Process automation system with secure interface
By verifying and verifying the security interface system and its rationality, the security and integration issues of remote control in industrial automation systems are resolved, realizing the security and flexibility of remote process control and supporting the automation control of multiple factories and the integration of advanced IT systems.
Patent Information
- Application Number
- CN202480031595.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2023-05-10
- Filing Date
- 2024-05-07
- Publication Date
- 2026-03-17
AI Technical Summary
Existing industrial automation systems struggle to integrate new technologies such as IoT, mobile devices, cloud computing, remote control, and VR/AR applications, and security issues exist, leading to the prohibition of remote control and ineffective integration with the overall IT system, thus impacting production efficiency and safety.
A secure interface system was designed that allows remote users to request machine operation through wearable devices. After verification and reasonableness checks through the secure interface, control parameters are stored and the operation is performed only with the consent of the local user, ensuring system security and flexibility.
It achieves security and flexibility in remote process control, reduces latency, supports automated control across multiple plants and integration with advanced IT systems, and improves fine-grained control and safety in the production process.
Smart Images

Figure CN121693707A_ABST
Abstract
Description
[0001] describe Technical Field
[0002] This invention relates to industrial automation systems, and more particularly to systems and methods for safely controlling automated manufacturing processes. Background Technology
[0003] EP 3 318 945 A2 discloses an industrial automation system for controlling automated manufacturing processes. The automation system specifically includes an industrial visualization system. This industrial visualization system generates virtual reality (VR) and augmented reality (AR) representations of industrial facilities and delivers them to wearable devices to facilitate remote or augmented interaction with automated systems within the facility. The VR representation can include a three-dimensional (3D) holographic view of the factory facility or a location within the facility. The system can selectively render a scaled-down view, rendering the facility as a 3D scale model, or a first-person view, rendering the facility as a full-size rendering simulating the user's presence on the factory floor. Camera icons rendered in the VR representation can be selected to switch to a live video stream generated by 360-degree cameras within the factory. The system can also render a workflow representation that guides the user through the process of correcting detected maintenance problems.
[0004] To address these and other issues, one or more embodiments of this disclosure provide a system that generates augmented reality (AR) or virtual reality (VR) presentations (collectively referred to herein as “VR / AR presentations”) and delivers them to a user via a wearable computer or other client device. The VR / AR presentations generated by the system may include a three-dimensional (3D) holographic view of a factory facility or location within a factory facility (e.g., a work area, production line, etc.). The holographic view may be delivered to a wearable visualization computer, which renders the 3D view based on the user’s current location and / or orientation. The system may render a scaled-down view of the factory floor area, providing the user with an external overview of the area. This external view may include real-time avatars representing human operators, overlaid production statistics and status data, and other information. Based on user input, the system can switch from this external view to an internal view, which renders a realistic representation of the factory floor area from the perspective of a person standing in the environment. This internal view may include overlaid operational and status data placed on or near a representation of relevant industrial equipment or control panels.
[0005] To date, remote factory control has been largely prohibited due to the potential risks associated with proper factory automation. Tasks performed "inside" and "outside" the factory are separated through mandatory manual activity.
[0006] For example, automation structures described by the Purdue reference model, and especially those used in traditional automation systems, have been in use for many years and have demonstrated operational reliability. However, these systems lack openness and flexibility—new technologies (IoT, mobile devices, cloud computing, remote control, VR and AR applications, etc.) are difficult or impossible to integrate, and are costly.
[0007] Integrating existing hardware-based automation technologies into a globally networked system has proven particularly problematic. Trained experts perform extensive setup work on the machines in the field. Incorrect settings, whether intentional or unintentional, can lead to substandard products, damage to individual machines, entire production plants, or even injuries to employees.
[0008] To prevent erroneous operations in the factory caused by external systems, users, and / or targeted hacking attacks, these systems have implemented security measures to disable the execution of remote control commands or significantly increase their complexity. Therefore, these automation systems cannot be fully integrated into the larger global IT system. Summary of the Invention
[0009] The object of this invention is to provide an improved system and corresponding method for process automation in a manufacturing plant, as specified in the independent claims. Embodiments of the invention are given in the dependent claims. These embodiments may be freely combined with each other unless they are mutually exclusive.
[0010] In one aspect, the present invention relates to a system for process automation in a manufacturing plant. The system includes: - Multiple machines in a manufacturing plant; - Factory machine database, which includes control parameters for the machines; - An automation system that automatically operates the machines in a manufacturing plant based on control parameters in a factory machine database; - Identity provider, which includes user profiles of the following: ○ Multiple remote users not located in the manufacturing plant, and ○ Multiple local users located in the manufacturing plant, - A visualization engine configured to create augmented reality for local users and virtual reality, including digital twins of factories, for remote users; - Security interface (142), which is configured for: ○ Receive a request from one of the remote users (108) to operate at least one of the machines. ○ The visualization engine generates an acceptance request, which is a signal prompting a local user (146) to accept the requested operation of at least one of the machines via augmented reality glasses worn by one of the local users. ○ Only when a request is accepted by a local user will the control parameters (402-408) included in and / or derived from the received request be stored in the factory machine database. The automation system is configured to perform automatic operations of the machine based on stored control parameters included in or derived from the accepted request.
[0011] According to the implementation scheme, the safety interface is configured to verify requests and store control parameters in the factory machine database only if the verification returns a valid request. More specifically, the safety interface can be configured to receive requests, verify requests, and, in response to determining that a request is valid, store control parameters included in or derived from the request in the factory machine database. The automation system can be configured to perform automated operation of the machines based on the stored control parameters included in or derived from a valid request. For example, a request could be a request to start, stop, or modify the operation of one or more machines. Requests can be received from clients via a network (e.g., the Internet).
[0012] This invention can provide existing and new factories with the possibility of effectively linking existing core automation systems with advanced IT systems used for monitoring, optimization, and control tasks, thereby enabling client devices or users to send requests via a network to a secure interface to operate one or more machines in the factory after successful request verification.
[0013] A secure interface can be one-way, meaning it allows machine-related data (e.g., machine-related control parameters) to be transferred from the client to the automation system via a request, but does not allow machine-related data to be returned to the client that submitted the request. This improves security because the client will not receive any information about the type or status of the machine whose operational status was modified in response to the request. The client will also not receive any information about the number of machines affected by the request, or any reason why the request could not be executed. According to some implementations, a one-way secure interface does not return any request-related feedback to the client other than information on whether the request was successfully executed. On another advantage, a secure interface can act as a secure and controlled access interface that supports request-based data ingestion from external sources to the automation system without compromising integrity and plant security.
[0014] According to the implementation scheme, request verification includes performing a reasonableness check, which involves determining whether the control parameters included in or derived from the request are safe for the machine and human operators. If at least one of the control parameters is determined to be unsafe, the request is considered invalid. In other words, it can be checked whether the control parameters included in or derived from the request are reasonable. Only when the reasonableness check returns that the request is reasonable can the request be considered a verified valid request. For example, the safety interface can be configured to verify requests, for example, by performing a reasonableness check to check whether the control parameters included in and / or derived from the request are reasonable. The safety interface can also be configured to store the control parameters included in and / or derived from the received request in a plant machine database only if the request is successfully verified as a valid (e.g., reasonable) request. This can further enhance the security of remote process control: if the safety interface determines, for example, that the temperature of the reaction mixture is set to a value that would damage the tank wall, the safety interface can consider the request invalid. Request verification can be implemented, for example, based on configurable rules and / or based on a combination of actions of a first and second submodule of the safety interface, as described herein with respect to various implementation schemes and examples.
[0015] For example, a rationality check may include checking whether the operation of one or more machines (for the product to be produced, for the machines and the workers) according to control parameters is preserved and will likely allow the production of a product with the desired properties. For example, a rationality check may include determining whether the control parameter values specified in or derived from the request are within a predefined range of permissible parameter values, and / or predicting (e.g., simulating) whether a process performed by one of the machines according to the control parameters will produce a product with product properties, such as product size, quantity, purity, shape, color, elasticity, viscosity, etc., within the permissible or preferred parameter value range. If the control parameters set the temperature of the can's heating element to a temperature that would damage the can's material or its components, the safety interface may consider the request unreasonable. Only when the check returns that the request is valid can the safety interface store the control parameters in the plant machine database, thereby modifying how the machines will operate.
[0016] A factory machine database may include control parameters for one or more machines, where control parameters are or include control parameters, and an automation system automatically operates the machines by setting the control parameters in the factory machine database to control parameter values provided with or derived from a request. Furthermore, the factory machine database may include models (e.g., structural models, such as simplified or realistic 3D models), location information, and status information of the machines and / or products produced by the machines, where the location information is continuously updated to reflect the actual location and status of the machines and / or products. Models, location information, and / or status information, or portions thereof, may be used to generate digital twins of the machines and / or objects manufactured or processed by the machines. For example, a digital twin of a corresponding machine in a machine database may be used to graphically represent the machine via its digital twin and / or to simulate the operation of the machine and / or to control the machine via its digital twin.
[0017] According to the implementation scheme, the safety interface is configured to map control parameters included in or derived from the request to additional control parameters included in the factory machine database to expand the control parameters. The safety interface is configured to perform a reasonableness check on the additional control parameters, which includes a check to determine whether the additional control parameters are safe for the machine and human operators. The request is considered invalid if at least one of the additional control parameters is determined to be unsafe.
[0018] The disclosed systems and methods can be advantageously used to control the operation of one or more machines within an automated system based on control parameters generated outside the automated system (e.g., generated by a client device that has already generated a request or input into a client device). These control parameters can be setpoints, i.e., parameters that can be set before and / or during machine operation and define how the machine operates. In this regard, the disclosed systems and methods can have the advantages of enabling remote process control of machines within an automated system without compromising safety, and this allows for faster and more granular process control: Typically, in the process industry, a local plant operator operating near the machine's physical location sets control parameter values for one or more machines in an automated system. For example, in a conventional process automation system, he or she might input control parameters via a local machine interface. The input control parameters may have been suggested by a customer or another human or non-human user who is not part of the automated system (and therefore considered less trustworthy than the local operator). By manually inputting control parameters suggested by a remote, advanced process control system, the local operator ensures that only validated external data is received within the automated system. However, the number of control parameters that human operators can understand and manually input is limited, and especially for complex manufacturing processes with multiple interdependencies, even skilled local users may not be able to take into account the relevant contextual information.
[0019] On the other hand, the systems and methods disclosed herein advantageously allow users or clients outside the automation system (e.g., clients hosting advanced process control systems or other client software not part of the automation system) to generate and submit requests including control data. Verification of these requests ensures that control parameters will not damage machines, reduce product quality, and / or harm people working near the relevant machines. Furthermore, the request verification implemented according to embodiments of the invention allows for greater complexity in the reasonableness checks of control parameters and allows for the processing and evaluation of requests at a high frequency, thereby providing more granular control over the automation process.
[0020] Therefore, the system disclosed herein may include a client configured to generate requests and submit them, for example, via a network such as the Internet, to a secure interface. Thus, the client that has generated requests may be configured to repeatedly generate and submit requests, specifically at least once per hour, preferably at least once per minute, preferably at least once per second, and in some embodiments at least once every 0.10 seconds. Each request may include one or more control parameters for controlling the operation of one or more machines in the machine. Furthermore, requests may be automatically generated and submitted by client software, whereby the control parameters specified in the requests are also dynamically calculated by the client software. Thus, verification of the requests may be repeatedly performed by the secure interface, specifically at least once per hour, preferably at least once per minute, preferably at least once per second, and in some embodiments at least once every 0.10 seconds.
[0021] The aforementioned client can be configured to repeatedly predict one or more control parameter values that are optimal or suitable for the operation of one or more machines in the control system, such that at least one feature of the automated production process performed by one or more machines is optimized, and to automatically and repeatedly submit requests to a security interface including one or more predicted control parameters, wherein, in particular, the prediction of control parameter values includes simulating the automated production process and the operation of one or more machines involved in the automated production process.
[0022] For example, client software can be configured to simulate a production process or its components, and identify control parameters suitable for optimizing the production process or ensuring safety or good product quality. Possible optimization criteria could include reductions in energy or material consumption, waste reduction, improved product quality or purity, the presence of desired characteristics, or product properties or process parameter values falling within desired ranges.
[0023] To provide a more concrete example, a manufacturing plant PA may include multiple machines and tanks configured to perform a continuous chemical synthesis workflow to continuously produce two products, A and B, whose relative proportions can be strongly dependent on process parameters, such as the temperature in the reaction mixture. Product A can be used as a precipitate in a different synthesis workflow to synthesize substance E in a different plant PE. Product B can be used as a precipitate in another synthesis workflow to produce substance F in another plant PF. The demand for A or B may depend on the demand for substances E and F. Because these products are synthesized in different plants, the machines in plants PA, PE, and PF are not part of the same automated system, making automated integration of synthesis workflows across different plants impractical to date. Fine-grained control is also impractical because human operators must manually set the temperature of the synthesis workflow in plant PA to a value suitable for producing proportions of products A and B that meet the demands of the final products E and F. This is associated with significant latency and prevents real-time synchronization of industrial manufacturing processes across distributed plants. By using secure interfaces and request authentication, manufacturing processes can be synchronized, minimizing latency. Requests can be generated automatically and frequently by a client that includes or belongs to an advanced process control system that integrates the requirements, needs, and available resources of multiple heterogeneous distributed factories.
[0024] Therefore, the systems and methods disclosed herein can advantageously support fully automated control of one or more plants, as well as the integration of process control in one or more plants into advanced process control systems. Latency can be significantly reduced without compromising safety.
[0025] The system disclosed herein can also be configured to use a secure interface as a single entry point into the automated system. The secure interface can be configured to receive and verify requests submitted by one or more different clients, such as advanced process control systems, edge computing systems, or remote operators using virtual reality glasses and / or mobile devices (e.g., smartphones), for remote control of the manufacturing process.
[0026] The systems for process automation disclosed herein may also include multi-level system architectures. A multi-level system architecture may include at least: - Level 1, which includes one or more machines and, optionally, additional objects involved in sensing and manipulating physical objects during the actual physical process, particularly during automated production workflows; - Level 2 (L2) includes components for supervising, monitoring, and / or controlling the physical processes of Level 1; the process control level includes equipment for controlling the entire process within the automated system; and - Level 3 (L3) includes a manufacturing operating system component configured to manage the production workflow to produce the desired product by supervising, monitoring, and / or controlling the components of Level 2. Level 3 is also known as the operational control level that supports the management of the production workflow, such as, for example, a manufacturing operations management system.
[0027] The first and second submodules of the security interface described above (which may belong to L3 and L2 layers, respectively) may include functions that are functionally complementary and have similar or identical structures (e.g., similar or identical number and types of input and output command-line arguments). Requests disclosed herein received by the security interface may be or include calls to one or more such functions.
