System and method for providing specific insights to data confidentiality protection applications upon deviation

By embedding IT security measures in the computing module and using post-hoc and prior methods, the problem of confidential data insight under data deviation in industrial plants is solved, realizing fast and reliable data deviation analysis and traceability, and supporting post-event analysis and action recommendations.

CN121786850APending Publication Date: 2026-04-03ABB (SCHWEIZ) AG
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-09-30
Publication Date
2026-04-03

AI Technical Summary

Technical Problem

In industrial plants, existing technologies struggle to provide effective insights into confidential data when data is skewed, especially in multi-party environments where users cannot identify and mitigate anomalies while maintaining data confidentiality.

Method used

By embedding IT security measures in the computing module, processing company data and obtaining key performance indicator (KPI) values, using posterior and prior methods to determine data bias, switching to different processing states to provide additional information, and applying zero-knowledge proof and remote verification methods.

Benefits of technology

It enables the rapid and reliable identification and analysis of data biases while maintaining data confidentiality, providing traceable and verifiable results, and supporting post-analysis and action recommendations.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121786850A_ABST
    Figure CN121786850A_ABST
Patent Text Reader

Abstract

Embodiments of the present disclosure relate to systems and methods for providing specific insights to data confidentiality protection applications upon deviation. A method for providing insight into confidential company data in the event of a data deviation in an industrial plant context is disclosed. The method includes processing company data by a computing module in a first processing state, and obtaining a key performance indicator (KPI) value from the processing. Company data is protected by a first IT security means and associated with a process associated with a first company. The computing module is protected by a second IT security means and is associated with a second company. The method further includes determining a data deviation by determining whether the acquired KPI value violates a predetermined KPI threshold; and using a posterior method and / or a priori method based on a result of the determination.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to providing specific insights into data confidentiality protection applications in the context of industrial plants when deviations occur. Background Technology

[0002] In a multi-party environment, applications protected by intellectual property (IP) may include algorithms or models that are critical to one provider’s business, as well as pending data that is critical to another provider’s business. That is, this data must not be exposed as raw data to the party running the application.

[0003] Even when application providers employ IT security measures to protect sensitive applications, the applications themselves may still experience unexpected states, exhibiting anomalous or unexpected conditions or outcomes. The frequency of such occurrences can range from very rare to regular, depending on the specific triggers for these anomalies or unexpected situations.

[0004] In this scenario, application users might want to identify, mitigate, or resolve the root cause of the anomaly or unexpected situation. However, they may be unable to perform such analysis because the application's execution and therefore all related details are likely protected by IT security measures. On the other hand, application providers might want to support users in this situation but cannot easily grant access to specific information because users may want to keep their data confidential or protected by IT security measures.

[0005] Generally speaking, protecting code and data from access by other parties is crucial for all applications that keep raw data confidential and protect it from the data owner, while providing aggregated or selected data items to higher-level users. This is, for example, applicable to the digital twin / Industry 4.0 domain, where parts of the model are confidential and accessible only to the owner, while access to aggregated or selected data is provided to other parts of the model or lifecycle roles.

[0006] Confidential computing is a well-known example of IT security measures. It is a potential technology that achieves confidentiality of applications and / or data by running sensitive applications or processing sensitive data protected by IT security measures, such as in a Trusted Execution Environment (TEE) with isolated execution environments and encrypted storage. This requires specialized hardware, such as ARM TrustZone for embedded, mobile, and server devices, or Intel SGX for server devices, and can be used in conjunction with other technologies such as remote authentication. Confidential computing is primarily used by cloud service providers such as Amazon, Google, IBM, and Microsoft, and by streaming services such as Netflix, in their Digital Rights Management (DRM) solutions, where the service's code and data often originate from the same source. However, in situations where the code and data do not originate from the same source, protecting such code or data from access by other parties may be of paramount importance. This is especially true in the context of industrial plants, as already noted above.

[0007] Therefore, in the context of industrial plants, there is still room for improvement and a need to improve the provision of insights into confidential data, such as corporate data, when data is biased. Summary of the Invention

[0008] In view of the foregoing, the purpose of this disclosure is to overcome at least some of the deficiencies in existing methods for providing insights into confidential data (such as corporate data) in the context of data bias in industrial plants.

