Management system for infrastructure of industrial system

By comparing the expected state and current state of virtual, physical and network infrastructure of industrial systems, automating differences to achieve automation of management, solving the problem of difficult automation of management decisions and implementations in the prior art, improving management efficiency and system reliability.

CN119948413APending Publication Date: 2025-05-06SCHNEIDER ELECTRIC USA INC +1
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
CN202380071777.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2022-10-10
Filing Date
2023-10-10
Publication Date
2025-05-06

AI Technical Summary

Technical Problem

There are a large number of manual processes in the management of existing industrial system infrastructure, which makes it difficult to automate management decisions and implementations when the system scales.

Method used

By receiving state modeling of virtual, physical and network infrastructure of industrial systems, the differences between the expected state and the current state are compared, and the infrastructure is automated according to the differences to automate management.

Benefits of technology

It realizes automation of industrial system infrastructure management, reduces manual intervention, and improves management efficiency and system reliability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119948413A_ABST
    Figure CN119948413A_ABST
Patent Text Reader

Abstract

Systems and methods for managing infrastructure of an industrial system are provided. The method includes receiving a desired state that models a state of two or more infrastructures of the industrial system, wherein the two or more infrastructures are a virtual infrastructure of the industrial system and at least one of a physical infrastructure and a network infrastructure of the industrial system. The method further includes receiving a current state modeling a current state of two or more infrastructures of the industrial system, determining a difference between the desired state and the current state, and causing one or more changes in the current state of the infrastructures of the industrial system according to the determined difference, wherein determining the difference and causing one or more changes involves two or more infrastructures.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] CROSS-REFERENCE TO RELATED APPLICATIONS

[0002] This application claims priority to U.S. Provisional Patent Application Serial No. 63 / 414,700, filed on October 10, 2022, which is incorporated herein by reference in its entirety.

[0003] ‎ Technical Field

[0004] The present disclosure relates to management of infrastructure of industrial systems, and more particularly, to increased automation of management of infrastructure of industrial systems. Background Art

[0005] Currently, the management of the infrastructure of industrial systems can include many manual processes, such as deploying software packages, containers, and workloads on target hardware or virtual components that may be included in any of the physical, virtual, or network infrastructures of the industrial system. As the size of the system increases, deciding when to manage and what to manage (e.g., deploy, remove, replace, or update) becomes more complex, and manually implementing these decisions becomes more cumbersome. An update to one of the physical, virtual, or network infrastructures may result in the need to update a different one of the physical, virtual, or network infrastructures.

[0006] While current systems and methods have performed adequately, there remains a need in the art for greater automation in deciding what to manage and in implementing that decision. The present disclosure is intended to meet that need. Summary of the invention

[0007] The purposes and advantages of the illustrated embodiments described below will be set forth and become apparent in the following description. Additional advantages of the illustrated embodiments will be realized and obtained by the devices, systems, and methods specifically pointed out in the written description and claims and the accompanying drawings. In order to achieve these and other advantages, and in accordance with the purposes of the illustrated embodiments, in one aspect, a computer-implemented method for managing the infrastructure of an industrial system is disclosed. The method includes receiving a desired state that models the state of two or more infrastructures of an industrial system, wherein the two or more infrastructures are virtual infrastructures of the industrial system, and additionally are physical infrastructures and / or network infrastructures of the industrial system. The method also includes: receiving a current state that models the current state of two or more infrastructures of the industrial system; determining the difference between the desired state and the current state; and causing one or more changes in the current state of the infrastructure of the industrial system based on the determined difference, wherein determining the difference and causing one or more changes involve two or more infrastructures.

[0008] In one or more embodiments, changes may be determined based on dynamic optimization of resources of two or more infrastructures of an industrial system.

[0009] In one or more embodiments, causing the change may include: selecting a workload; selecting or instantiating a virtual controller of the virtual infrastructure; and deploying the workload on the selected or instantiated virtual controller to cause the virtual controller to operate within the infrastructure of the industrial system.

[0010] In one or more embodiments, the infrastructure of the industrial system may include at least one virtual controller, and causing the change includes at least one of deploying a workload on the virtual controller and modifying the workload deployed on the virtual controller.

[0011] In one or more embodiments, the workload may be stateful.

[0012] In one or more embodiments, causing the change may further include selecting a rule based on the difference, applying the rule, and outputting a workflow based on the applied rule, wherein the workflow causes the change affecting the controller.

[0013] In one or more embodiments, receiving the current state, determining differences, and incurring changes may be performed automatically or semi-automatically with configurable user intervention.

[0014] In one or more embodiments, the difference may be determined based on a physical device being physically added to the physical infrastructure as an unconfigured or misconfigured device, and causing the change may include provisioning the physical device to perform a task associated with the physical device.

[0015] In one or more embodiments, a difference can be determined based on a failure of a first node included in one of a physical, virtual, or network infrastructure, where the first node can be initially designated as requiring high availability and a second node operates as a redundant pair of the first node, where causing the change can include: upon failure of the first node, causing the second node to automatically assume the role of the first node instead of its original role; and automatically assigning the original role of the second node to a third node, thereby automatically re-establishing a redundant pairing between the second and third nodes.

[0016] In one or more embodiments, causing changes may include optimizing operations and / or resource usage in physical, virtual, and / or network infrastructure.

[0017] According to another aspect of the present disclosure, a management system is provided, which has one or more memories configured to store a plurality of programmable instructions, and one or more processing devices in communication with the one or more memories. The one or more processing devices are configured to perform the disclosed method when executing the plurality of programmable instructions.

[0018] According to other aspects of the present disclosure, one or more non-transitory computer-readable storage media and one or more computer programs embedded therein are provided, which, when executed by a computer system, cause the computer system to perform the corresponding disclosed method.

[0019] These and other features of the systems and methods disclosed herein will become more apparent to those skilled in the art from the following detailed description of preferred embodiments in conjunction with the accompanying drawings. BRIEF DESCRIPTION OF THE DRAWINGS

[0020] A more detailed description of the disclosure, briefly summarized above, can be obtained by reference to various embodiments, some of which are shown in the accompanying drawings. Although the drawings illustrate selected embodiments of the disclosure, these drawings are not to be considered limiting of its scope, as the disclosure may admit to other equally effective embodiments.

[0021] Figure 1 is a block diagram illustrating an example orchestration system for managing industrial system infrastructure according to an embodiment of the present disclosure;

[0022] Figure 2 According to the embodiment of the present disclosure Figure 2 A block diagram of a management module of an orchestration system;

[0023] Figure 3A is a block diagram of a computing node of a virtual infrastructure of an industrial system infrastructure according to an embodiment of the present disclosure;

[0024] Figure 3B is a block diagram of a physical node of a physical infrastructure of an industrial system infrastructure according to an embodiment of the present disclosure;

[0025] Figure 3C is a block diagram of a network node of a network infrastructure of an industrial system infrastructure according to an embodiment of the present disclosure;

[0026] Figure 3D is a schematic diagram of nodes of an industrial system infrastructure under management of a management module during an event resulting in a changed role to achieve high availability according to an embodiment of the present disclosure;

[0027] Figure 4 is a flow chart illustrating an example method for managing infrastructure of an industrial system according to an embodiment of the present disclosure; and

[0028] Figure 5 is a block diagram of an exemplary processing system according to an embodiment of the present disclosure, which can be used to implement a method for providing customized logic for orchestration of an industrial system. ‎‎

[0029] Wherever possible, identical reference numerals have been used to designate identical elements that are common to the figures. However, elements disclosed in one embodiment may be beneficially utilized on other embodiments without specific recitation. DETAILED DESCRIPTION

[0030] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which the present disclosure belongs. Although any methods and materials similar or equivalent to those described herein can also be used in the practice or testing of the present disclosure, exemplary methods and materials are now described.