[0028] The first submodule of the security interface described above may be part of the third level (L3), while the second submodule of the security interface may be part of the second level (L2): the components of the second level may be protected from the third level and higher-level components by at least one security means, particularly a firewall.
[0029] For example, the multi-level system architecture for process automation can be implemented based on a typical automation pyramid model (e.g., the Purdue reference model or other similar automation pyramid models).
[0030] In this multi-level system architecture, the security interface disclosed herein may include one or more software programs and / or software services that act as an interface between the automation system (and therefore also the automation system level of the automation system pyramid, "level L2") and components at level L3 of the automation system pyramid structure. Embodiments of the present invention allow for the implementation of a security interface on top of existing automation systems, thereby preferably enabling request-based (and optionally remote) control of the automation system without requiring adaptation to existing automation systems. Requests are checked and verified, and only valid requests for control parameters are forwarded to and stored in the automation system's factory machine database. This protects the automation system and the manufacturing plant from hacking and from requests that set critical control parameters to values that could have negative or even harmful consequences for the machines in the plant or for the entire manufacturing plant.
[0031] For example, a request may be generated by a remote client, thereby being transmitted via a network such as the Internet to a system according to an embodiment of the invention. A secure interface may receive the request via one or more intermediate interfaces or modules (e.g., service interfaces). In some embodiments, the request is generated by a remote user via a metaworld engine, for example, by setting one or more control parameters of the machine to control the operation of one or more machines within the machine.
[0032] The security interface disclosed herein can also be configured to enable the secure one-way transmission of at least control parameters to the automation system via a control communication channel, and to prevent the transmission of any machine-related control parameters or status information back to the client that has submitted the request.
[0033] According to some examples, the second submodule of the safety interface includes machine-specific functions, each configured to control the operation of one or more machines based on one or more control parameters from a factory machine database. The number and type of input command-line arguments and the number and type of output control commands of the one or more machine-specific functions at least partially correspond to the control interface of the machine controlled by the corresponding machine-specific function. For example, the structure of the one or more machine-specific functions is at least partially identical to the corresponding function of the machine's control interface.
[0034] The first submodule of the security interface includes one or more generic functions. Each generic function is assigned to a corresponding machine-specific function within the machine-specific functions. The first submodule of the interface receives a request to trigger the execution of at least one generic function, and upon successful execution of that at least one generic function, triggers the execution of one or more machine-specific functions, which are assigned to the at least one generic function being executed. For example, the structure of the one or more generic functions is at least partially the same as the machine-specific function called by the corresponding generic function.
[0035] As used herein, a "generic function" is a function that does not include or depends on knowledge of the technical characteristics of a machine, such as its manufacturer, type, current status, orientation, etc. For example, the generic function "Operate centrifuge (INT revolutions per minute, FLOAT temperature)" could be a generic function that expects the control parameters "revolutions per minute" and "(centrifuge) temperature" as input parameters. While a generic function may not include indexing for any particular type of centrifuge, calling such a function can trigger the execution of a rule that checks whether the specified revolutions per minute and temperature values are reasonable, regardless of the specific properties of a particular centrifuge. For example, if the temperature is higher than the boiling point of the liquid to be centrifuged, that temperature could be considered unreasonable without considering any details of the centrifuge being used. If the reasonableness check triggered by executing the generic function "Operate centrifuge" returns that the command-line parameters are reasonable, then a machine-specific function with the same structure can be called. Machine-specific functions may include or be configured to read machine-specific properties, such as the maximum revolutions per minute (RPM) and the highest (or lowest) temperature supported by the centrifuge to be operated. Execution of a machine-specific function may involve performing a reasonableness check to verify that the control parameters provided as command-line arguments are supported by the specific centrifuge. Machine-specific functions may have the same structure as calls to general functions, such as "operate centrifuge (INT RPM, FLOAT temperature)".
[0036] According to another example, the request may include control parameters instructing that the reaction mixture of the chemical reaction should be set to 120°C to trigger the formation of the desired substance. Receipt of this request by a first submodule of the safety interface may trigger the execution of a first general function that performs a rationality check to determine if the current energy price is below a predefined threshold. If so, the first general function returns that heating the reaction mixture to 120°C is valid and should be permitted. As a result of the successful rationality test performed by the first general function, the first submodule causes a second submodule of the safety interface to trigger the execution of a first machine-specific function, to which the first general function is assigned. The first machine-specific function checks whether the reaction vessel containing the reaction mixture allows the chemical reaction to proceed at that temperature. For example, this check may include verifying whether the vessel material is sufficiently robust and whether the heating element is strong enough to support a temperature of 120°C. If so, the second submodule of the safety interface will cause the heating element of the vessel to heat the reaction mixture to 120°C. If the first general function returns that the current energy price is above the predefined threshold, the first submodule may return via a feedback channel that the request cannot be executed and the execution of the first machine-specific function is not triggered.
[0037] According to some examples, the first part of the verification request is executed by at least one general function, and the second part of the verification request is executed by one or more machine-specific functions assigned to the at least one general function being executed.
[0038] This can have the advantage of allowing the execution of justification checks on criteria that can be evaluated at L3 level, as well as on criteria related to more sensitive machine-related criteria, which may involve sensitive machine parameters and state information that should not be disclosed for security reasons. Another advantage is that the two-step implementation of request verification reduces CPU and memory consumption, since the machine-specific function is only executed if the associated first function has already returned a valid request. Therefore, the general and machine-specific functions assigned to each other are functionally complementary, providing a single function, specifically a justification check function, that covers both L3 and L2 aspects of the automation system.
[0039] According to some examples, the system includes a function synchronization module configured to: automatically determine if the number or type of input command-line arguments required by a machine-specific function in a machine-specific function, or the number or type of output command-line arguments provided by a machine-specific function in a machine-specific function, changes, and automatically copy the change to a general function assigned to the changed machine-specific function, such that the input and output command-line arguments of the general function also reflect the change.
[0040] This offers the following advantages: the specific implementation of request verification is transparent. Function calls to L2-level machines and / or components of the system used for process automation, implemented by machine-specific functions, are represented via structurally identical generic functions and are "visible" to the client or service interface. Therefore, the structure of the generic functions exposed to the client or service interface (the type and number of input and / or output command-line arguments and / or function names) is identical to that of the machine-specific functions. Implementing request verification by two different submodules using the generic and machine-specific functions specified above decouples L2-level automation machines and components from L3-level components and systems outside the plant, thereby ensuring that inbound requests are forwarded only if the request has been successfully verified as legitimate (and preferably, if the requesting client can successfully authenticate at the ID-providing module).
[0041] On another beneficial side, when a machine is replaced by a different version, any modifications to the structure of machine-specific functions that may need to adapt to the system are automatically propagated to generic functions. This ensures that function interfaces automatically remain synchronized and avoids errors caused by incompatible function calls.
[0042] Optionally, the safety interface can be configured to receive feedback data from the automation system via a feedback communication channel, which is a communication channel separate from the control channel.
[0043] For example, a security interface may completely lack any option to receive data from an automated system and / or forward that data to a client.
[0044] In some implementations, a separate communication channel, referred to as a feedback channel, may exist to transmit feedback information indicating whether a request is executed or rejected.
[0045] For example, feedback information can be transmitted from the machine to a service interface (between the security interface and the factory machine database) via a database service interface, which then forwards the feedback data to the client that has submitted the request. Furthermore, the security module may include an interface for receiving feedback information from the automation system, and / or a feedback channel may be used to notify the client whether the request has been successfully validated and executed.
[0046] Preferably, the feedback channel for transmitting feedback data from the automation system or security interface to the client is technically separate from the unidirectional control channel for forwarding requested control parameters from the client / service interface to the automation system via the security interface.
[0047] This offers the advantage that even if the feedback channel is compromised due to malware or hacking, the communication channel for processing and forwarding requests, provided by the secure interface, remains unaffected. Therefore, using separate communication channels for feedback data and request-based control parameters (which act as control data) ensures that typically non-critical feedback data can be easily distributed to one or more receivers via the feedback channel. The feedback channel can be a communication connection with a lower level of data security and integrity than the communication channel provided by the secure interface for control parameters. This facilitates the propagation of feedback data while maintaining a highly secure communication channel for configuration data. For example, different encryption techniques can be used for different channels to ensure the integrity of data transmitted via the respective channels.
[0048] The verification of requests disclosed herein can be repeatedly performed by a secure interface. Specifically, verification can be performed at a frequency of at least once per hour or at least once per minute, preferably at least once per second, and in some embodiments at least once every 0.10 seconds.
[0049] This can be beneficial because it allows the security interface to provide fine-grained control over the manufacturing process, which can be adapted very quickly to changing requirements and / or changing production goals. For example, validation could include testing whether one or more control parameters provided by a request received at 12:00 remain reasonable under given environmental parameters at 12:05, 12:10, ..., 13:05, 13:10, etc. For instance, a manufacturing plant could control a chemical reaction in which specific chemicals are produced in a reaction that can occur in a temperature range preferably from 30°C to 60°C, whereby the purity of the product decreases with temperature. Continuous monitoring of product purity is possible. A request received at 14:00 could instruct that the chemical reaction should be performed at 45°C instead of 40°C to increase the speed of the manufacturing process, while other control parameters in the request could specify that the product purity should be at least 80%. The service interface could assess at 14:00 upon receiving the request whether the desired purity can be achieved at the reaction temperature of 45°C, and if so, the temperature could be increased accordingly. For example, after successfully completing the rationality check, the new reaction temperature of 45°C can be stored in the plant machine database and used by the heating element of the reaction vessel to heat the reaction mixture to the indicated temperature. Due to various reasons, the purity of the ongoing reaction may decrease significantly until 14:35. This can be measured by sensor devices in the reaction vessel and transmitted to the safety interface via a feedback channel. When the safety interface re-verifies the request (which it received at 14:00) at 14:35, it can determine that the desired 45°C and currently set temperature may not provide a product with at least 80% purity (given the currently measured purity data). In this case, the safety interface can autonomously modify the control parameters provided in the request, for example, reducing the temperature from 45°C to 40°C, and storing the new temperature instead of the old temperature in the plant machine database. Additionally or alternatively, the safety interface can issue a message and return it to the entity that submitted the request. This message may include notification that the requested temperature value is no longer valid and has been replaced by a different temperature value better suited to achieving optimization objectives (e.g., product purity). In other implementations, the notification may simply include an indication that the request has been rejected or that the value of the corresponding control parameter in the factory machine database is no longer available.
[0050] It should be noted that if some of the requested control parameters remain valid / acceptable in terms of process safety, product quality, cost, or other optimization criteria, then performing multiple consecutive checks per minute or even per second is not feasible for a human operator. Therefore, embodiments of the present invention allow automated systems to react immediately to changing production conditions and changing requirements, thereby reacting faster and more accurately than automated systems that rely on additional manual quality testing of the production process.
[0051] The security interface disclosed herein can be configured to count the number of requests received within a predefined time interval (e.g., within an hour, or within minutes or seconds). If the number of requests changing a given control parameter exceeds a predefined maximum request threshold, any further requests changing that control parameter can be rejected, at least until a predefined time has elapsed. This can provide protection against denial-of-service (DoS) attacks and can also protect the machine from wear and tear, as changes to some parameter values may trigger movement of the machine's mechanical parts, and therefore it may be preferable to limit the number of times machine parts move to a maximum value.
[0052] The automation systems disclosed herein may include programmable logic controllers (PLCs) configured to control one or more manufacturing processes performed by machines in a factory. A PLC may be, for example, an industrial computer that has been enhanced and is suitable for controlling manufacturing processes such as assembly lines, machines, robotic arms, or any activity requiring high reliability, ease of programming, and process fault diagnosis. This PLC can operate in a program scan cycle, repeatedly executing its program within that cycle. The simplest scan cycle can consist of three steps: reading inputs, executing the program, and writing outputs. The program may follow a sequence of instructions. The processor may typically spend tens of milliseconds evaluating all instructions and updating the state of all outputs.
[0053] It must be mentioned that most PLCs lack strict access control and version control systems. This allows unauthorized changes to the program to go unnoticed. Therefore, for security reasons, remote control of automation systems, especially those comprising one or more PLCs, is generally prohibited.
[0054] The system for process automation disclosed herein advantageously allows for the remote control of the automation system to be enabled in a cost-effective manner because the security interface verifies each request and only forwards control parameters for those requests that have been verified as valid. According to a preferred embodiment, the entity submitting the request must be successfully authenticated at the system. If authentication fails, the request is not even forwarded to the security interface. Therefore, the system according to an embodiment of the invention guarantees that only requests from authenticated, trusted entities that include verified, valid control parameters will be propagated to and stored in the factory machine database, which is the fundamental means of controlling the operation of machines in a manufacturing plant.
[0055] According to the method for verifying a request disclosed herein, verifying a request may include performing a reasonableness check. Performing a reasonableness check includes checking whether control parameters included in or derived from the request meet one or more criteria selected from the group consisting of: - The value of the control parameter can be achieved by one or more machines that are to operate according to the stored control parameter; for example, if the control parameter sets the pressure to be generated in a given tank to a value that the corresponding pump used to generate the desired pressure cannot reach, the request will be considered invalid; and / or - The value of the control parameter is safe for one or more machines to be operated according to the stored control parameter; for example, if the control parameter is to set the pressure to be generated in a given tank to a value that the corresponding pump can reach but would pose a safety risk, such as because it exceeds the maximum pressure limit considered safe, then the request would be considered invalid; and / or - The values of the control parameters are appropriate to provide manufactured products that meet quality standards; for example, if the control parameters are set to produce a pressure in a given tank that is within a range of pressures known to result in poor product quality, the request will be considered invalid.
[0056] Verification requests may also include checking whether the control parameters included in the request meet two or more of the criteria described above, and optionally, whether the parameters meet additional criteria related to manufacturing process time, material costs, energy consumption, etc., that can be associated with a given control parameter. Verification requests may be rule-based and may include evaluating the control parameters using one or more global machine-agnostic and / or plant-agnostic rules and / or using one or more machine-specific or plant-specific rules. Furthermore or alternatively, verification of control parameters may include performing complex computational tasks. For example, predictive models (e.g., machine learning models such as support vector machines or neural networks) may be used to simulate the manufacturing process or its individual steps during production under the assumption of the control parameters specified in the request, and to check whether the predicted / simulated manufacturing process meets one or more criteria related to safety, efficiency, cost, and / or product quality.
[0057] It must be mentioned that a machine that performs its automated operation based on stored control parameters included in or derived from a valid request can be a robot, specifically a robot controlled by a remote user via a visualization engine. Furthermore, the machine performing its automated operation based on stored control parameters included in or derived from a valid request, and / or another machine in the manufacturing plant, can include a local control interface that allows a local operator to access and control the machine via a separate local communication channel. For example, the local interface could be a display screen of one of the machines.
