Modular and dynamic control of machines in network

By adopting software-defined edge devices and virtual machine monitors in machine production lines, modularization and dynamic control of machine networks are achieved, solving the problems of complex network configuration, difficult management, and insufficient security in existing technologies, improving network flexibility and security, and reducing operating costs.

CN120692302APending Publication Date: 2025-09-23KRONES AG
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510296788.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2024-03-20
Filing Date
2025-03-13
Publication Date
2025-09-23

AI Technical Summary

Technical Problem

The network configuration of existing machine production lines is complex, difficult to manage, has a low degree of modularity, high hardware costs, insufficient security, and is difficult to expand and maintain, which poses a financial burden especially for small businesses and is vulnerable to cyber attacks.

Method used

Adopting software-defined edge devices and virtual machine monitors, modular machine networks are implemented through industrial computers (IPCs). Utilizing virtualized environments and software-defined network technologies, physical network components are reduced, flexible scalability and security are provided, and highly flexible network management and firewall protection are achieved.

Benefits of technology

It simplifies network management, reduces hardware and maintenance costs, improves network modularity and scalability, enhances security, reduces the risk of network attacks, and reduces operating costs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120692302A_ABST
    Figure CN120692302A_ABST
Patent Text Reader

Abstract

The invention relates to a machine production line and a machine in the machine production line, in particular a machine in a machine production line for filling and packaging food and / or beverages. The machine includes an industrial computer (IPC) that implements a software-defined edge device for the machine and includes a virtual machine monitor. The virtual machine monitor provides a virtual operating platform to host and / or run corresponding services for operating the machine production line. According to an embodiment, the IPC or virtual machine monitor implements a non-military zone (DMZ) with its own network segment, within which a virtual operating platform is implemented. Further, the IPC may establish a connection with a network of the machine production line, the network interconnecting a plurality of machines, each including an IPC. The IPC is further designed such that it can distribute workloads between the machine and at least one second machine in the network of the machine production line.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The invention relates to a machine, a machine production line and a computer program, a computer-readable storage medium, for modular and dynamic control of a machine, in particular a machine in a machine production line for filling and packaging food and / or beverages. Background Art

[0002] In industrial manufacturing, particularly in the beverage and food technology industry, significant progress has been made in integrating network capabilities into machine lines. This development enables improved monitoring, efficiency, and automation of production, packaging, and filling processes. However, existing technologies have significant drawbacks that impact both operating costs and safety, for example.

[0003] Currently, most machines are equipped with dedicated line-level network switches. These switches facilitate communication within individual production lines. While this solution ensures efficient data transmission within the production line, it increases the complexity of network management. Each production line requires a separate switch, making network maintenance and expansion more difficult. This becomes particularly problematic when equipment needs to be adjusted or expanded, as each change must be made individually for each production line.

[0004] In addition to switches, each production line or machine is connected to the central enterprise network via a separate hardware router (i.e., a line switch across each line). This requires a central location / network cabinet, which is correspondingly costly and complex, while also lacking modularity and preventing decentralized scalability. This separate network infrastructure for each line not only increases management complexity but also hardware and maintenance costs. Especially in facilities with multiple machines, the need for a central network cabinet represents a significant investment. The cost of such an installation, including the necessary engineering services, can exceed €10,000, a significant financial burden, particularly for smaller companies.

[0005] Another key aspect is the so-called "bare-2-metal" installation, in which the software is installed directly on the hardware without an intermediate layer like an operating system. Although this configuration offers advantages in terms of performance, it limits the flexibility and scalability of the system.

[0006] The inadequate security of these network configurations presents other drawbacks. Many devices fail to implement basic security measures, such as firewalls. This lack of attention to network security, coupled with inconsistencies with ISA95 (a key industry standard for enterprise system and control system integration), leaves devices vulnerable to cyberattacks and data breaches. This can lead to serious consequences, including business interruption, data loss, and even physical damage to the equipment. Summary of the Invention

[0007] Therefore, there is a need for a solution that overcomes these drawbacks of the prior art and thus provides a modular and dynamic control system for machines in machine networks for filling and packaging machines, production lines and installations.

[0008] According to the invention, this object is achieved by a machine, a computer-readable storage medium and a machine production line.

