System apparatus and method for managing access to data in an automation environment
By classifying analytical operations into a first set of operations and a second set of operations in an automated environment, the problem of restricted data access management is solved, enabling controlled transmission of restricted data and secure transmission of unrestricted data, reducing the consumption of computing resources, and making it suitable for edge computing and cloud computing scenarios.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- SIEMENS AG
- Filing Date
- 2021-01-29
- Publication Date
- 2026-07-28
AI Technical Summary
In automated environments, existing technologies struggle to effectively manage access to both restricted and unrestricted data, leading to excessive consumption of computing and storage resources and difficulty in ensuring data privacy.
By classifying analytical operations into a first set of operations and a second set of operations, which are executed within and outside the trusted computing platform respectively, it ensures that only unrestricted data is transmitted externally, and protects data security through trust policies and inversion control modules.
It enables controlled access and transmission of restricted data, reduces the computational cost of data encryption, and improves data processing efficiency and privacy, making it suitable for edge computing and cloud computing scenarios.
Smart Images

Figure CN115210707B_ABST
Abstract
Description
Technical Field
[0001] This invention generally relates to the Internet of Things (IoT) field, and more specifically to methods, devices, and systems for managing access to data in Internet of Things (IoT) environments / automated environments. Background Technology
[0002] In automated environments such as industrial IoT environments, interface devices connect to IoT cloud platforms, sensors, and actuators via the Internet. Interface devices are often referred to as edge devices.
[0003] Edge devices are lightweight, low-cost devices that collect, store, and buffer data from various sensors and actuators deployed throughout a factory, analyze the data, and execute actions (e.g., issue control commands) based on the analysis results. Edge devices can also be configured to aggregate, filter, selectively report, compress, encrypt, and / or preprocess data, resulting in less data and / or value-added data being communicated to the IoT cloud platform. Therefore, edge devices ensure that data associated with an automated environment is processed within that environment. Furthermore, edge devices can communicate data to the IoT cloud platform in a controlled manner. Thus, the use of edge devices enables faster data processing while maintaining data privacy.
[0004] Examples of ensuring privacy include data encryption through the application of digital access control technologies. The application of data encryption can involve significant expenditure of computing and storage resources. This expenditure can be particularly substantial at the edge. Therefore, systems, devices, and methods used to manage access to data can benefit from improvements. Summary of the Invention
[0005] In one example, a method for managing access to data associated with assets in an automated environment is disclosed. The data includes one of restricted and unrestricted data, and the automated environment is accessible via one or more computing platforms, which include multiple computing resources that can be categorized as trusted and untrusted computing platforms. The method includes: classifying analytical operations that can be performed on the data into a first set of operations, which can be executed on a trusted computing platform, wherein the analytical operations are associated with one or more applications that can be executed on at least one computing platform; and enabling access outside the trusted computing platform to at least one of a first unrestricted output and unrestricted data of the first set of operations.
[0006] In another instance, an apparatus for managing access to data associated with assets in an automated environment is disclosed, wherein the data includes one of restricted data and unrestricted data, the apparatus comprising: an operating system; and a trusted processing module including computer-readable instructions that, when executed by the operating system, configure the trusted processing module to perform the methods described herein.
[0007] In yet another example, a system for managing assets in an automated environment is provided. The system includes one or more computing devices configured to execute one or more applications for managing assets, wherein the computing devices can be classified as trusted computing platforms and untrusted computing platforms based on a trust policy, and wherein the trusted computing platform includes the aforementioned devices, and wherein the computing devices classified as trusted computing platforms are integrated trusted platforms. Another example may include a non-transitory computer-readable medium (such as software components on a storage device) encoded with executable instructions that, when executed, cause at least one processor to perform the described methods.
[0008] Before describing the proposed conventions in more detail, it should be understood that various definitions of certain words and phrases are provided in this patent document, and those skilled in the art should understand that these definitions apply in many (if not most) cases to the prior and future use of the defined words and phrases. While some terms can encompass a wide variety of embodiments, the appended claims expressly limit these terms to specific embodiments. It should also be understood that features interpreted in the context of the proposed method can also be included in the proposed system by appropriate configuration and adaptation, and vice versa.
[0009] Assets can be control equipment, sensors, and actuators. Examples include computer numerical control (CNC) machines, automation systems in industrial production facilities, motors, and generators. An automation environment refers to facilities used for manufacturing and production, and can be semi-automated or fully automated. Examples include industrial automation environments, laboratory automation environments, and building automation environments. Furthermore, according to the present invention, an automation environment can include a combination of one or more industrial automation environments, laboratory automation environments, and building automation environments.
[0010] An automated environment contains multiple types of data that can be generated within or associated with that environment. For example, sensor data can be generated within the automated environment, while control data can be associated with that environment, even if it wasn't generated within it. This data can be sensitive and is referred to hereinafter as restricted data. Restricted data can be referred to as unprotected data to indicate that it is not protected and therefore cannot leave the trusted platform. Insensitive data can be referred to as unrestricted data. By performing one or more transformation functions, restricted data can be converted into unrestricted data. Through these functions, unprotected data can be converted into protected data.