[0058] The system disclosed herein may include a service interface. The service interface can be configured to receive requests from clients and forward them to a secure interface. The secure interface can thus be configured to receive requests only from the service interface. This further enhances security because the secure interface does not receive requests directly from clients. Instead, the secure interface is shielded from direct contact with clients via the service interface. This ensures that only requests that have been processed and actively forwarded by the service interface to the client interface will be processed and verified by the secure interface. In another advantageous aspect, this allows the service interface to be implemented as an interface easily accessible to a variety of different clients. For example, the service interface may include multiple different web services suitable for different types of clients, such as remote users using VR glasses to submit requests for controlling robots or other machines in a factory, remote client applications operated by clients of a company operating a factory, or edge computing systems. Each service can be customized for optimized interaction with the corresponding type of client. For example, each service may include a REST API, which enables clients to specify requests and submit them to the appropriate service.
[0059] The system disclosed herein may also include an ID provider module operatively coupled to the service interface. For example, the ID provider module may be an LDAP directory or other authentication system. The service interface is configured to: receive requests from at least one client; authenticate the at least one client; and, in response to the at least one client successfully authenticating at the service interface, forward the request to a security interface. If the at least one client fails to authenticate at the service interface, the service interface does not forward the request to the security interface. This also improves security because automated systems typically do not include authentication mechanisms. By requiring clients to successfully authenticate with the service interface in order to forward requests submitted by those clients to the security interface for verification by the security interface, the security of process automation systems can be significantly improved.
[0060] The security interface disclosed herein can also be configured to identify one or more additional control parameters whose values depend on the values of one or more control parameters specified in or derived from the request, and to replace at least one control parameter included in or derived from the request with the identified one or more additional control parameters, and / or supplement the control parameters included in or derived from the request with the identified one or more additional control parameters. The identified one or more additional control parameters can be stored in a factory machine database for use in controlling the operation of one or more machines (instead of or as a supplement to the control parameters originally included in or derived from the request).
[0061] The steps described above can also be referred to as a "parameter mapping" process. Identifying additional parameters can include analytical mappings, such as file or database records or any other form of data structure, that assign one or more control parameters to one or more additional control parameters. Mapping can, for example, involve mapping machine-agnostic (machine-independent) parameters such as temperature to machine-specific parameters, such as temperatures specified in a machine-specific temperature scale ranging from 0 to 5, rather than absolute temperatures specified in Kelvin or °C. The mapping process can also include more complex calculations of one or more additional control parameters. For example, the initially specified control parameter may be a desired product property, and the calculation of additional control parameters may include predicting one or more additional control parameters required to provide a product with the desired property and / or to provide a product with the desired property (see, for example, [link to relevant documentation]). Figure 4A and Figure 4B (Description).
[0062] Mapping control parameters can allow for an increase in the number of control parameters and / or mapping machine-agnostic parameters to machine-specific parameters. This can have the advantage of allowing remote clients (e.g., edge devices of clients wishing to monitor and / or control the manufacturing process of products already ordered by the client) to control and / or monitor the production process with client-specific control parameters without having to disclose too many details of the manufacturing plant, such as the type and number of machines used to manufacture the products. Embodiments of the present invention can enable owners of manufacturing plants to allow their clients to monitor and / or control the manufacturing process without the risk that clients might intentionally or unintentionally control the manufacturing process in a way that puts the plant and the employees working there at risk, and without the plant owner having to disclose sensitive details of the machines included in the manufacturing plant to the client.
[0063] According to one example, the control parameter initially specified in the request may be the desired temperature of the reaction vessel (a machine-agnostic parameter), and the other parameters identified may be the heating or cooling rate (a machine-specific control parameter or setpoint) to be set on a particular heater or cooling device of the vessel to achieve the desired temperature.
[0064] The security interface disclosed herein can also be configured to verify one or more additional control parameters identified, also known as verifying “mapped” control parameters. Verification may include performing a reasonableness check on the additional control parameters, wherein the reasonableness check includes checking whether the additional control parameters meet one or more criteria selected from the group consisting of: - The values of the additional control parameters identified can be implemented by one or more machines that are to operate according to the stored additional control parameters identified; and / or - The values of the additional control parameters identified are stored for one or more machines that are to operate according to the stored additional control parameters identified; and / or - The values of the additional control parameters identified are suitable for providing manufactured products that meet quality standards.
[0065] If one or more of the identified additional control parameters are determined to be invalid due to non-compliance with the criteria, neither the control parameters originally included in the request nor the additional identified control parameters are stored in the plant machine database. Instead, the request is considered invalid.
[0066] The system disclosed herein may also include a feedback interface configured to return request-related feedback information to a client that has submitted a request. This feedback information does not contain any control parameters or status information for one or more machines and only indicates whether the request was successfully executed. Providing a feedback channel separate from the communication channel used for forwarding configuration data can have advantages such as increased security (a compromised feedback channel will not affect the transmission of control parameters) and flexibility (the security measures for the feedback channel can be less stringent). Furthermore, the accuracy of request verification performed by the security interface can be improved, as the validity and reasonableness of the request can depend on the current and changing status of one or more machines in the manufacturing plant.
[0067] The security interfaces disclosed in this article can also be configured for: - Generate an acceptance request, which is configured to prompt an entity to accept the requested modification to one or more control parameters stored in the factory machine database; the entity may be, for example, a human user or a software program operating locally at the factory. - Provide the entity with an acceptance request; for example, a security interface may enable software (e.g., a visualization engine) to generate a message that prompts the local user for approval of the requested control action via AR glasses or via a display of a machine within the machine; - In response to receiving a response indicating acceptance from the entity, the execution will include or derive control parameters from the request and store them in the factory machine database.
[0068] Storing control parameters only in response to an entity's indication of acceptance of the proposed control parameters can have the advantage of improved security. Remote users may not have a full view of all processes taking place on the manufacturing line in the factory, so machine reconfiguration could negatively impact the product, the machine, the manufacturing process, or the personnel working in the factory, which may or can be better perceived by the local user. By requiring the local user to accept control commands in the form of modified control parameters provided by the remote client, the risk of such negative impacts can be reduced. The acceptance request can be generated by a second submodule of the security interface. The entity's response can then be transmitted back to the client and / or the second submodule of the security interface. In response to receiving a response indicating that the entity does not accept, the security interface can store the control parameters (included in or derived from the request) in the factory machine database.
[0069] The security interface disclosed herein may also include at least a first submodule and a second submodule. The first submodule is configured to perform a first part of the verification of the request, which uses general non-machine-specific and non-factory-specific rules. The second submodule is configured to perform a second part of the verification of the request, which uses machine-specific rules and / or factory-specific rules. The first submodule is part of level L3 of a multi-level automation pyramid, and the second submodule is part of level L2. For example, the first submodule is hosted on a computer system hosting level L3 components, and the second submodule is part of level L2.
[0070] According to some examples, the first submodule includes a first rule engine and multiple first functions, which are configured to trigger the execution of one or more non-machine-specific rules and non-factory-specific rules by the first rule engine. The second submodule includes a second rule engine and multiple second functions, which are configured to trigger the execution of one or more machine-specific rules and / or factory-specific rules by the second rule engine.
[0071] Using a security interface that includes two distinct submodules hosted on different computer systems and an automaton control level can increase system flexibility. For example, the second submodule can be defined or customized by a factory operator who has a better understanding of the details of the machines used in the specific factory. This simplifies the specification of factory-specific or machine-specific rules used to validate requests. The first submodule can be defined or customized by a user who may be familiar with the globally machine-agnostic and / or factory-agnostic aspects of the manufacturing workflow. Because the two submodules are instantiated and maintained separately, there is no need to allow factory operators to modify global machine-agnostic rules, and there is no need to allow L3 and higher-level automation control operators to modify the factory-specific or machine-specific rules of the second submodule. This improves security. Therefore, the second submodule only allows control parameters provided by the first submodule and does not accept or process control parameters provided by different software programs or requests including such control parameters.
[0072] It must be mentioned that requests submitted by the requesting client may also include one or more machine-agnostic function calls indicating steps in the manufacturing workflow to be performed. Therefore, the security interface can be configured to perform a mapping of machine-agnostic function calls to calls that can be interpreted by the control interfaces of the corresponding machines in the factory. If the request is deemed valid, the security interface will forward the mapped machine-specific function calls directly or preferably indirectly, for example, via a database service interface, to one or more machines configured to interpret and execute the machine-specific function calls.
[0073] The system disclosed herein may further include a first virtual machine and a second virtual machine, the first virtual machine being configured to host a first submodule of the security interface (and optionally additional components of the third level (L3) of the multi-level automation system architecture), and the second virtual machine being configured to host a second submodule of the security interface (and optionally additional components of the second level (L2) of the multi-level automation system architecture). The first and second virtual machines are hosted by different virtual machine hosts and / or separated from each other via firewalls. This strengthens the separation between tasks performed by the first submodule / L3 level of the security interface and tasks performed by the second submodule / L2 level of the multi-level automation system, thereby ensuring that any malware or other security issues that may exist in the L3 level cannot propagate to the typically more vulnerable L2 level and automation system. For example, the only supported means of data exchange between the L3 and L2 level components and the machines of the automation system may be a data communication channel provided by the security interface, namely a one-way channel for verifying requests with control parameters and forwarding them to the automation system, and a feedback channel for returning feedback information from the automation system to the client.
[0074] It must be mentioned that the first and second virtual machines can be implemented as containers. Using different virtual machines that can be implemented as containers ensures that the L2 component (which is the only component of the machine that can control the automation system) is strictly isolated from the outside world and exchanges data with the outside world only through defined and secure data exchange interfaces, especially with L3 level components.
[0075] The secure interface disclosed in this document can also be implemented as a DMZ or demilitarized zone (sometimes called a perimeter network or shielded subnet). A DMZ is a physical or logical subnet that contains an organization's externally-facing services and exposes them to an untrusted, typically larger network, such as the Internet. This adds an additional layer of security to processes executing within the secure interface: external network nodes can only access what is exposed in the DMZ / secure interface, while the remaining data and software programs executing within the DMZ / secure interface are protected behind a firewall. A DMZ serves as a small, isolated network between an external network, such as the Internet, and a dedicated internal network for IT resources. The specific implementation of the firewall, particularly the firewall between the secure interface and the service interface, ensures that the secure interface is a DMZ.
[0076] It must be mentioned that the request is generated by a remote client (e.g., a remote human user, remote client device, or client software), which connects to the system via a network (e.g., the Internet). Typically, the remote client is located far from the manufacturing plant. The secure interface serves as a remote control access path from the remote client to the automation system and the machines controlled by the automation system. This can have the advantages of providing a common entry point for clients (specifically users) at many different remote locations via the secure interface, and integrating (existing) automation systems into new and often more complex control software. The secure interface provides a remote control access path to the automation system and the machines controlled by the automation system.
[0077] It must also be mentioned that one or more machines controlled by the automation system disclosed herein may include a local access interface to enable local users and / or local robots to directly control the machines via a second (e.g., field-based) communication channel. This provides a high degree of flexibility, as both remote and local users can execute control functions on the respective machines. In some examples, the access and control permissions for remote and local users can differ from each other. For example, only (remote) expert users may be allowed to make changes to some control parameters, which can affect many machines and processes in the automation system. On the other hand, if only a local user is allowed to initiate certain operations, such as opening or closing a door, activating a press, etc., this could pose a safety risk if initiated only by a remote user who might not be aware that moving parts such as doors or presses could potentially hit people or damage objects blocking the way.
[0078] The system disclosed herein may also include a visualization engine configured to generate graphical representations of digital twins of the machines in a factory and / or the products manufactured by those machines. According to some examples, a request is submitted by a remote human user wearing virtual reality (VR) glasses operatively coupled to the visualization engine. The visualization engine visualizes at least some aspects of a manufacturing process performed by the machines via the VR glasses. For example, the visualization engine may enable a remote user wearing VR glasses to see one or more machines that he or she is currently attempting to reconfigure and control. Additionally or alternatively, the visualization engine is configured to create augmented reality for one or more local users wearing AR glasses and operating within the factory, the augmented reality including an avatar of the remote user and / or virtual graphical objects that assist in the maintenance or control of one or more machines. Furthermore, a robot operating locally in the factory may be controlled by the remote user and act as a physical representation of the remote user. When the remote user turns in a given direction, the local robot will follow that movement. The local robot may include one or more cameras, and images acquired by the robot's cameras are transmitted to the visualization engine and forwarded by the visualization engine to the remote user's VR glasses. Thus, the remote user can see what the robot can see via the VR glasses. This improves security because it allows remote users to perceive objects in the vicinity of one or more machines to be controlled by them. This allows remote users to identify any obstacles or other objects or events that could indicate whether a control command should not be submitted because it poses a safety risk to humans or components in the manufacturing plant, or vice versa. Control commands can be submitted as requests to modify one or more control parameters in the control parameters of one or more machines in the plant's machine database. The visualization engine can also support voicemail and / or chat between remote clients (as remote human users) and local users at the manufacturing plant wearing AR glasses. For example, a remote user can wear VR glasses, while a local user can wear AR glasses. Both VR and AR glasses can include microphones and audio output interfaces, such as speakers. Remote and local users can exchange real-time voice messages via their respective VR or AR glasses' microphones and speakers.
[0079] The aforementioned AR application can also be configured to control the volume of the audio output generated by the local user's AR glasses, such that the volume of the remote user's output voice is positively correlated with the spatial proximity of the local user and the position of the remote user's avatar in the coordinate system used by the AR glasses to display virtual objects. Alternatively, the VR application can be configured to control the volume of the audio output generated by the remote user's VR glasses, such that the volume of the local user's output voice is positively correlated with the spatial proximity of the remote user and the position of the local user's avatar in the coordinate system used by the VR glasses to display virtual objects.
[0080] The system disclosed herein may also include a factory environment database and a database replication module. The factory machine database may include models, location information, and status information of the machines and / or products produced by the machines. Location information may be continuously updated to reflect the actual location and status of the machines and / or products processed or produced by the machines. The database replication module may be configured to continuously replicate only a predefined subset of the data from the factory machine database to the factory environment database, thereby filtering out sensitive machine-related data. The factory machine database may be configured to prevent access by the visualization engine. The visualization engine may be configured to generate visual representations of the factory's machines and / or products processed by the machines using only the data included in the factory environment database.
[0081] Using two different databases as described above offers the advantage of enhanced security: the visualization engine continuously generates graphical representations of digital twins of the machines and / or objects involved in the automated production process, providing human users with a continuously updated overview of the process. The filtering functionality ensures that sensitive machine-related data (such as exact location, sensitive status parameters, or control parameters) is not exposed to Layer 3 or any other system outside the automation system. The database replication module only replicates the information needed to create a graphical representation of the machine or product—for example, a model with the same or similar structure as the machine, or a very abstract representation of the operations performed by the machine.
[0082] The graphical representation of a digital twin can be, for example, a conventional 2D representation of a machine and / or product, generated for display via a computer screen or smartphone screen. According to other examples, the graphical representation is a 3D representation to be displayed via VR or AR glasses, providing a 3D representation within a 3D coordinate system.