[0009] One embodiment of the present invention relates to a machine in a production line, particularly a machine in a production line for filling and packaging food and / or beverages. The machine includes an industrial computer (IPC) that implements a software-defined edge device for the machine and includes a hypervisor. The hypervisor provides a virtual operating platform for hosting and / or running services used to operate the production line. Depending on the implementation configuration, the IPC has a "bare metal" installation of the virtual operating platform or hypervisor.

[0010] Other embodiments relate to a computer-readable storage medium and a machine production line. BRIEF DESCRIPTION OF THE DRAWINGS

[0011] Exemplary aspects of the present invention are illustrated in the accompanying drawings. In the drawings:

[0012] Figure 1 shows a diagram illustrating a cellular arrangement of cells in a network according to an embodiment of the present invention;

[0013] Figure 2 An exemplary machine is shown that displays IPC and multiple virtualized network layers;

[0014] Figure 3 An exemplary equipment configuration for PET containers and bonded strapping is shown;

[0015] Figure 4 An exemplary equipment configuration for a PET container and shrink wrap machine is shown;

[0016] Figure 5 An exemplary apparatus configuration for use with cans or bottles is shown; and

[0017] Figure 6 An exemplary equipment configuration for a can is shown. DETAILED DESCRIPTION

[0018] The present invention provides a method to overcome the above-mentioned disadvantages by implementing a "software-defined" edge device for each machine in the machine production line. This can be implemented on an industrial computer (IPC) depending on the implementation. This allows the organization of independent edge devices to be designed so modularly that each machine operates like a unit that can be added modularly like a cellular concept. This concept is Figure 1 As can be seen in the figure, the exemplary arrangement of the machines is organized in a honeycomb structure. Each machine in the exemplary machine has a corresponding IPC, which implements an operating platform or a virtual machine monitor. Such an operating platform can provide various services for the operation of the machine production line. The virtual machine monitor can be implemented on the IPC in a "bare metal" manner and provide a virtualization environment that makes it possible for multiple operating systems or virtual machines to execute simultaneously on a single physical IPC. This makes it possible to execute different services on the same IPC without interfering with each other or causing conflicts. In addition, services can be moved or copied between different IPCs with the help of the virtual machine monitor to ensure flexible scalability and fault safety, which will be further explained below.

[0019] The more machines in a production line are organized in this way, the more robust the given infrastructure becomes, because the load can be distributed thanks to the implementation. Examples of loads to be distributed are various edge device functions or production line management services, each of which is executed on the IPC.

[0020] Using software-defined networking technology, as demonstrated in the embodiments described herein, enables a high degree of flexibility and simplifies network management. In the exemplary network architecture, this can be leveraged to virtualize network components. This reduces the number of physical network components and simplifies the modular and scalable design of machine production lines.

[0021] According to an embodiment, the IPC is designed to implement a software-defined edge device for the machine and includes a virtual machine monitor. The virtual machine monitor provides a virtual operating platform to host and / or run corresponding services for operating the machine production line.

[0022] A hypervisor can also implement a demilitarized zone (DMZ) with its own network segment, in which at least a portion of the virtual operating platform is implemented. For example, services that publicly provide services to the internet and / or exchange data with other cloud platforms can be hosted in the DMZ. A DMZ is a zone or exemplary network segment. A DMZ is primarily used for public services hosted on the internet. Other network zones / segments can also be provided, depending on how deeply segmented the services require or require.

[0023] Depending on the implementation, machines or their IPCs can be connected to each other and to the network of a machine line. The machine line network thus interconnects multiple machines, each of which also includes an IPC as a software-defined edge device, configured according to the implementation. Through the modular combination of these "units" (a unit is defined as a machine with an IPC on which a virtual machine monitor / operating platform is implemented), workloads can be distributed across the machines in the machine line network.

[0024] Each unit in the machine line, according to the embodiment, forms a separate unit with independent communication capabilities. Using authorization, a unit can automatically connect to the machine line's network, and thus to other units. The IPC within the unit can serve as the unit's input / connection point and provide a firewall for inbound and outbound communications.

[0025] When connecting a machine / unit to a network, the connection can be automatically identified and the correct allocation of the corresponding zone / VLAN can be made for the device once it is connected to, for example, a switch. For example, a central network management service can connect automatically connected (known / verified) devices to the correct network.

[0026] As in Figure 1 As can be seen further in FIG, it is also possible to connect machines without corresponding authorization ("external machines") to the network. In this example, such an external machine is a pallet wrapping machine. Figure 1 If a machine / unit in a machine line is found to be unauthorized (non-trusted), limited communication with the unauthorized machine / unit may still be established or maintained. Limited communication may, for example, enable limited access to network resources and / or network segments by the external machine. Alternatively or additionally, limited communication with the external machine may be monitored and recorded.