[0011] Non-restricted examples of restricted data include high-precision sensor data, which is restricted if it is transmitted to an external user at its original generation rate. In another instance, high-precision sensor data transmitted to an external user at a slow sampling frequency is unrestricted data. Another example of restricted data includes data points associated with anomalies detected during asset operations. Detected anomalies can be unrestricted data, while associated data points can be restricted data.
[0012] In one embodiment of the invention, the method can include determining whether data associated with an automated environment is restricted or unrestricted data. Therefore, the method can include identifying restricted data in data associated with an asset. In one embodiment, identifying restricted data can include identifying high-frequency signals in the data as restricted data based on a frequency threshold. In another embodiment, identifying restricted data can include identifying high-bandwidth data points in the data as restricted data based on a bandwidth threshold of at least one computing resource / device.
[0013] Furthermore, the method can include identifying restricted data associated with an asset based on one or more constraints related to the data and / or computing resources. Constraints can include at least one of the following: data size, data velocity, data generation time, data generation location, asset generating the data, computing resources processing the data, data processing time, data type, data quality, data correctness probability, data consistency, data integrity, data structure, data semantics, and data confidentiality.
[0014] As used herein, "application" refers to software code used to perform functions using data from an automated environment. For example, an application is a web-based condition monitoring application configured to monitor the condition of assets in an automated environment. The application can be hosted on one or more devices. These devices can be trusted or untrusted. This invention allows applications hosted on untrusted devices to perform the application using both restricted and unrestricted data, while ensuring that only unrestricted data communicates outside the trusted platform.
[0015] This invention advantageously determines whether computing resources can be classified as trusted or untrusted computing resources. In one embodiment, the method can include classifying multiple computing resources into trusted and / or untrusted computing platforms based on a trust policy among the computing resources. The trust policy depends on the communication protocols, digital certificates, and / or cryptographic signatures associated with the data and / or computing resources.
[0016] In one embodiment, the computing resource can be a computing device including a data bus. The data bus can be configured to communicate asset-related data to a trusted processing module. Furthermore, the data bus can be configured to communicate unrestricted data to one or more applications hosted on a computing platform.
[0017] For example, an IoT platform could belong to the computing infrastructure of a third party different from the party responsible for the automated environment. However, this third party can be legally and technically certified by the owner of the automated environment. If, from a legal and technical perspective, the IoT platform itself and all its communications with the automated environment are secure, then in such an instance, the IoT platform can be classified as being within a trusted computing platform.
[0018] A combination of trusted computing resources can be termed a trusted computing platform. Therefore, this method can include implementing communication between one or more trusted computing resources to form a trusted computing platform. The trusted computing platform can act as an integrated overall platform across multiple asset types and trusted computing resources. For example, a CNC controller in an industrial facility is associated with a first trusted computing resource, while the automation system of the industrial facility is associated with a second computing resource. The first and second trusted computing resources are configured to communicate with each other to execute applications. Furthermore, the industrial facility can access the cloud computing platform via a cloud computing platform with authorized access to both restricted and unrestricted data. In this case, the trusted computing platform includes a combination of the first and second trusted computing resources and the cloud computing platform.
[0019] The method analyzes applications that use both restricted and unrestricted data. It can include analyzing the application to determine whether restricted and / or unrestricted data is required for execution. This analysis advantageously ensures that only unrestricted data is accessed outside the trusted computing platform. Furthermore, this analysis can be performed at different stages of the application (i.e., before deployment and / or during runtime). This analysis can be performed through a human code review of the application. In another embodiment, the application can consist of multiple services that can be accessed in combination through a single entry point (such as a plugin). This plugin can be configured to ensure that only unrestricted data is accessible outside the trusted computing platform. Therefore, the present invention overcomes the need for encryption of each data point.
[0020] In one embodiment, the analysis can be performed by representing the application as an analysis operation based on one of the following: the input data required by the application, the predicted output data, or the transformation function between the input and output data. For example, the input data can be constrained or unconstrained data associated with an automated environment. By decomposing the application into operations, it is easy to identify which operations require constrained data and produce constrained outputs. This analysis achieves the classification of operations in a first set of operations, where only the execution of the operations is feasible. Therefore, the method can include classifying analysis operations into a first set of operations based on the constrained data requirements for performing the analysis operations. To facilitate classification, communication of the results of the first set of operations is only possible in the case of unconstrained outputs and through separate communication operations.
[0021] The method can include executing application logic using restricted and / or unrestricted data via a first set of operations; and generating an output of the first set of operations based on the executed logic, wherein the output can be classified as a first restricted output and a first unrestricted output. Therefore, the output of the first set of operations can be restricted or unrestricted. If unrestricted, it can be available outside the trusted computing platform via communication operations. If the output is a first restricted output, further processing is performed via a second set of operations.
