System and method for monitoring or controlling assets of industrial automation environment
By establishing bidirectional communication between assets and digital twins, and using asset twins as an intermediary, the access restrictions between assets and digital twins in industrial automation environments are resolved. Controlled bidirectional interaction and data access under firewall settings are achieved, adapting to the connection needs of multiple digital twins.
Patent Information
- Application Number
- CN202480045108.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2023-07-03
- Filing Date
- 2024-06-06
- Publication Date
- 2026-01-30
AI Technical Summary
In industrial automation environments, the lack of bidirectional communication between assets and their digital twins leads to situations where direct access to the twin is not possible and commands are not transferred asymmetrically. Furthermore, firewall settings restrict direct data access. Existing technologies address this through REST APIs and web connections, but these methods suffer from security and connectivity limitations.
By establishing bidirectional communication between assets and digital twins, and using asset twins as an intermediary, comprehensive write access from the asset side to the digital twin side is achieved. This allows for the setting of twin attributes on both sides and interaction through the asset twins, including the transmission of values and setpoints, and resolves access permissions and consistency checks.
It enables controlled access from digital twins to assets under firewall settings, supports bidirectional interaction, improves the flexibility and security of data access, and adapts to the connection needs of multiple digital twins.
Smart Images

Figure CN121444033A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The invention relates to a method for monitoring or controlling an asset of an industrial automation environment according to the preamble of patent claim 1, and a system for monitoring or controlling an asset of an industrial automation environment according to the preamble of patent claim 12. BACKGROUND
[0002] A digital twin is a virtual representation that is a real-time digital counterpart of a physical object or process (in the following disclosure referred to as "asset"). "Digital twins can also be used for monitoring, diagnostics, and predictions to optimize asset performance and utilization" (from Wikipedia - https: / / en.wikipedia.org / wiki / Digital_twin). Typically, a digital twin is limited to representing certain aspects, properties or functions (so-called aspects) of the asset. A typical example is a CAD drawing of a device or the actual state of a machine. In this disclosure, we are not interested in specific aspects.
[0003] Recently, the functionality of digital twins has been extended so that one can interact with a digital twin in a command-like fashion. However, a digital twin is mainly seen as a representation of the real object and in this respect, read operations and more generally all operations are performed on the twin side of the asset.
[0004] In our focus on digital twins, the digital twin is more a digital shadow than a digital twin. The invention is more focused on the fact that the asset and the related digital twin are two things that are able to interact with each other.
[0005] The problem is that there is usually no two-way communication, but only an asymmetric transfer of values and commands / setpoints, which means that: On the asset, there is no access to what is happening on the twin side. For example, if there is some post-processing or setting of values, these cannot be accessed directly from the asset side.
[0006] There is no possibility to issue commands from the digital twin to the asset side.
[0007] These problems occur frequently because for security reasons, direct access from the area where the asset is located (e.g. a plant area, an industrial automation environment) to the site where the twin exists (e.g. a cloud, the internet) and especially vice versa is usually prohibited or restricted: Assets (e.g., PLCs - Programmable Logic Controllers) are logically or physically located in the shop floor or otherwise in a restricted site, making direct connections to (e.g., HTML-based access) impossible. This typically occurs when firewalls are configured to block direct internet access from the shop floor via the production network (industrial automation network) or vice versa.
[0008] The Internet is physically inaccessible, for example due to network failure or because a dial-up connection is being used (possibly due to bandwidth or cost reasons, or in situations where there is no connection at all, such as on a ship).
[0009] Currently, the problem is being addressed by using a web (HTTP) connection, for example, a REST-API, to a twin provider (REST: representation of state transfer).
[0010] As described above, security settings typically restrict what can and should be visible from the asset side to the digital twin side (or vice versa). The connection between the asset and the digital twin is often tailored to the requirements of IoT data flow. Therefore, firewalls inspect or control data traffic between the source and destination. Access from a browser is often blocked.
[0011] Publication US 2023 / 0017142 A1 (Dunn et al., “Digital Engineering Secure Remote Access”) proposes the use of so-called industrial information hubs to exchange data among multiple participants via virtual private network connections.