[0083] In another aspect, the present invention relates to the use of a system according to any one of the embodiments described herein for automating processes in a manufacturing plant.
[0084] In another aspect, the present invention relates to a method for automating processes in a manufacturing plant, the method comprising: - Provide systems for process automation in manufacturing plants, including: ○ Multiple machines in a manufacturing plant; ○ Factory machine database, which includes control parameters for the machines; ○ An automation system that automatically operates the machines in a manufacturing plant based on control parameters in a factory machine database; ○ Security interface; - Requests are received via a secure interface; - The request is verified by the security interface; - In response to confirming that the request is valid, the security interface stores the control parameters included in or derived from the request in the factory machine database; - The machine is operated automatically by the automation system based on the stored control parameters included in or derived from the valid request.
[0085] The automation system disclosed herein can be configured to perform automated operations of a machine based on stored control parameters included in or derived from an accepted request.
[0086] The combined use of AR and VR visualization technologies for safe operation in industrial production processes, as described in the above system, can be beneficial because it can significantly improve operational safety. Equipment and processes are increasingly being remotely controlled. However, this creates significant safety risks, especially in controlling industrial manufacturing processes: intentional or accidental input of incorrect or inappropriate control parameters can lead to poor product quality, high levels of waste, defective machinery, and in the worst case, even personal injury. Remote users often have limited knowledge of the process currently occurring in or at the machine. For example, a remote user may not know that a container is almost full and may add even more material, causing it to overflow. While the use of VR glasses improves the overview, the digital twin of the machine displayed to the remote user via VR glasses may have reduced detail. Furthermore, not all aspects important for assessing the overall situation (such as the presence of people near the machine (e.g., for maintenance purposes) or the presence of hazardous materials near the machine) can be fully captured by the plant's sensor systems and then displayed in the VR world by a visualization engine. However, local users typically have this overview. By providing a secure interface, damage to products, machines, and people can be prevented. This interface automatically prompts local users to approve control commands before executing any or at least potentially safety-critical control commands from remote users. Remote control of production processes, especially with the help of VR glasses, is significantly improved and made safer.
[0087] Remote users can be located in locations different from the factory, such as different cities or countries. The visualization engine can be configured to create a VR world that includes a visible digital twin of one or more machines in the factory or the entire factory. The digital twin can be a 2D or 3D representation of the machine and / or physical objects processed by the machine, such as a hologram, and can represent the current state of the factory. Typically, the visible digital twin is only a coarse-grained visual representation of real-world objects.
[0088] According to some implementations, the request is created by an action of a remote user, which is recognized as a control command by the VR glasses worn by the remote user. For example, a visualization engine can display a virtual object in the form of a control panel next to a visible digital twin representing one of the machines. The remote user can move a controller and press a button on the controller to select an item in the control panel. The selection of this item (e.g., a virtual button or menu element) can trigger the generation of a request to operate the machine represented by the visible digital twin. This request could, for example, instruct the machine to start or stop operation, to open or close a door, etc.
[0089] According to the implementation plan, the secure interface only generates an acceptance request if the request is successfully validated as valid. This reduces the CPU resources consumed by processing requests and also reduces network traffic, as the generation of virtual objects (e.g., windows prompting the user to accept the requested action) and the rendering of objects in the metaverse typically require significant CPU resources. Furthermore, prompting the local user to accept an inherently unreasonable or risky action could unnecessarily distract them from their normal work.
[0090] According to one implementation, the system includes an ID provider computer system configured to authenticate users who have submitted requests. In the event of authentication failure, another implementation involves a request to operate a robot located at a factory. In this case, if the user fails to authenticate as a client authorized to control a robot, the security interface will not store the control parameters in the factory machine database, and the request will be rejected.
[0091] The system disclosed herein may also include a VR system that enables a remote user to submit requests using the VR system and VR glasses, and enables the remote user to control at least one machine, such as a robot, only after successful authentication. This can have the advantage of providing a fully immersive metaverse, allowing a remote user to monitor and control an ongoing production process by submitting requests to operate one or more machines to the automation system using VR glasses and / or controllers or handles interoperable with the VR glasses.
[0092] According to the implementation scheme, the visualization system is configured to generate a visual representation of the remote user in the form of an avatar, and display the avatar to the local user via AR glasses worn by the local user. Preferably, the visualization engine also supports the exchange of voice and text messages between the remote user and the local user. This can have the advantage that the visualization engine provides communication options to both users if the local user needs more information to decide whether he or she should accept a request. Thus, the local user can have the impression of speaking to a real person, as the avatar is displayed as an overlay of a real-world factory environment via AR glasses. The local user wearing AR glasses can observe the VR user's avatar moving around the factory, so the VR user can collaborate, assist, instruct, and / or teach the AR user about processes in the factory (e.g., production or maintenance processes).
[0093] According to the implementation scheme, the system includes an update engine, a visualization database, and a replication module, wherein the visualization database comprises a subset of data from a factory machine database. The update engine is software configured to continuously receive spatial and / or status information of machines and / or objects processed by machines from multiple sensors during the ongoing manufacturing process, and continuously update the factory machine database using the received information. The replication module is software configured to continuously select data from the factory machine database that enables the generation of digital visual representations of one or more physical objects, wherein the selected data has no control parameters. The replication module is further configured to copy only the selected data to the visualization database, wherein the visualization engine is configured to generate digital visual representations of one or more physical objects based on the data in the visualization database. The visualization software is also configured to display the visual representations of one or more physical objects to one or more users via a display device, enabling users to monitor the manufacturing process, wherein the visualization engine does not have access to the factory machine database.
[0094] According to the implementation plan, the automation system and factory machine database are implemented in the process control level (L2), and the visualization engine is implemented in the operation control level (L3). Thus, the safety interface is the only interface that allows control parameters to be transferred from L3-level system components to L2-level system components.
[0095] Regarding the verification of the aforementioned request, this includes performing a reasonableness check on the control parameters at the ID provider's computer system and / or authenticating the client that has submitted the request. Only if the remote user can be successfully authenticated at the ID provider's computer system and the control parameters are determined to be reasonable, can the control parameters included in or derived from the request be stored in the factory machine database. Thus, the control parameters included in or derived from the request can be mapped to additional control parameters included in the factory machine database to expand the control parameters and also perform reasonableness checks on the additional control parameters.
[0096] In another aspect, the present invention relates to a computer-implemented method for process automation in a manufacturing plant, the computer-implemented method comprising: - Provide a system that includes: ○ Multiple machines in a manufacturing plant; ○ Factory machine database, which includes control parameters for the machines; ○ An automation system that automatically operates the machines in a manufacturing plant based on control parameters in a factory machine database; ○ User registry, which includes user profiles for the following: Multiple remote users not located in the manufacturing plant, and Multiple local users located in the manufacturing plant, ○ A visualization engine configured to create augmented reality for local users and virtual reality, including digital twins of factories, for remote users; ○ Security interface; The method includes the following steps: - A request to operate at least one of the machines is received from one of the remote users via a secure interface; - A security interface enables the visualization engine to generate an acceptance request, which is a signal sent by augmented reality glasses worn by one of the local users, prompting that the local user to accept the requested operation of at least one of the machines; and - Only when a local user accepts the request will the control parameters included in and / or derived from the received request be stored in the factory machine database by the security interface.
[0097] Systems for monitoring manufacturing plants can be implemented as part of systems for automating processes in manufacturing plants, and vice versa. The modules and software architecture elements described in the examples and implementations of systems for monitoring manufacturing plants can be freely combined with the modules and software architecture elements described in the examples and implementations of systems for automating processes in manufacturing plants, and vice versa.
[0098] As used in this article, an “interface” is a software-based / hardware-based boundary on which two or more individual components of a data processing system exchange information.
[0099] As used herein, a "service interface" is an interface through which two or more clients exchange information with a system used for automating processes in a manufacturing plant. Specifically, a client can be a remote client connected to the service interface via a network such as the Internet. Clients can be users, client devices, client software programs, edge computing systems, or combinations thereof.
[0100] As used in this article, a “security interface” is an interface through which requests (especially requests to change the configuration of machines in a manufacturing plant) are transmitted to an automation system.
[0101] As used herein, “machine” refers to any physical entity involved in the manufacture and / or handling of a product produced in a factory. For example, a machine can be an apparatus powered by electrical, mechanical, thermal, chemical, or other forms of energy to perform one or more operations. A machine can also be equipment or equipment components, apparatus, robotic arms, conveyors, robots, extruders, rollers, ovens, or any other type of physical component that can perform one or more operations in a manufacturing workflow. The nature and location of machines in a factory can depend on the type of product to be manufactured.
[0102] As used herein, "systems for process automation" refers to a distributed, networked system comprising multiple machines in one or more plants and one or more additional system components, such as L3 and / or L4 components of the process automation pyramid, for automatically controlling the operation of the respective plants' machines, thereby enabling workflows to be executed. This system is used and / or configured for process automation, particularly process automation of processes in one or more manufacturing plants.
[0103] As used herein, an "automation system," also known as a "process automation system (PAS)," is a system used to automatically control processes in plants such as chemical plants, oil refineries, paper mills, and pulp mills. PASs typically use networks to interconnect sensors, controllers, operator terminals, and actuators. A PAS, as used herein, can be based on open standards, but it can also be based on and / or include proprietary standards, in which case it is also referred to as a DCS (Distributed Control System). Automation systems can be associated with SCADA systems. Automation systems can use established, possibly plant-specific, protocols or technologies. Depending on the implementation, an automation system includes one or more machines in the plant, PLC (Process Logic Control) interfaces for the machines, and / or PCS (Process Control System) interfaces. Optionally, it may also include a plant machine database containing control parameters for the machines.
[0104] As used herein, the term "Level 3" or "Level 3 IT Infrastructure System" refers to IT system components included in the manufacturing operations level. This level is referred to as "Level 3" or "Level 3" in the Purdue model of multi-level automation systems; however, the term "Level 3" or "Level 3 IT Infrastructure System" is also used herein to refer to IT system components included in the manufacturing operations level, which may have different meanings in other models of multi-level automation systems. Level 3 components execute control functions at a higher level than those in the core process control system.
[0105] As used herein, the term "Level 2" or "Level 2 IT Infrastructure System" refers to IT system components included in the core process control level. This level is referred to as "Level 2" or "Level 2" in the Purdue model of multi-level automation systems; however, the term "Level 2" or "Level 2 IT Infrastructure System" is also used herein to refer to IT system components included in the core process control level, which may refer to different things in other models of multi-level automation systems.
[0106] As used in this article, "database" refers to any data structure that allows for temporary or permanent storage of data. For example, a database can be a data store managed by a database management system (DBMS), a directory of files, a collection of one or more files, a single file such as a spreadsheet, etc. A database can also be a data structure suitable for storing data in digital form, such as electronic or optical storage media.
[0107] As used herein, a “factory machine database” is a database that includes data related to one or more machines in a manufacturing plant. For example, the database may include control parameters for one or more machines, and / or data describing one or more machines, such as machine models, machine status data, machine configuration data, and / or other machine-related data that allows the generation of digital twins of the machines, and / or data that allows the simulation of machine operation or measurement data obtained by one of the machines. A factory machine database may also include location and / or status information of objects (e.g., sequestra or products) processed or generated by the machines in the plant.
[0108] As used herein, the “metaverse” is a virtual representation of parts of a world that is customized, preferably displayed via virtual reality glasses and / or augmented reality glasses. The metaverse can be implemented as a spatially merged network of 3D virtual worlds, for example, as a 3D world that is a digital twin of a factory and its machines, and a 3D world for one or more remote and / or local users wearing VR and AR glasses.
[0109] As used in this article, a “digital twin” is a digital representation of a real-world physical object or process that is used as its digital counterpart for practical purposes such as visualization, simulation, integration, testing, monitoring, or maintenance.
[0110] As used herein, a “factory” (also referred to as a “facility” or “manufacturing plant”) is an industrial facility, typically a complex of several buildings filled with machinery, in which workers and / or machines manufacture articles or process each article into another. A manufacturing plant can be, for example, a plant for producing vehicles or vehicle parts, a plant for producing consumer electronics, or a plant for synthesizing or processing chemicals.
[0111] As used herein, a "factory environment database" is a database that includes data related to a factory or factory environment. A factory environment database may include copies of portions of data, such as a factory machine database. Preferably, sensitive machine-related data (e.g., status parameters, location, configuration parameters, etc.) are not included in the factory environment database.
[0112] According to some examples, portions of the data in the factory machine database, included within the factory environment database, comprise data used during reasonableness checks performed by the L3 submodule of the safety interface. This data may include, for example, reasonableness criteria, thresholds, and reference parameter values relevant to the factory or its environment but not to individual machines. For instance, the data may include acceptable energy price thresholds, weather data, information about ongoing manufacturing processes at other factories and their corresponding requirements, quality indications required by different customers for the products to be manufactured, etc.
[0113] In addition to the data used for requesting verification, or as an alternative, the data included in the factory machine database of the factory environment database includes data that enables the visualization engine to generate digital visual representations of one or more machines whose data are included in the factory machine database and / or generate digital visual representations of objects processed or produced by said machines.
[0114] As used herein, a "visualization database" is a database that includes data that enables software (e.g., a visualization engine) to generate digital visual representations of one or more physical objects. For example, a visualization database may include 2D or 3D models of physical objects, such as realistic or simplified images or holograms of the objects. A visualization database may include spatial information about the objects, such as spatial information about the orientation of the objects or about their location within a virtual coordinate system. Preferably, the visualization database does not contain indications of the exact geographical location of the objects. For example, a visualization database may include digital models and / or general status information of one or more machines whose control data is included in a factory machine database, and / or digital models and / or general status information of objects processed or produced by said machines.
[0115] Based on some specific implementation examples, the factory environment database is used as a visualization database, and vice versa.
[0116] As used herein, an "edge computing system" is a computer system installed spatially near the machines in a factory and configured to process data generated by the factory's machines. This data may specifically include real-time data. Despite its spatial proximity, according to some examples, an edge computing system is not part of the factory's automation system. For example, an edge computing system may not be part of Level 1, Level 2, or Level 3 of a factory's multi-level automation architecture. An edge computing system can be configured to continuously receive, store, and evaluate data provided by the machines during the manufacturing process, such as machine status data, product status data, process parameter values, product properties, etc. Due to its spatial proximity to the data source, an edge computing system can be able to react very quickly to events occurring during the manufacturing process with very low latency. However, for security reasons and due to the lack of suitable interfaces, it has been impossible to integrate edge computing systems into process automation systems until now. By enabling the edge computing system to generate requests for controlling one or more machines and submit them to a secure interface, embodiments of the present invention can allow the integration of edge computing systems into systems for automated process control. For example, an edge computing system can be configured to continuously analyze status information received from one or more machines in a factory, and when it determines that an undesirable event has occurred or is predicted to occur during the production workflow, submit a request to a safety interface. This request includes control parameters suitable for preventing or mitigating the impact of the undesirable event. Undesirable events could be, for example, a shortage of consumables, congestion on a product conveyor belt, or a machine temperature exceeding a threshold.
