or remove tags associated with the plurality of rules for at least one of the activation, deactivation, and modification of the plurality of rules.
5. One or more hardware-based nontransitory memory devices according to claim 4, wherein the controller includes a HIVE coordinator (210).
6. An apparatus comprising: The controller is configured to: Controlling a computing device and bringing another computing device to an initial state, wherein the controller is further configured to: Receive a request from the application to interact with the other computing device; and Using multiple rules (140) associated with the other computing device in the dynamic rule-based system (150), it is determined whether the interaction between the application and the other computing device can occur, wherein if the application violates one of the multiple rules (140), the interaction is not allowed to occur, wherein each of the multiple rules is associated with a tag; as well as Add or remove tags associated with the plurality of rules for at least one of the activation, deactivation, and modification of the plurality of rules.
7. The device of claim 6, wherein the initial state is an initial configuration or a configuration after a reboot.
8. The device according to claim 6, wherein the plurality of rules comprises a plurality of tags (280).
9. The device of claim 6, wherein the controller comprises a HIVE coordinator (210).
Citation Information
Patent Citations
Control hive architecture engineering efficiency for an industrial automation system
US20200319623A1
Methods and Apparatuses for Securely Operating Shared Host Computers With Portable Apparatuses
US20090031403A1