Method and system for providing data from an internal data processing system of an industrial plant to an external data processing system
By using digital signatures and user-defined data filters on industrial edge devices, the data packets are signed and filtered, and the second digital signature is applied in the data processing module to form a double-signed data packet, which solves the security and trust problems of data exchange between internal and external data processing systems in industrial factories, and achieves the secure transmission and integrity of data.
Patent Information
- Application Number
- CN202080082616.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2019-11-28
- Filing Date
- 2020-10-29
- Publication Date
- 2025-06-10
- Estimated Expiration
- 2040-10-29
AI Technical Summary
In industrial plants, data exchange between internal data processing systems and external data processing systems has security and trust issues, especially when sensitive data needs to be transmitted, how to ensure the security and integrity of the data is a challenge.
By signing the data packets with a first digital signature on an industrial edge device and applying a user-defined data filter in the data processing module, it is ensured that only authenticated and filtered data packets are sent to the external data processing system. In addition, the filtered data packet is re-signed using a second digital signature to form a double-signed data packet to increase the authenticity and integrity of the data.
This method effectively solves the security and integrity of data transmission in an untrusted industrial environment, ensures the security of sensitive data, and realizes the authenticity and end-to-end integrity of data packets.
Smart Images

Figure CN114746818B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to a method for providing data from an internal data processing system of an industrial plant to an external data processing system, wherein the internal data processing system includes at least one industrial edge device and at least one, in particular a plurality of, industrial machines, such as machine tools, in particular cutting, drilling, grinding, shearing machine tools.
[0002] Furthermore, the present invention relates to a data processing module for providing data from an internal data processing system of an industrial plant to an external data processing system, wherein the internal data processing system includes at least one industrial edge device and at least one industrial machine.
[0003] Furthermore, the present invention relates to an industrial edge device and an industrial data processing system having at least one of the above data processing modules.
[0004] Furthermore, the present invention relates to a computer program comprising instructions for causing the above industrial data processing system to perform the steps of the above method, and to a computer-readable medium having such a computer program stored thereon. Background Art
[0005] The industrial network environment can include an ecosystem hereinafter referred to as an external data processing system and an industrial data processing system hereinafter referred to as an internal data processing system. The internal data processing system can use the infrastructure of the external data processing system to perform certain tasks.
[0006] The industrial / internal data processing system includes or consists of an industrial or internal computer network (networks) of an industrial plant or a plurality of industrial plants. The external data processing system includes or is a computer network, such as a public computer network, which is external to the industrial or internal computer network.
[0007] Various data of industrial plants that can be part of the industrial / internal data processing system are regularly stored and available in the local and / or internal industrial equipment network. These networks are typically isolated from the public network because the stored data (such as machine, production, planning or scheduling data) is sensitive or confidential and can contain information about production methods and processes. These data are typically used to control, monitor and supervise production flows and processes. Therefore, it can be advantageous not to disclose or transmit such data to external entities in the external data processing system, i.e., entities outside the private industrial plant network (e.g., intranet). Conversely, direct access to the data by external entities is generally not desirable because it is associated with certain risks.
[0008] For the above reasons, there are some technical measures aimed at ensuring the security of internal or confidential data in the network of private industrial plants. An example of such a technical measure is a firewall, such as a network-based firewall, which is located, for example, at the gateway between a local industrial plant network and a public (untrusted) network (such as the Internet or the cloud). Further technical measures can involve a tunneling protocol, such as a VPN tunneling protocol, to extend the internal / private industrial network over the public network and enable communication between devices on the public network (as if these devices were directly connected to the internal industrial network) to communicate with each other, especially to exchange data with the internal industrial network.
[0009] It is known from the prior art to arrange industrial edge devices at the "edge" between a private industrial plant network and an external / public network. The industrial edge device is located within the internal industrial network and, on the one hand, provides (at least some) resources for data processing within the internal industrial network, and on the other hand, provides data from the internal data processing system to external entities, such as cloud-based solutions, edge backend devices, etc. The industrial edge device can also be adapted to obtain such data from one or more industrial machines (e.g., machine tools) and / or one or more processes of an industrial plant. Conversely, the industrial edge device is adapted to receive data and commands from external entities and apply or implement these data and commands within the internal industrial network.
[0010] As long as the provider of the external entity or the external data processing system or the entire ecosystem is the same as the operator of the internal industrial network or there is a special loyalty and confidentiality relationship between them, the data exchange between the external and internal data processing systems can be planned and executed amicably.
[0011] Those skilled in the art will understand that the term "internal data processing system" refers to an industrial data processing system that is internal relative to the entire ecosystem, for example, relative to an external data processor system. It should be understood that such an industrial data processing system can be implemented as hardware or software, or more commonly, as a combination of hardware and software, where the hardware and / or software of such an "internal data processing system" can be, for example, part of the same legal entity or a group of affiliated legal entities, such as an enterprise group.