[0117] As used herein, “control parameters” are parameters that affect the state of the machine and / or the way the machine operates. For example, control parameters can be configuration parameters, function command-line arguments used to invoke the machine’s PLC interface, commands, or a combination of both or more of the foregoing.
[0118] As used in this article, a “request” is a message sent between objects. For example, a request can be sent from a client to a system used for process automation via a network. There, the request can be processed, optionally modified or supplemented, and forwarded by multiple interfaces until it reaches its destination or until the forwarding of the request is rejected.
[0119] As used herein, a “visualization engine” is monolithic or distributed software configured to generate visual representations of physical objects. The visual representation can be, for example, a 2D representation to be displayed via a computer or smartphone screen, and / or a 2D or 3D representation to be displayed via VR glasses and / or AR glasses. In the latter case, the visualization engine (also referred to as a “metaverse engine”) interoperates with an AR application to enable AR glasses controlled by that AR application to display a virtual object representation to a user wearing the AR glasses. Additionally or alternatively, the visualization engine is configured to interoperate with a VR application to enable VR glasses controlled by that VR application to display streaming status information to a user wearing the VR glasses. Where the visualization engine is operatively coupled to multiple users wearing AR glasses, VR glasses, or a combination of VR and AR glasses via one or more AR and / or VR applications, the visualization engine can be configured to globally align the virtual objects (their properties, size, orientation, and position) with the coordinate systems used by the VR and AR glasses to display the virtual objects. Due to this global alignment of virtual objects, multiple users wearing VR glasses and / or AR glasses can at least partially share a common virtual object world, which may include multiple machines in a factory, one or more production lines in a factory, and / or digital twins of the factory or users operating in the factory.
[0120] As used herein, a “client” refers to computer hardware or software that accesses a service provided by a server via a computer network, where the service is specifically accessed as part of a client-server model of the computer network. The server is typically (but not always) located on another computer system, in which case the client accesses the service via a network (e.g., the Internet). Client software can be software that translates user actions into requests and other actions of the client software; therefore, the term “client” can also refer to a user who uses hardware or software to access a service via a network. The term “client” can also be applied to the computer or device running client software.
[0121] For example, a client can be a computer program that, as part of its operation, relies on sending requests to another program or computer hardware or software to access services provided by a server (which may or may not be located on another computer). For example, a web browser can be used as a client to connect to a web server and retrieve web pages for display.
[0122] As used herein, "computer system" refers to a machine or collection of machines that can be instructed to automatically perform sequences of arithmetic or logical operations via computer programming. Modern computers have the ability to follow a general set of operations known as "programs," "software programs," or "software applications." These programs enable computers to perform a wide range of tasks. According to some embodiments, a computer system includes hardware (specifically, one or more CPUs and memory), an operating system (main software), and additional software programs and / or peripherals. A computer system can also be a group of interconnected and working computers, specifically a computer network or computer cluster, such as a cloud computing system. Therefore, as used herein, "computer system" can refer to a monolithic standard computer system, such as a single server computer, or a computer network, such as a cloud computing system. In other words, one or more computerized devices, computer systems, controllers, or processors can be programmed and / or configured to operate as explained herein to perform different embodiments of the invention.
[0123] The embodiments and examples described herein should be understood as illustrative examples of the invention. Further embodiments of the invention are contemplated. Although the invention has been described by way of example through specific combinations and distributions of software programs and computer systems, it should be understood that any feature described with respect to any embodiment may be used alone, or in combination with other described features, and may also be used in combination with one or more features of any other embodiment, or in any combination of any other embodiment, provided that these features are not mutually exclusive.
[0124] Therefore, some embodiments of this application relate to computer program products. Other embodiments of this application include corresponding computer-implemented methods and software programs to perform the steps and operations of any of the method implementations outlined above and detailed below.
[0125] Any software program described herein can be implemented as a single software application or a distributed, multi-module software application. One or more software programs described herein can be carried by one or more carriers. Carriers can be signals, communication channels, non-transitory media, or computer-readable media. Computer-readable media can be: magnetic tape; disks, such as CDs or DVDs; hard disks; electronic storage; or any other suitable data storage medium. Electronic storage can be ROM, RAM, flash memory, or any other suitable electronic storage device, whether volatile or non-volatile.
[0126] Each of the different features, technologies, configurations, etc. discussed in this article can be performed independently or in combination, and can be performed in combination of processes via a single software process, such as in a client / server configuration.
[0127] It should be understood that the computer system and / or computer-implemented method implementation described herein can be strictly implemented as a software program or application, software and hardware, or hardware alone, such as within a processor, or within an operating system, or within a software application.
[0128] The operation of the flowchart is described with reference to the systems / apparatus shown in the block diagram. However, it should be understood that the operation of the flowchart can be performed by embodiments of systems and apparatus other than those discussed in the block diagram, and the embodiments discussed with reference to the systems / apparatus can perform operations different from those discussed in the flowchart. Attached Figure Description
[0129] Referring to the accompanying drawings, the following embodiments of the invention will be explained in more detail by way of example only, wherein: Figure 1 A high-level block diagram of a system for process automation is shown; Figure 2 A block diagram of another system for process automation is shown; Figure 3 A block diagram of a system for safety visualization of components used in an automation system is shown. Figure 4A An example of a GUI that allows local users to monitor the status of manufacturing process steps is shown; Figure 4B Another example is shown, illustrating a GUI that enables local users to monitor the status of manufacturing process steps; Figure 5 A distributed system for controlling manufacturing processes in multiple factories is shown; Figure 6 An example is shown of a system configured to display various virtual objects to "operator" users; Figure 7 An example is shown of a system configured to display various virtual objects to "maintenance worker" users; Figure 8 This illustrates the avatar of a remote user; Figure 9 An example is shown of a coordinate system used to represent a real-world machine and a local user avatar in a virtual metaverse for remote operation; and Figure 10 This is a flowchart of a method for achieving safe remote control of automated manufacturing processes. Detailed Implementation
[0130] Figure 1A block diagram of a process automation system 100 for use in a manufacturing plant is shown. The plant may be, for example, a plant for synthesizing chemical compositions, manufacturing vehicles, computers or consumer products, furniture, or food.
[0131] A factory comprises multiple machines 140 used to manufacture and / or process one or more physical objects. The type of machine depends on the type of product to be manufactured and / or the machine manufacturer selected by the factory owner. For example, machines can be electronic equipment, grippers, robotic arms, conveyors, robots, extruders, rollers, ovens, etc.
[0132] The system also includes a factory machine database 128, which can be part of the factory's L2-level IT infrastructure. For example, the machine database can be a file directory, a single file, a combination of files, a database managed by a database management system (DBMS), or a graph database (GDB) such as Neo4J, or a combination thereof.
[0133] The factory machine database 128 includes control parameters, such as configuration parameters, location information, and / or structural or functional models of machines and / or processed digital objects, and / or data used to generate digital twins of one or more machines 140 in the manufacturing plant and / or physical objects processed in the plant. For example, control parameters could be the temperature of a reaction vessel for a chemical reaction, the temperature of an oven, the rotational speed of a stirrer, the speed of a pump, the pressure in a pressurized gas tank, the amount of a specific substance to be added to the reaction vessel, the desired pH value in the reaction vessel, and the desired CO2 in the gas tank. 2 Concentration, etc. Control parameters may include target parameter values, i.e., parameter values indicating the machine state that should be achieved or the product state to be manufactured. Data used to generate digital twins may include, for example, continuously updated location information of machines and / or physical objects, digital 2D or 3D models of the corresponding machines in the factory, and may also include data indicating the dynamic behavior of the machines according to environmental parameters, control parameters, or other parameters.
[0134] System 100 includes an automation system 102 for automatically operating the machines 140 of a manufacturing plant based on control parameters in a factory machine database. For example, the automation system may include one or more programmable logic controllers (PLCs) 125 configured to control one or more manufacturing processes performed by the factory machines 140. A safety interface may be configured to control one or more machines directly or via the PLC / PCS interface 125.
[0135] A PLC can execute a program periodically. In each cycle, the program reads one or more control parameters from the current measurement parameters provided by the machine and the control parameters stored in the factory machine database 128 as inputs, processes the inputs, and writes output parameters. The output parameters are forwarded to one or more machines and control the actions performed by those machines. Therefore, these output parameters, and the control parameters upon which they depend, can act as control commands, as they determine the machine's behavior and thus the manufacturing process. The processor of an automation system typically spends tens of milliseconds evaluating all instructions and updating the status of all outputs. For example, a SIMATIC S7 can be used as a PLC for an automation system.
[0136] System 100 also includes system components in manufacturing operation level (level 3 in the Purdue model) 104, hereinafter referred to as "L3 components". L3 components execute control functions at a higher level than the control functions in the core process control system (level 2 in the Purdue model, hereinafter referred to as "L2 components") 102. For example, at least some of the control functions executed by the L3 components may be machine-agnostic. The L3 system components are preferably hosted on one or more monolithic or distributed computer systems 104 operating separately from the L2 system components 102.
[0137] System 100 includes a security interface 142, which includes a first submodule 122 as part of the L3-level IT infrastructure of system 100 and a second submodule 124 as part of the L2-level IT infrastructure. The two submodules implement different parts of the request authentication process.
[0138] Security interface 142 is configured to receive requests from one or more clients 106, 107, 108, 110, such as requests to manufacture a specific product and / or to modify the production of the product. Clients can be mobile clients, such as smartphones, laptops, or VR glasses, or fixed clients, such as desktop computer systems or edge computing systems.
[0139] For example, edge computing system 110 may be a computer system located near one or more machines in machine 140 of a factory, but may not be fully integrated into the IT environment of system 110. The edge computing system may be configured to collect log data and / or status data from one or more machines in machine 140 during an ongoing manufacturing process, analyze the data, and automatically determine control parameter values (e.g., temperature, amount of added substances, pH, etc.) deemed suitable for improving the quality of the automated manufacturing process and / or the products produced. In determining these control parameters, the edge computing system creates a request to forward the control parameters and submits it to machine 140 via a secure interface.
[0140] The client computer system 106 can be any type of computer system, such as a desktop computer, laptop computer, tablet computer, notebook computer, or mobile phone.
[0141] Client 108 can be a remote user wearing VR glasses. The remote user can use the VR glasses to monitor one or more machines within the machine during the manufacturing process or maintenance intervals. The remote user can use the VR glasses to specify requests, including corresponding control commands, and submit them to a secure interface. Instead of implementing advanced IT equipment such as VR glasses into core process control (L2), embodiments of the present invention can allow direct control of such machines to be constrained to the L2 level and provide remote clients with security options to securely transmit control information to the machine via access to a protected one-way secure interface 142.
[0142] Advanced process control client 107 can be a client that includes advanced process control software to integrate the requirements, needs, and available resources of one or more plants. It can integrate multiple heterogeneous distributed plants. Advanced process control software includes model-based software used to guide process operation and is often referred to as multivariate predictive control (MPC) or model predictive control. These applications require that the created process model accurately represent process dynamics.
[0143] The secure interface is configured to receive requests from clients. Preferably, the requests are not received directly from the client, but rather via... Figure 2 The request is received by one or more of the illustrated service interfaces. The request is verified by the security module. If the security module determines the request is valid, it stores the control parameters included in or derived from the request (e.g., during mapping and / or normalization operations) in the factory machine database 128. If the request verification returns an invalid request, the control parameters are not stored in the factory machine database.
[0144] Optionally, the security interface returns a response message to the entity that submitted the request to indicate that the request was not executed. Preferably, the security interface prompts the local operator 146 or the software application to approve the storage of verified control parameters and / or to approve the machine operation triggered by the control parameters, thereby storing the control parameters in the database 128 only if the security interface receives an acceptance message.
[0145] The automation system is configured to repeatedly read control parameters stored in a factory machine database and control machine operation based on the currently stored control parameters. A remote operator 108 can continuously monitor at least some aspects of the manufacturing process via VR glasses and a visualization engine 134.
[0146] Figure 2A system 200 for process automation according to another embodiment is shown. It includes components already referenced. Figure 1 The components and subsystems described.
[0147] According to the depicted example, each submodule 122, 124 of the security interface 142 includes task engines 144, 141. Task engine 144 is configured to process incoming requests by applying a configurable rule set 132. Rule 132 may include rules independent of the specific nature of machine 140, but may relate to more general parameters, such as requirements or settings provided by the client (e.g., a customer), cost-related reference parameters and thresholds, required product properties, availability of the ionizer, environmental parameters such as ambient temperature, etc. For example, proprietary or open-source solutions such as Node Red or Drools may be used to implement the task engine.
[0148] Task engines 144 and 141 can be implemented as event-handling software with a low / no-code interface (e.g., GUI 133 and 123), enabling users to create and maintain rules 132 and 137 without programming skills. The rule set representation allows task engines 144 and 141 to inspect inbound requests, and specifically, to check the legitimacy of those requests. Thus, rule 132 can perform machine-agnostic checks, while at least some of the rules in rule 137 can perform machine-specific checks, such as checking whether control parameters (e.g., temperature or RPM values) are supported by and safe for the machine to operate on. Rule execution by the task engines can include comparing control parameters included in or derived from the request with reference values, with the history of corresponding control parameters previously used by the relevant machine, with predefined syntax, or with predefined fixed or dynamic value ranges.
[0149] The reference values and thresholds used by the first security interface submodule 120 to verify the request can be stored in and read from the factory environment database 130, and the reference values and thresholds used by the second security interface module 124 can be stored in and read from the factory machine database 128.
[0150] In addition to rules, or as an alternative to rules, task engines 144, 141 train machine learning models, such as neural networks, to examine control parameters. For example, the trained machine learning model may have been trained on a training dataset that includes at least some of the control parameter values previously used to operate the machine, and may have learned to associate these control parameter values with information about the nature of the product and / or the safety of the manufacturing process.
[0151] According to some examples, submodule 122 of the safety interface includes first functions (F1', F2'), and second submodule 124 includes second functions F1, F2, whereby the structures of the first and second functions (i.e., the number and type of input and output command-line arguments) are continuously synchronized between the first and second submodules, such that any changes to the structure of the second functions (F1, F2) in second submodule 124 are propagated to the first functions F1', F2' in submodule 122. The names and / or structures of the second functions F1, F2 may reflect the names and structures of the corresponding functions of the PLC / PCS interface 125 that directly control one or more machines in machine 140. Client requests may be or include calls to one or more functions. Automatically synchronizing function structures offers the following advantages: it makes calls to PLC / PCS interface functions transparent to the client without granting the client direct, unrestricted access to interface 125, as the client can only trigger function execution after successful authentication and verification. Furthermore, only a subset of functions on PLC / PCS interface 125 are accessible via functions F1, F2 / F1', F2' of the security interface. Synchronizing the structure of functions F1 and F2 of the second submodule 124 with the structure of functions F1' and F2' of the first submodule 122 of the security interface 142, or with the corresponding functions of multiple first security interface submodules of multiple different L3-level IT infrastructure systems, allows for the transparent integration of L2-level IT infrastructure into two or more different L3-level IT systems. Therefore, functions F1 and F2 can also be used and called by two or more different security interface submodules 122 and the corresponding L3-level IT systems.