[0031] It should be noted that as used herein and in the appended claims, the singular forms "a", "an", and "the" include plural references unless the context clearly dictates otherwise. Thus, for example, reference to "a stimulus" includes a plurality of such stimuli, reference to a "signal" includes reference to one or more signals and equivalents thereof known to those skilled in the art, and so on. It should be understood that the embodiments of the present disclosure as described below are implemented using software algorithms, programs, or codes, which may reside on a computer-usable medium for enabling execution on a machine having a computer processor. The machine may include a memory configured to provide output from the execution of the computer algorithm or program. ‎

[0032] As used herein, the term "software" is meant to be synonymous with any logic, code, or program that can be executed by a processor of a host computer, regardless of whether the implementation is in hardware, firmware, or as a software computer product available on a memory storage device or downloaded from a remote machine. The embodiments described herein include such software to implement the above equations, relationships, and algorithms. Based on the above embodiments, those skilled in the art will understand the further features and advantages of the present disclosure. Therefore, except as indicated in the appended claims, the present disclosure is not limited by what has been specifically shown and described.

[0033] As used herein, the term "device" refers to a hardware component before or after any application is deployed on the hardware component.

[0034] The present disclosure relates to automation of industrial system infrastructure management, including deciding when to make changes and implementing the decisions. A management system is disclosed that systematically and automatically compares the current state of an industrial system infrastructure with a desired state of the industrial system infrastructure. The desired state of the industrial system infrastructure is represented by logic, which may be in the form of a system state machine, as described in a concurrently filed patent application entitled "PROVISION OF CUSTOMIZED LOGIC FORORCHESTRATION," which is also assigned to Schneider Electric USA, the contents of which are incorporated herein by reference in their entirety.

[0035] The disclosed management system is capable of automatically executing one or more management tasks for managing multiple sub-infrastructures of an industrial system infrastructure based on a comparison of a global view of the industrial system infrastructure. Management tasks include device onboarding, device provisioning, orchestration of multiple sub-infrastructures, device discovery, device management, aggregation of real-time data from sub-infrastructures, monitoring diagnosis of sub-infrastructures to optimize operations, optimizing resource usage, visualization of operations of multiple sub-infrastructures, achieving a "plug and play" user experience, achieving high availability in a stateful manner, fault recovery, and error recovery, but are not limited to these management tasks. Management tasks can be dynamically executed based on real-time data.

[0036] Sub-infrastructures include physical infrastructure, virtual infrastructure, and network infrastructure. Physical infrastructure includes physical nodes that can be connected to each other. Physical nodes and the relationships between physical nodes are defined by topology. Software and / or workloads can be deployed on physical nodes in a non-virtualized manner. Physical nodes are hardware components and can include a combination of one or more memories, one or more processors, and firmware. Software can be stored in memory and executed by a processor, also known as deployment.

[0037] Virtual infrastructure includes applications that define virtual nodes, such as virtual machines, containers, workloads that configure physical node firmware, and container clusters. A virtual node can be deployed on a hardware component or on another virtual node.

[0038] The network infrastructure includes network nodes, which may include dumb and / or intelligent network components that provide communication between any combination of physical nodes, their software, and virtual nodes. Network nodes include hardware components. The hardware components of the intelligent network components also include one or more memories and one or more processors. Applications including software applications or virtual nodes can be deployed on the intelligent network components.

[0039] The industrial system infrastructure is managed by a management system. The management system is provided with a desired state and a current state, and manages the industrial system infrastructure based on the difference between the desired state and the current state. Each state (desired state and current state) models the industrial system infrastructure by defining two or more of the physical, virtual, and network infrastructures. The state defines the relationship between any combination of nodes (physical, virtual, or network nodes), their configurations, and hardware components (of the physical and / or network infrastructures) and virtual infrastructures and applications of at least one of the physical and network infrastructures. For example, the configurations and relationships may be represented by metadata.

[0040] The desired state defines the industrial system infrastructure according to the policy rules. The current state models the industrial system infrastructure based on feedback from the actual industrial system infrastructure. When there is a determined difference between the desired state and the current state, the management system causes one or more changes to the current state of the industrial system infrastructure according to the determined difference.

[0041] This is a state-seeking model, whereby the management system causes changes to the current state of the industrial system infrastructure in order to achieve a desired state. Whenever the industrial system infrastructure deviates from the desired state, whether intentionally (e.g., due to the addition of a hardware component, a policy change, an application upgrade) or unintentionally (e.g., due to a problem in development or a change in conditions), the management system causes a change to the current state in order to bring the current state into line with the desired state.

[0042] For example, when workloads of a virtual infrastructure are moved to different physical and / or virtual locations, the network infrastructure may be changed to accommodate the movement and provide new communication paths.

[0043] In another example, when a software application executing on a physical node of a physical infrastructure receives user input that changes the task of an industrial system infrastructure (e.g., producing peanut butter cookies instead of chocolate chip cookies), the workload of a virtual node, such as the virtual infrastructure in a desired state, will be updated, causing the workload in the current state to be updated.

[0044] In another example, when a physical node of the physical infrastructure is added to the current state, the desired state can be processed to include the new physical node. The desired state can be processed by the orchestration function, which provides load balancing and redefines the deployment of the workload by including the newly added physical node, thereby updating the virtual infrastructure of the desired state. The management system will detect the difference between the updated desired state and perform the same update in the current state.

[0045] In another example, when a physical node of a physical infrastructure in a current state is updated by upgrading a software application of the physical or network infrastructure, the desired state may be processed to include upgrading the corresponding software application. The desired state may be processed by an orchestration function that determines that a policy rule is no longer met or that a configuration of a hardware component or application is no longer valid. The desired state may be modified to correct the non-compliance or invalidity, thereby updating the physical infrastructure, virtual infrastructure, and / or network infrastructure in the desired state. The management system will detect the difference between the updated desired state and perform the same update in the current state.

[0046] The desired state and the current state may each simulate two or more of a virtual infrastructure, a physical infrastructure, and / or a network infrastructure. When the management system detects a difference between the desired state and the current state and causes a change, the change may involve two or more sub-infrastructures. For example, when a difference is detected between one of the infrastructures in the desired state and the current state, the management system may cause a change to a different one of the infrastructures in the current state.

[0047] The desired state provides a first twin (e.g., a digital twin) of the desired industrial system infrastructure. The current state provides a second twin of the industrial system infrastructure based on its actual state. The first and second twins can be compared to detect differences between them. When the management system causes changes, it can change the current state and implement one or more changes in the actual industrial system infrastructure, such as by causing the deployment of workloads, firmware updates, software updates, changes in load balancing, onboarding processes, or provisioning processes.

