Distributed industrial private cloud system

By deploying a distributed industrial private cloud system in industrial application environments, the problem that public clouds cannot meet actual needs is solved, and a secure industrial control and data storage solution tailored to the customer is achieved.

CN116366689BActive Publication Date: 2026-01-06SIEMENS (CHINA) CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202310282493.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-03-22
Publication Date
2026-01-06
Estimated Expiration
2043-03-22

AI Technical Summary

Technical Problem

Public cloud services cannot meet the actual needs of industrial applications, and there are problems such as data security, resource competition and regulatory compliance difficulties. Moreover, users are only users, not owners.

Method used

A distributed industrial private cloud system is provided, including master nodes and child nodes. Each node has an industrial platform, on which server hosts and virtual machines are deployed to realize industrial functions and data storage. The nodes are deployed locally to ensure control and security.

Benefits of technology

It enables customized industrial control and data storage based on customer needs, avoids resource competition, ensures local data storage and security, and complies with security regulations for industrial application scenarios.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116366689B_ABST
    Figure CN116366689B_ABST
Patent Text Reader

Abstract

The embodiment of the present application provides a kind of distributed industrial private cloud system, including main node and at least one subnode, each subnode is respectively with the main node through internet network connection;Wherein: the main node and each node in the at least one subnode includes at least one industrial platform, each industrial platform includes at least one server host, each server host in the same industrial platform is located in the same network segment;At least one virtual machine is deployed on each server host, each virtual machine is used to realize the industrial function corresponding to the industrial platform of belonging, and each server host is also used to store the data resource of the industrial platform of belonging.The embodiment of the present application can satisfy the actual demand of customer in industrial application environment.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of industrial control technology, and in particular to a distributed industrial private cloud system. Background Technology

[0002] In industrial applications, it is often necessary to rent public cloud services from public cloud providers to achieve functions such as industrial control and data storage. However, public cloud services cannot meet the actual needs of industrial applications and are therefore not suitable for all customers. Summary of the Invention

[0003] This invention provides a distributed industrial private cloud system that can meet the actual needs of customers in industrial application environments.

[0004] The distributed industrial private cloud system provided in this embodiment of the invention includes a master node and at least one child node, each child node being connected to the master node via the Internet; wherein:

[0005] Each of the master node and the at least one child node includes at least one industrial platform, and each industrial platform includes at least one server host. The server hosts within the same industrial platform are located in the same network segment. Each server host is equipped with at least one virtual machine. Each virtual machine is used to implement the industrial functions corresponding to its industrial platform, and each server host is also used to store the data resources of its industrial platform.

[0006] The distributed industrial private cloud system provided in this embodiment of the invention has at least the following technical effects:

[0007] Because each node contains at least one industrial platform, and each industrial platform has a server host with virtual machines deployed on it, the corresponding industrial functions of that platform are implemented through the virtual machines. Therefore, the required industrial platform can be set according to the actual industrial application scenario. Different customers can set up different industrial platforms, realizing the customization of the distributed industrial private cloud system to fully meet their actual needs. Moreover, the master node and each child node form a customer-specific distributed industrial private cloud system. The customer has ownership of their distributed industrial private cloud system, not just usage rights. Since nodes can be set up locally in the factory, production activities can be controlled locally, and data resources related to these activities can be stored locally, achieving local control and local data storage, eliminating resource contention issues. Attached Figure Description

[0008] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0009] Figure 1 This is a structural block diagram of a distributed industrial private cloud system in one embodiment of the present invention;

[0010] Figure 2 This is a structural block diagram of the master node in a distributed industrial private cloud system according to one embodiment of the present invention.

[0011] Figure label:

[0012]

[0013] Detailed Implementation

[0014] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are some embodiments of the present invention, but not all embodiments. All other embodiments obtained by those skilled in the art based on the embodiments of the present invention without creative effort are within the scope of protection of the present invention.

[0015] One embodiment of the present invention provides a distributed industrial private cloud system, which includes a master node and at least one child node, wherein each child node is connected to the master node via the Internet; wherein:

[0016] Each of the master node and the at least one child node includes at least one industrial platform, and each industrial platform includes at least one server host. The server hosts within the same industrial platform are located in the same network segment. Each server host is equipped with at least one virtual machine. Each virtual machine is used to implement the industrial functions corresponding to its industrial platform, and each server host is also used to store the data resources of its industrial platform.