[0012] Document EP 3 971 666 A1 (Miller et al., “Connectivity to an Industrial Information Hub”) discloses a user interface for simultaneous access to multiple assets coupled via multiple gateways and for a unified presentation of the assets.
[0013] The disclosure in US 2022 / 0051171 A1 ("Digital Twin for Control Tower and Enterprise Management Platform Managing Entity Replicas and E-Commerce Systems") relates to the use of digital twins in logistics, where one digital twin represents the environment of a system to be optimized with the aid of artificial intelligence. Summary of the Invention
[0014] The objective of this invention is to improve and better control data access between assets and their digital twins, and to provide a communication framework for new services that require full write access from digital twins to assets.
[0015] Our solution for this task establishes bidirectional communication between the asset and the digital twin. This bidirectional communication can be conducted indirectly via an established IoT connection or initiated specifically from the asset or twin side. This connection is not part of this disclosure. Essentially, we create a twin of a twin, a so-called asset twin. This enables interaction in the following ways: We allow setting “asset values” on the asset twin – which makes it possible to set expected values not only on the “digital twin” side (e.g., parameters, setpoints, function calls, etc.) but also on the “asset twin” side.
[0016] Instead of simply sending reported attributes from the asset to the digital twin, we also report "twin attributes" from the "twin" side to the asset side.
[0017] We allow setting "twin attributes" on both sides.
[0018] All interactions on the “asset twin” side can be performed via human users (e.g., using a web-based UI), or from the asset itself, or from other assets or users (machine users or “computer-based entities”) on the asset side (typically the workshop).
[0019] In particular, the problem is solved by the method according to claim 1 and the system according to claim 12.
[0020] The solution includes a method for monitoring or controlling assets in an industrial automation environment, wherein the asset is communicatively coupled to at least one digital twin that receives value attributes about the asset and transmits desired setpoints to the asset. In this method, bidirectional communication between the asset and the at least one digital twin is routed at least partially via the asset twin, which is a service located in the industrial automation environment. The asset twin receives values from the asset and forwards these values to the at least one digital twin, and the asset twin receives setpoints or desired values from the at least one digital twin, checks the access permissions and / or consistency of these setpoints or desired values with other values, setpoints, and / or attributes of the asset, and applies these desired values or setpoints to the asset. Thus, controlled access from the digital twin to the asset is possible even within a firewall setup of the digital twin. The asset (e.g., a PLC) can even be affected by an external digital twin during operation.
[0021] The problem is also addressed by a system for monitoring or controlling assets in an industrial automation environment, wherein the asset is communicatively coupled to at least one digital twin, and the digital twin is configured to receive value attributes regarding the asset and transmit desired setpoints to the asset. The system includes a bidirectional communication channel between the asset and at least one digital twin, routed at least partially via the asset twin, which is a service located in the industrial automation environment. The asset twin is configured to receive values from the asset and to forward these values to the at least one digital twin. The asset twin is also configured to receive setpoints or desired values from the at least one digital twin, to check the access permissions of these setpoints or desired values and their consistency with other values, setpoints, and / or attributes and / or functions of the asset, and to apply these desired values or setpoints to the asset. Data communication can also be based on a polling-based communication protocol, particularly initiated by the asset twin. The advantages associated with the method of the present invention can be achieved through this system.
[0022] Advantageous embodiments of the invention are given in the dependent claims. Features of the embodiments of the method also apply to the system of the invention, and vice versa. Several advantageous embodiments can be combined in a meaningful manner.
[0023] In one implementation, multiple digital twins can be connected to an asset via a shared asset twin. These multiple digital twins may at least partially have different purposes or aspects. Therefore, a system can connect different digital twins to a single asset, thereby covering better functional bandwidth without adapting the asset to multiple digital twin connections.
[0024] In another implementation, the method and system include establishing at least one digital twin in an external environment (e.g., but not limited to the cloud, the internet, a corporate on-premises data center, or a web server), with the industrial automation environment protected by a firewall relative to the external environment. Thus, the industrial environment can be protected in a manner where the external digital twin has access to it.