[0048] Therefore, the desired state and the current state each include a set of hardware components and multiple applications deployed on the hardware components in accordance with policy rules, wherein, when in operation, when the application is deployed on the hardware components of the industrial system infrastructure and the application is executed, the industrial system infrastructure affects the relevant industrial system (e.g., by controlling, monitoring, providing communication, providing local or cloud-based services, using local or cloud-based services). The actions performed by the industrial system of the task (controlled or monitored) may include moving an object with a robotic arm, filling a bottle with milk, taking a picture for image processing, etc. The industrial system may include multiple subsystems that perform multiple tasks. The industrial system infrastructure is not limited to clusters and / or cluster-related hosts. The desired state and current state of the industrial system infrastructure can model all of its hardware components and applications or a portion of them. This can include all or part of the hardware components and software components of any combination of physical infrastructure, virtual infrastructure, and network infrastructure. Networked assets within the industrial system infrastructure 101 include, but are not limited to, servers, inter-process communications (IPC), programmable logic controllers (PLC), drivers, I / O interfaces, sensors, actuators, gateways, routers, switches, etc.

[0049] The set of hardware components and multiple applications deployed on the hardware components can be integrated so that changes to the hardware components (e.g., adding new hardware components, failure or failure of hardware components, upgrades to hardware components) can affect other hardware components, may result in the need to change the deployment of applications, and / or may result in the need to update policies. In addition, changes to applications (e.g., deploying new applications on hardware components, failure or failure of applications, upgrades to applications) can affect other applications, may result in the need to change the deployment of applications, may result in the need to change or upgrade hardware components, and / or may result in the need to update policies. In addition, changing policies may result in the need to upgrade or change the deployment of hardware components and / or applications.

[0050] Furthermore, a change to one of the physical, virtual, or network infrastructures that is in one of a desired state or a current state may affect a different one of the physical, virtual, or network infrastructures that is in another of the desired state or the current state.

[0051] The term "plug and play" refers to the ability to integrate a device into an industrial system in response to the device receiving power so that the device can perform its function. Plug and play may implement any or all management tasks to automatically enable a device to be production-ready when a user plugs in or powers it on, including the device straight out of the box. Production means that the device can perform its task and integrate into the industrial system.

[0052] The management system can manage the corresponding hardware components and applications (for and following deployment) of the industrial system from the beginning of the life cycle within the industrial system and throughout its life cycle. This management can be performed with minimal or no human intervention. The amount of human intervention required or allowed is configurable. Any user intervention can reduce the user's expertise requirements relative to the manual tasks currently required to be performed.

[0053] By requiring two-way authentication between the devices of the industrial system and the management system, the security of the management system and the industrial system can be protected.

[0054] Reference will now be made to the drawings, wherein like reference numerals represent similar structural features or aspects of the subject disclosure. For purposes of explanation and illustration, and not limitation, a block diagram of an exemplary embodiment of a management system for an industrial system according to the present disclosure is shown in FIG. Figure 1 , and is generally indicated by reference numeral 100. Other embodiments of the management system 100 or aspects thereof according to the present disclosure are described in Figure 2-5 provided in, as will be described.

[0055] The following patent applications and patent disclosures assigned to Schneider Electric Industries SAS describe aspects of presentation and updating of topology and deployment and management of assets in industrial systems, and each is incorporated herein by reference in its entirety: US10845786B2, US11079744B2, US11579595B2, US20210356944A1, and US20230161332A1.

[0056] The management system 100 for managing the industrial system infrastructure 101 includes an ingestion tool front end 110, an orchestration service back end 130, a management service back end 170, and a display tool front end 190. The industrial system infrastructure 101 is an infrastructure of an industrial system, such as but not limited to a refinery system, a chemical production system, an electronic manufacturing system, a vehicle production system, etc. The industrial system infrastructure includes assets, including hardware components (physical assets) and applications (software, virtual and / or logical assets). The industrial system infrastructure 101 includes a physical infrastructure 180 having a plurality of physical nodes (also referred to as hardware components), a virtual infrastructure 182 having a plurality of virtual nodes (also referred to as computing nodes), and a network infrastructure 184 having a plurality of network nodes.

[0057] Some or all of the hardware components may be on-site, allowing the industrial system infrastructure 101 to be isolated from any network that is not on-site. In one or more embodiments, the hardware components may include remote hardware components. All or a portion of the hardware components may always be connected to an external network, intermittently or periodically connected to an external network (e.g., once a day or a week), or spaced out and never connected to an external network.

[0058] The introduction tool front end 110 includes an introduction module 111, which allows a user to build or update the topology of the industrial system infrastructure 101 by inputting and / or updating the assets (hardware components and applications) of the industrial system infrastructure 101, the configuration of the assets, the logical and / or physical connections between the hardware components, and the policy rules.

[0059] Hardware components are physical modules that can be used by industrial systems once applications are deployed on them. Hardware components may include an operating system, or may be simple devices that do not require an operating system (e.g., sensors, simple actuators, simple input / output (I / O) modules). Application deployment on hardware systems is handled by management tasks performed by the management system 100. Hardware components may be configured with applications (meaning that one or more applications are deployed on the hardware components). Configured hardware components may be included in the physical infrastructure 180 and the network infrastructure 184. Some examples of hardware components include, but are not limited to, servers, inter-process communications (IPC), programmable logic controllers (PLC), drivers, I / O interfaces, sensors, actuators, gateways, routers, and switches.

[0060] Applications may include software (nodes of the physical infrastructure 180 or network infrastructure 182), compute nodes of the virtual infrastructure 182, such as but not limited to virtual controllers (e.g., virtual PLCs or distributed programmable automation controllers (DPACs)), control applications (for distributed control nodes (DCNs)), virtual machines (VMs), Docker™ containers, Kubernetes™ workloads, containers and / or container clusters, and / or web components (WASMs).

[0061] The policy rules define the policy of the industrial system infrastructure 101 and / or include optimization goals for the configuration of the industrial system infrastructure 101. For example, the policy may include high availability and one or more optimization goals. For example, the optimization goals may include a minimum or maximum number of devices to be used and / or whether the load should be evenly distributed across all devices, implementing pilot applications away from the production environment to detect and respond to suspected network threats, requiring user authorization before allowing the orchestration to perform actions (such as firmware or container updates), maximum coexistence of two applications on the same node for policy or compatibility reasons, functional limitations during certain operating modes, etc.

[0062] Optimization goals may be defined by policy rules entered by a user using the input tool front end 100. Some examples of optimization goals include, but are not limited to, minimum number of devices running, minimum or even CPU consumption per device, minimum power consumption, scaling up or down for production variations, batch processing variations (e.g., for producing cookies vs. cupcakes), network security hardening in case of suspected attacks, thermal response, minimizing resource costs, etc.

[0063] The introduction module 111 may provide a user-friendly graphical user interface (GUI) that allows customers to build a topology for the industrial system infrastructure 101. The GUI may provide one or more menus through which the user can select to create or update a topology. The menu may access one or more libraries. The library may be used to populate one or more drop-down lists. The information in the library may be standardized or may be converted into a standardized format used by the topology. In this way, assets selected and configured by the user are entered into the topology using a standardized format. Libraries of fully assembled hardware components, subcomponents for assembling into hardware components, software programs, control applications (e.g., workloads), and the like may be provided. An example of a subcomponent in a subcomponent library is a specific driver that is required in certain circumstances, such as a graphics processor driver required to run an AI application in a software library, which may run on an IPC in a hardware library.