[0152] Any requests for control and / or reconfiguration of the machine submitted by remote user 108 or another client are not submitted directly to secure interface 124, but rather via service interface 120, which may be part of the system's L3-level IT infrastructure. For example, service interface 120 may include web service interfaces tailored to each of several different client types, such as edge computing system 110, remote users submitting requests using VR glasses and / or VR applications, or client applications from customers attempting to order and initiate the production of a specific product. Each of these services can be accessed via a REST API (Representative State Transfer Application Interface). Using a REST API ensures the system's flexibility and scalability. It shields the secure interface from untrusted clients, enables client authentication processes, and enforces that only requests from authorized clients are forwarded to the secure interface.
[0153] When the first submodule 122 successfully verifies the request, the first submodule or the task engine included therein can forward the request or the control parameters included therein or derived therefrom to the second submodule 124 by calling one of the functions F1 or F2 of the second submodule via the service interface 121.
[0154] According to the example described, service interfaces 120 and 121 can both be implemented as web services using an industry-standard web server, thereby exposing the first functions F1' and F2' via the REST API of interface 120, and thus exposing the functions F1 and F2 via the REST API of interface 121.
[0155] The system comprises multiple firewalls 114 and 116, which shield the automation system 103, as well as security interfaces and other components, from unauthorized access. Any attacker wishing to modify the factory machine database must compromise multiple firewalls. Each firewall acts as a network security system, monitoring and controlling incoming and outgoing network traffic based on predefined security rules. It establishes a barrier between trusted networks or subsystems and untrusted networks or subsystems.
[0156] Some implementations may include a log database, and security interface 142 can be configured to log all requests and the results of request validation in the log database. This can facilitate error analysis and fraud detection. In some examples, factory environment database 130 is used as the log database.
[0157] According to some examples, the system (e.g., the system's L3 IT infrastructure) may include a visualization engine 134 configured to enable a remote user 108 to submit requests to a secure interface via VR glasses. The visualization engine may support collaboration between the remote user 108 and one or more local operators 146 working in the factory via shared virtual reality (remote user) or augmented reality (local user, not shown). For example, the visualization engine 134 may be operatively coupled to a database 130 that includes data objects as digital twins of factory objects, particularly machines 140. The database may also include objects as digital representations of the remote user 108, specifically avatars, whereby the coordinate system of these objects in database 130 is continuously updated using the current location of the respective object and the user, and where the positions of these objects and the user in a shared metaverse coordinate system are continuously mapped to the factory's real-world coordinate system.
[0158] The system can also include an identity provider 135, such as a corporate ID provider like Active Directory, Azure AD, or any LDAP service. Any client can be authenticated by the identity provider 135. Depending on the requesting system, authentication can use personal or function / machine identities. Service interface 120 can support different authentication workflows for different types of clients. Similarly, corporate authentication standards can be applied to the system and authentication process, such as single-factor or multi-factor authentication, credentials, certificates, etc. The ID provider 135 can be configured to check the authorization of requesting clients based on the client's group and group membership.
[0159] In some implementations, security interface 142 does not directly store the control parameters provided in the verified request in the factory machine database. Instead, the security interface invokes a database service interface to cause the database service interface to store the control parameters in the factory machine database. The factory machine database can be configured to grant write access only to the database service interface and optionally to some other trusted entities. This can further enhance security and protect the automated system from unauthorized manipulation.
[0160] As from Figure 2 It can be inferred that system 100 implements a unidirectional and highly secure communication channel for transmitting control parameters, included in requests from clients 108, 106, and 110, to the machines in the factory. Before the parameters are finally stored in database 128 to make them accessible to the machines, the requests and / or control parameters must successfully pass through multiple firewalls, request verification steps, and preferably additional security checks, such as authentication via ID provider 135 at service interface 120.
[0161] The system, particularly its L3 IT infrastructure, may include a communication module, which includes a key manager module. The communication module can establish an encrypted one-way communication channel between service interface 120 and security interface 142. The communication module can also establish encrypted communication channels between the service interface and a first sub-module of the security interface, and between the first and second sub-modules of the security interface. For example, an encrypted communication channel, as used herein, could mean that only the first sub-module of the security interface is allowed to receive data from and access the service interface from service interface 120. In some implementations, the communication module may also include a user registry, user-specific keys, and other user-related data. The user registry may include registered local users, registered remote users, and other clients.
[0162] According to some implementations, system 100 includes a feedback channel 143, which is separate from the communication channel used to transmit control parameters to a factory machine database. For example, the first and second submodules of the security interface may each include functions that report whether a processed request is accepted or rejected. Preferably, the reason for rejection (e.g., authentication failure, unreasonable control parameters, etc.) and / or machine status information is not transmitted to the client.
[0163] According to some implementation schemes, the first submodule of the security interface and optional additional components of the system's L3 IT infrastructure, as well as the second submodule of the security interface and optional additional L2-level components of the IT infrastructure system, are instantiated within different virtual machines operated by different virtual machine hosts. The virtual machines can be containers, such as Docker containers operated by different container management systems. This improves the system's security and robustness because the sensitive L2 layer is isolated and protected from the L3 level and any untrusted entities that have managed to infiltrate the L3 level.
[0164] According to a preferred embodiment, the system is configured to process requests using a predefined sequence of processing steps: the system accepts requests from untrusted sources such as remote clients 106, 107, 108, and 110.
[0165] First, the client that has submitted the request must successfully authenticate at service interface 120, for example by providing one or more credentials to ID provider 135, such as a signing certificate, a secret shared with the security interface, biometric data, a password, appearance on a whitelist, or a combination thereof. Only when the client is able to authenticate itself as a trusted entity at the ID provider will the service interface forward the request to the security interface, in this case, to the first submodule 122 of security interface 142. According to the implementation, authentication of the entity at the service interface includes checking the integrity of the request, for example, by means of signature verification, checksum verification, etc.
[0166] A security interface (here, for example, security interface submodule 122) verifies a request, for example, by performing various reasonableness and / or security checks on the control parameters included in the request, wherein these checks are preferably based on global, non-machine-specific (machine-agnostic) rules. For example, some rules may analyze whether the control parameters are acceptable given current weather conditions (such as ambient temperature or humidity). Request verification may include checking whether the parameter value of a given control parameter is specified with the correct data type (e.g., integer, string, boolean, etc.). Verification may include checking whether requests to modify a particular control parameter are received no more than the maximum allowed frequency, for example, to protect the system from denial-of-service attacks. Submodule 122 forwards the control parameters to the automation system-side submodule 124 of security interface 142 only if the verification returns that the request is valid (the control parameters are reasonable and safe). Additionally or alternatively, the security interface may check whether the request, combined with a predefined number of previously received requests, has modified a particular control parameter such that it exceeds the maximum acceptable variability threshold. If the variability is too high, this may indicate that the entity that submitted the request is unfamiliar with the corresponding machine, or that multiple users are attempting to guide the manufacturing process in different directions.
[0167] According to some implementations, request verification by the security interface also includes checking whether the client that submitted the request has the necessary permissions to modify a specific control parameter. For example, if remote user 148 is not allowed to modify the temperature of a specific tank, then the user's request to modify the temperature of that tank will be considered invalid. Additionally or alternatively, the verification request may include a simulation of the future state of one or more machines that will be affected by changes in control parameters. If the simulated future state would violate constraints, such as being associated with low-quality products or a production process deemed unsafe, then the request is considered invalid.
[0168] Submodule 124 verifies the forwarded control parameters, for example, by performing various further rationality and / or safety checks, wherein these checks preferably include enforcing machine-specific and / or plant-specific rules. Only if the verification return request is valid (the control parameters are rational and safe), submodule 124 forwards the control parameters to a database service interface configured to store the control parameters included in the request in the plant machine database 128.
[0169] According to the implementation plan, request verification performed by the safety interface can be used to determine whether the control parameters specified in the request are reasonable, achievable, acceptable, and safe for the plant and its machines. Verification requires the safety interface to have at least coarse-grained knowledge of the processes performed by the machines during the manufacturing process. For example, if the request specifies a 10°K reduction in the temperature of a reaction vessel, the safety interface must examine how this change affects specific machines and control signals, and whether the temperature reduction would exceed any safety parameter ranges.
[0170] According to some implementations, the safety interface is further configured to perform mapping of control parameters specified in the request. Specifically, if the safety interface is a distributed safety interface, the control system portion of the safety interface can implement the mapping process. During mapping, the safety interface determines how changes in the specified parameters affect other control signal thresholds and machine settings, which may also be represented and controlled by corresponding control parameters in the plant machine database. For example, to achieve a 10°K reduction in the temperature in the tank, it may be necessary to reduce the activity of the heating element and / or increase the activity of the cooling element. It may also be necessary to increase the stirring speed to compensate for the increased viscosity of the fluid contained in the tank. During mapping, one or more additional control parameters are determined, the values of which depend on the value of one of the control parameters specified in the request. Furthermore, the desired values of additional control parameters (e.g., desired stirring speed, cooling rate, and / or heating intensity) after a change in the value of one control parameter are determined.
[0171] Preferably, additional control parameters identified during the mapping step are also verified; that is, they are checked to see if they are feasible, reasonable, and / or safe. If the mapped parameters fail verification, the entire request can be rejected, and the control parameters in the request will not be stored in database 128.
[0172] After the control parameters have been successfully validated and mapped, and the mapped parameters have also been successfully validated, the mapped parameters, together with the control parameters originally included in the request, are transmitted to the database service interface 126 and are ultimately stored in the factory machine database 128.
[0173] After the mapping step is completed, the control parameters in the request and any additional control parameters identified during the mapping process are stored in the factory machine database.
[0174] According to a preferred embodiment, the security interface is configured to generate an acceptance request after a request has been successfully validated. The acceptance request is configured to prompt a user 146 operating locally at the plant, or software included in the security interface (not shown), to accept a requested change to one or more control parameters stored in a plant machine database. For example, the acceptance request may be displayed or otherwise output to the local user 146 via a local operating user interface, such as a display included in one of the machines 140 at the plant or coupled to that machine. An acceptance check may be the final step in request validation performed by the security interface. For example, if the security interface is a distributed interface, the acceptance check may be performed by the security interface submodule 124. The local user / software sends an acceptance message to the security module only if the local user 146 or the software included in the security interface accepts the proposed control parameter setting. The request is considered successfully validated (valid) only if the local user or software has accepted the proposed change. Otherwise, the request is considered invalid, and its contained control parameters are not stored. For example, a request from remote user 108 to lower the temperature in the reaction vessel can trigger the creation of an acceptance request, which is displayed to local operator 146 via the reaction vessel's display. Compared to the remote user, the local operator has a better understanding of the entire manufacturing process and / or critical status parameters of the vessel. For enhanced safety, local operator 146 must confirm new control parameters, for example, by clicking the "OK" button displayed on screen 125. If the operator does not accept the proposed parameter change, the safety interface will not forward the control parameter to machine database 126. For example, if no acceptance message is received from local operator 146 within a predefined timeout interval, the safety interface can determine that the request is invalid.
[0175] If a valid request is confirmed by local user 146, the security interface submodule stores the corresponding control parameters in the factory machine database.
[0176] In other implementations, the security interface may not be implemented as a multi-modal distributed system and may be an integral part of L2 or L3 IT infrastructure (and corresponding virtual machines).
[0177] Figure 3 A block diagram of a system 300 for monitoring a manufacturing plant is illustrated. This system includes an automation system 103 comprising multiple machines 140 of the manufacturing plant and a plant machine database 128. The plant machine database includes control parameters for the machines and spatial and / or status information of physical objects (machines and / or objects processed by the machines).
[0178] The automation system is configured to operate machines automatically based on control parameters in a factory machine database. For example, the automation system may include a PLC and / or PCS interface 125 to enable local operator and / or safety interfaces 142 to operate the machines via these interfaces 142.
[0179] The system also includes an update engine 160. The update engine is software configured to continuously (e.g., at least once per hour, or at least once per minute, or at least once per second) receive spatial and / or status information of physical objects from multiple sensors 162 during the ongoing manufacturing process and update the machine database 128 with the received information. For example, sensors may include temperature sensors, humidity sensors, pH meters, and internal machine sensors configured to determine the operating state or mode of the machine (e.g., the rotational speed of a centrifuge or agitator, the speed of a conveyor belt, the open-closed state of doors and other openings, etc.).
[0180] The system also includes a visualization database 130, which comprises a subset of the data from the factory machine database.
[0181] System 300 also includes a copy module 150. The copy module is software configured to continuously (e.g., at least once per hour, or at least once per minute, or at least once per second) select data that enables the generation of digital visual representations of one or more physical objects from data in a factory machine database, whereby the selected data has no control parameters and only the selected data is copied to the visualization database. Therefore, the copy module can be considered as filtering the data content of the factory machine database such that only a selected subset of the data is copied to the visualization database 130. For example, the visualization database may include 2D or 3D models of machines and / or objects processed by the machines. The models may be static or dynamic models that can be used to visualize the state of the machines or the state of the manufacturing workflow. Furthermore, the visualization database may include spatial information about the objects, such as the current orientation of robots and other machines or machine parts, the location of segregated objects or products in the production line, etc. Preferably, the spatial information does not include information that would allow identification of the exact geographical location of the corresponding physical object. At least some of the 2D or 3D models of the machines are not scaled and / or are coarse-grained abstractions of the machines. This allows for the protection of expertise related to the structural design of the machine and other sensitive information, such as the total / maximum production capacity of the plant, machine, or production line.
[0182] The system further compresses the visualization engine 134. A visualization engine is a software program, such as a monolithic software application or a set of interoperable software programs, configured to generate digital visual representations of one or more physical objects based on data in a visualization database. Preferably, the visualization engine does not access the factory machine database, but instead uses a subset of data copied to the visualization database by the replication module as the basis for generating visual representations of one or more physical objects involved in the manufacturing process of the factory, particularly visual representations of the machines involved in the process and / or objects processed by the machines.
[0183] In some examples, replication module 150 can use a streaming protocol to continuously stream database updates from factory machine database 128 to visualization database 130. For example, Apache Kafka can be used to create a continuous stream of measurement values stored in the factory machine database and deliver it to the visualization database. Measurement parameter values may indicate the orientation or status of one or more machines and / or the result of previously executed control commands that have requested new configuration data. By streaming the measurement parameter values to the visualization database, they become accessible to the visualization engine.
[0184] The visualization engine is interoperable with one or more client software programs running on corresponding client devices, including display devices 154 and 108. The client software receives visual representations of physical objects from the visualization engine and causes the corresponding display devices to display these representations to the user. This allows the user to monitor the manufacturing process without disclosing sensitive control parameters or other sensitive data and expertise.