[0012] If there are problems with certain industrial plant-related data, such as not allowing production-related data to leave the internal, for example, local industrial network, but at the same time, it is necessary to provide it to an external entity or entities for business model implementation, optimization, etc.
[0013] This situation is possible, for example, if an original equipment manufacturer supplies an industrial machine to an operator of an industrial plant and the two parties agree on a so-called pay-per-use payment model, where remuneration is to be charged according to, for example, the operating time or the number of production operations. Thus, the original equipment manufacturer and the owner of the industrial machine have a legitimate interest in obtaining data on the use and utilization of the industrial machine regularly (e.g., monthly) in order to correctly charge the operator and monitor all maintenance-related events, such as overloading. However, the operator of the plant is reluctant to expose themselves by disclosing sensitive data and may disclose confidential information, such as information on production cycles, order peaks and stagnations, types and designs of products produced, etc. Therefore, there is a conflict of interest between the provider of an external data processing system and the operator of an internal data processing system.
[0014] Those skilled in the art will understand that the operator can be an automated device, such as a robot or artificial intelligence, which can, for example, execute and monitor application programs on one or more industrial machines.
[0015] Those skilled in the art can understand that the provider of an external data processing system and the provider of the entire ecosystem can be different entities. The provider of an external data processing system can, for example, be the provider of application software apps for industrial machines, which optimize their use, for example, based on the usage data of the machines. Such application programs can be stored and run in the cloud, which is part of the ecosystem and provided by another party.
[0016] It will also be understood that the provider of the entire ecosystem, the provider / owner of the internal data processing system (such as application software apps and the operator) can be different entities, especially different legal entities. The operator can run application programs in the ecosystem on one or more industrial edge devices located in the internal data processing system.
[0017] Therefore, there is a need to provide a communication scheme suitable for an untrusted industrial environment. Summary of the Invention
[0018] For achieving the above object, the present invention provides a method for providing data from an internal data processing system of an industrial plant, in particular an automated industrial plant, to an external data processing system. The internal data processing system includes at least one industrial edge device, at least one, in particular a plurality of, industrial machines, and at least one data processing module. The at least one data processing module is provided with a user-defined data filter, such as an authenticated, in particular a trusted third-party authenticated, data filter. The method includes: generating, by at least one industrial edge device, a plurality of data packets, such as unencrypted data packets, from or based on data related to at least one industrial machine; and signing, by at least one industrial edge device, in particular by each industrial edge device among the at least one industrial edge device, each of the plurality of, such as unencrypted, data packets using a first digital signature so as to produce a plurality of signed data packets, in particular a plurality of signed read-only data packets. The method further includes reading each of the plurality of signed data packets and, while reading, allowing those signed data packets that pass through the user-defined data filter or rejecting those signed data packets that fail to pass through the user-defined data filter. This is done by the data processing module. The method further includes sending all those data packets that have passed through the user-defined data filter to the external data processing system.
[0019] Signing using the first digital signature can be performed (locally) on the corresponding industrial edge device. In some embodiments, signing using the first digital signature can be performed remotely, for example, by a software component (such as a license manager) that is not co-located with the industrial edge device and / or the industrial plant and can be accessed by the industrial edge device to perform the signature using the first digital signature.
[0020] The data related to at least one industrial machine can be, for example, (raw) data extracted / exported from at least one industrial machine by at least one industrial edge device that is particularly associated with the at least one industrial machine.
[0021] Therefore, in some embodiments, generating a plurality of data packets based on data related to at least one industrial machine can include a sub-step of extracting data from at least one industrial machine.
[0022] In one embodiment, at least some data packets, in particular all data packets, are log files.
[0023] Data related to at least one industrial machine can also be data generated on at least one industrial edge device. Such data can be based on, for example, edge platform data and / or edge application infrastructure data and / or billing data and / or licensing data, etc. Such data can be produced / generated on at least one industrial edge device by analyzing and processing data from at least one industrial machine and / or from another (raw) data source in an internal data processing system, for example, data generated by the workflow of a software application (edge device application) being processed by one or more edge devices. Such data can be generated by an edge device application that receives data from another edge application, which in turn receives data from an industrial machine.
[0024] In some embodiments, data related to at least one industrial machine can be based on infrastructure data, for example, edge log files or information about the frequency of failures of edge devices or edge applications or pay-per-use billing information of edge applications, etc.
[0025] Thus, in some embodiments, multiple data packets can be generated based on billing data and / or licensing data related to at least one industrial machine. The billing data and / or licensing data can be related to the use of the industrial machine itself or the use of an application that can perform some tasks and process some functions related to the industrial machine.