[0064] The user may make this submission by selecting a designated graphical button on the GUI, or the submission may be autonomous once the process of building or updating the topology has been confirmed to be complete. Once the topology has been built or updated, it represents the desired topology for the entire (meaning global) industrial system infrastructure 101. The desired topology is submitted to the orchestration service backend 130.

[0065] The orchestration service backend 130 includes a validation module 131 and an optimal orchestration module 140. The validation module 131 checks the validity of individual hardware components and applications, as well as the combination of hardware components, applications, and policy rules. Any aspects of the topology that are found to be invalid are marked and provided to the ingestion tool frontend to correct the invalidity. Once the validation is complete, the desired and validated topology is provided to the optimal orchestration module 140.

[0066] The optimal orchestration module 140 is configured to generate logic from the standardized topology of the entire industrial system infrastructure 101, which can be used for the management of the industrial system 131. The logic can be provided in the form of a system state machine, but is not limited to a specific format. The format can be compatible with the modules of the management service backend 170 so that the logic can be implemented. The optimal orchestration module 140 optimizes the logic by using one or more optimization algorithms. The logic represents an optimized deployment of the topology of the entire industrial system infrastructure 101, including a representation of the application deployment on the hardware components of the entire industrial system infrastructure 101 that complies with policy rules. The optimization algorithm evaluates different versions of the deployment that can be derived from the topology and determines which version of the deployment has the best result in achieving one or more optimization goals. The logic corresponds to the deployment version selected as the desired state of the industrial system infrastructure 101 and provided to the management service backend 170.

[0067] The optimization goal may be defined by policy rules input by a user using the orchestration policy introduction module 120. Some examples of optimization goals include a minimum number of running devices, a minimum and uniform CPU consumption of each device, and the like.

[0068] The desired state defines the configuration and can be expressed in software, which can be provided in a format usable by the management service backend 170, such as a descriptive format. Some descriptive formats that can be used include JSON™, YAML™, or TOSCA™. The desired state defines and describes the optimal deployment of applications on hardware devices, including different states of the industrial system infrastructure 101 and optimal operation of assets.

[0069] An explanation of the operation of the import tool front end 110 and the orchestration service back end 130 is described in detail in a concurrently filed non-provisional application entitled "PROVISION OF CUSTOMIZED LOGIC FOR ORCHESTRATION," assigned to Schneider Electric Systems USA, the entire contents of which are incorporated herein by reference.

[0070] Management service backend 170 includes memory 171, management module 174, asset database 176, and system monitor 178. Management service backend 170 receives the desired state from orchestration service backend 130 and stores it as desired state 173, for example, in the form of a state machine, in memory 171. Expected state 173 is accessed by or provided to management module 174. Figure 2 Management module 174, shown in more detail in FIG. 1 , may be included in, for example, a computer integrated management system (CIMS). Management module 174 may utilize logic provided by desired state 173 to invoke and implement tasks.

[0071] The desired state 173 may have a format that is compatible with the management module 174 and its components, which allows the management module 174 and its components to use and implement the logic represented by the desired state 173 .

[0072] System monitor 178 monitors industrial system infrastructure 101 and outputs a current state, which is the overall state of industrial system infrastructure 101. Current state 177 may be in a format (eg, a state machine) that is compatible with desired state 173 so that comparisons can be made between the two.

[0073] The management module 174 can continuously or periodically compare the current state 177 to the desired state 173, both of which refer to the state of the entire industrial system infrastructure 101. This comparison can be performed in real time. The detection of a difference between the current state 177 and the desired state 173 can be referred to as a detected difference event. The management module 174 can respond to a detected difference event, such as by performing one or more tasks, also referred to as an orchestration workflow. The management module 174 can also be triggered to perform these tasks by an application executing within the industrial system infrastructure, which reports the detection of an event, such as its own state or an event external to the application. The management module 174 can apply orchestration rules that define an orchestration workflow to be executed in response to a specific detected difference event or reported event.

[0074] Tasks may include, but are not limited to, deploying workflows on hardware components of the industrial system infrastructure 101 (e.g., upon detecting the presence of a hardware component or virtual controller in the current state 177 that is not included in the desired state 173, then prompting automatic plug and play), providing higher availability by re-establishing high availability (e.g., upon detecting a lack of high availability in the current state 177 relative to the high availability provided by the desired state 173); recovering from failures or failures of applications and hardware components of the industrial system infrastructure 101 detected in the current state 177 (e.g., upon detecting missing or faulty components in the current state 177 relative to the desired state 173), provisioning and bringing online assets of the industrial system infrastructure 101 once they are added, changes in device configuration, updates to firmware, changes to the network, etc.

[0075] Some other tasks include orchestration, device management, real-time data aggregation from devices, device and network monitoring for optimized operational diagnostics, optimization of network resource usage, and asset deployment.

[0076] Recipients of the management and orchestration provided by the management module 174 may include various hardware components and applications of the industrial system infrastructure 101, such as controllers, edge devices, network switches, containers, and non-containerized software applications. Managed devices may be clustered (including management across multiple clusters) or non-clustered. Managed devices may or may not have an operating system. Some examples of devices without an operating system include, for example, but not limited to, I / O interfaces, sensors, actuators, protection relays, etc.

[0077] These tasks can be performed automatically with or without user intervention. The amount of user intervention is configurable. For example, the user can be prompted to give permission for the action to be performed. This allows tasks that were previously time-consuming and required user expertise to be performed quickly with little or no user intervention.

[0078] The management and orchestration provided by the management module 174 depends on the desired state 173, which is configurable logic. The configuration of the desired state 173 can be used to customize the management system 100 for different industrial systems, for different applications of the same industrial system, and / or change dynamically in real time. The desired state 173 can be changed at any time by changing the selected hardware components, their configurations, and / or their topologies; the selected applications (virtual and non-virtual) and / or their configurations, and / or policy rules. Policy rules can define stateful protocols for critical workloads, such as workload failure response, workload failure recovery, and workload high availability. The desired state 173 can be changed to accommodate orchestrations in stateless computing environments that go far beyond scaling up or down and load balancing.

[0079] In addition, the optimization of the desired state 173 by the optimal orchestration module 140 according to the optional optimization goal of each policy rule provides further ability to customize the management system 100 for a specific industrial system and adapt to the constraints of the industrial system. Such industrial system constraints may include, for example, safety, network security, system interrupt response, air gap domains, and compliance with regulatory policies.

[0080] The system monitor 178 is configured to monitor the industrial system infrastructure 101, including the status of its hardware components and applications, and output the current state (e.g., a state machine) presented to the management module 174. For example, the system monitor 178 can monitor the properties of the industrial system infrastructure 101, such as the CPU usage of each hardware component and the application health status. The system monitor 178 can further gather information about the monitoring results, which can be provided for further data analysis. The monitored characteristics can be encoded in the current state 177 in a manner that can be compared with the expected state 173.

[0081] The current state 177 and the desired state 173 may be represented in a similar ontology using a language such as TOSCA. In this way, the lists of deployed containers, firmware versions, CPU temperatures, network interface states, application recorded response times, etc. of the current state 177 and the desired state 173 may be compared, and the differences between the current state 177 and the desired state 173 may be determined.

[0082] Current state 177 and desired state 173 may each be represented as a digital twin, which is a digital representation of an asset of industrial system infrastructure 101. The digital twin may include asset metadata with references to, for example, but not limited to, dependent artifacts, an enumeration of application programming interfaces (APIs), callout services for connecting to assets, relationships between assets of industrial system infrastructure 101, asset instance policy information, and asset-specific orchestration workflows.