[0185] For example, client software that interoperates with the visualization engine can be software configured to display visual representations on a 2D screen (e.g., the screen of a smartphone, laptop, or desktop computer). This can allow remote users to monitor production processes via standard devices without requiring users to use specialized equipment such as VR glasses.
[0186] According to another example, the client software that interoperates with the visualization engine can be VR software (virtual reality software), which is configured to display a visual representation via the user's VR glasses, thereby giving the user an immersive impression of being in the vicinity of the physical object represented by its visual representation, even though the user may be far away from the factory.
[0187] According to another example, the client software interoperating with the visualization engine can be AR (Augmented Reality) software configured to display visual representations via AR glasses worn by a local user 146 operating at the factory, thereby providing the user with additional information that may be useful for operating or maintaining the machines in the factory. For example, system 300 may also include a security interface 142 configured to receive and verify requests from one or more of the operating machines of remote clients 106, 107, 108. The security interface can be configured to prompt the local user 146 to accept the requested action via a visual object generated by the visualization engine and displayed via the local user's AR glasses. For example, the visual object can be a menu describing the requested action and / or the identity or role of the requesting user, whereby the menu includes one or more selectable items, such as buttons, allowing the local user to accept or reject the requested action. Additionally or alternatively, the visualization engine interoperating with the AR software can enable the AR glasses to display menus, text, video, or other types of data related to the machine or manufacturing process. For example, the data may include instructions in text or video on how to operate or maintain the machine, may include a GUI that allows local users to input configuration data locally, or may include alarms or error messages.
[0188] The remote user wearing VR glasses for remotely monitoring the manufacturing process can be the user who has submitted the request. However, the request can also be submitted by another remote user or remote client software, and the user 108 wearing the VR glasses can monitor only the process.
[0189] According to the implementation scheme, the visualization database 130 includes two or more different user role-specific models for at least one of the machines. The visualization engine is configured to identify the role of a remote user wearing VR glasses, identify one of the models assigned to that role, and use the identified models to generate a visual representation of the machine. The different models can differ from each other in the degree of structural detail or state information exposed in the models. This allows for flexible and fine-grained control over the level of detail that the remote user can see.
[0190] Safety interface 142 and its interoperability with the client, PLC / PCS interface 125, and machine 140 can be implemented as described herein with respect to other embodiments and examples. However, the safety interface is optional, and the factory machine database 128, visualization database 130, visualization engine 134, update engine 160, and replication module 150 can also be used in computer systems for monitoring and / or operating manufacturing processes that do not include these optional components. Using the database replication mechanism as described herein in conjunction with the safety interface can have the advantage of providing a highly secure system for remotely monitoring and controlling automated manufacturing processes: there is only a one-way communication channel for transmitting control parameters from the remote client to the machine, and another one-way path for providing visual feedback to the remote user. This ensures that the remote user cannot access or see sensitive control parameters, or know how he or she only sees a predefined and typically simplified visual representation of real-world objects in the form of digital twins.
[0191] Figure 4A Example 400 of GUI 144 is shown, which enables user 146 (e.g., a local user) to monitor and / or control the status of the manufacturing process. Because the status information may reveal sensitive data about the manufacturing process, GUI 400 may be accessible only from within the automation system / plant, rather than from a remote user.
[0192] In the illustrated example, a remote user or edge computing system may have requested that the "target bulk density" control parameter 402 be set to a value of 115,000 g / L. During the mapping operation performed by the security interface, the security interface may have calculated additional control parameter values for temperature 408 and pressure 406. For example, the manufacturing process may be chemical synthesis, and the security interface may include a predictive model configured to predict temperature and pressure values that may provide the material at (at least approximately) the desired bulk density. The predicted bulk density 404 and predicted temperature and pressure for the corresponding reaction vessel can be calculated during the parameter mapping step and can be passed by the security interface to the database service interface and stored in the plant machine database. One or more machines in the plant's machines 140 (e.g., local computers) can be configured to read the parameters from the plant machine database and generate a GUI displaying the parameter values (the target bulk density specified by the requesting entity, the bulk density predicted by the service interface, and the temperature and pressure).
[0193] Local users can choose whether to manually or automatically set machine parameters, pressure, and temperature to achieve a given target bulk density of the material produced by the manufacturing plant. When... Figure 4AWhen the machine control values are set to "automatic mode," the control parameters predicted by the safety interface are automatically set and used as the basis for controlling the synthesis process and process conditions. Prediction is preferably performed at level L2 of the safety interface. Therefore, automatically calculated parameter values (e.g., 8.48 bar and 37°C) are automatically set and can be continuously updated during the ongoing manufacturing process.
[0194] According to some implementation schemes, the local operator 146 must select "Automatic Mode" or "Manual" at least once to start the synthesis process. By selecting "Automatic Mode," the local operator sends an acceptance message to the safety interface, indicating that the local operator considers the specified control parameters (particularly temperature and pressure) to be safe and appropriate.
[0195] Figure 4B Another example 410 of a GUI 144 is shown, enabling local users to monitor and / or control the manufacturing process. In the illustrated GUI 410, it corresponds to... Figure 4A As shown in GUI 400, the machine control values have been set to "Manual" by the local user. Therefore, the local user has the ability to edit values calculated by the security interface, thereby overriding any control parameters deemed unsafe, unrealizable, or otherwise problematic.
[0196] Figure 5 A distributed system 500 for controlling manufacturing processes in multiple factories is shown.
[0197] A user 108, who may work at factory A and is therefore far from factory B, can wear VR glasses. Through the VR glasses, user 108 can see video and / or images captured by cameras placed in factory B. For example, the cameras can be attached to a mobile robot 510, the movement and / or position of which can be controlled by a remote operator 108. Thus, the remote operator sees through his VR glasses what the robot 510 sees as it moves through factory B. Image and / or video data can be transmitted via, for example... Figure 3The illustrated database replication module and visualization engine are transmitted from robot 510 to a remote user. At least some of the machines or physical objects handled by the machines are graphically represented to the remote user in the form of visual digital twins via VR glasses as part of “virtual reality.” When a user attempts to monitor the operation of one of the machines 140 in the factory, for example, wanting to turn robot 510 to the left, user 108 can simply turn his body to the left. Sensors in the VR glasses will recognize the change in position and / or orientation and send a new position and orientation and / or left-turn command in the form of a request to control the robot to turn left. As described herein with respect to embodiments and examples, the request to the mobile robot is transmitted to the robot via security interface 142. For example, forwarding a request from L3 to L2 may involve authenticating the remote user 108, verifying the request, mapping control parameters, verifying the mapped control parameters, and storing the new position or movement specification in database 128. Robot 510 and other machines 140 are configured to repeatedly read control parameters from database 128 and adjust their position and / or perform corresponding actions.
[0198] The current position and / or orientation of one or more machines 140, including the robot, can be continuously sensed and stored in a factory machine database 128, and the acquired position data can be used to continuously update the database 128. At least some of the data indicating the robot's position and / or orientation is copied to a factory environment database 130, which serves as the data basis for a visualization engine to generate and display a continuously updated visual representation of the robot and / or other machines 140 in the factory to remote users.
[0199] In some embodiments of the implementation as depicted, visualization engine 134 may be configured to create avatar 505, which is a virtual representation (or “twin”) of remote user 108. The avatar may be displayed to one or more local operators 146 operating at plant B and wearing AR glasses. Thus, local operator 504 sees the digital twin of the remote user through his or her AR glasses.
[0200] User 146 can wear AR glasses, meaning that user 146 can still see the real machines 140 in factory B. However, some virtual objects, including avatar 505, are displayed in the AR glasses as an overlay on the "real world," which is still visible through the AR glasses. Therefore, user 146 perceives a realistic impression that remote user 108 will actually be present at the location of factory B because he sees the avatar moving and / or hears the avatar speaking through the AR glasses. The impression of the avatar and other virtual objects through user 146's AR glasses can be generated by augmented reality application 504 locally installed in the IT infrastructure of factory B. Furthermore, the IT infrastructure of factory B can include virtual reality application 506, which is configured to interoperate with virtual reality application 524 locally installed in the IT infrastructure of other factories (e.g., factory A) via visualization engine 134. Thus, operators from different factories can share a common virtual reality, which could be useful for users operating in different countries who want to discuss manufacturing-related issues without having to meet physically.
[0201] The visualization engine can be configured to align virtual objects, such as avatars, virtual user menus, instruction manuals, or videos, with both the virtual reality coordinate system and the "real world" coordinate system. The visualization engine has access to the global object representation layer, so any user wearing VR or AR glasses and registered with the visualization engine can see any virtual object, such as a machine's instruction manual.
[0202] Remote user 108 can remotely control not only some manufacturing tasks at factory B, but also some manufacturing tasks at factory A. For example, user 108 may typically be a local operator at factory A, but may wish to remotely control tasks from home. In this case, user 108 is also a remote user of the system used to control manufacturing at factory A.
[0203] User 108's remote control of one or more machines 526, 528, 530, 532 and / or 534 via security interface submodules 542, 544 can be as already shown in other figures (e.g., Figure 1 , Figure 2 and / or Figure 3 Implemented as described. Service interfaces 540 and 120 can be based on REST APIs, can involve streaming applications such as Apache Kafka, and can use MQTT or WebSocket protocols to forward requests.
[0204] At Level 3, security interface submodules 542 and 122 include or have access to rules and / or object representations related to objects at the manufacturing site, cluster, or plant level, which are typically machine-agnostic. These rules and object representations can be used to validate requests at Level 3.
[0205] At Level 2 (automation system level), security interface submodules 544 and 124 include or have access to rules and / or object representations related to objects at the factory, production line, or machine level. These rules and object representations can be used to validate requests within the automation system / Level 2.
[0206] The embodiments of the present invention enable users 108 of machines located far from multiple factories to control these machines without posing a security risk to the factories.
[0207] Figure 6 System 600 is illustrated, configured to display various virtual objects in a location-dependent manner to a user wearing AR glasses and having an "operator" role. For example, an operator can wear AR glasses and view real physical objects, such as machines in a factory or objects being handled by machines. Task instructions A1-A6 are displayed by the AR glasses at predefined x / y / z coordinates in an augmented reality coordinate system aligned with the real-world coordinate system. For example, the AR glasses can use the x / y coordinates of a machine (such as a dispensing unit, conveying and heating unit, or packaging unit) to display a corresponding instruction manual or video at a predefined distance relative to the real-world location of the real-world object.
[0208] For example, a user wearing glasses may have a registered user account in the user database of the visualization engine and / or ID provider 135, and their user ID may be associated with one or more user roles (in this case, the "operator" role). Additionally or alternatively, each user role may optionally include one or more user permissions.
[0209] Therefore, the visualization engine is configured to select the content of the received data to be displayed based on one or more user roles and / or one or more user permissions associated with a user ID (e.g., "filtering" the content of received task instructions). For example, by way of non-limiting exemplary implementation only, the one or more user roles include operator roles, maintenance roles, engineering design roles, management roles, and visitor roles. The one or more user permissions and / or roles restrict and determine what virtual objects / information can be displayed through AR glasses. For example, in the sense of viewing data corresponding to a machine by displaying the corresponding task instructions, user permissions for the engineering design role can define which machines in the factory a user associated with a user ID who has an engineer role can access. A user associated with a user ID can have more than one role and more than one user permission.
[0210] exist Figure 6 In the illustrated example, the user wearing the AR glasses has been assigned the role of "operator." Therefore, the executable program logic causes the AR glasses to display view 600, where the user sees instruction manual A1 on how to clean the filter when approaching the dispensing unit, and can further see additional task instructions and corresponding instruction videos A2 and A3. When the user approaches the conveying and heating unit, task instruction A7 will be seen via the AR glasses. Similarly, when approaching the packaging machine, task instructions A4-A6 will be seen. Tasks A1-A7 pertain to standard tasks that must be performed under normal operating conditions in an industrial plant.
[0211] Figure 7 System 700 is illustrated, configured to display various virtual objects in a location-dependent manner to a user already assigned the role of "maintenance worker" via AR glasses. When the maintenance worker wears the AR glasses and views the actual machine, they will see task instructions related to maintenance tasks rather than operational tasks. For example, when approaching the dispensing unit, the user will see task instruction B1 for changing the defective pressure sensor 1234, and / or when approaching the delivery and heating unit, they will see instruction B2 on how to inspect the heater.
[0212] Figure 8 A system 800 for a manufacturing plant utilizing spatial anchor points is illustrated, and an avatar of a remote user 108 at the plant to be controlled is shown.
[0213] The remote human operator 108 may be an expert maintaining one or more machines in the plant (e.g., complex machine 808). Both the machine and the local operator 146 are located in industrial plant B in country B. The remote user 108 is located in a different location, such as plant A in country A. The remote user 108 wears VR glasses operatively coupled to a virtual reality application 524 (“VR application”). The VR application is interoperable with an AR application 504 operatively coupled to AR glasses worn by the local operator 146. The VR application 524 and the AR application 504 may be interconnected via a visualization engine configured to spatially align virtual objects of virtual and augmented reality with each other. The AR application enables the remote user to support the local colleague 146 in various operational and / or maintenance tasks performed locally on or at the machine 808. The AR application is configured to create an avatar 505 for the remote user and position the avatar at a defined location, such as near the machine 808 requiring the support of user 108.
[0214] According to a preferred embodiment, VR application 524 is configured to generate virtual reality for remote user 108, enabling the remote user to see other real-world objects of the local user 146 and / or industrial plant (e.g., machine 808), as perceived from the perspective of avatar 505. For example, the remote user can see real-time values of production lines and machines through a robot equipped with cameras and / or other sensors located at the same position and orientation as his avatar 505. For example, the robot could be a reference... Figure 5 Robot 510 is described. In some examples, factories A and B and their corresponding IT infrastructure can be referenced as follows. Figure 5 The operation is performed as described.
[0215] In some implementations, the robot is remotely controlled by a remote user 108, enabling the remote user to perform defined operations through the robot. The avatar has a defined location within a 3D environment generated by the AR application 504 and displayed to a local user 146 via AR glasses. Furthermore, the local human user 146 (the AR user) and the machine 808 have defined locations within the 3D environment, which serves as the coordinate system for augmented reality (“mixed reality”).
[0216] The AR application 504, which interoperates with the visualization engine, is configured to ensure that the VR coordinate system seen by the remote user and the AR coordinate system seen by the local user 146 via AR glasses have the same coordinate system as the basis for locating virtual objects (avatars, holograms, GUIs, etc.). Both the AR application 504 and the VR application 524 receive positional information of the virtual objects to be displayed in the augmented / virtual reality from the same global object representation layer 503. According to some embodiments, the VR application 524 of the remote user 108 generates a virtual reality (“manufacturing metaverse”) within which the avatar of the local human operator 146 is displayed in a defined optical representation (e.g., name only or even a 3D avatar shape), allowing the remote user to see the local user within the VR application (not shown). Conversely, the local user (AR user) 146 can view the avatar 505 of the remote user 108 as a hologram (e.g., name only or as a 3D avatar shape) within the “manufacturing metaverse” presented to the local user 146 as augmented reality via AR glasses 804.