[0009] Therefore, to address one or more of these deficiencies, in a first aspect, a method is provided for providing insights into confidential company data in the context of data bias within an industrial plant. The method includes: processing the company data by a computational module in a first processing state and obtaining Key Performance Indicator (KPI) values ​​from the processing. The company data is protected by a first IT security measure and is associated with processes related to a first company. The computational module is protected by a second IT security measure and is associated with a second company. The method further includes: determining data bias by identifying whether the obtained KPI values ​​violate a predetermined KPI threshold. The method further includes: using a posterior method and / or a prior method based on the determined result. Using a posterior method includes providing action recommendations for reducing data bias based on a confidential machine learning model and / or switching the computational module to a second processing state, wherein, compared to the first processing state, the second processing state enables the computational module to perform additional processing related to the company data and provide additional information related to the company data. Using a prior method includes applying zero-knowledge proof methods and / or remote verification methods related to the company data.

[0010] It is important to note that examples of IT security measures can include encryption, digital signatures, message authentication codes, anonymization, and obfuscation. These examples are outlined in more detail below. Therefore, the phrase "company data is protected by a first IT security measure" can be understood as meaning that company data is protected by at least one of encryption, digital signatures, message authentication codes, anonymization, and obfuscation. That is, for example, company data is encrypted, accessing company data may require a (specific) digital signature, accessing company data may require a message authentication code, company data is anonymized, or company data is obfuscated. Similarly, the phrase "computing module is protected by a second IT security measure" can be understood as meaning that the computing module is protected by at least one of encryption, digital signatures, message authentication codes, anonymization, and obfuscation. That is, for example, computing module data (e.g., computing module data including mathematical formulas or code data of the computing module) is encrypted, accessing the computing module may require a (specific) digital signature, accessing the computing module may require a message authentication code, the computing module may be anonymized, or the computing module may be obfuscated.

[0011] Obtaining KPI values ​​from processing can be a continuous monitoring of KPI values ​​obtained from processing. Furthermore, for ease of understanding, as outlined in more detail below, obtaining KPI values ​​from processing company data can be understood as determining, calculating, deriving, or extracting corresponding KPI values ​​from company data for one or more predetermined KPIs. For example, a KPI could be "Total Energy Consumption," and company data could include energy consumption data indicating energy consumption at several process steps during a production process at an industrial plant. Therefore, based on company data, the total energy consumption for a production process at an industrial plant can be obtained. This obtained total energy consumption could be a KPI value corresponding to the KPI "Total Energy Consumption." Thus, in other words, KPI values ​​are obtained from processing, where the KPI values ​​are associated with one or more predetermined KPIs, and where the KPI values ​​are obtained from company data, for example, calculated by a calculation module from the company data.

[0012] It is important to note that "company data" may refer to confidential data provided by and / or associated with a company. For example, company data could include production-related data concerning process steps in an industrial plant, such as CO2 emissions, resource consumption, or production costs. Company-related data could include technical details of automated equipment, such as the battery characteristics of a particular piece of equipment (e.g., a vehicle as part of a fleet).

[0013] The first and second processing states can be different operating states or modes for the computing module. Based on the state or mode of the computing module, it can access certain data and / or certain calculation methods. For example, the first processing state may allow access to a first portion of confidential data, while the second processing state may allow access to both the first and second portions of confidential data. Therefore, it can be said that the corresponding state or mode is associated with a corresponding portion of one or more confidential data. For example, in the first processing state, the computing module can access company data at the highest aggregation level, i.e., company data can be aggregated to the highest degree. In the second processing state, the computing module can access company data at a lower or lowest aggregation level, i.e., company data can be aggregated less or not aggregated at all. Less aggregated data may include more detailed information available from the company data, thereby obtaining more detailed information about a second company. Furthermore, regarding certain calculation methods, the computing module in the second state may be able to perform calculations that it cannot or is not allowed to perform in the first state. For example, the computing module may be able to calculate carbon dioxide emission data for each processing step of a production process at an industrial plant. In the first state, the computing module may only be able to calculate the total carbon dioxide emissions for the entire production process at the industrial plant.

[0014] The processes associated with the first company could be, for example, production processes at an industrial plant. For example, the processes associated with the first company could be the operation of automated equipment linked to production processes at an industrial plant. For instance, the processes associated with the first company could be the operation of a fleet of vehicles used to transport resources to and / or from the production site.

[0015] The first company can provide company data (which is associated with the first company) and can be a data provider or data supply party. The second company can provide computing modules or applications that include such computing modules, and therefore can be a computing module / application provider or computing module / application supply party.

[0016] It is important to note that, regarding determining data deviation, it may mean, in other words, determining whether one or more predetermined KPI thresholds, or thresholds related to one or more predetermined KPIs mentioned above, are violated (e.g., exceeded or fell below limits) by one or more KPI values ​​obtained from the processing of company data.