[0017] In other words, the system includes a master node and one or more child nodes. Each child node is connected to the master node via the internet, enabling information exchange within the system. Both the master and child nodes contain one or more industrial platforms. Each industrial platform includes one or more server hosts, and each server host deploys one or more virtual machines. Each virtual machine installs a corresponding application, enabling the industrial platform to perform its specific industrial functions. Furthermore, the server host can store the data resources of its respective industrial platform. In short, each industrial platform can perform corresponding industrial functions and has data storage capabilities.

[0018] For example, a company with multiple factories located in different locations, such as Shanghai, Hangzhou, Beijing, and Chengdu, can set up a node at the location corresponding to each factory, designating one of them as the master node. For instance, a node could be set up in Shanghai, Hangzhou, Beijing, and Chengdu, with the Shanghai node serving as the master node and the nodes in the other locations as child nodes. The master node and all the child nodes form the company's proprietary distributed industrial private cloud system. The company owns this distributed industrial private cloud system, not just has the right to use it. Specifically, the node in Shanghai is used to control the industrial production activities of the Shanghai factory and store the data resources related to the Shanghai factory; the node in Beijing is used to control the industrial production activities of the Beijing factory and store the data resources related to the Beijing factory; and the nodes in the other two locations serve similar purposes. This enables local control and local data storage. Because the nodes are set up locally at the factories, production activities can be controlled and data resources related to these activities can be stored locally, thus eliminating resource competition issues.

[0019] See Figure 1 A distributed industrial private cloud system includes a master node 100 and a child node 200. The master node 100 includes an industrial platform 110, which has a server host 111. The child node 200 includes an industrial platform 210, which also has a server host 211. The master node 100 and the child node 200 are connected via the Internet.

[0020] Understandably, since each node contains at least one industrial platform, and each industrial platform has a server host with virtual machines deployed on it, the corresponding industrial functions of that industrial platform are implemented through the virtual machines. Therefore, the required industrial platform can be set according to the actual industrial application scenario. Different customers can set up different industrial platforms, realizing the customization of a distributed industrial private cloud system that can fully meet the actual needs of customers.

[0021] In one embodiment, the first industrial platform in the at least one industrial platform is a process control platform, and each virtual machine deployed on each server host in the process control platform has a first application installed, which is used to control industrial production activities.

[0022] In other words, one of the industrial platforms in at least one industrial platform is referred to as the first industrial platform. The first industrial platform is a process control platform. Since the process control platform includes at least one server host, each server host has at least one virtual machine deployed on it. A first application can be installed on each virtual machine. The first application can be used to control industrial production activities, such as controlling various devices in the work site, so that each device can complete the predetermined industrial production activities.

[0023] In one embodiment, the second industrial platform in the at least one industrial platform can be a manufacturing operations platform. Each virtual machine deployed on each server host in the manufacturing operations platform has a second application installed. The second application is used to manage production information involved in the operation process of the process control platform. The network segment of the manufacturing operations platform and the network segment of the process control platform are connected through a first firewall to realize the connection between the manufacturing operations platform and the process control platform.

[0024] In other words, in addition to the first industrial platform, at least one industrial platform exists, referred to as the second industrial platform, which is the manufacturing operations platform. The manufacturing operations platform includes at least one server host, each server host having at least one virtual machine deployed on it, and each virtual machine having a second application installed on it. The function of the second application is to manage production information related to industrial production activities.

[0025] For example, the second application is the MES system. MES stands for Manufacturing Execution System. It's a production information management system for the shop floor execution layer of manufacturing enterprises. MES provides enterprises with management modules including manufacturing data management, planning and scheduling management, production scheduling management, inventory management, quality management, human resource management, work center / equipment management, tooling management, procurement management, cost management, project dashboard management, production process control, lower-level data integration and analysis, and upper-level data integration and decomposition, creating a robust, reliable, comprehensive, and feasible manufacturing collaborative management platform for client companies.

[0026] It is evident that the manufacturing operations platform is located above the process control platform and plays a role in various information management functions.

[0027] In this system, the servers in the manufacturing operations platform are on the same network segment as the servers in the process control platform. These two network segments are different, and they are connected by a first firewall, thereby enabling the connection between the two industrial platforms. This allows the two industrial platforms to exchange information securely.

[0028] In one embodiment, the third industrial platform in the at least one industrial platform can be a boundary application platform, the network segment of which is connected to the first firewall to achieve interconnection between the boundary application platform, the process control platform, and the manufacturing operation platform; each virtual machine deployed on each server host in the boundary application platform is used for: security protection between the process control platform and the Internet, and security protection between the manufacturing operation platform and the Internet.