[0083] In the event that a system monitor detects a problem in the industrial system infrastructure 101, such as an overloaded hardware component or application, an elevated temperature of a hardware component, etc., this information can be provided to the input validation module 131 in the orchestration service backend 130. For example, an orchestration rule can define a temperature operating range. When a rule is violated, an orchestration workflow associated with the orchestration rule can be initiated that will reconcile the temperature issue.

[0084] The input validation module 131 may repeat cross-input validation to cause adjustments to one or more assets or policy rules of the topology of the industrial system infrastructure 101. Some examples of adjustments include moving an application from one hardware component to another, or removing a hardware component with elevated temperatures. In one or more embodiments, the adjustment may be automatic (e.g., may be driven by an optimization policy rule) or may include user intervention. Different degrees of user intervention may be used, such as prompting the user to perform an adjustment or recommending an adjustment based on user consent. The degree of user intervention required or allowed may be configurable. Once the input validation module 138 validates the modified topology, the modified topology may be submitted to the optimal orchestration module 140 so that new logic may be provided to the deployment service backend 170.

[0085] The system monitor 178 may further report real-time information regarding the status of the industrial system infrastructure 101 to a display tool front end 190 .

[0086] The display tool front end 190 outputs the information received from the system monitor 178 to a display device 192, thereby providing a real-time view of the status of the industrial system. A user can view the system status information on a user interface of the display device 192. The user can view the displayed information on the display device 192 of a mobile device or a fixed computer.

[0087] When system monitor 178 detects a problem, such as a damaged hardware component or a software error, the user may receive an alert via display device 192. The display device may also indicate when the problem is resolved and the alert is cleared, such as by repeating a validation process and an optimization process performed by orchestration services backend 130. The display device may also indicate to the user when a problem requires manual support, such as when a hardware component is powered off and needs to be reconnected, there is a high frequency of false alarms, or detected errors indicate that an escalation is required.

[0088] The management module 174 can detect changes in the current state 177 by comparing the current state 177 to the desired state 173. Some exemplary, non-limiting changes that can be detected by such comparisons include adding, removing, or upgrading hardware components or applications. For example, the management module 174 can detect that: when a powered-off hardware component is reconnected to a power source, a hardware component is added to the industrial system infrastructure 101, multiple hardware components are enlarged or reduced, and a hardware component is removed.

[0089] Management module 174 may also detect differences between current state 177 and desired state 173, which will trigger a workflow to be executed. Desired state 173 may be considered a single source of truth under certain conditions, such as OS version. An OS upgrade may be performed in desired state 173 by declaring a new version of the OS for the relevant hardware component in the desired state. Inequality between the OS of the hardware component in current state 177 and desired state 173 will be detected, and the appropriate workflow will be triggered to update the OS on each instance of the hardware component.

[0090] In response to detecting a change to the industrial system infrastructure 101, the management module 174 may alert the input validation module 138 of the change. The input validation module 138 will then prompt the user to update the topology via the ingestion tool front end 110. The validation process is then repeated by the validation module 131, thereby validating the updated topology. After its validation, the updated topology is processed by the optimal orchestration module 140 to update the logic. The updated logic is provided to the management service back end 170. The updated logic may be provided to the management engine 176 to update the deployment.

[0091] The ingestion tool front end 110, the orchestration service back end 130, the management service back end 170, and the display tool front end 190 are configurable to accommodate different types of industries and enterprises. The orchestration service back end 130 can be configured with different types of management and monitoring services to reflect various industries, such as proprietary or newly developed device management and monitoring protocols, cluster or node agent services (e.g., virtual kubelets, WASM), proprietary or newly discovered network security connections, etc. The configuration may include configuration of libraries used by the ingestion module 111, configuration of validation rules used by the validation module 131, configuration of rules applied to management and orchestration by the management module 174, and proprietary or newly derived optimization goals. Different enterprise owners can configure and use the ingestion tool front end 110, the orchestration service back end 130, the management service back end 170, and the display tool front end 190 to manage and adjust (e.g., scale or update) the industrial system infrastructure 101.

[0092] Figure 2 The management module 174 is shown in more detail. The management module 174 includes a management module 202 and an example implementation module 203. The example implementation model 203 shown includes an orchestrator service module 204, an onboarding service module 206, and a provisioning service module 208. Different use cases may use other implementation modules 203, so the present disclosure is not limited to the example implementation modules 203 shown. The management module 202 receives and compares the current state 177 and the desired state 173. Based on the results of the comparison, the management module 202 sends a request to one or more implementation modules 203 to implement the tasks of the workflow.

[0093] The orchestrator service module 204 may include orchestration tools for implementing deployment tasks, such as Kubernetes™, Ansible™, K3s™, WASM, proprietary tools, etc.

[0094] The provisioning service module 208 may register a device (eg, a hardware component) and then perform software installation, configuration, and updates as needed to bring the device to a state where it is considered a ready device in the system.

[0095] The concept of registration is to establish trust with the device to verify authenticity, ownership, and authorization.

[0096] For compute devices, registration may require OS installation or updates, device service installation, driver updates, and workload management services to be installed. Provisioning actions are idempotent - they can be started from a device in any state in the chain and always start from devices at the same functional level. When completed, the device is considered a "node" in the system or cluster.

[0097] For non-compute devices (drivers, I / O interfaces, etc.), provisioning will involve registration and firmware installation, and potentially service and driver library installation, along with any associated licenses. When complete, the device will be considered a resource in the system.

[0098] After provisioning is performed, onboarding is performed by the onboarding service module 206. Onboarding involves loading the device and its associated configuration, workload, and workload configuration commensurate with its role defined in the desired state of the system model being used.

[0099] In one example use case for plug and play, the comparison indicates that the current state 177 includes a hardware component A that is not included in the desired state 173, and indicates that a new hardware component A has been connected and / or powered on in the industrial system infrastructure 101. When this occurs, it is determined whether the hardware component A is expected and trusted. Once trust is established, the system can utilize plug and play orchestration to bring the hardware component A from a blank, unconfigured state (or a misconfigured state in the case of reusing a previously used and removed device) to an operational state.

[0100] In one or more embodiments, the corresponding hardware component B has been added by the introduction tool front end 110, including pre-declared device-level configuration (driver, network interface configuration, etc.). The configuration can be verified by the verification tool 131. Any workload intended to be explicitly deployed on hardware component A is also added and configured via the introduction tool front end 110 and verified by the verification tool 131. The configuration may include, for example, workload configuration, including network security certificates, license certificates, etc., and external configuration, including VLAN membership, routing updates, firewall configuration, etc. Explicitly assigned workloads may be added to the desired state 173 for deployment on hardware component B. When a workload is not explicitly assigned to hardware component B, the workload may be selected by the optimal orchestration module 140 using an optimization function to be added to the desired state 173 for deployment on hardware component B. The updated desired state 173 is provided to the management module 164.

[0101] In one or more embodiments, if the corresponding hardware component and / or workload is not correctly added or verified, a prompt may be sent to the user to provide intervention to update the desired state 173. The management module 174 may detect a difference between the deployment configured for the hardware component B of the desired state 173 and the blank hardware component A of the current state 177. Therefore, the detected difference invokes the orchestrator service module 204 to perform a deployment task, which includes deploying the workload configured for the hardware component B on the new blank hardware component A.