[0027] For unknown devices (external machines), the user can be asked in an HMI dialog box whether the device is trusted, what type of device it is, which group it belongs to, etc. The network management service can then move the device to the correct zone and give it limited communication capabilities if appropriate.

[0028] According to an embodiment, if a machine in a machine production line is found to be infected with malware, communication with the infected machine can be terminated. This is particularly efficient and feasible because each IPC or each IPC's software-defined firewall performs corresponding packet monitoring on incoming and / or outgoing messages.

[0029] Distributing workloads between machines / units in a network of machine production lines involves distributing tasks necessary for the execution of the network itself. For example, the distribution of tasks refers to software-defined network services from a list of services required by the network, such as APN services, DHCP services, DNS services, MQTT services, etc. Other examples are Figure 2 , which shows an exemplary machine on which a virtual DMZ is implemented on an IPC. The IPC can execute various services (e.g., in a DMZ and / or virtual business functional area) or only execute a portion thereof, thereby distributing tasks between units in the network.

[0030] For example, some IPCs can access the network (such as the Internet, VPN, etc.), some can provide DHCP services, some can provide DNS services, and some can take on production workloads. This makes a high degree of flexibility and security possible, while saving resources.

[0031] The distribution of tasks between units can include a range of other exemplary tasks and aspects. For example, a unit can be used to undertake dynamic package distribution for the life cycle of at least one IPC. In addition, a unit can be responsible for controlling the communication of management commands via a mobile data connection (e.g., via 5G) and the downloading of control packages and / or artifacts via a fiber / DSL connection. This can achieve faster equipment commissioning. In addition, if there is no available fiber / DSL connection, the unit can also additionally use a mobile 5G data connection to download the required data to achieve faster commissioning.

[0032] For example, Figure 2 As can be seen in the figure, virtual access zone 203 can be implemented in a different kernel than the DMZ. Virtual access zone 203 controls and receives data from the machine's IPC 205 and from sensors 206 that collect data at the machine. Communication via virtual access zone 203 is possible, for example, via a trunk port and a Profinet-compatible "managed switch." Direct access to an HMI or mobile device can also be achieved via data connection 207.

[0033] The embodiments of the present invention thus provide a network technology concept that is highly software-defined, so that no additional network hardware is required between machines or production lines. This enables a simple, modular, and scalable design of machines and their networks.

[0034] Depending on the implementation, the IPC, or a software-defined edge device or its corresponding virtual machine monitor, can, for example, connect to a backend service, providing various additional services on that backend service. These services can be transmitted to the IPC or executed on a backend server. Furthermore, a connection can be established with a data center, which can provide additional data, such as enterprise-specific data, for the service.

[0035] The present invention can be implemented on a computer that is configured so that it executes specific program instructions that make the functions of the present invention possible. The basic architecture of the computer includes multiple core components, such as a central processing unit (CPU), memory, input / output system, network connection, bus, etc. The CPU is responsible for executing program instructions. It processes data and controls the other components of the system. The memory may include volatile memory (RAM) and non-volatile memory (such as a hard disk or SSD). RAM provides temporary storage space for ongoing processes and data, while non-volatile memory makes permanent data storage possible. The input / output system makes it possible for the computer to interact with the outside world, including input devices such as a keyboard and mouse, and output devices such as a display and printer. The network connection makes it possible for the computer to be connected to other computers and networks, thereby making data exchange and remote access capabilities possible. Components can be interconnected via a bus system.

[0036] Computer-readable storage media contain program instructions that, when executed by a computer device, configure the device to implement the specific functions and processes of the present invention. These instructions may be in the form of software code, written in a programming language and stored on the storage medium. When executed by a CPU, this code enables the computer to implement the present invention by executing specific algorithms and processing steps.

[0037] In the following Figures 3 to 6 Various exemplary apparatus configurations are described in detail for various bottle filling apparatuses in which the present invention, or at least parts and aspects of the present invention, may be implemented. Figures 3 to 6 The description is intended only to provide a general overview of the machines for which status data can be collected and on the basis of which LLM can process user requests.