[0026] Signing of a data packet in a plurality of, in particular unencrypted, data packets using a first digital signature can be performed by at least one industrial edge device on which the data packet is generated. In this case, signing using the first digital signature is done by an ecosystem provider, such as the manufacturer of the industrial edge device.
[0027] Those skilled in the art will understand that the above steps can be repeated for any industrial edge device.
[0028] In one embodiment, those signed data packets that pass through a user-defined data filter can include (before sending them to an external data processing system) signing of these signed data packets using a second digital signature in order to produce doubly signed data packets. This increases the authenticity of the data and the end-to-end data integrity. Signing using the second digital signature can be done, for example, by an operator of the above-mentioned internal data processing system, where the operator can perform the signature from the ecosystem while running one or more applications, for example, on one or more industrial edge devices located in the internal data processing system.
[0029] In some embodiments, signing using the second digital signature can be performed not on the industrial edge device, but by another part of the internal data processing system, such as by a certificate authority. Such a certificate authority does not have to be located at the same location as the industrial plant. For example, it can be implemented as software in the cloud part of the internal industrial network of the internal data processing system.
[0030] In some embodiments, the method can further include verifying the first digital signature of each data packet or recording the absence of the data packet by an external data processing system.
[0031] In some embodiments, the method can further include storing the first key at the external data processing system, where the first key corresponds to the first signature and is used to verify the first signature.
[0032] In some embodiments, the method can further include encrypting each signed data packet by at least one industrial edge device.
[0033] In some embodiments, the internal data processing system can further include at least one gateway component, and the method can further include sending all those data packets that have passed the user-defined data filter to the external data processing system through at least one gateway component.
[0034] In embodiments where the data processing module signs the signed data packet with the second digital signature, sending all the double-signed data packets to the external data processing system through at least one gateway component can include the following partial steps:
[0035] - Sending all the double-signed data packets to at least one gateway component;
[0036] - Verifying the second digital signature of each double-signed data packet with the second key, where the second key corresponds to the second digital signature;
[0037] - Sending all the verified double-signed data packets to the external data processing system.
[0038] In some embodiments, the second key can be queried by the gateway component, so that the verification of the second digital signature can be performed by the gateway component. For example, it can be stored on at least one gateway component itself, or stored at a different location within the internal data processing system but not within the industrial plant, and this location can be accessed by at least one gateway component.
[0039] In some embodiments, the second key can be stored within the internal industrial network rather than on physical devices within the industrial plant. For example, the second key can be stored in the cloud (the cloud portion of the internal industrial network that is part of the internal data processing system) such that verifying the second digital signature can be performed, for example, by an application within the cloud.
[0040] In one embodiment, sending all the double - signed data packets to an external data processing system via at least one gateway component can further include:
[0041] - Encrypting each of the double - signed data packets.
[0042] In one embodiment, a user - defined data filter can be implemented as a whitelist that contains allowed items that can be detected in the content of the data packet, particularly by searching for the item by text of the item and / or applying image classification and / or object detection and / or mapping the objects detected in the image to one or more items.
[0043] In one embodiment, the user - defined data filter is adapted to (e.g., according to the whitelist) filter data packets based on the semantic content of the data, i.e., what data is contained in the data packet.
[0044] In one embodiment, the data filter can be implemented as a whitelist containing matching patterns, particularly regular expressions, especially those regular expressions that can be applied to the content of the data packet.
[0045] To achieve the above - mentioned object, there is also provided a data processing module for providing / filtering / whitelisting data from the internal data processing system of an industrial plant to an external data processing system, wherein the internal data processing system includes at least one industrial edge device and at least one (particularly multiple) industrial machines, and wherein the at least one industrial edge device is adapted / configured to:
[0046] - Generate multiple (particularly unencrypted) data packets related to at least one industrial machine, and
[0047] - Sign each of the multiple data packets with a first digital signature so as to produce multiple signed data packets, wherein the data processing module is provided with at least one, particularly authenticated, even more particularly authenticated by a trusted third party, user - defined data filter and is adapted / configured to:
[0048] - Read each of the multiple signed data packets and, while reading, apply at least one user - defined data filter to each of the signed data packets;
[0049] - Release the signed data packets that pass through the user-defined data filter, or reject the signed data packets that fail to pass through the user-defined data filter;
[0050] - Send all the data packets that have passed through the user-defined data filter to an external data processing system.
[0051] In one embodiment, the data processing module can also be configured to sign the signed data packets that pass through at least one user-defined data filter using a second digital signature so as to generate doubly-signed data packets and send all the doubly-signed data packets to an external data processing system.
[0052] To achieve the above object, an industrial data processing system is also provided, which can be connected to an external data processing system to exchange data with the external data processing system, and includes at least one industrial edge device, at least one, in particular, a plurality of industrial machines, and at least one of the above data processing modules.