[0017] It is also important to note that the statement "The method also includes, based on a determined result, using a posterior method, the posterior method including switching the computation module to a second processing state" can also be understood as the method also includes, based on a determined result, switching the computation module to a second processing state. Therefore, the statement "using a posterior method" can be avoided and is instead used in this document to distinguish methods used for posterior application to the determined bias. Similarly, it is important to note that the statement "The method also includes, based on a determined result, using a prior method, the prior method including applying zero-knowledge proof methods and / or remote verification methods related to company data" can also be understood as the method also includes, based on a determined result, applying zero-knowledge proof methods and / or remote verification methods related to company data. Therefore, the statement "using a prior method" can be avoided and is instead used in this document to distinguish methods used for prior application to the determined bias. The prior method can be a zero-knowledge proof (ZKP) or a remote verification method, which can allow verification of the validity of the model used by the sub-supplier or partner without the sub-supplier or partner revealing the model itself. For example, using zero-knowledge proofs, any sensor on the platform (where the computation module can be provided) that uses an invalid model or needs to be recalibrated or recalibrated may be flagged. Similarly, remote verification can be used to ensure the integrity of the computing engine, for example by verifying the origin and authenticity of all algorithms, execution engines, and underlying platforms. It is important to note that, regarding the models of sub-suppliers or partners, the term "model" can be understood as a synonym for algorithm, computing engine, or code. Based on several examples in this disclosure, throughout the application, the term "model" can be understood as a synonym for algorithm, computing engine, or code. Furthermore, such sub-suppliers and partners can generally be understood as external parties providing models that can be verified via remote verification or ZKP without disclosing the model itself.

[0018] Action recommendations can include recommendations for actions to be performed at one or more processing steps in the production process. For example, it could be recommended to reduce the boiler's maximum temperature by a certain amount to reduce carbon dioxide emissions.

[0019] The advantage of the approach based on the first aspect lies in its ability to enable enhanced traceability of information flow and algorithmic decision-making, at least for post-hoc verification, and to provide verifiable results in the case of prior verification. It also allows for the prevention of leakage of IP knowledge or confidential data when the process is operating normally (i.e., the process does not violate predetermined key performance indicators), and also prevents leakage when analysis or limited analysis is performed in the event of violations or deviations. Furthermore, it enables collaboration with third-party data providers to provide partial root cause analysis (e.g., post-hoc analysis) and to provide action recommendations based on confidential data from IP-protected applications.

[0020] According to several examples of this disclosure, the method may further include: embedding or incorporating one or more predetermined KPI thresholds into a calculation module; and determining whether a predetermined KPI threshold has been violated based on whether the embedded predetermined KPI threshold has been violated.

[0021] It is important to note that embedding one or more predetermined KPI thresholds into the calculation module can be understood as embedding one or more "traps" into the calculation module. A "trap" can be associated with a predetermined KPI value, for example, with a KPI value that is higher (or lower) than or between predetermined thresholds. Therefore, for example, if it is determined that an acquired KPI value violates a predetermined threshold or falls within a predetermined range between predetermined thresholds, it can be understood that a "trap" has been hit. In other words, a "trap" can be defined by predetermined "trap conditions," which can be understood as including "trap boundaries" representing one or more predetermined thresholds. Therefore, if an acquired KPI value satisfies such "trap conditions" and violates a "trap boundary" or falls within a range between "trap boundaries," it can be determined that the embedded predetermined KPI threshold has been violated.

[0022] It's also important to note that the computation module itself can be designed to provide additional insights into company data when a "trap" is hit. Therefore, determining whether an embedded predetermined KPI threshold has been violated can be understood as the computation module determining whether the embedded predetermined KPI threshold has been violated. Furthermore, using posterior and / or prior methods can be understood as the computation module using posterior and / or prior methods. In other words, the computation module can be configured to perform specific processing or operations based on a violation of a predetermined threshold.

[0023] Furthermore, it should be noted that when it can be determined that a predetermined KPI threshold has been violated, for example, based on a predetermined KPI threshold that has already been violated, the calculation module can be triggered to execute one or more predetermined processing steps. Such triggering, i.e., executing processing steps due to a violation of a predetermined KPI threshold, can be understood as a "hit trap".

[0024] For example, if a KPI value violates a predetermined KPI threshold, that KPI value covers or hits a "trap" and can trigger further processing steps. Several "traps" or "triggers" may exist associated with several predetermined KPIs. The process could be a production process, for which raw materials might need to be delivered by a first company. For example, the total CO2 emissions of a production process over a predetermined time period could be an example of a KPI. Additionally or alternatively, total energy consumption, total production time, or total rest time could also be other examples of other KPIs for a production process. Hitting a "trap" or meeting a trigger / trigger criterion can include one of the violated predetermined KPI thresholds. For example, additionally, hitting a "trap" or meeting a trigger / trigger criterion can trigger the calculation module to switch from a first state to a second state. As already noted above, in doing so, the calculation module may become able to process additional data that was previously unprocessable (i.e., previously inaccessible or unusable).