[0029] In other words, in addition to the first and second industrial platforms, at least one industrial platform includes a third industrial platform, which is the boundary application platform. The boundary application platform includes at least one server host, each server host deploying at least one virtual machine, and each virtual machine installing a corresponding application, which can be called the third application. The role of the third application is to buffer between the internet and the process control platform, providing security protection for the process control platform; and to buffer between the internet and the manufacturing operations platform, providing security protection for the manufacturing operations platform. Therefore, the boundary application platform acts as a bridge between the process control platform and the internet, and also as a bridge between the manufacturing operations platform and the internet, while also providing security protection.

[0030] In this system, all server hosts in the boundary application platform reside within a single network segment, which differs from the network segments of the process control platform and the manufacturing operations platform. The boundary application platform's network segment connects to the first firewall, enabling connections between the boundary application platform and both the process control platform and the manufacturing operations platform. Furthermore, since the process control platform and the manufacturing operations platform are also connected via the first firewall, the first firewall facilitates interconnection among these three industrial platforms: the boundary application platform, the process control platform, and the manufacturing operations platform.

[0031] In one embodiment, the network segment of the border application platform in the master node can be connected to the Internet through a second firewall; the border application platform in the master node also includes a remote connection server, which is also connected to the second firewall to enable the remote connection server to connect to the Internet.

[0032] In other words, the network segment of the master node's border application platform is connected to the second firewall, which in turn is connected to the internet. This means the second firewall enables the network segment of the master node's border application platform to connect to the internet. Furthermore, the master node's border application platform may also include a remote connection server, which is also connected to the second firewall; that is, the remote connection server connects to the internet through the second firewall.

[0033] A remote connection server is set up in the boundary application platform of the master node, which facilitates the access of child nodes with remote connection clients to the master node. A second firewall serves as a security protection mechanism.

[0034] In one embodiment, the second firewall supports Internet access requests for preset IP addresses, which include the IP addresses of each sub-node.

[0035] In other words, the second firewall supports internet access requests from preset IP addresses, which include the IP addresses of each sub-node. This ensures that the master node receives internet access requests from all sub-nodes within the same distributed industrial private cloud system. Specifically, by using fixed IP address bandwidth access, the master node can connect to all sub-nodes within the same distributed industrial private cloud system. This avoids coupling between nodes belonging to different distributed industrial private cloud systems, ensuring the independence of each system and preventing it from being affected by other distributed industrial private cloud systems, thus improving the security of each system.

[0036] In one embodiment, the at least one child node includes a first child node, which is a child node based on an industrial 5G network. The first child node further includes an industrial 5G gateway integrating a remote connection client. The industrial 5G gateway integrating the remote connection client is connected to the Internet to realize the connection between the first child node and the Internet. The network connection between the first child node and the master node can be realized through the industrial 5G gateway integrating the remote connection client, the Internet, the second firewall, and the remote connection server.

[0037] In other words, the distributed industrial private cloud system includes a first sub-node, which is a sub-node based on an industrial 5G network, meaning that the first sub-node connects to the Internet through the industrial 5G network. Specifically, in addition to at least one industrial platform, the first sub-node also includes an industrial 5G gateway that integrates a remote connection client. The industrial 5G gateway with integrated remote connection client is connected to the Internet, thereby enabling the industrial platform in the first sub-node to connect to the Internet.

[0038] The network connection between the first sub-node and the master node is achieved through the industrial 5G gateway integrating a remote connection client, the Internet, the second firewall, and the remote connection server. Specifically, the industrial 5G gateway in the first sub-node, after passing through the Internet and the second firewall, connects to the remote connection server, thus establishing the connection between the first sub-node and the master node.

[0039] The 5G SIM card is installed in the industrial 5G gateway that integrates a remote connection client, thereby ensuring the connection between the industrial 5G gateway and the Internet. SIM stands for Subscriber Identity Module.

[0040] As can be seen, the system provided in this embodiment of the invention supports sub-nodes connected to the Internet via an industrial 5G network.

[0041] In one embodiment, the at least one child node includes a second child node, which is a child node integrating an industrial firewall. The second child node also includes a third firewall integrating a remote connection client. The third firewall integrating the remote connection client is connected to the Internet to realize the connection between the second child node and the Internet. The network connection between the second child node and the master node can be realized through the third firewall integrating the remote connection client, the Internet, the second firewall, and the remote connection server.