[0102] In summary, the pre-declared device-level configuration (drivers, network interface configuration, etc.) can first be deployed and validated. Then, any assigned workloads (either explicitly assigned or assigned as a result of optimization functions) can be deployed. In addition, any workload configurations, network security certificates, licenses, etc. can be deployed. In addition, any relevant external configurations (such as VLAN membership, routing updates, firewall configuration, etc.) can be formulated.

[0103] Unless deployment is explicitly provided by the user, the desired state 173 defines the deployment of the application according to the policy rules input via the ingestion tool front end 110, and the desired state 173 is verified and optimized by the optimization service back end 130, and the implementation of the deployment defined by the orchestrator service module 204 is according to the verified and optimized policy rules. Similarly, the implementation performed by the implementation model 203 can be according to the verified and optimized policy rules.

[0104] Although in the example, hardware component A is destined to be configured to run with a dynamic workload, hardware component A is a driver that only requires an appropriate configuration file. The plug-and-play process will allow the configuration to be added to the desired state 173 and then configured on hardware component B in the current state 177. The newly added asset may be a virtual node or a network node, rather than hardware component B. In other examples, the application to be deployed may be a reprogramming of the firmware of the hardware component, a software program, etc.

[0105] In another use example for achieving high availability, assume that a first controller and a second controller are configured as a redundant pair, with one acting as the primary role and the other acting as the secondary role, and when one controller fails, the other controller assumes (or remains) the primary role. The controller now operates as the only controller without redundancy. The desired state 173 is defined as maintaining the redundant pair; therefore, the management module 174 directs a new instance of the controller to be created and assigned the role of the first controller. Therefore, it pairs with the second controller to restore redundancy.

[0106] In another use example, a device in the industrial system infrastructure 101 requires a firmware update. Via the user input device 122, the user updates the firmware version of the digital twin representation of the device in the desired state. This results in a difference between the firmware versions of the digital twin representation of the current state 177 and the desired state 173. The management module 174 detects this difference and initiates a task to update the firmware of the corresponding device in the industrial system infrastructure 101. Once updated, the desired state 173 is equal to the current state 177.

[0107] In another use example, due to a change in the desired state of the system to optimize power consumption, a change in production levels, a response to a network threat, or any other reason, the optimal orchestration module 140 determines that the virtual workloads will be consolidated onto a reduced number of computing nodes to allow some hardware components to be turned off. This change requires a change in the network infrastructure to allow the consolidated workloads to continue to communicate. The optimal orchestration module 140 also instructs the desired state 173 to formulate a new network infrastructure configuration to facilitate the optimal change.

[0108] Figure 3A An example computing node is shown in detail. Computing node 301 includes a set of one or more virtual applications 302 that have been deployed on computing node 301. The deployment of a given virtual application 310 is affected by management engine 202 instructing provisioning client 304 to create and potentially configure virtual application 310 on behalf of management engine 202. Similarly, management engine 202 can direct device management module 306 to affect changes on computing node 301 to support virtual application 310, update software on computing node 301, or change the networking configuration of computing node 301.

[0109] refer to Figure 3B , the non-compute node 321 is a device with a dedicated purpose (such as a PLC, motor drive, gateway, etc.) that does not allow dynamic workloads to be deployed to the device. It includes device application firmware 322, device configuration 324, device management service 326, and optional device OS 328, as well as potential other services and capabilities. The device application firmware 322 executes the dedicated purpose logic that provides the non-compute node 321 with its dedicated purpose. The device configuration 324 provides instance configuration information (such as PLC program logic, motor output tuning, addressing, etc.). Depending on the device requirements and capabilities, the non-compute node 321 may or may not include a device OS 328. The device management service 326 provides a method for remotely managing the device life cycle. ‎

[0110] refer to Figure 3C , the network node 341 is a device that provides network connectivity and network traffic forwarding. The network node 341 includes a network device firmware 342, a network configuration 346, a set of network interfaces 350, and a network device management service 348. The network configuration 346 configures the traffic forwarding rules of the network node between the network interfaces, including but not limited to Vlan membership, traffic shaping, prioritization, etc. The network device management service 348 provides a method for remotely managing the life cycle of the network node 341. ‎

[0111] Reference now Figure 4 , shows a flow chart demonstrating the implementation of various exemplary embodiments. Note that Figure 4The order of operations shown in the description is not required, so in principle, the various operations may not be performed in the order shown. In addition, some operations may be skipped, different operations may be added or replaced, some operations may be performed in parallel rather than in a strict order, or selected operations or groups of operations may be performed in separate applications that follow the embodiments described herein.

[0112] Beginning at block 402, the method includes receiving a desired state that models a state of two or more infrastructures of an industrial system. The two or more infrastructures include a virtual infrastructure of the industrial system and, in addition, a physical infrastructure and / or a network infrastructure of the industrial system. At block 404, the method includes receiving a current state that models a current state of the two or more infrastructures of the industrial system.

[0113] At block 406, the method includes determining a difference between the desired state and the current state. At block 408, the method includes causing one or more changes to the current state of the infrastructure of the industrial system based on the determined difference. Determining the difference and causing one or more changes involves two or more infrastructures.

[0114] In one or more embodiments, the one or more changes caused may be determined based on dynamic optimization of resources of two or more infrastructures of the industrial system.

[0115] In one or more embodiments, causing the change includes selecting a workload, selecting or instantiating a virtual controller of the virtual infrastructure, and deploying the workload on the selected or instantiated virtual controller for causing the virtual controller to operate within the infrastructure of the industrial system.

[0116] In one or more embodiments, the infrastructure of the industrial system includes at least one virtual controller, and causing the change includes at least one of deploying a workload on the virtual controller and modifying the workload deployed on the virtual controller.

[0117] In one or more embodiments, the workload is stateful.

[0118] In one or more embodiments, causing the change further comprises selecting a rule based on the difference, applying the rule, and outputting a workflow based on the applied rule, wherein the workflow causes the change that affects the controller.

[0119] In one or more embodiments, receiving the current state, determining differences, and initiating changes are performed automatically or semi-automatically with configurable user intervention.

[0120] In one or more embodiments, at block 410, implementation of the plug and play process may be performed as included in block 408 for causing one or more functions. Plug and play may be triggered when a difference is determined based on the physical device being physically added to the physical infrastructure as an unconfigured or misconfigured device. Causing a change may include provisioning a physical device to perform a task associated with the physical device. Determining the difference includes detecting that the unconfigured or misconfigured device has a corresponding configured device included in a desired state. The misconfigured or unconfigured device may be brought online and / or provisioned so that it has the same application and configuration as its corresponding configured device in the desired state. In this way, once brought online and / or configured, the device may perform its task.

[0121] In one or more embodiments, at block 412, implementation of high availability is performed as included in block 408 to cause one or more functions. Figure 3D A non-limiting example is shown, in which, in a nominal situation (362), a first device (device 1) hosts virtual controller A (VC-A) and a second device (device 2) hosts virtual controller B (VC-B). The two controllers, as they are in a desired state (e.g. Figure 1 173) as defined by the roles in the desired state shown in Figure 174, forming a redundant pair with primary and secondary roles respectively. Some other device (device n) is available in the system as a backup device. In the event of a failure (364), for whatever reason, VC-A, its host device 1, or an associated network connection fails. When VC-A or its associated device fails, VC-B automatically assumes the role of VC-A as the primary, rather than its original secondary role. The management module 174 can detect this difference as a change in the desired state and the current state of any of the roles in device 1, VC-A, the associated network connection, or VC-B (e.g., Figure 1 As shown in recovery scenario 366, management module 174 instructs the third node, device n, to instantiate a replacement virtual controller A' and configure it so that it assumes the original role of VC-B as secondary. Management module 174 may also update the relevant network devices to enable paired communications between VC-B and VC-A'. Redundant pairing is now reestablished between VC-B and VC-A'; therefore, high availability has also been automatically reestablished.