[0053] In one embodiment of the present invention, the industrial data processing system can be implemented as a combination of hardware and software components. In one embodiment, at least one industrial edge device of the internal data processing system can include at least one hardware controller, which is configured to encrypt data packets. In particular, the industrial data processing system can include a hardware controller, such as an FPGA (Field Programmable Gate Array). BRIEF DESCRIPTION OF THE DRAWINGS
[0054] The above and other objects and advantages of the present invention will become apparent upon consideration of the following detailed description in conjunction with the accompanying drawings, in which like reference numerals refer to like parts throughout, and in which:
[0055] Figure 1 A block diagram of an exemplary industrial network environment is shown, in which an embodiment with a plurality of industrial machines and industrial edge devices can be implemented;
[0056] Figure 2 A flowchart of an example of a method for providing data from an internal data processing system of an industrial plant to an external data processing system is shown;
[0057] Figure 3 A block diagram of an exemplary industrial network environment having a single gateway component between an internal network and an external network is shown; and
[0058] Figure 4 A block diagram of an exemplary industrial network environment and a trusted third party for providing a key pair is shown. DETAILED DESCRIPTION
[0059] Turning toFigure 1 , which shows a block diagram of an exemplary industrial network environment. The industrial network environment can include an ecosystem hereinafter referred to as an external data processing system (EDP) and an industrial data processing system hereinafter referred to as an internal data processing system (IDP). The internal data processing system (IDP) can use the infrastructure of the ecosystem to perform certain tasks. In particular, the external data processing system (EDP) can be a cloud-based external data processing system (EDP) (cloud-based ecosystem). The external data processing system (EDP) can include a network environment hereinafter referred to as an external network for enabling communication of entities and computing devices and / or systems of the ecosystem (such as backend devices (EB) or systems suitable for analyzing data and performing analytics).
[0060] The internal data processing system (IDP) can include an industrial plant (PL). It should be understood that the internal data processing system (IDP) can be part of or co-located with the local data processing system of the industrial plant (PL). The industrial plant (PL) can be an automated industrial plant. The internal data processing system (IDP) can include a plurality of industrial machines (IM1, IM2,... IMn), such as motors, robots, industrial equipment, automated equipment, and (multiple) industrial edge devices (ED1, ED2,... EDn), where each industrial edge device can be connected to a single industrial machine (IM1, IM2,... IMn) and can communicate with it to exchange data. Different industrial edge devices (ED1, ED2,... EDn) can be connected to different industrial machines (IM1, IM2,... IMn). The industrial edge devices (ED1, ED2,... EDn) and the industrial machines (IM1, IM2,... IMn) can be co-located with the industrial plant (PL) ( Figure 1 ).
[0061] The industrial plant (PL) can be a manufacturing and / or testing facility, an industrial power plant, an industrial plant engineering facility, etc.
[0062] The industrial edge devices (ED1, ED2,... EDn) can be connected (for data exchange, e.g., wirelessly) to the controllers of the machine tools (IM1, IM2,... IMn) within the industrial plant (PL), and thus are co-located with the physical systems in the industrial plant environment. The industrial edge devices (ED1, ED2,... EDn) can be suitable for extracting data from at least one of the plurality of industrial machines (IM1, IM2,... IMn). In addition, the industrial edge devices (ED1, ED2,... EDn) can be suitable for providing (at least some) data processing resources within the internal data processing system (IDP) of the industrial plant (PL) or (briefly) within the internal network of the industrial plant (PL) (e.g., within the plant LAN).
[0063] Industrial edge devices ED1, ED2, ... EDn can be configured to generate packets DP1, DP2, ... DPn, such as unencrypted packets. Packets can be generated based on data related to one or more industrial machines IM1, IM2, ... IMn (on industrial edge devices ED1, ED2, ... EDn). In one embodiment, at least one or a portion or all of the industrial edge devices ED1, ED2, ... EDn can include hardware components configured to encrypt the packets DP1, DP2, ... DPn. In particular, such a hardware component can be a field programmable gate array (FPGA) controller. Such a hardware component can increase the computing power of the industrial edge device, since the resources required for encryption can be used to perform other tasks, such as running applications.
[0064] For example, the packets can be generated based on raw data extracted from industrial machines IM1, IM2, ... IMn, and / or based on data related to the raw data, but which has been analyzed and / or processed by one or more industrial edge devices ED1, ED2, ... EDn, such as by a software application (of an edge application). For example, such applications can use the hardware resources of one or more industrial edge devices ED1, ED2, ... EDn to process the raw data to generate the packets DP1, DP2, ... DPn. Data related to one or more industrial machines IM1, IM2, ... IMn can also be provided to one or more industrial edge devices ED1, ED2, ... EDn by an internal data processing system IDP, such as by a software component of the internal data processing system IDP, such as by another application (such as an edge application), which can be processed on the same industrial edge device. The latter data works based on a data workflow in the internal data processing system IDP, such as between applications deployed on one or more industrial edge devices ED1, ED2, ... EDn. It should be understood that the above software components (such as applications or edge applications) can be processed remotely, for example from the cloud, i.e., the user running a particular application does not have to be located at the same location as the industrial plant PL. In this way, the internal data processing system IDP can use the infrastructure of the ecosystem.