[0022] In one embodiment, the first set of operations can include multiple operations. For example, the first set of operations can be executed using multiple computing resources distributed across an automated environment. Therefore, the method can include generating intermediate results capable of communication between operations within the first set of operations; and generating at least one of a first constrained output and a first unconstrained output when executing the first set of operations. Thus, the present invention advantageously utilizes existing computing resources that can be distributed across an automated environment.
[0023] In one embodiment of the invention, the method can include defining the communication operation as including inversion control to ensure that the output of the trusted computing platform cannot be converted into restricted data. The method can include restricting the conversion of the trusted platform output into restricted data, wherein the trusted platform output includes one of unrestricted data, a first restricted output, and / or a second unrestricted output. Therefore, the invention proposes an additional mechanism to verify that the output from the trusted platform is irreversibly engineered. Thus, the invention makes it impossible to retrieve restricted data or restricted output from operations performed within the trusted computing platform.
[0024] In one embodiment of the invention, the method can include classifying analytical operations into a second set of operations. The second set of operations is performed using at least one of restricted data, unrestricted data, and output from a first set of operations to generate a second unrestricted output. This second unrestricted output can be communicated outside a trusted platform via a communication operation. In one embodiment, the first set of operations can produce a restricted output. The second set of operations advantageously converts the restricted output into a second unrestricted output. This mechanism is applicable to analytical operations used for condition monitoring.
[0025] For example, a first set of operations is configured to detect anomalies in assets by identifying anomalous data points. The output of the first set of operations can include anomalous data points. These anomalous data points can be classified as restricted data. Therefore, a second set of operations can extract samples of the anomalous data points to present them as unrestricted data. The detected anomalies and samples can be communicated outside the trusted computing platform via communication operations. This invention advantageously ensures that business logic is executed within the trusted computing platform while preventing restricted data from being exposed outside the trusted computing platform.
[0026] In one embodiment of the invention, the method can include using at least one of unrestricted data, a first unrestricted output, and a second unrestricted output to further execute the application. For example, the application can be used to generate a visual representation indicating the condition of assets. The invention advantageously allows the use of unrestricted output and unrestricted data from a trusted computing platform for such further processing.
[0027] This invention includes several aspects, including data classification. Furthermore, applications using the data can be decomposed into operations and / or functions. These operations are then classified based on the data used. Additionally, computing resources linked to the automated environment can be classified into trusted and untrusted platforms. The results of unrestricted data and application operations are selectively transmitted outside of trusted platforms.
[0028] This invention addresses the problem of providing controlled access to restricted data in distributed computing environments. Furthermore, by avoiding the overhead of data encryption, it simplifies the implementation of applications in cyber-physical systems. It combines multiple technical approaches: identifying data to be protected, requiring protected data, and allowing link functionality across trusted computing platforms. Specifically, this invention is well-suited for resource-efficient use cases, such as edge computing and cost-constrained local servers / clusters, as well as cloud computing scenarios for machine tool data analysis, etc.
[0029] The technical features of this disclosure have been outlined quite broadly above to enable those skilled in the art to better understand the detailed description that follows. Additional features and advantages of this disclosure that form the subject matter of the claims will be described below. Those skilled in the art will understand that other structures for achieving the same purpose as this disclosure can be readily modified or designed based on the disclosed concepts and specific embodiments. Those skilled in the art will also recognize that such equivalent constructions do not depart from the scope of the broadest form of this disclosure. Attached Figure Description
[0030] The present invention will now be described using embodiments shown in the accompanying drawings.
[0031] Figure 1 An apparatus for managing access to data associated with assets in an automated environment is shown according to an embodiment of the present invention;
[0032] Figure 2 A trusted computing platform and an untrusted computing platform according to embodiments of the present invention are illustrated;
[0033] Figure 3 A system for managing access to data associated with assets in an automated environment is illustrated according to an embodiment of the present invention;
[0034] Figure 4 This illustrates the ability, according to embodiments of the present invention, to enable Figure 3 The system management's data model for accessing data;
[0035] Figure 5 A method for managing access to data associated with assets in an automated environment is illustrated according to embodiments of the present invention; and
[0036] Figure 6 A method for managing access to data associated with assets in an automated environment is illustrated according to an embodiment of the present invention.
[0037] The embodiments for carrying out the present invention will now be described in detail. Various embodiments are described with reference to the accompanying drawings, wherein the same reference numerals are always used to refer to the same elements. In the following description, numerous specific details are set forth for purposes of explanation in order to provide a thorough understanding of one or more embodiments. It will be apparent that these embodiments can be practiced without these specific details. Detailed Implementation
[0038] As used herein, an automation environment refers to an environment comprising multiple devices and assets. Devices can include interface devices, control devices, edge devices, and Internet of Things (IoT) enabled devices that collect data from various sensors and / or actuators deployed within the automation environment. Those skilled in the art will understand that an automation environment is not only a physical entity but also a logical entity defining the relationships between devices and assets. Example automation environments include industrial automation environments with process automation and quality analysis. Other automation environments include milling and engineering automation environments, laboratory automation environments, building automation environments, etc.