[0025] In one implementation, in cases where both the asset twin and at least one digital twin concurrently, conflictingly, or simultaneously access the same values, setpoints, parameters, or functions of an asset, access via the asset twin is given priority. Alternatively, or in an alternative solution, the method and system are adapted to employ or establish a policy engine for the asset twin or within the asset twin for rule-based access conflict resolution.
[0026] According to the present invention, the method and system include: authorization of at least one digital twin or other user or entity by asset twin verification to authorize access to the value, setpoint, parameters or functions of the asset (“user-based authorization”).
[0027] Asset twins control access via access privilege protocols. These protocols can be defined by user roles or based on the identity of a user or computer, which is associated with specific access permissions.
[0028] To enable fast and comprehensive data access, asset twins can directly access assets via industrial communication protocols and industrial data bus systems such as OPC / UA, Profinet, or Industrial Ethernet. Attached Figure Description
[0029] An example of the invention is shown in the accompanying drawings. In the drawings, Figure 1 This illustrates an abstract view of asset access based on existing technology. Figure 2 An abstract view of the system of the present invention is shown. Figure 3 An example table of conflict resolution rules is shown during the synchronization of concurrent access to the asset twin by both the digital twin and the local entity. Detailed Implementation
[0030] Figure 1This explains the current issues with accessing assets (e.g., PLCs in a shop floor). A single digital twin (shown on the right) can access the asset independently. Both internal (shop floor-based) and external users (“users” can be people or machines, e.g., HMI panels) are restricted to access via the digital twin, and their access is limited through authorization and authentication, including firewalls. As described above, security typically restricts what can and should be visible from the asset side. The connection between the asset and the digital twin is often provided due to IoT data flow requirements. Therefore, firewalls inspect data traffic between the source and destination. Access from a browser is typically blocked.
[0031] Figure 2 An abstract view of the system of the present invention is shown, in which the asset (e.g., PLC or other industrial automation equipment) in a shop floor or similar local industrial automation environment is on the left, and a public environment (e.g., cloud, internet) with one or more digital twins of the asset is on the right. Although only one digital twin is shown on the right, multiple digital twins can actually be coupled to a single asset. Advantageously, each digital twin is customized for a limited number of functions (such as HMI, control parameter calculation, simulation, alarms, predictive maintenance, or other functions). The automation environment (shop floor) and the public area (cloud, internet) are separated by a firewall.
[0032] Both asset twins and digital twins can be accessed by the same or different human users (administrators, general users) or machine users (e.g., other assets, computers, or HMI entities). IoT (“Internet of Things”) values are attributes of sensors that are part of an asset or other “read-only” data connected to the asset or an asset, or controlled processes or automated environments. Setpoints or values are process parameters stored in an asset that affect controlled processes or automated entities. These parameters can be changed through internal software functions or external access, especially through asset twins. Asset values held in an asset twin have a shadow in the digital twin (expected asset values, reported asset values) and can be rewritten from the digital twin in the form of value targets (e.g., a temperature value can be set to an expected temperature, and that target temperature can be reported to the asset twin, and the asset twin can create new setpoints for the asset to achieve the target temperature). Twin attributes are internal parameters of each twin (asset twin, digital twin) and are part of the twin's internal operations; these can be accessed and changed externally.
[0033] Various parameters, such as twin attributes or asset values (or expected asset values), can be accessed / changed from different sites (e.g., local or remote users on the asset twin and digital twin). Therefore, concurrent access must be handled by the asset twin (or by an external service employed by the asset twin), especially for near-simultaneous conflicting write operations on the asset and digital twin (e.g., due to communication latency).
[0034] Figure 3 The table shown is an example of a conflict resolution rule. The first column indicates the affected parameter or function type (“Attribute”). The second and third columns describe the source of access (digital twin or asset twin). The last column describes the conflict resolution rule. Parameters or other “topics” can be tagged with meta-information to aid in decision-making during access control and access conflict resolution. For example, in the third row, the parameter type “Asset Value” has the meta-information “Twin Orchestrated”. This means that the asset twin is responsible for changes to parameters of this type. Note that definitions and meta-information can be applied not only to parameter types, functions, or other entities (defined as “Attributes” in the table) but also to definitions specific to a particular parameter. The table (or additional tables) can also contain information about which user (identity) or which type of user (role) can access the attribute, and the table can also define the type of access permission; access control is not specified in the table. Figure 3 As shown in the diagram. In this respect, access control can involve human user and / or machine / computer access.