[0042] In other words, the distributed industrial private cloud system includes a second sub-node, which connects to the internet via an integrated industrial firewall. Specifically, in addition to at least one industrial platform, the second sub-node also includes a third firewall with integrated remote connection clients, which connects to the internet, thereby enabling connectivity between the various industrial platforms within the second sub-node and the internet.

[0043] Specifically, the network connection between the second child node and the master node is achieved through the third firewall integrating the remote connection client, the Internet, the second firewall, and the remote connection server. That is, the third firewall integrating the remote connection client in the second child node connects to the remote connection server in the master node via the Internet and the second firewall, thereby establishing the connection between the second child node and the master node.

[0044] As can be seen, the system provided in this embodiment of the invention supports sub-nodes connected to the Internet through an integrated industrial firewall.

[0045] In one embodiment, the fourth industrial platform in the at least one industrial platform is a virtualization management platform, and each virtual machine deployed on each server host in the virtualization management platform is used to manage the other industrial platforms in the node besides the virtualization management platform.

[0046] In other words, one of the industrial platforms in at least one industrial platform is called the fourth industrial platform. The fourth industrial platform is a virtualization management platform, which includes at least one server host. Each server host has at least one virtual machine deployed on it, and each virtual machine has a corresponding application installed on it. Through this application, the management of other industrial platforms can be realized.

[0047] For example, a virtualization management platform in a node can manage process control nodes, manufacturing operation nodes, and edge application nodes within the same node. Management methods include adding new server hosts in the industrial platform, deploying virtual machines on server hosts, deleting virtual machines on server hosts, and configuring server hosts, virtual machines, and applications.

[0048] As can be seen, a virtualization management platform in a node can be used to perform various management operations on the various industrial platforms within that node.

[0049] For example, see Figure 2The master node 100 includes a boundary application platform 110a, a process control platform 110b, a manufacturing operations platform 110c, and a virtualization management platform 110d. Boundary application platform 110a includes two server hosts 111a and 112a, connected to a network segment 10a. Boundary application platform 110a also includes a remote connection server 113a. Both remote connection server 113a and network segment 10a are connected to a second firewall 12, which is connected to the Internet 300. Process control platform 110b includes two server hosts 111b and 112b, connected to a network segment 10b. Manufacturing operations platform 110c includes two server hosts 111c and 112c, connected to a network segment 10c. Process control platform 110b, manufacturing operations platform 110c, and boundary application platform 110a are all connected to a first firewall 11. The virtualization management platform 110d includes two server hosts, 111d and 112d, which are connected to a network segment 10d. The virtualization management platform 110d is connected to the process control platform 110b, the manufacturing operations platform 110c, and the boundary application platform 110a, enabling the management of these platforms.

[0050] In one embodiment, a computing device integrated with a remote connection client receives a user's access request to any node in the distributed industrial private cloud system.

[0051] In other words, external users can access any node in the distributed industrial private cloud system through computing devices that integrate remote connection clients, thereby meeting the access needs of external users and ensuring the security of data and access.

[0052] Understandably, in a distributed industrial private cloud system, applications are installed in virtual machines on the server host, and data resources are also stored on the server host. Since the distributed industrial private cloud system is customized for customers, customers own the distributed industrial private cloud system, rather than having a rental right.

[0053] When an industrial platform has a large number of server hosts, industrial switches can be added to meet industrial application standards. The firewalls within a distributed industrial private cloud system provide security protection, thereby ensuring the security of data resources.

[0054] The hardware platform in a distributed industrial private cloud system can be a data center composed of high-performance server clusters, a traditional IT infrastructure with separated computing and storage resources, or a hyperconverged infrastructure where software is embedded in the data center. Applications in the distributed industrial private cloud system are deployed in the form of server virtualization, with all hardware and software deployed locally, giving customers complete ownership.

[0055] The distributed industrial private cloud system is designed according to actual industrial application scenarios. It includes process control platforms, manufacturing operation platforms, boundary application platforms, virtualization management platforms, etc., and is equipped with industrial 5G gateways, industrial firewalls, etc., which meet the needs and requirements of industrial application scenarios.

[0056] In this distributed industrial private cloud system, all data is stored on a local server, giving the system complete control over data resources and eliminating the constraints of security regulations. Furthermore, since the nodes are deployed locally within the factory, there are no resource contention issues at the local factory level.