[0039] Assets refer to systems and equipment in an automated environment. Assets can be located away from IoT platforms. For example, assets can be equipment, sensors, actuators, robots, and machines in an industrial automation environment. Assets can also be medical devices and equipment in a medical automation environment. Furthermore, assets can be household appliances or office appliances or systems in a building automation environment.
[0040] Figure 1 An apparatus 190 for managing access to data associated with assets 112 in an automated environment 110 is shown according to an embodiment of the present invention. The apparatus 190 can be physically located within or outside the automated environment 110. For example, in Figure 1 In this context, the automation environment 110 is a process automation environment configured to perform process and quality analysis of workpieces in an industrial workshop. Therefore, asset 112 includes workpieces and machines associated with those workpieces. Furthermore, asset 112 can include equipment for performing quality analysis of the workpieces, such as sensors and actuators.
[0041] Device 190 is a gateway device configured to communicate with external users / clients 170 and assets 112. Gateway device 190 is configured to monitor, modify, and control assets 112 using control device 120. Figure 1 In this document, control devices 120 are referred to as control devices 122, 124, 126, and 128, respectively. Process data from asset 112 can be transmitted to gateway device 190 via control devices 120. In one embodiment, control devices 120 can be used alone or in conjunction with gateway device 190 to perform one or more features of the invention. Those skilled in the art will understand that process data is an instance of data occurring in an automated environment. Process data can be measured using sensors. Therefore, process data can include time-series sensor data and control data having control signals generated by control devices 120.
[0042] External user 170 includes a combination of one or more clients, including software applications hosted on Internet of Things (IoT) platform 172 or website 174. Furthermore, clients can include Open Platform Communications Unified Architecture (OPC UA) client 176 and Message Queuing Telemetry Transport (MQTT) client 178. Other clients can include authentication application 175 and standard application 180. Gateway device 190 advantageously manages access to process data of asset 112. Therefore, gateway device 190 is configured to ensure that clients 172, 174, 175, 176, 178, and 180 do not have unimpeded access to process data. Therefore, the present invention advantageously protects restricted data 104 from unauthorized access by client 170.
[0043] To ensure secure management of process data, gateway device 190 is configured to identify whether process data is restricted data 104 or unrestricted data 106. In one embodiment, gateway device 190 is configured to identify restricted data 104 based on one or more constraints associated with process data and / or computing resources (i.e., external user 170). Constraints as used herein refer to data size, data rate (the rate at which data is generated and / or made available), data generation time, data generation location, assets that generate the data, computing resources that process the data, data processing time, data type, data quality, probability of data correctness, data consistency, integrity of process data, structure of process data, semantics of process data, and confidentiality of process data.
[0044] In one embodiment, the semantics of the process data are determined. Semantics are used to classify process data into categories such as events or samples of process and condition parameters. Furthermore, semantics are used to establish relationships between asset 112 and its components and associated functions. For example, gateway device 190 can be configured to determine that a sample of high-frequency, high-precision sensor data is restricted data 104 if it is transmitted to external user 170 at its original generation rate. In another instance, gateway device 190 can be configured to determine that a sample of high-precision sensor data is unrestricted data 106 if it is transmitted to external user 170 at a slow sampling frequency of 10 seconds.
[0045] Those skilled in the art will understand that the identification of restricted data 104 and unrestricted data 106 can also be performed by the control device 120. The control device 120 can be configured to determine restricted data 104 and indicate a confidentiality metric so that the gateway device 190 can restrict access accordingly.
[0046] To implement this invention, device 190 can be configured to include a southbound interface 130 and a northbound interface 160. Southbound interface 130 can include physical and logical adapters 132, 134, 136, and 138 capable of communicating with control devices 122, 124, 126, and 128, respectively. Similarly, northbound interface 160 includes client interfaces 162, 164, 166, and 168 for IoT platform 172, website 174, OP CUA client 176, and MQTT client 178. Furthermore, northbound interface 160 includes a file export interface 165 configured to transfer restricted data 104A to authentication application 175 and unrestricted data 106A to standard application 180. Those skilled in the art will understand that, based on the operations performed by gateway device 190, restricted data 104 and 104A can be the same, similar, or different. Similarly, based on the operations performed by gateway device 190, unrestricted data 106 and 106A can be the same, similar, or different.
[0047] Gateway device 190 is also configured with service module 140. Service module 140 includes data bus module 142 and persistent service module 144. In one embodiment, data bus module 142 is configured to allow external users 172, 174, 176, and 178 to access unrestricted data 106A. In one embodiment, persistent service module 144 is used as a database to store restricted data 104A and / or unrestricted data 106A generated during application runtime.