Claims
1. A method for monitoring or controlling an asset of an industrial automation environment, wherein said asset being communicatively coupled with at least one digital twin, said digital twin receiving from said asset a value attribute on a value of said asset and transmitting a desired setpoint to said asset, said value and said setpoint being a process parameter of said asset or of the automation environment and affecting a controlled process or an automation entity, wherein a bidirectional communication between said asset and said at least one digital twin is at least partially routed via an asset twin, said asset twin being a service located in said industrial automation environment, said asset twin receiving values from said asset and forwarding these values to said at least one digital twin, said asset twin receiving setpoints or desired values from said at least one digital twin, checking access rights of these setpoints or desired values and / or consistency with other values, setpoints and / or attributes of said asset, and applying these desired values or setpoints to said asset, characterized in that an authorization of said at least one digital twin or of other users or entities to said asset twin is checked by said asset twin to grant access to values, setpoints, parameters or functions of said asset, and said access is controlled by said asset twin via an access privilege protocol, said access privilege protocol being based on a user or computer based identity, said identity being associated with a certain access right.
2. The method of claim 1, wherein, a plurality of digital twins is connected with said asset via a common asset twin.
3. The method of claim 2, wherein, said plurality of digital twins is at least partially arranged such that each digital twin has a different purpose or a different aspect.
4. The method according to any of the preceding claims, characterized in that said at least one digital twin is established in an external environment, preferably in a cloud, the internet, a company local data center or a web server, said industrial automation environment is firewall protected with respect to said external environment.
5. The method according to any of the preceding claims, characterized in that, in case of a concurrent, conflicting or simultaneous access of said asset twin and said at least one digital twin to the same value, setpoint, parameter or function of said asset, the access via said asset twin is prioritized.
6. The method according to any of the preceding claims, characterized in that, a policy engine is established for said asset twin or in said asset twin for a rule based access conflict resolution.
7. The method according to any of the preceding claims, characterized in that said access privilege protocol is based on a user role definition. The method according to any of the preceding claims, characterized in that said asset twin directly accesses said asset via an industrial communication protocol.
8. A system for monitoring or controlling an asset of an industrial automation environment, wherein, said asset being communicatively coupled with at least one digital twin, said digital twin being arranged for receiving from said asset a value attribute on a value of said asset and transmitting a desired setpoint to said asset, said value and said setpoint being a process parameter of said asset or of the automation environment and affecting a controlled process or an automation entity, wherein a bidirectional communication channel between said asset and said at least one digital twin, said communication channel being at least partially routed via an asset twin, said asset twin being a service located in said industrial automation environment, The asset twin is configured to receive values from the asset and to forward these values to the at least one digital twin, The asset twin is configured to receive setpoints or desired values from the at least one digital twin, to check access rights to these setpoints or desired values and consistency with other values, setpoints and / or properties and / or functions of the asset, and to apply these desired values or setpoints to the asset, characterized in that The asset twin is configured for authorization of the at least one digital twin or other users or entities to grant access to values, setpoints, parameters or functions of the asset, and The asset twin is configured to control access via an access privilege protocol that is based on the identity of a user or computer, which is associated with specific access rights.
9. The system of claim 8, wherein, The at least one digital twin and the asset twin each have an interface that is accessed by a user and / or by a computer-based entity, which has write access to at least one value, setpoint, parameter or function of the asset, the asset twin is configured to check and coordinate concurrent write access to at least one value, setpoint, parameter or function of the asset, in particular for quasi-simultaneous conflicting write operations on the asset and the digital twin, for example caused by communication latencies.
Citation Information
Patent Citations
Connectivity to an industrial information hub
EP3971666A1
Digital twin for control tower and enterprise management platform managing entity replicas and e-commerce systems
US20220051171A1
Energy industry metaverse digital twin cloud rendering dynamic allocation method and system
CN114020474A
Connection to industrial information center
CN114257609A
Multi-concurrent execution method for digital twin industry cloud rendering service
CN115914338A