[0057] Understandably, the current application of public cloud in industrial application environments faces numerous problems, such as: (1) Public cloud provides services, and users are merely users of those services; (2) As a commercial solution, public cloud cannot meet the actual needs of industrial application scenarios; (3) Data security issues. Users lack control over cloud resources, cannot ensure the security of privacy and confidential data, and find it difficult to meet many security regulatory compliance requirements, because different public cloud servers reside in multiple countries and are subject to various security regulations, requiring user data to meet these constraints; (4) Resource competition. Due to the shared resource nature of public cloud, performance problems are prone to occur during peak traffic periods, such as network congestion.

[0058] Based on the above description, it can be seen that the distributed industrial private cloud system provided by the embodiments of the present invention does not have the above-mentioned problems of public clouds. Therefore, the distributed industrial private cloud system provided by the embodiments of the present invention is very suitable for customers who are sensitive to the above-mentioned problems of public clouds.

[0059] The various embodiments in this specification are described in a progressive manner. Similar or identical parts between embodiments can be referred to mutually. Each embodiment focuses on describing the differences from other embodiments. In particular, the apparatus embodiments are basically similar to the method embodiments, so the description is relatively simple; relevant parts can be referred to the descriptions of the method embodiments.

[0060] The specific embodiments described above further illustrate the purpose, technical solution, and beneficial effects of the present invention. It should be understood that the above description is only a specific embodiment of the present invention and is not intended to limit the scope of protection of the present invention. Any modifications, equivalent substitutions, improvements, etc., made on the basis of the technical solution of the present invention should be included within the scope of protection of the present invention.

Claims

1. A distributed industrial private cloud system, characterized by, The system comprises a master node and at least one slave node, each slave node is connected to the master node through the Internet. Each of the master node and the at least one slave node comprises at least one industrial platform, each industrial platform comprises at least one server host, and each server host in the same industrial platform is located in the same network segment. Each server host is deployed with at least one virtual machine, each virtual machine is used to realize the industrial function corresponding to the industrial platform, and each server host is also used to store the data resources of the industrial platform. The at least one industrial platform comprises a first industrial platform, a second industrial platform and a third industrial platform. The network segment of the manufacturing operation platform and the network segment of the process control platform are connected through a first firewall to realize the connection of the manufacturing operation platform and the process control platform. The network segment of the boundary application platform is connected with the first firewall to realize the interconnection of the boundary application platform, the process control platform and the manufacturing operation platform. The network segment of the boundary application platform in the master node is connected with the Internet through a second firewall.

2. The system of claim 1, wherein, The boundary application platform in the master node further comprises a remote connection server, and the remote connection server is also connected with the second firewall to realize the connection of the remote connection server and the Internet.

3. The system of claim 2, wherein, The access request of a user to any node in the distributed industrial private cloud system is received through a computing device integrated with a remote connection client.

4. The system of claim 3, wherein, Each virtual machine deployed on each server host in the process control platform is installed with a first application program for controlling industrial production activities.

5. The system of claim 1, wherein, Each virtual machine deployed on each server host in the manufacturing operation platform is installed with a second application program for managing production information related to the working process of the process control platform.

6. The system of claim 1, wherein, Each virtual machine deployed on each server host in the boundary application platform is used for security protection between the process control platform and the Internet and security protection between the manufacturing operation platform and the Internet. The second firewall supports Internet access requests of preset IP addresses, and the preset IP addresses include IP addresses of each slave node. The at least one slave node comprises a first slave node based on an industrial 5G network, and the first slave node comprises an industrial 5G gateway integrated with a remote connection client, which is connected with the Internet to realize the connection of the first slave node and the Internet. Through the industrial 5G gateway integrated with the remote connection client, the Internet, the second firewall and the remote connection server, the network connection between the first slave node and the master node can be realized.

7. The system of claim 1, wherein, The at least one sub-node includes a second sub-node, the second sub-node is a sub-node of an integrated industrial firewall, the second sub-node further includes a third firewall integrated with a remote connection client, the third firewall integrated with the remote connection client is connected with the Internet to realize the connection between the second sub-node and the Internet, and the network connection between the second sub-node and the main node can be realized through the third firewall integrated with the remote connection client, the Internet, the second firewall and the remote connection server.

8. The system of claim 1, wherein, The fourth industrial platform in the at least one industrial platform is a virtualization management platform, and each virtual machine deployed on each server host in the virtualization management platform is used for managing each industrial platform in the node except the virtualization management platform.

Citation Information

Patent Citations

  • Industrial control system safety protection method based on private cloud

    CN106899553A

  • Long -range operation and maintenance system based on cloud platform

    CN208506549U