[0038] Figure 3An exemplary apparatus configuration 1000 for PET bottles or PET containers and adhesively bonded bundles is shown. Figure 3 As shown, the equipment configuration 1000 includes different modules that form a production line at the end of which the filled PET containers are delivered in bundles on pallets. Some of the modules and machines may be optional, and the present invention is not limited to a specific form and arrangement of the equipment configuration.

[0039] Equipment configuration 1000 includes an oven 1002 for preforms, a preform sorter 1004 with a feeder, and a blow molding machine 1008. Modules 1002, 1004, and 1008 typically form a stretch blow molding machine, in which PET containers are formed and shaped from the starting material. The finished PET containers are then transferred to a filler 1010, where they are filled into bottles. The filler may optionally include a rinser. During storage or transportation, various particles, such as dust and remnants of cardboard or wooden pallets, may accumulate in the preforms. These particles can be removed using a rinser. A sealer may be located at the end of the filler to seal the PET containers after filling.

[0040] Optionally, the plant configuration 1000 may include a carousel 1014 for hot filling of PET containers after the filler 1010. The filled PET containers are conveyed via one or more conveyor belts 1016 (which may also include a buffer 1018 for intermediate loading of filled containers) to a separator 1020 and further to a drying device 1024, in which the PET containers are dried.

[0041] After drying, the PET containers are conveyed to a labeler 1026. Labeler 1026 can be designed for various labeling techniques, such as hot glue, cold glue, self-adhesive labels, or sleeve labels. After printing or labeling, the PET containers are conveyed to a handle applicator 1040 via a second drying unit 1028, a line dispenser 1030, a conveyor belt 1032, an adhesive bundle production unit 1034, and a curing path 1036. In the adhesive bundle production unit 1034, the PET containers are grouped together in specific group sizes and packaged into bundles, such as "six-packs." In the handle applicator, handles are attached to the containers, making the bundles comfortable to carry. The finished bundles are then arranged into layers by a robot 1042 and packaged on pallets by a palletizer 1044.

[0042] In the system configuration 1000, so-called format carts or format racks can be arranged at the various modules and machines to provide quickly exchangeable format sets for short changeover times and automatic tool switching. Examples of format carts are the format cart 1006 for the blow molding machine 1008, the format cart 1012 for the filling machine 1010, the format cart 1022 for the labeling machine 1026, the format cart 1038 for the adhesive bonded bundle production device 1034, and the format cart 1046 for the palletizer 1044.

[0043] Figure 4 Another exemplary equipment configuration 1100 for a PET container and shrink wrap machine is shown. Figure 4 The device 1100 includes a Figure 3 The equipment configuration of the 1000 modules and machines has many modules and machines, however there are some differences. Figure 4 Omitted already combined Figure 3 A description of the module.

[0044] A significant difference between the two exemplary machine configurations 1000 and 1100 is that a labeling machine 1126 with a labeling module 1127 can be installed after the blow molding machine 1008 and before the filling machine 1010. To this end, the machine configuration 1100 can include up to six transport tracks 1150 on which PET containers can enter. After the PET containers have respectively entered one of the six tracks 1150, they are conveyed to a film wrapping module 1152 and then to a shrink tunnel 1154.

[0045] Figure 5 An exemplary device configuration 1200 for cans or bottles is shown. Figure 5 The exemplary device configuration 1200 is again related to Figure 3 and Figure 4 The device configurations 1000 and 1100 have some similarities, so the description of the device configurations is limited to the differences in the device configurations.

[0046] like Figure 5 As shown, an exemplary apparatus configuration may include two separate feed sections. Figure 5 The first infeed on the left shows a branch for cans, or alternatively a sub-branch for new, reusable bottles. Here, containers (i.e., cans or new bottles) are introduced into the machine by a depalletizer 1302, where they are guided to a filling machine 1010 via a conveyor belt. Figure 5 The second feed section on the right shows the sub-branch for reusable bottles, which are introduced into the device from a reusable sorting device (not shown).

[0047] In the case where already used reusable bottles are introduced into the apparatus 1200 via the sub-branch for reusable bottles, the reusable bottles first pass through a cleaning or washing machine 1304. Another possible difference in the exemplary apparatus configuration 1200 is a converting packaging machine 1306 following the labeling machine 1026. The converting packaging machine can sort the bottles or cans into cardboard clip application devices or boxes, or both.

[0048] Figure 6 An exemplary system configuration 1300 for cans is shown, wherein elements already described in other system configurations are not described again. The cans in system configuration 1300 are introduced from a can magazine 1402 containing cans into a depalletizer 1302. After the cans have passed through the filling machine and been filled, they are sealed using a sealing magazine 1404 and transported further along system 1400 via a conveyor belt, as described above.