[0048] Furthermore, the persistence module can include a trusted processing module configured to implement the methods described in this invention. The persistence service module 144 can also be configured to export records of restricted data 104A to the authentication application 175, and to export records of unrestricted data 106A to both the authentication application 175 and the standard application 180. In one embodiment, the authentication application 175 can identify itself based on confidentiality restrictions imposed on its use. Therefore, the gateway device 190 identifies the authentication application 175 as part of a trusted platform, and thus makes the restricted data 104A available to the authentication application 175. Figure 2 It describes how to identify trusted and untrusted platforms.
[0049] Gateway device 190 also includes application module 150, wherein multiple applications 154, 156, and 158 can be executed using application development / execution module 152. Those skilled in the art will understand that applications 154, 156, and 158 can also include instances of their respective applications. In one embodiment, instances of applications hosted on IoT platform 172 can be executed in application module 150. Therefore, gateway device 190 advantageously brings the functionality of applications in IoT platform 172 to a secure processing environment (i.e., a trusted computing platform). Consequently, these applications can execute without encrypting restricted data 104, thereby reducing computational overhead.
[0050] Gateway device 190, control device 120, asset 112, and IoT platform 172 can also be referred to as computing resources. In this invention, computing resources are classified into trusted computing platforms and / or untrusted computing platforms based on a trust policy. The trust policy can be between computing resources and can depend on the communication protocols, digital certificates, and / or cryptographic signatures associated with the data and / or computing resources.
[0051] Figure 2 A trusted computing platform 250 and an untrusted computing platform 260 according to embodiments of the present invention are shown.
[0052] Trusted platform 250 includes asset 210, data collection device 220, edge computing device 230, and IoT platform 240 hosting application 242. Untrusted platform 260 includes external IoT platform 270 hosting application 272 to monitor asset 210. Untrusted platform 260 also includes user device 280 capable of interacting with application 272 hosted on external IoT platform 270.
[0053] Based on the trust policy among data collection device 220, edge computing device 230, and IoT platform 240, IoT platform 240 is classified as part of trusted computing platform 250. The trust policy depends on the communication protocol used for communication between IoT platform 240 and devices 220 and 230. Furthermore, the trust policy can depend on the digital certificates and cryptographic signatures associated with devices 220, 230, and platform 240. Additionally, the trust policy can depend on the certificates or signatures associated with data associated with asset 210.
[0054] For example, IoT platform 240 is configured to communicate with one of edge device 230 and / or data collection device 220 using the Transport Layer Security (TLS) protocol, which provides communication security. Furthermore, IoT platform 240 can be configured to manipulate asset data using cryptographic signatures / extensions. In such an instance, IoT platform 240 can be classified as being within trusted platform 250.
[0055] In another example, the IoT platform 240 is built on a distributed computing infrastructure with a management model based on the International Organization for Standardization (ISO), the National Institute of Standards and Technology (NIST), and the Federal Information Processing Standard (FIPS). Furthermore, edge devices 230 and / or data collection devices 220 can be configured based on ISO, NIST, and FIPS. Therefore, in such an example, the IoT platform 240 can be classified as being within a trusted platform 250.
[0056] In another instance, IoT platform 240 is a third-party computing infrastructure, legally and technically certified by the owner of collection device 220, who thus trusts the third-party IoT platform 240. If, from a legal and technical perspective, IoT platform 240 itself and all its communications with collection device 220 are secure, then in such an instance, IoT platform 240 can be classified as being within trusted computing platform 250.
[0057] Figure 3 A system 300 according to an embodiment of the present invention is shown for managing access to data associated with assets 312, 314 in an automated environment 310. The data associated with assets 312 and 314 and the automated environment 310 can be restricted data or unrestricted data, collectively referred to as data 302.
[0058] System 300 includes a trusted computing platform 350 and an untrusted computing platform 360. The untrusted platform 360 is configured to host one or more applications 370. Applications 370 are capable of performing one or more operations associated with assets 312 and 314 and / or the automation environment 310. Applications 370 execute based on output 355 from the trusted platform 350.
[0059] Trusted platform 350 can include multiple computing devices, such as control devices, edge devices, and / or trusted IoT platforms. Trusted platform 350 can be similar to trusted platform 250. Trusted platform 350 can use the trust policies disclosed above for identification.
[0060] The operation of the trusted platform 350 is described according to the first operation set 320, the second operation set 330, the execution interface 340, and the inversion control module 345. Those skilled in the art will understand that a combination of the IoT platform and one or more edge devices can be configured to perform the above operations. The output 355 of the trusted platform 350 includes unrestricted data associated with assets 312, 314 and / or unrestricted results / outputs from the first operation set 320 and / or the second operation set 330.
[0061] During operation, system 300 is capable of the following operations: Analyzing application 370 and representing the application as one or more analysis operations. Based on the input data required by application 370, the predicted output data from application 370, and the transformation functions between the input and output data, application 370 is represented as an analysis operation.