[0122] In one or more embodiments, causing changes optimizes operations and / or resource usage in physical, virtual, and / or network infrastructure.

[0123] Various aspects of the present disclosure are described above with reference to flowcharts and / or block diagrams of methods, apparatus (systems) and computer program products according to embodiments of the present disclosure. It will be understood that each block of the flowcharts and / or block diagrams and combinations of blocks in the flowcharts and / or block diagrams can be implemented by computer program instructions.

[0124] These computer program instructions may be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device create a device for implementing the functions / actions specified in one or more boxes of the flowchart and / or block diagram.

[0125] These computer program instructions may also be stored in a computer-readable medium, which may direct a computer, other programmable data processing apparatus, or other device to operate in a specific manner so that the instructions stored in the computer-readable medium produce a product including instructions for implementing the functions / actions specified in one or more boxes of the flowchart and / or block diagram.

[0126] Computer program instructions may also be loaded onto a computer, other programmable data processing apparatus or other device to cause a series of operational operations to be performed on the computer, other programmable apparatus or other device, thereby producing a computer-implemented process, so that the instructions executed on the computer or other programmable apparatus provide a process for implementing the functions / actions specified in one or more boxes of the flowchart and / or block diagram. ‎

[0127] refer to Figure 5 , shows a block diagram of an example processing system 500 that provides a computing component (e.g., Figure 1 An example configuration of one or more computing systems used by the management system 100 and its components shown in FIG. Figure 5 . In various embodiments, the processing system 500 may be a server, a mainframe computer system, a workstation, a network computer, a desktop computer, a laptop computer, a handheld computer, etc., and / or include one or more of a field programmable gate array (FPGA), an application specific integrated circuit (ASIC), a microcontroller, a microprocessor, etc. The processing system 500 is only one example of a suitable system and is not intended to impose any limitations on the scope of use or functionality of the embodiments of the present disclosure described herein. The processing system 500 may be implemented using hardware, software, and / or firmware. In any event, the processing system 800 is capable of implementing and / or performing the functions set forth in the present disclosure. ‎

[0128] In addition, all or part of the computing components of the orchestration system may be configured as software, and processing system 500 may represent these parts. Processing system 500 is merely one example of a suitable system and is not intended to impose any limitations on the scope of use or functionality of the embodiments of the present disclosure described herein. Processing system 500 may be implemented using hardware, software, and / or firmware. In any event, processing system 500 is capable of implementing and / or performing the functions set forth in the present disclosure.

[0129] Processing system 500 is shown in the form of a general purpose computing device. Processing system 500 includes a processor 502, a memory 504, an input / output (I / O) interface (I / F) 506 that can communicate with internal components (e.g., user interface 510), and optionally one or more external components 508, such as another processing device that manages system 100 or a processing device of an industrial system, e.g. Figure 1 An industrial system infrastructure 101 is shown.

[0130] Processor 502 may include, for example, a CPU, a programmable logic device (PLD), a microprocessor, a discrete signal processor (DSP), a microcontroller, a field programmable gate array (FPGA), an application specific integrated circuit (ASIC), and / or other discrete or integrated logic circuits with similar processing capabilities. Processor 502 and memory 504 may be included in components provided in, for example, an FPGA, an ASIC, a microcontroller, or a microprocessor.

[0131] The memory 504 may include, for example, volatile and non-volatile memory for temporary or long-term storage of data and for storing programmable instructions executable by the processor 502. The memory 504 may be a removable (e.g., portable) memory for storing program instructions. The I / OI / F 506 may include interfaces and / or conductors to couple to one or more internal components, such as a user interface 510 and / or external components 508.

[0132] These computer program instructions may also be stored in a computer-readable medium, which can instruct a computer, other programmable data processing apparatus, or other device to operate in a specific manner so that the instructions stored in the computer-readable medium produce a manufactured product including instructions for implementing the functions / actions specified in one or more boxes of the flowchart and / or block diagram.

[0133] Computer program instructions may also be loaded onto a computer, other programmable data processing apparatus, or other devices to cause a series of operations to be performed on the computer, other programmable apparatus, or other devices, thereby producing a computer-implemented process, so that the instructions executed on the computer or other programmable apparatus provide a process for implementing the functions / actions specified in one or more blocks of the block diagram.

[0134] Embodiments of the processing components of the orchestration system may be implemented or executed by one or more computer systems such as microprocessors. A processing system 500 or multiple instances thereof may be included in a module of the orchestration system. In various embodiments, the processing system 500 may include one or more of a microprocessor, an FPGA, an application specific integrated circuit (ASIC), a microcontroller. The processing system 500 may be provided as an embedded device. Portions of the processing system 500 may be provided externally, such as by a virtual, centralized and / or cloud-based computer.

[0135] Processing system 500 is only one example of a suitable system and is not intended to impose any limitations on the scope of use or functionality of the embodiments of the present disclosure described herein. Regardless, processing system 500 is capable of implementing and / or performing any of the functions set forth above.

[0136] Processing system 500 may be described in the general context of computer system executable instructions, such as program modules, that are executed by a computer system. Generally, program modules may include routines, programs, objects, components, logic, data structures, etc. that perform specific tasks or implement specific abstract data types.

[0137] By using orchestration tools that use such technologies, such as Docker, Kubernetes™, WASM, etc., management systems can use and exploit the potential advantages of virtualization and clustering technologies. Other potential benefits include optimal dispatching of workloads and other applications (independent of hardware), reliable operation, and enhanced resilience of the industrial system infrastructure 101 through automatic adjustments in response to changes in the current system state or desired system state. Further potential advantages include applying advanced information technology (IT) to the industrial system infrastructure 101 (which has an operational technology (OT) environment) without requiring users of the industrial system to have IT expertise.

[0138] In the above, reference is made to various embodiments. However, the scope of the present disclosure is not limited to the specifically described embodiments. On the contrary, any combination of the described features and elements, whether or not related to different embodiments, is considered to implement and practice the contemplated embodiments. In addition, although the embodiments may achieve advantages over other possible solutions or prior art, whether a given embodiment achieves a particular advantage does not limit the scope of the present disclosure. Therefore, the foregoing aspects, features, embodiments and advantages are merely illustrative and are not considered to be elements or limitations of the appended claims unless expressly stated in the claims.

[0139] Various embodiments disclosed herein may be implemented as systems, methods, or computer program products. Thus, various aspects may take the form of a complete hardware embodiment, a complete software embodiment (including firmware, resident software, microcode, etc.), or an embodiment combining software and hardware aspects, which are generally referred to herein as "circuits," "modules," or "systems." Additionally, various aspects may take the form of a computer program product contained in one or more computer-readable media having computer-readable program code embodied thereon.