[0065] Data related to at least one industrial machine IM1, IM2, ... IMn can be based on, for example, data or an edge platform and / or edge application infrastructure and / or billing and / or licensing data, etc.
[0066] Figure 1An example is shown where each individual industrial edge device ED1, ED2, ... EDn can be connected to / associated with a single industrial machine IM1, IM2, ... IMn corresponding to that industrial edge device to communicate with each other, and in particular, to exchange and / or receive / extract data therefrom. For simplicity, Figure 1 A situation is described where individual data packets DP1, DP2, ... DPn are generated on each industrial edge device ED1, ED2, ... EDn. However, it should be understood that over time, multiple data packets can be generated on each of the industrial edge devices ED1, ED2, ... EDn.
[0067] The industrial edge devices ED1, ED2, ... EDn are applicable to directly (i.e., without any further processing and / or via other devices) provide the data packets DP1, DP2, ... DPn to external entities in an external data processing system EDP (in the ecosystem). Such entities can be located in the external data processing system EDP, for example, in the cloud, and can be, for example, external software applications (application app) or cloud-based solutions or edge backends EB. In this case, each industrial edge device ED1, ED2, ... EDn acts as a gateway proxy, for example, as an IoT gateway. This can be the case when the entire industrial network environment, including the communication channel between the internal data processing system and the external data processing system (e.g., the edge-to-cloud communication channel), can be fully trusted. The industrial edge devices ED1, ED2, ... EDn are also applicable to encode / encrypt the data packets DP1, DP2, ... DPn, for example, before sending them via one or more uplinks UL1, UL2, ... ULn to the external data processing system EDP, for example, to an external entity in the external data processing system EDP, such as an edge backend EB. This can be advantageous if the communication channel between the internal data processing system IDP and an external entity in the external data processing system EDP or the external data processing system EDP itself cannot be fully trusted.
[0068] The data packets DP1, DP2, ... DPn can have different structures. Generally, they can be unstructured, semi-structured, and structured. For example, the data packets DP1, DP2, ... DPn can be log files.
[0069] In certain scenarios, especially in untrusted situations, the data packets DP1, DP2, ... DPn from the industrial edge devices ED1, ED2, ... EDn can pass through a separate gateway device GW before they leave the internal network of the internal data processing system IDP (e.g., the local network of an industrial plant PL) Figure 3 andFigure 4 ) This may be for security reasons, as it is more feasible to monitor one upload link rather than n, where n is the number of edge devices.
[0070] Before being provided to an external entity (such as a backend device EB in an external data processing system EDP), the data can also be pre - processed / processed, for example, encrypted and / or signed by industrial edge devices ED1, ED2,... EDn. In addition, industrial edge devices ED1, ED2,... EDn are applicable to receive data from the external data processing system EDP. Such data can include data from an external application software app, and / or commands and / or firmware updates from an external entity, etc. Industrial edge devices ED1, ED2,... EDn are applicable to implement / apply the received data in the internal data processing system IDP of the industrial plant PL accordingly.
[0071] However, as described above, there are cases where only a very low level of trust is allowed because the data packets DP1, DP2,... DPn contain sensitive and / or confidential data.
[0072] For this purpose, at least one data processing module DPM is provided. The data processing module DPM is contained in the internal data processing system IDP and can be a separate network component or a software module, particularly a software component, more particularly a plugin, which can be installed on a network component (such as a proxy server, a gateway component, or an industrial edge device of the internal data processing system IDP) and can be implemented by this network component. In particular, the data processing module DPM can be co - located with the industrial plant PL.
[0073] At least one data processing module DPM is provided with a user - defined data filter DF. The user - defined data filter DF can be authenticated, for example, by a trusted third party. The term "user - defined" means that the data filter DF is defined by the user of the provided product in the current context defined by the operator of the industrial plant PL. The user - defined data filter DF contains information about which data is allowed to leave the internal data processing system IDP and which is not allowed to leave. The user - defined data filter DF can be a whitelist. Thus, in one embodiment, the data processing module DPM can be a whitelist plugin with a user - defined data filter DF in the form of a whitelist. The user - defined data filter DF and / or the data processing module DPM can be authenticated. The authentication can be performed by the providers of the industrial machines IM1, 1M2,... IMn and the industrial edge devices ED1, ED2,... EDn and / or the provider of the external entity (for example, by the provider of the application software or an independent trusted third party TC (see Figure 4 ) such as the German Technical Inspection Association ) to execute.