[0217] According to the implementation scheme, AR glasses 804 include a microphone 810 and an acoustic output interface 812, such as a speaker providing a user interface to a local user. Similarly, VR application 524 may include a user interface including a microphone and an acoustic output interface for enabling a remote user 108 to interact with the VR application. AR application 504, operatively coupled to the AR glasses of the local user, interoperates with the VR application, allowing the remote user 108 and the local user 146 to converse with each other. Preferably, the AR application uses position information of the avatars of the local and remote users in a shared coordinate system to control the volume of the acoustic output interface of the AR glasses: the closer the local user 146 is to the avatar 505, the louder the volume. Similarly, the sensitivity of the microphone can be adjusted according to the distance between the two users in the shared coordinate system: the greater the distance, the lower the microphone sensitivity.
[0218] Therefore, the AR system, including AR and VR applications, according to the described implementation scheme, allows two users to collaborate using a shared coordinate system also known as the "manufacturing metaverse." The manufacturing metaverse consists of a virtual coordinate system shared by all users and AR objects within the metaverse, which is mapped to and rendered as an overlay of real-world objects 808 in an industrial plant. This allows experienced remote users to experience the same or similar visual context as guided local users.
[0219] According to the first scenario, thermoplastic polyurethane (TPU) production is carried out at factory B. The production line has been modified to accommodate this new product, which has never been produced on this line before. The remote operator is an expert in this type of production and resides at location A (country A, factory A). The remote user will instruct the local operator when and which valves should be inspected. The remote user will also inform the local operator of important matters requiring attention to ensure smooth production. Furthermore, the remote user can guide the local operator to perform the correct operating procedures under the right conditions and at the right time.
[0220] According to the second scenario, TPU production is already underway at location B. The night shift coordinator is ill. An experienced human operator at remote location A (other time zone, country A, factory A) can support production at location B during the day shift. He will use his avatar to collaborate directly with one or more local human operators. The remote user can coordinate the work of local workers by creating processes / tasks that can be executed by the local user (AR user).
[0221] According to the third scenario, autonomous TPU production is underway at Factory B. Under normal / standard conditions, the production line can operate completely autonomously. Manual operation is only required in the event of unforeseen circumstances. This supervision will be accomplished using a VR application from a remote location via a manufacturing metaverse. One or more robots are coordinated and triggered by a remote human operator by creating / using the correct processes / tasks for the robots. When the remote human operator needs to see realistic images and / or video streams of the local situation, the remote user is enabled to move to the machine of interest via VR and AR applications associated with the robot's control program. The robot is equipped with a camera and is controlled to take the same position and orientation as the remote user's avatar. When the robot has reached that position, the robot's camera captures images and / or videos of the machine in front of the avatar / robot and transmits the images or videos to the VR application. The remote user will see the images and / or videos via virtual reality created by the VR application. When the robot is controlled to capture images and / or videos from the same position and orientation as the remote user's avatar in the mixed reality coordinate system of the industrial plant, the photos and images will show the machine of interest from the same angle as the local human operator has at that position and orientation.
[0222] The embodiments of this invention can be applied to many other scenarios and industries. For example, embodiments of this invention can be used in the automotive manufacturing industry, and allow experienced engineers to support colleagues working at other locations within the automotive manufacturing company.
[0223] Similarly, systems used for automated production control and / or for graphically representing ongoing manufacturing processes via VR glasses, AR glasses, or other display types using visualization engines can be used in the chemical industry or any other type of industry in which physical objects are handled to manufacture one or more products.
[0224] In some use cases, robots are used not only to acquire images or videos, but also to solve problems under the control of a remote user. For example, robots can be used to perform maintenance tasks in locations that are dangerous to human operators, such as in cases involving chemical synthesis routes involving toxic chemicals, or in environments contaminated with radioactive materials or toxic chemicals, or at risk of such contamination.
[0225] According to some implementation schemes, spatial anchors are used to position virtual objects at a defined location and orientation relative to a real-world object such as machine 808. For example, it might be desirable to display a GUI hologram so that a user can monitor and control machine 808 from a distance of approximately 40 cm in front of the machine.
[0226] To ensure that local user 146 always sees the GUI hologram at the defined location in augmented reality, regardless of user 108's current location, the AR application generates and displays the GUI hologram at the spatial anchor or at a defined distance relative to the spatial anchor. According to some implementations, the spatial anchors (i.e., at least anchor IDs and anchor coordinates) are stored in a database system, making them accessible to VR application 524. The VR application is configured to read the stored spatial anchors and generate and display the same virtual object, such as the GUI hologram of machine 708, at the spatial anchor or at a defined distance relative to it.
[0227] According to some implementations, spatial anchors are defined and created by placing machine-readable codes (e.g., QR codes 811, 813, 814) at various locations within an industrial plant. The AR glasses may include a camera that acquires a digital image of the machine-readable code, extracts the anchor ID encoded therein, creates anchors with the coordinates of the machine-readable code in a real-world coordinate system, and stores these anchors in a database system. Alternatively, a user 146 can create spatial anchors by performing an anchor-creating gesture at a desired location in the real world. This gesture is captured by the AR glasses' camera, and the spatial anchors are similarly created and stored by a visualization engine. Anchor IDs can be automatically created when spatial anchors are created.
[0228] Figure 9An example of a coordinate system 900, usable by a visualization engine and VR application 524, is illustrated for representing real-world objects and local user avatars in a virtual metaverse to a remote operator 108. VR application 524 generates a virtual representation 908 of a real-world machine 808 in an industrial plant and displays this virtual representation to the remote user 108 via virtual reality display technology. This virtual reality coordinate system 900 may also include a virtual representation 904, such as an avatar, of a local user 146 operating spatially close to the real-world object 808. The distances between the virtual representations 908 and 904 of machine 808 and local user 146 within coordinate system 900 correspond to and reflect the actual distances to the real-world objects. Coordinate system 900 may include a spatial grid aligned with "real-world" objects, such as machine 808 and local user 146 in an industrial plant. The grid may also be aligned with the corresponding virtual representations 908 and 904 (digital twins) of the real-world objects. Furthermore, remote user 108 can be represented as a virtual entity in coordinate system 900, such as avatar 505 that local user 146 can see through AR glasses 804. Figure 9 The coordinate system shared by the virtual reality generated by the VR application and the AR reality generated by the AR application is shown, but preferably, the remote user 108 sees the virtual objects representing real objects and other users in the coordinate system 900 from the perspective (position and orientation) of his avatar 505.
[0229] Figure 10 A flowchart illustrating a method for automating processes in a manufacturing plant is provided. The method includes providing (602) systems 100, 200, 300, and 500 for automating processes in a manufacturing plant as described herein with respect to various example implementations. The system may include multiple machines 140 and 536 of the manufacturing plant, a plant machine database 128 and 548 including control parameters for the machines, an automation system 103 for automatically operating the machines of the manufacturing plant based on the control parameters in the plant machine database, and a security interface 142. The method also includes receiving (604) a request from a client via a network and verifying (604) the request by the security interface. If the security interface determines the request is valid, the security interface stores (608) the control parameters 402-408 included in or derived from the request in the plant machine database. The automation system automatically operates (610) the machines based on the stored control parameters included in or derived from the valid request. If the security interface determines the request is invalid, the security interface returns (612) a message to the client via a feedback channel that the request was not executed.
[0230] List of icon numbers 100 Systems for Process Automation 102 Automation System (L2) 103 Automation System 104 Control System (L3) 106 Client: Computer System 107 Client: Advanced Process Control Software 108 Client: Remote users with VR glasses 110 Client: Edge Computing System 114 Firewall 116 Firewall 120 Service Interface 121 Service Interface 122 Submodule of Security Interface 123 Rule 137 Configuration GUI 124 Submodule of the security interface 125 to the machine's PLC / PCS interface 128 Factory Machine Database 130 Factory Environment Database Rule 132 133 Configuration GUI for Rule 132 134 Visualization Engine Rule 137 135 ID Provider 140 Manufacturing assets of physical entities (such as factories, production lines or units, machines, and equipment). 141 Task Engine 142 Security Interface 143 Feedback Channel 144 Task Engine 146 local users 150 Copy Module 154 2D / 3D Representation of Physical Objects / Machines 200 Systems for Process Automation 202 Administrator 214 Local Operators 400 GUI 402 Control parameter "Target packing density" 404 Calculation of other control parameters 406 Calculated additional control parameters 408 Calculation of other control parameters 410 GUI 500 system 501 L3 IT Infrastructure System 502 Global Object Presentation Layer 503 L2 IT Infrastructure System 504 Factory B's Local AR Application 505 Incarnation 506 Factory B's Local VR Application 508 Factory B's local web application 510 Robots controlled by remote users 512-518 Machines / Equipment 520 Factory A's local web application 522 Factory A's Local AR Application 524 Factory A's Local VR Application 540 Service Interface 542 Security Interface Submodule 544 Security Interface Submodule 546 Database Service Interface 548 Configure the database 526 Robots 528-534 Machines / Equipment 552 L2 IT Infrastructure System 554 L3 IT Infrastructure System 600 system Steps 602-612 700 System 800 system 804 AR Glasses 808 Machines / Equipment 810 microphone 811 QR code 812 Acoustic Output Interface 813 QR code 814 QR code 900 coordinate system The digital twin of machine 908 and machine 808 904 users' digital twins
Claims
1. A system (100, 200, 300, 500) for process automation of a manufacturing plant, the system comprising: - a plurality of machines (140, 536) of the manufacturing plant, - a plant machines database (128, 548) comprising control parameters for the machines; - an automation system (103) for automatically operating the machines of the manufacturing plant according to the control parameters in the plant machines database; - an identity provider comprising a user profile of: o a plurality of remote users not located in the manufacturing plant, and o a plurality of local users located in the manufacturing plant, - a visualization engine configured to create an augmented reality for the local users and a virtual reality comprising a digital twin of the plant for the remote users; - a security interface (142) configured for: o receiving a request from one of the remote users (108) to operate at least one of the machines, o causing the visualization engine to generate an acceptance request, the acceptance request being a signal to one of the local users (146) wearing augmented reality glasses to accept the requested operation of the at least one of the machines, o storing control parameters (402-408) comprised in and / or derived from the received request in the plant machines database only in case the one local user accepts the request, wherein the automation system is configured to perform the automatic operation of the machine according to the stored control parameters comprised in or derived from the accepted request.
2. The system of claim 1, wherein the security interface is configured to validate the request and store the control parameters in the plant machines database only in case the validation returns that the request is valid.
3. The system of claim 2, wherein the validation of the request comprises performing a sanity check, the sanity check being a check comprising determining whether the control parameters comprised in or derived from the request are safe for the machine and a human operator, wherein the request is considered invalid if at least one of the control parameters is determined to be unsafe.
4. The system of any one of the preceding claims, wherein the security interface is configured to map the control parameters included in the request or derived from the request to further control parameters included in the factory machine database in order to extend the control parameters, wherein the security interface is configured to perform a plausibility check on the further control parameters, the plausibility check being a check including determining whether the further control parameters are safe for the machine and human operators, and wherein the request is considered invalid if at least one of the further control parameters is determined to be unsafe.
5. The system of any one of the preceding claims, the request being created by an action of the remote user, the action being recognized as a control command by VR glasses worn by the remote user.
6. The system of any one of the preceding claims, wherein the security interface generates the accept request only if the request is successfully validated as valid.
7. The system of any one of the preceding claims, the system further comprising an ID provider computer system configured to authenticate the user that has submitted the request, wherein the security interface is configured to not store the control parameters in the factory machine database if the authentication fails.
8. The system of any one of the preceding claims, wherein the request is a request to operate a robot located at the factory.
9. The system of any one of the preceding claims, the visualization system being configured to generate a visual representation of the remote user in the form of an avatar and to display the avatar to the local user via the AR glasses worn by the local user.
10. The system of claim 9, wherein the visualization engine is configured to support an exchange of voice and text messages between the remote user and the local user.
11. The system of any one of the preceding claims, the system further comprising an update engine (160), a visualization database (130) and a replication module (150), - wherein the visualization database (130) comprises a subset of the data of the factory machine database; - wherein the update engine is software configured to continuously receive spatial and / or state information of the machine and / or of objects handled by the machine from a plurality of sensors (162) during an ongoing manufacturing process and to continuously update the factory machine database with the received information, and - wherein the replication module is software configured to continuously select data of the factory machine database that enables generation of a digital visual representation of one or more physical objects, the selected data being free of the control parameters, wherein the replication module is further configured to replicate only the selected data to the visualization database; and - wherein the visualization engine is configured to generate the digital visual representation of the one or more physical objects from the data in the visualization database and to display the visual representation of the one or more physical objects to one or more users via a display device (154, 108) to enable the users to monitor the manufacturing process, wherein the visualization engine has no access to the plant machine database.
12. The system of any one of the preceding claims, the automation system and the plant machine database being implemented in a process control level (L2) and the visualization engine being implemented in an operation control level (L3), whereby the security interface is the only interface allowing to transfer control parameters from system components of the L3 level to system components of the L2 level.
13. Use of the system according to any one of the embodiments described herein for automating a process of a manufacturing plant.
14. A computer-implemented method for automating a process of a manufacturing plant, the computer-implemented method comprising: - providing a system (100, 200, 300, 500) comprising: o a plurality of machines (140, 536) of the manufacturing plant, o a plant machine database (128, 548) comprising control parameters for the machines; o an automation system (103) for automatically operating the machines of the manufacturing plant in accordance with the control parameters in the plant machine database; o a security interface; wherein the method comprises the steps of: - receiving a request by the security interface; - verifying the request by the security interface, - in response to determining that the request is valid, storing control parameters comprised in or derived from the request in the plant machine database by the security interface; - automatically operating the machines by the automation system in accordance with the stored control parameters comprised in or derived from the valid request.
15. The method of claim 14, further comprising: o a user registry comprising a user profile for each of: Multiple remote users not located in the manufacturing plant, and Multiple local users located in the manufacturing plant, o a visualization engine configured to create an augmented reality for the local users and a virtual reality comprising a digital twin of the plant for the remote users; o a security interface (142); wherein the method comprises the steps of: - receiving a request to operate at least one of the machines from one of the remote users (108) by the security interface; - causing the visualization engine to generate an acceptance request by the security interface, the acceptance request being a signal to one of the local users (146) wearing augmented reality glasses to accept the requested operation of the at least one of the machines via the augmented reality glasses; and - storing, by the secure interface, control parameters (402-408) included in the received request and / or derived from the received request in the factory machine database only in case the one local user accepts the request.
Citation Information
Patent Citations
Virtual reality and augmented reality for industrial automation
EP3318945A2