[0140] Any combination of one or more computer-readable media may be utilized. The computer-readable medium may be a non-transitory computer-readable medium. The non-transitory computer-readable medium may be, for example, but not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any suitable combination of the foregoing. More specific examples (a non-exhaustive list) of non-transitory computer-readable media may include the following: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing. The program code contained on the computer-readable medium may be transmitted using any appropriate medium, including but not limited to wireless, wired, fiber optic cable, RF, etc., or any suitable combination of the foregoing.

[0141] The computer program code for performing the operations of various aspects of the present disclosure can be written in any combination of one or more programming languages. In addition, such computer program code can be executed using a single computer system or by multiple computer systems that communicate with each other (e.g., using a local area network (LAN), a wide area network (WAN), the Internet, etc.). Although various features are described above with reference to flow charts and / or block diagrams, it will be understood by those of ordinary skill in the art that each frame of the flow charts and / or block diagrams and the combination of frames in the flow charts and / or block diagrams can be implemented by computer logic (e.g., computer program instructions, hardware logic, a combination of the two, etc.). Typically, computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device. In addition, a processor is used to execute such computer program instructions to generate a machine that can perform the functions or actions specified in one or more frames of the flow charts and / or block diagrams.

[0142] The flow charts and block diagrams in the accompanying drawings illustrate the possible architectures, functions and / or operations of various embodiments of the present disclosure. In this regard, each frame in the flow chart or block diagram may represent a module, a code segment or a code portion, which includes one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions annotated in the frame may not appear in the order annotated in the figure. For example, the two frames shown in succession can actually be performed substantially simultaneously, or these frames can sometimes be performed in reverse order, depending on the functions involved. It should also be noted that each frame in the block diagram and / or the flow chart diagram and the combination of frames in the block diagram and / or the flow chart diagram can be implemented by a system based on dedicated hardware or a combination of dedicated hardware and computer instructions that performs a specified function or action.

[0143] It should be understood that the above description is intended to be illustrative, not restrictive. After reading and understanding the above description, many other implementation examples are apparent. Although the present disclosure describes specific examples, it should be appreciated that the systems and methods of the present disclosure are not limited to the examples described herein, but can be implemented by modification within the scope of the appended claims. Therefore, the description and drawings should be considered illustrative, not restrictive. Therefore, the scope of the present disclosure should be determined with reference to the appended claims and the full scope of the equivalents of these claims.

Claims

1. A method for managing an infrastructure of an industrial system, the method comprising: receiving a desired state modeling a state of two or more infrastructures of the industrial system, the two or more infrastructures being a virtual infrastructure of the industrial system and additionally being a physical infrastructure and / or a network infrastructure of the industrial system; receiving a current state modeling a current state of two or more infrastructures of an industrial system; Identify the difference between the desired state and the current state; as well as Based on the determined differences, one or more changes are caused to a current state of infrastructure of the industrial system, wherein determining the differences and causing the one or more changes involve two or more infrastructures. 2 . The method of claim 1 , wherein the one or more changes are determined based on a dynamic optimization of resources of two or more infrastructures of the industrial system.

3. The method of claim 1 , wherein causing the change comprises: Select the workload; selecting or instantiating a virtual controller of the virtual infrastructure; as well as A workload is deployed on the selected or instantiated virtual controller to cause the virtual controller to operate within the infrastructure of the industrial system.

4. The method of claim 1, wherein the infrastructure of the industrial system includes at least one virtual controller, and causing the change includes at least one of deploying a workload on the virtual controller and modifying the workload deployed on the virtual controller. The method of claim 4 , wherein the workload is stateful.

6. The method of claim 1, wherein causing the change further comprises selecting a rule based on the difference, applying the rule, and outputting a workflow based on applying the rule, wherein the workflow causes the change affecting the controller.

7. The method of claim 1, wherein receiving the current state, determining the difference, and causing the change are performed automatically or semi-automatically with configurable user intervention.

8. The method of claim 1, wherein the difference is determined based on a physical device being physically added to the physical infrastructure as an unconfigured or misconfigured device, and causing the change includes provisioning the physical device to perform a task associated with the physical device.

9. The method of claim 1, wherein the difference is determined based on a failure of a first node included in one of the physical, virtual, or network infrastructures, wherein the first node is initially designated as requiring high availability and a second node operates as a redundant pair of the first node, wherein The changes caused include: Upon failure of the first node, causing the second node to automatically assume the role of the first node instead of its original role; and The original role of the second node is automatically assigned to the third node, thereby automatically re-establishing a redundant pairing between the second and third nodes.

10. The method of claim 1, wherein causing the change comprises optimizing operations and / or resource usage in the physical, virtual, and / or network infrastructure.

11. A management system for managing an infrastructure of an industrial system, the management system comprising: one or more memories configured to store a plurality of programmable instructions; and One or more processing devices in communication with the one or more memories, wherein when executing the plurality of programmable instructions, the one or more processing devices are configured to: receiving a desired state modeling a state of two or more infrastructures of the industrial system, the two or more infrastructures being a virtual infrastructure of the industrial system and additionally being a physical infrastructure and / or a network infrastructure of the industrial system; receiving a current state modeling a current state of two or more infrastructures of an industrial system; Identify the difference between the desired state and the current state; as well as Based on the determined differences, one or more changes are caused to a current state of infrastructure of the industrial system, wherein determining the differences and causing the one or more changes involve two or more infrastructures.

12. The management system of claim 11, wherein the one or more changes are determined according to dynamic optimization of resources of two or more infrastructures of the industrial system.

13. The management system of claim 11, wherein causing the change comprises: Select the workload; selecting or instantiating a virtual controller of the virtual infrastructure; as well as A workload is deployed on the selected or instantiated virtual controller to cause the virtual controller to operate within the infrastructure of the industrial system.

14. The management system of claim 11, wherein the infrastructure of the industrial system includes at least one virtual controller, and causing the change includes at least one of deploying a workload on the virtual controller and modifying the workload deployed on the virtual controller.

15. The management system of claim 14, wherein the workload is stateful.

16. The management system of claim 11, wherein causing the change further comprises selecting a rule based on the difference, applying the rule, and outputting a workflow based on applying the rule, wherein the workflow causes the change that affects the controller.

17. The management system of claim 11, wherein receiving the current state, determining the difference, and causing the change are performed automatically or semi-automatically with configurable user intervention.

18. The management system of claim 11, wherein the difference is determined based on a physical device being physically added to the physical infrastructure as an unconfigured or misconfigured device, and causing the change includes provisioning the physical device to perform a task associated with the physical device.

19. The management system of claim 11, wherein the difference is determined based on a failure of a first node included in one of the physical, virtual, or network infrastructures, wherein the first node is initially designated as requiring high availability and a second node operates as a redundant pair of the first node, wherein The changes caused include: Upon failure of the first node, causing the second node to automatically assume the role of the first node instead of its original role; and The original role of the second node is automatically assigned to the third node, thereby automatically re-establishing a redundant pairing between the second and third nodes.

20. The management system of claim 11, wherein causing the change comprises optimizing operations and / or resource usage in the physical, virtual, and / or network infrastructure.

Citation Information

Patent Citations

  • Method for arranging workloads in a software defined automation system

    US10845786B2

  • Centralized management of a software defined automation system

    US11079744B2

  • Software defined automation system and architecture

    US11579595B2

  • Centralized management of a software defined automation system

    US20210356944A1

  • Software Defined Automation System and Architecture

    US20230161332A1