[0074] For example, the user-defined data filter DF can include a list of words and / or matching patterns (e.g., regular expressions, also referred to as "search patterns", that match allowed items) and / or object descriptions (if the data packet contains an image). For example, the data processing module DPM can use a neural network to perform object recognition in the recorded image and, when a certain object (e.g., a spindle or a spindle nose) is recognized, compare it with the content of the user-defined data filter DF. Then, if, for example, the form of the spindle is an industrial secret, the corresponding data packet containing an image of the spindle can be blocked by the data processing module DPM.
[0075] Turning to Figure 2 , an example of a method for providing data from the internal data processing system IDP of an industrial plant PL to an external data processing system EDP is shown.
[0076] In a first step S1 of the method, raw data can be extracted from at least one industrial machine IM1, IM2,... IMn. Multiple data packets DP1, DP2,... DPn can be generated from this data (step S2). At this stage, the data packets can be encrypted or not. Each data packet DP1, DP2,... DPn can be signed with a first digital signature PR1 in order to generate multiple signed data packets (step S3). Steps S1 to S3 can be performed by industrial edge devices ED1, ED2,... EDn. Step S3 ensures that the data comes from the industrial machines IM1, IM2,... IMn (authentication), and that the data has not been changed during transmission when the signature is verified (integrity).
[0077] As described above, the generation of multiple data packets DP1, DP2,... DPn can also be based on data provided by an edge application and related to one or more industrial machines IM1, IM2,... IMn. In this way, the edge application can generate new process-related data that can be further processed in the form of data packets DP1, DP2,... DPn.
[0078] In addition, multiple data packets DP1, DP2,... DPn can be generated based on infrastructure data, such as edge log files or information about the frequency of failures of edge devices or edge applications or pay-per-use billing information of edge applications, etc. This information can be of interest to ecosystem providers and / or edge application developers and / or industrial machine manufacturers.
[0079] Then, each signed data packet can be forwarded to a data processing module DPM, which can, for example, read them (step S4) and compare their content with the content of a user-defined data filter DF, where the content of the user-defined data filter DF can include a list of words (whitelist), matching patterns, or object descriptions. The data processing module DPM can also apply the matching patterns of the DF whitelist of the data filter to the content to obtain filtered data that matches the pattern.
[0080] If the data processing module DPM determines that a particular signed data packet does not contain sensitive data and / or confidential information, then after step S5, the signed data packet is released (arrow Y). In one embodiment, the data processing module DPM can sign the signed data packet with a second digital signature PR2 and generate double-signed data packets SDP1, SDP2,... SDPn (step S6). Doing so can ensure the integrity of the data passing through the user-defined data filter DF. The signature can be performed by a hardware component, such as via an FPGA controller.
[0081] If, when comparing the content of a particular signed data packet with the user-defined data filter DF, the data processing module DPM determines that the signed data packet contains sensitive data, then it can reject the signed data packet after step S5 (arrow N). The term "reject" can indicate, for example, that the signed data packet is not further forwarded, or the data processing module DPM marks the packet, such as by marking "rejected" and further processing the packet, but only within the internal data processing system IDP, specifically only within the local network of the industrial plant PL.
[0082] The first digital signature PR1 can be owned by the provider of the industrial machines IM1, IM2,... IMn and / or the provider of the industrial edge devices ED1, ED2,... EDn and / or the ecosystem provider. The second digital signature PR2 can be owned by the owner of the data processing module DPM and / or the owner of the user-defined data filter DF (usually by the industrial plant PL owner / operator). Both signatures can be provided by the corresponding agency within the external data processing system EDP or the corresponding agency within the internal data processing system IDP. In one embodiment, both digital signatures PR1 and PR2 are provided by an independent trusted entity, such as Figure 4 the trust center TC shown in
[0083] All data packets passing through the user-defined data filter DF (such as the double-signed data packets SDP1, SDP2,... SDPn) can then be sent to the external data processing system EDP (step S7).
[0084] In one embodiment, signing using the first and / or second digital signature can be performed by a hardware component, e.g., by an FPGA controller.
[0085] In some embodiments, the data processing module DPM can be a plug-in installed on each industrial edge device ED1, ED2, ... EDn. Thus, the double-signed data packets SDP1, SDP2, ... SDPn can be provided to the corresponding industrial edge devices ED1, ED2, ... EDn for further processing, e.g., encryption. Those skilled in the art will understand that the data processing module DPM can be designed as a network component, which can be designed separately from the industrial edge devices ED1, ED2, ... EDn.
[0086] In one embodiment, the data processing module DPM can encrypt the double-signed data packets.