[0062] For example, application 370 is a condition monitoring application. Condition monitoring application 370 is capable of performing analytical operations, including reading data 302 to identify vibration data and analyzing deviations in the vibration data. In the above example, the reading and analytical operations execute application-specific logic associated with condition monitoring application 370. The analytical operations that execute the logic of application 370 are categorized into a first set of operations 320 and executed by trusted platform 350. Non-limiting examples of application-specific logic may include mathematical equations, relational / continuous queries, rule-based mapping of data 302, constraint solving logic, mathematical optimization logic, and / or inference logic.
[0063] For the classification of analytical operations, it may be necessary to determine in parallel or in advance whether data 302 is restricted or unrestricted data. Therefore, system 300 can be configured to identify restricted data based on one or more constraints associated with data 302 and / or computing resources 350, 360. For example, constraints include the data size of data 302, the speed of data 302, the time of data generation, the location of data generation, the assets that generated data 302, the computing resources that processed the data, the data processing time, the type of data, the quality of the data, the probability of data correctness, the consistency of the data, the integrity of the data, the structure of the data, the semantics of data 302, and the confidentiality of data 302.
[0064] Consider an example of condition monitoring application 370. If the vibration data generation rate is faster than 10,000 data points / second, the vibration data used to execute application 370 can be classified as restricted data. Alternatively, if the vibration data is associated with asset 312 (classified as a sensitive asset), the vibration data is classified as restricted data. The above examples are not limiting. Those skilled in the art will understand that there are many such examples that can be used to explain how data 302 can be classified as restricted data.
[0065] The analysis operations, as the first set of operations 320, are based on the availability of the data 302 used to perform the analysis operations. By classifying the analysis operations into the first set of operations 320, the logic of application 370 is executed using restricted and / or unrestricted data. Therefore, the logic of application 370 is deployed within the trusted platform 350.
[0066] In one embodiment, intermediate results can be generated in a first set of operations 320. For example, the first set of operations 320 includes operations 322 and 324. Intermediate results can be generated by operation 322 and communicated to operation 324. Those skilled in the art will understand that operation 322 can be executed on one computing resource, while operation 324 can be executed on the same or another computing resource.
[0067] The result / output of the first operation set 320 can include a first unrestricted output of the first operation set 320 and / or a first restricted output of the first operation set. Therefore, it is understood that the output of the first operation set 320 can be restricted, unrestricted, or both. For example, the first operation set 320 can output aggregated vibration data, metadata of the vibration data, and deviations detected in the vibration data. The aggregated vibration data and the detected deviations can be considered as the first unrestricted output. The data points associated with the detected deviations and the vibration metadata can be considered as the first restricted output.
[0068] like Figure 3 As shown, the first operation set 320 communicates only with the execution interface 340 and the second operation set 330. The first operation set 320 does not communicate outside the trusted platform 350. Furthermore, the first unrestricted output communicates outside the trusted platform 350 via the second operation set 330. Therefore, the system 300 advantageously ensures access to both restricted and unrestricted data to execute the logic of application 370. The system also advantageously ensures that the output of the first operation set 320 is within the trusted platform 350. Therefore, the first operation set 320 acts as a protected application space for executing the logic of application 370.
[0069] Execution interface 340 can be configured as a runtime interface. Execution interface 340 defines the common lifecycle management of analytical operations. Furthermore, execution interface 340 provides connections to assets 312 and 314. Additionally, execution interface 340 can be configured to process data 302.
[0070] In one embodiment, the analysis operation can be classified as a second operation set 330. The second operation set 330 includes operations 332 and 334. The second operation set 330 outputs a second unrestricted output. The second operation set 330 operates in a manner similar to the first operation set 320. Furthermore, the second operation set 330 can include communication operations that enable communication between the unrestricted data and the second unrestricted output outside the trusted platform 350. Therefore, the analysis operation that uses restricted data, unrestricted data, and the output of the first operation set 320 to generate the unrestricted output can be classified as the second operation set 330.
[0071] Therefore, system 300 advantageously classifies the operations of application 370 into two types. The first type of operation can process and execute logic associated with application 370. This is referred to as the first operation set 320. The second type of operation can process and execute logic, and can communicate the results of the operation back to application 370 hosted on untrusted platform 360. This is referred to as the second operation set 330. Since the first operation set 320 can only communicate within trusted platform 350, encryption overhead is reduced. Furthermore, the second operation set 330 can communicate data only outside trusted platform 350 in a controlled manner, thus protecting the privacy of data 302.
[0072] A reversal check is performed before communication with output 355 occurs outside of trusted platform 350. Reversal control module 345 is configured to detect and restrict conversions from output 355 to restricted data or a first restricted output. In one embodiment, reversal control module 345 may include modules for automatic checks when the logic of application 370 is deployed within trusted platform 350. In another embodiment, a manual review can be performed before the logic of application 370 is deployed within trusted platform 350. For example, reversal check interface 345 is configured to review the code of application 370 to ensure that restricted data cannot be reconstructed from output 355.
[0073] In one embodiment, the inversion check can also be performed via the second set of operations 330. By restricting the transformation of output 355, copying of the restricted data is prevented. Thus, unauthorized use of the restricted data or the first restricted output is prevented outside the trusted platform 350.