[0049] If not required, the optional pasteurizer 1408 can be bypassed via bypass 1412. In the pasteurizer 1408, the freshly filled product can be pasteurized for storage.

[0050] Compared to equipment configurations 1000, 1100, and 1200, exemplary equipment configuration 1300 shows different tanks for corresponding consumables, such as tank 1410 for flushing liquid and / or filling product and tank 1406 for lubricant. These tanks can also be included in the exemplary equipment configurations described above. For example, chemical products transferred from a mixer to a machine can be stored in tanks 1406 and 1410.

Claims

1. A machine in a machine production line, including a machine in a machine production line for filling and packaging food and / or beverages, wherein the machine comprises: An industrial computer (IPC) implementing a software-defined edge device for the machine and comprising a virtual machine monitor, wherein the virtual machine monitor is designed to: A virtual operating platform is provided to host and / or run corresponding services for operating the machine production line.

2. The machine of claim 1 , wherein the virtual machine monitor is further configured to: A demilitarized zone (DMZ) having its own network segment is implemented, at least a portion of the virtual operating platform is implemented in the DMZ, wherein services are hosted in the DMZ, which publicly provide services to the Internet and / or exchange data with other cloud platforms.

3. The machine according to any one of claims 1 or 2, wherein the virtual machine monitor is further configured to: establishing a connection with a network of the machine production line, wherein the network of the machine production line interconnects a plurality of machines, wherein each of the plurality of machines respectively implements IPC as a software-defined edge device for the corresponding machine and includes a corresponding virtual machine monitor; and distributing a workload between said machine and at least one second machine in said network of machine lines; in, If an IPC of a machine in the network fails, the virtual machine monitor is designed to redistribute and / or take over the workload of the failed IPC.

4. The machine according to any one of claims 1 to 3, wherein: The machines form a unit in the machine production line with independent communication capabilities; The machine automatically connects to the network of the machine production line with authorization; and The IPC within the unit is the entry / connection point for the unit and provides a firewall container for inbound and outbound communications.

5. The machine according to any one of claims 1 to 4, wherein the IPC is further equipped with WAN, 5G and / or LTE communication means and is capable of autonomously connecting to the Internet via the WAN, 5G and / or LTE communication means.

6. The machine according to any one of claims 3 to 5, wherein the virtual machine monitor is further configured to: a machine in the line of machines is found to be an unauthorized machine; and establishing limited communications with the unauthorized machine, wherein the limited communications enable limited access by the unauthorized machine to network resources and / or network segments, and / or wherein the limited communications with the unauthorized machine are monitored and logged; and / or The IPC of one of the machines in the machine production line is discovered to be infected with malware, and communication with the infected machine is terminated.

7. The machine according to any one of claims 3 to 6, wherein said distributing the workload between said machine and at least one second machine in said network of machine lines comprises: Assigning tasks regarding software-defined network services from a list of services required by the network, including APN services, DHCP services, DNS services, and / or MQTT services; and / or Dynamic package distribution for the lifecycle of at least one IPC; and / or Controlling the communication of management commands via a mobile data connection and the downloading of packages and / or artifacts via a fiber / DSL connection; and / or If no fiber / DSL connection is available, use mobile 5G data connection for faster commissioning.

8. The machine according to any one of claims 1 to 7, wherein the virtual machine monitor is further configured to: Virtualizing firewall and / or router functions as software-defined functions enables integration of the access layer and the core layer into one hardware unit of the IPC.

9. A computer-readable storage medium having program instructions recorded thereon, wherein when the program instructions are executed by at least one computer device, the program instructions configure the at least one computer device to: Implementing a virtual machine monitor for a software-defined edge device for a machine, wherein the virtual machine monitor is designed to: Providing a virtual operating platform to host and / or run corresponding services for operating the machine production line, The machine is part of a machine production line, including part of a machine production line for filling and / or packaging food and / or beverages.

10. A machine line comprising a machine line for filling and packaging food and / or beverages, wherein the machine line comprises: A plurality of machines are interconnected via a network, wherein each of the machines includes an industrial computer (IPC) that implements a software-defined edge device for the machine and includes a virtual machine monitor designed to: A virtual operating platform is provided to host and / or run corresponding services for operating the machine production line.