[0087] The first digital signature PR1 of each data packet passing through the user-defined data filter DF, e.g., can be signed with the second digital signature PR2, i.e., the double-signed data packets SDP1, SDP2, ... SDPn, can be verified in an external data processing system EDP (S8), e.g., by the original equipment manufacturer (provider of the industrial machine) or the provider of the industrial edge device or the provider of the software application executed at the industrial edge. For control purposes, the external data processing system EDP can record the absence of data packets from the internal data processing system IDP. In this way, e.g., it can be determined that the user-defined data filter DF is not performing in an appropriate manner. This can be due to the unclear content of the user-defined data filter DF, e.g., an ill-defined whitelist and / or matching pattern and / or object description, which can result in blocking all data uploads to the external data processing system EDP, e.g., into the cloud.
[0088] One embodiment of the method includes storing a first key PUB1 at the external data processing system EDP, wherein the first key PUB1 corresponds to the first signature PR1 and can be used to verify the first signature (at any time in the future). The verification can be performed, e.g., by the edge backend device EB. Figure 4 It is shown that the first key PUB1 can be provided to the edge backend device EB.
[0089] As mentioned before, the internal data processing system IDP can also include a gateway component GW, and can send all data packets passing through the user-defined data filter DF to the external data processing EDP system through at least one gateway component GW. Figure 3 and Figure 4It shows that these data packets can be signed with a second digital signature PR2 before reaching the gateway GW.
[0090] The gateway component GW can be controlled by the industrial plant PL owner. If the data packet is signed with the second digital signature PR2 by the data processing module DPM, the gateway component GW can be equipped with a second key PUB2 for verifying the second digital signature PR2. In some embodiments, the verification of the second digital signature PR2 can be performed somewhere within the internal data processing system IDP but outside the gateway component GW. In one embodiment, the verification of the second digital signature PR2 can be performed by an application within the internal network of the internal data processing system IDP. For example, such an application can remotely access the gateway component GW to perform the verification. Verifying the second digital signature PR2 through the gateway component GW, for example, increases the overall security of the solution. In the case of a positive verification, the double-signed data packets SDP1, SDP2,... SDPn can be sent to the external data processing system EDP via the uplink UL, for example, through the gateway component GW or through an application that remotely accesses the gateway component GW for verifying the second digital signature PR2. In one embodiment, the double-signed data packets SDP1, SDP2,... SDPn can be sent to the edge backend device EB.
[0091] In some embodiments, the gateway component can also prevent data packets marked with "DENY" from leaking outside the internal network of the internal data processing system IDP, especially outside the local network of the industrial plant PL.
[0092] In some embodiments, the gateway component GW encrypts the data packets (such as the double-signed data packets) before sending them to the external data processing system EDP.
[0093] In one embodiment, the encryption can be performed by an additional hardware component (such as an FPGA controller).
[0094] As Figure 4As shown, in some embodiments, the internal data processing system IDP can include additional network components NC. The component can be located within the local network of the industrial plant PL, for example, between the industrial edge devices ED1, ED2, ... EDn and the gateway component GW. The network component NC can be a proxy server. The data processing module DPM (such as the plug-in) can be installed on the network component NC. In some embodiments, the digital signatures (private keys) PR1, PR2 can be provided by a trusted third party, such as by the trust center TC. In this case, the trust center TC can generate at least two key pairs KP1, KP2 for the providers of the industrial edge devices ED1, ED2, ... EDn and correspondingly for the users (owners) of the industrial plant PL. The public keys PUB1, PUB2 for verifying the digital signatures PR1, PR2 can also be provided.
[0095] The above embodiments of the present disclosure are presented for illustrative purposes and not for purposes of limitation. In particular, the embodiments described with respect to the drawings are only several examples of the embodiments described in the introductory part.
Claims
1. A method for providing data from an internal data processing system (IDP) of an industrial plant (PL) to an external data processing system (EDP), wherein, the internal data processing system (IDP) includes at least one industrial edge device (ED1, ED2,... EDn), at least one industrial machine (IM1, IM2,... IMn) and at least one data processing module (DPM), wherein the at least one data processing module (DPM) is provided with a user-defined data filter (DF), and wherein the method includes the steps: by the at least one industrial edge device (ED1, ED2,... EDn), - generating a plurality of data packets from data associated with the at least one industrial machine (IM1, IM2,... IMn), and - signing each of the plurality of data packets (DP1, DP2,... DPn) with a first digital signature (PR1) to produce a plurality of signed data packets; by the data processing module (DPM), - reading each of the plurality of signed data packets and applying the user-defined data filter (DF) to each signed data packet while reading, - releasing those signed data packets that pass the user-defined data filter (DF), or rejecting those signed data packets that fail to pass the user-defined data filter (DF), and - sending all those data packets that have passed the user-defined data filter (DF) to the external data processing system (EDP).
2. The method according to claim 1, wherein, the internal data processing system (IDP) further includes at least one gateway component (GW), and sending all those data packets that have passed the user-defined data filter (DF) to the external data processing system (EDP) through the at least one gateway component (GW).