[0074] Figure 4 This illustrates the ability, according to embodiments of the present invention, to enable Figure 3 System 300 manages access to data 302 via data model 400. Data model 400 includes multiple levels to indicate the flow of data 302 from the component level (assets 312, 314) to the platform level. Therefore, asset model 410 can be generated specific to assets 312 and 314. Asset model 410 is then transformed or mapped to reference model 420. Mapping to reference model 420 can be performed using a general data model tool 430. General data model tool 430 can include a perception model 432, a graphical model 434, a semantic model 436, and a cognitive model 438. The general data model is then transformed into an IoT model or an application-specific model 440. Thus, application 370 is executed using output 355.
[0075] Those skilled in the art will understand that various data modeling techniques can be used to implement the data model 400 described above. For example, semantic model 436 can identify data points in data 302 by asset type, asset name, data point type, and parameter type. Semantic model 436 can be implemented using knowledge graphs. In another instance, graph pattern 434 can discover graphs in data 302 using computational processes based on machine learning and statistical techniques.
[0076] Therefore, system 300 is configured to determine application-specific data model 440 and is able to map data 302 to data model 440.
[0077] Figure 5 A method for managing access to data associated with assets in an automated environment, according to an embodiment of the present invention, is illustrated. The method begins at step 510, where an application is represented as one or more analytics operations. The application can be hosted on untrusted computing resources. Before or at step 510, the determination of trusted and untrusted computing resources can be performed. Furthermore, at step 510, the analytics operations are classified into a first set of operations based on the input data required by the application, the predicted output data, and the transformation functions between the input and output data.
[0078] At step 520, the application logic is executed using restricted and / or unrestricted data associated with assets in the automated environment via a first set of operations.
[0079] At step 530, based on the executed logic, the output of the first set of operations is generated. This output is classified as either a first restricted output or a first unrestricted output.
[0080] At step 540, the analysis operations can be classified into a second set of operations to generate a second unrestricted output. Analysis operations in the second set of operations are performed using restricted data, unrestricted data, and / or output from the first set of operations. The second set of operations ensures that restricted data and / or the first restricted output are transformed into the second unrestricted output. In other words, restricted data / output is transformed into unrestricted output.
[0081] At step 550, the transformation from the second unrestricted output to restricted data and / or the first restricted output is examined. This examination determines whether the restricted data and / or the first restricted output can be reconstructed from the second unrestricted output. If so, restrictions are imposed on the analysis operation to ensure that it is impossible to reconstruct the first restricted output and / or the restricted data.
[0082] At step 560, unrestricted data and / or a second unrestricted output are further used to enable application execution. This prevents application execution by transmitting the unrestricted data and / or the second unrestricted output to the computing device hosting the application.
[0083] Figure 6 A method for managing access to data associated with assets in an automated environment, according to an embodiment of the present invention, is illustrated. The method begins at step 610, identifying restricted data associated with the asset based on one or more constraints. These constraints can be associated with the data associated with the asset. Furthermore, the constraints can be associated with computing resources in the automated environment or computing resources hosting applications. For example, constraints may include at least one of the following: data size, data speed, data generation time, data generation location, asset generating the data, computing resources processing the data, data processing time, data type, data quality, probability of data correctness, data consistency, data integrity, data structure, data semantics, and data confidentiality.
[0084] In step 620, the application's analytical operations are categorized based on the requirements of the limited data for execution.
[0085] At step 630, computing resources are classified into trusted computing platforms or untrusted computing platforms based on a trust policy. The trust policy can be applied across computing resources. For example, the trust policy can depend on communication protocols, digital certificates, and / or cryptographic signatures associated with the data and / or computing resources. For the purposes of explaining this invention, the application is hosted on an untrusted computing platform.
[0086] In step 640, the application's analysis operation is performed within the trusted computing platform, resulting in the generation of unrestricted output from the trusted computing platform. The unrestricted output is then transmitted to the application for further processing.
[0087] This invention can take the form of a computer program product comprising program modules accessible from a computer-usable or computer-readable medium storing program code used or in connection with one or more computers, processors, or instruction execution systems. For the purposes of this specification, a computer-usable or computer-readable medium can be any means capable of containing, storing, communicating, propagating, or transmitting a program for use by or in connection with an instruction execution system, apparatus, or device. The medium can be an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system (or apparatus or device) or a propagation medium (which itself is not included in the definition of a physical computer-readable medium as a signal carrier), including semiconductor or solid-state memory, magnetic tape, removable computer disks, random access memory (RAM), read-only memory (ROM), hard disks, and optical disks, such as optical disc read-only memory (CD-ROM), read / write optical discs, and DVDs. As those skilled in the art will appreciate, the processors and program code used to implement various aspects of this technology can be centralized or distributed (or a combination thereof).