3. The method according to claim 1 or 2, wherein, releasing those signed data packets that pass the user-defined data filter (DF) includes: - signing these signed data packets with a second digital signature (PR2) to produce doubly-signed data packets (SDP1, SDP2,... SDPn).
4. The method according to claim 3, wherein, sending all the doubly-signed data packets (SDP1, SDP2,... SDPn) to the external data processing system (EDP) through the at least one gateway component (GW) includes partial steps: - sending all the doubly-signed data packets (SDP1, SDP2,... SDPn) to the at least one gateway component (GW); - verifying the second digital signature (PK2) of each of the doubly-signed data packets (SDP1, SDP2,... SDPn) with a second key (PUB2), wherein the second key (PUB2) corresponds to the second digital signature (PK2); - Send all the verified and double - signed data packets to the external data processing system (EDP).
5. The method according to claim 4, wherein, sending all the double - signed data packets (SDP1, SDP2,... SDPn) to the external data processing system (EDP) through the at least one gateway component further includes: - Encrypt each of the double - signed data packets (SDP1, SDP2,... SDPn).
6. The method according to claim 1 or 2, further including: Verify the first digital signature (PR1) of each data packet through the external data processing system (EDP) or record the absence of the packet.
7. The method according to claim 6, wherein, The method further includes: Store a first key (PUB1) at the external data processing system (EDP), wherein the first key (PUB1) corresponds to the first digital signature (PR1) and is used to verify the first digital signature.
8. The method according to claim 1 or 2, wherein, The method further includes: - Encrypt each signed data packet through the at least one industrial edge device (ED1, ED2,... EDn).
9. The method according to claim 1 or 2, wherein, The user - defined data filter (DF) is implemented as a whitelist, and the whitelist contains allowed items, and the allowed items can be detected in the content of the data packets (DP1, DP2,... DPn) by searching for the items by text of the items and / or applying image classification and / or object detection and / or mapping the objects detected in the image to one or more items.
10. The method according to claim 1 or 2, wherein, The data filter (DF) is implemented as a whitelist containing matching patterns.
11. The method according to claim 10, wherein, The matching patterns are those regular expressions that can be applied to the content of the data packets (DP1, DP2,... DPn).
12. A data processing module (DPM) for providing data from an internal data processing system (IDP) of an industrial plant (PL) to an external data processing system (EDP), wherein, The internal data processing system (IDP) includes at least one industrial edge device (ED1, ED2,... EDn) and at least one industrial machine (IM1, IM2,...... IMn), wherein the at least one industrial edge device (ED1, ED2,... EDn) is adapted to: - Generate a plurality of data packets from data related to the at least one industrial machine (IM1, IM2,... IMn), and - Sign each of the plurality of data packets (DP1, DP2,... DPn) using a first digital signature (PK1) so as to produce a plurality of signed data packets, wherein the data processing module (DPM) is provided with at least one user - defined data filter (DF) and is adapted to: - Read each of the plurality of signed data packets and apply the at least one user-defined data filter (DF) to each signed data packet while reading; - Release the signed data packets that pass the user-defined data filter (DF) or reject the signed data packets that fail to pass the user-defined data filter (DF); - Send all the data packets that have passed the user-defined data filter (DF) to the external data processing system (EDP).
13. The data processing module according to claim 12, wherein, the at least one industrial edge device (ED1, ED2,... EDn) is adapted to generate a plurality of unencrypted data packets from data associated with the at least one industrial machine (IM1, IM2,... IMn).
14. The data processing module according to claim 12 or 13, wherein, the user-defined data filter (DF) is authenticated.
15. The data processing module according to claim 14, wherein, the user-defined data filter (DF) is authenticated by a trusted third party.
16. An industrial edge device (ED1, ED2,... EDn) comprising the data processing module (DPM) according to any one of claims 12 to 15.
17. An industrial data processing system that can be connected to an external data processing system (EDP) to exchange data with the external data processing system, and the industrial data processing system includes at least one industrial edge device (ED1, ED2,... EDn), at least one industrial machine (IM1, IM2,... IMn), and at least one data processing module (DPM) according to any one of claims 12 to 15.
18. The industrial data processing system according to claim 17, wherein, the at least one industrial edge device (ED1, ED2,... EDn) includes at least one hardware controller configured to encrypt the data packets (DP1, DP2,... DPn).
19. The industrial data processing system according to claim 18, wherein, the at least one hardware controller is a field programmable gate array controller.
20. A computer program product comprising instructions for causing the industrial data processing system according to any one of claims 17 to 19 to perform the steps of the method according to any one of claims 1 to 11.
21. A computer-readable medium having stored thereon the computer program product according to claim 20.
Citation Information
Patent Citations
Communication method and apparatus for an industrial control system
US20200128042A1