Claims
1. A method for managing access to data associated with assets (112, 312, 314) in an automated environment (110, 310), wherein, The data includes one of restricted data and unrestricted data, wherein restricted data includes sensitive and unprotected data, and The automated environment (110, 310) is accessible via one or more computing platforms, which include multiple computing resources that can be categorized into trusted computing platforms (150, 250, 350) and untrusted computing platforms (170, 260, 360). The method includes: The application is represented as an analysis operation based on one of the input data required by the application, the predicted output data, or the transformation function between the input data and the output data. Based on the requirements for performing analytical operations on the restricted data, the analytical operations that can be performed on the data are classified into a first set of operations (320). This first set of operations can be executed on the trusted computing platforms (150, 250, 350), wherein the analytical operations are associated with one or more applications that can be executed on at least one of the computing platforms; and Access to at least one of the unrestricted data and the first unrestricted output of the first operation set (320) is achieved from the trusted computing platform (150, 250, 350) via communication operations; The analytical operations, which include determining restricted data related to the analytical operations, are classified based on one or more constraints associated with the data and / or the computing resources, wherein the constraints include at least one of the following: data size, data speed, data generation time, data generation location, and assets (112, 312, 314).
2. The method according to claim 1, further comprising: The application logic is executed using the restricted data and / or the unrestricted data via the first operation set (320); as well as The output of the first operation set (320) is generated based on the executed logic, wherein the output can be classified into a first restricted output and a first unrestricted output.
3. The method according to claim 2, further comprising: The logic is executed using the restricted data and / or the unrestricted data associated with the assets (112, 312, 314); Generate intermediate results that enable communication between operations (322, 324) in the first operation set (320); as well as Generate at least one of the first restricted output and the first unrestricted output.
4. The method according to claim 2 or 3, further comprising: The analysis operations are classified into a second set of operations (330), which is performed using at least one of the restricted data, the unrestricted data, and the output from the first set of operations (320) to generate a second unrestricted output of the second set of operations (330); wherein the second unrestricted output is capable of communicating outside the trusted platform via a communication operation.
5. The method according to any one of claims 1 to 3, wherein, The analytical operations that can be performed on the data are classified into the first set of operations (320), and the classification further includes: The data generation, computational resources for processing the data, data processing time, data type, data quality, probability of data correctness, data consistency, data integrity, data structure, data semantics, and data confidentiality; and Based on the requirements of the restricted data for performing the analysis operation, the analysis operation is classified into the first operation set (320).
6. The method according to claim 1, wherein, Identify restricted data in the data associated with the assets (112, 312, 314), the identification including at least one of the following: Based on a frequency threshold, high-frequency signals in the data are identified as restricted data; as well as Based on the bandwidth threshold of at least one of the computing resources, high-bandwidth data points in the data are identified as restricted data.
7. The method according to any one of claims 1 to 3, wherein the method comprises: Based on the trust policy among the computing resources, the multiple computing resources are classified into trusted computing platforms (150, 250, 350) and / or untrusted computing platforms (170, 260, 360), wherein the trust policy depends on the communication protocol, digital certificate and / or cryptographic signature associated with the data and / or the computing resources.
8. The method according to claim 4, wherein the method comprises: The application is further executed using at least one of the unrestricted data, the first unrestricted output, and the second unrestricted output.
9. The method according to claim 4, wherein the method comprises: The conversion from the trusted platform output (355) to the restricted data is restricted, wherein the trusted platform output (355) includes one of the unrestricted data, the first restricted output, and / or the second unrestricted output.
10. A device (190) for managing access to data associated with assets (112, 312, 314) in an automated environment (110, 310), wherein, The data includes one of restricted data and unrestricted data, and the device includes: Operating system; and A trusted processing module (144) includes computer-readable instructions, which, when executed by the operating system, are configured to perform the steps of any one of claims 1 to 9.
11. The device (190) according to claim 10, wherein, The automated environment (110, 310) can be accessed via one or more computing platforms, which include multiple computing resources that can be classified into trusted computing platforms (150, 250, 350) and untrusted computing platforms (170, 260, 360), and wherein the trusted computing platforms (150, 250, 350) include the device.
12. The device (190) according to any one of claims 10 and 11, further comprising: Data bus (142), the data bus being configured to: The data associated with the assets (112, 312, 314) is communicated to the trusted processing module; The unrestricted data is communicated to one or more applications hosted on a computing platform.
13. A system for managing assets (112, 312, 314) in an automated environment (110, 310), the system comprising: One or more computing devices configured to execute one or more applications for managing the assets (112, 312, 314), wherein, based on a trust policy, the computing devices can be classified as trusted computing platforms (150, 250, 350) and untrusted computing platforms (170, 260, 360), and wherein the trusted computing platforms (150, 250, 350) include at least one device according to any one of claims 11 to 12, wherein the computing device classified as the trusted computing platform (150, 250, 350) is a configured integrated trusted platform.
14. A computer-readable medium storing machine-readable instructions that, when executed by a processor, cause the processor to perform the steps of the method according to any one of claims 1 to 9.