[0025] Therefore, due to the embedding, it is possible to predetermine how to handle the problem situation (e.g., alarm situation) when the calculation module is violated when a predetermined threshold KPI value is violated, and the calculation module is also protected by a second IT security measure without the need for interaction between the first company or the second company.

[0026] According to several examples of this disclosure, the method may further include: if a predetermined KPI threshold is determined to be violated, triggering the calculation module to perform a switch and / or application.

[0027] It's important to note that triggers can be associated with specific threshold violations. In other words, different KPI threshold violations can be associated with corresponding triggering processes.

[0028] Therefore, identified violations, i.e., identified deviations or data biases, can be handled quickly, reliably, transparently, and autonomously.

[0029] According to several examples of this disclosure, switching the computing module to a second processing state may include making additional company data accessible to the computing module, wherein the additional company data is associated with a process related to the first company. The switch may also include processing the additional company data by the computing module.

[0030] It should be noted that, as pointed out above, the additional company data may differ from the company data based on the data aggregation level and / or the content of the included information.

[0031] Therefore, the source or cause of the deviation can be identified or determined more reliably and accurately, while still ensuring data confidentiality.

[0032] According to several examples of this disclosure, at least a portion of the additional company data may be included in the company data, and making the additional company data accessible to the computing module may include transferring at least a portion of the additional company data to the computing module. Additionally or alternatively, making the additional company data accessible may include enabling the computing module to access at least a portion of the additional company data included in the company data.

[0033] Therefore, it avoids the need for the computing module to access or receive data from directions or addresses different from those of the company's data.

[0034] Regarding supplementary company data, for illustrative purposes, consider the following example. Company data could be data used to analyze the fleet of autonomous equipment of a first company, where supplementary company data could be data used to analyze the fleet based on individual autonomous equipment (e.g., based on vehicles or devices). Therefore, it is possible to identify individual vehicles or individual devices responsible for hitting a "trap" (i.e., violating a predetermined KPI threshold).

[0035] According to several examples of this disclosure, at least a portion of the additional company data may not be included in the company data and may be protected by a third IT security measure. Making the additional company data accessible to the computing module may include transferring at least a portion of the additional company data to the computing module. Additionally or alternatively, making the additional company data accessible may include enabling the computing module to access at least a portion of the additional company data protected by the third IT security measure.

[0036] Therefore, for example, based on the importance of the relevant data to the primary company, different IT security measures or different security protection solutions, including different security protection levels, can be used for the primary company data and supplementary company data.

[0037] According to several examples of this disclosure, switching the computing module to a second processing state may include enabling the computing module to perform additional computing methods. This switching may also include processing company data and / or additional company data using one or more of the additional computing methods.

[0038] It is important to note that additional computational methods can include, for example, algorithms, AI / ML models, or mathematical formulas, which can then enable the computational module to use these methods.

[0039] Therefore, for example, more insights into data bias can be gained by processing the same company data in different ways.

[0040] According to several examples of this disclosure, enabling the calculation module to perform additional calculation methods may include enabling the calculation module to process company data and / or additional company data, and to obtain values ​​for additional KPIs from the processing.

[0041] It should be noted that additional KPIs may be KPIs whose values ​​are not allowed or cannot be obtained by the calculation module in the first state.

[0042] Therefore, having more values ​​for a single KPI allows for more detailed analysis of data bias.

[0043] According to several examples of this disclosure, at least two of the first IT security measure, the second IT security measure, and the third IT security measure may be different from each other, or the first IT security measure, the second IT security measure, and the third IT security measure may be the same IT security measure.

[0044] Therefore, IT security measures can be applied according to the specific circumstances.

[0045] According to several examples of this disclosure, in order to provide protection through at least one of a first IT security measure, a second IT security measure, and a third IT security measure, at least one of the following may be included:

[0046] - Provide computing modules, company data, and / or additional company data within a Trusted Execution Environment (TEE);

[0047] - Encrypt and / or verify company data and / or additional company data;

[0048] - Use distributed ledger technology (e.g., blockchain) to protect company data and / or additional company data;

[0049] - Use homomorphic encryption to perform computations on encrypted and / or additional company data without decrypting it;

[0050] - Obfuscation of company data and / or supplementary company data;

[0051] - Prove the status of company data and / or additional company data through zero-knowledge proofs;

[0052] - Anonymize company data and / or additional company data;

[0053] - Enforce access control on company data and / or additional company data through attribute-based, role-based, and / or context-based authorization.

[0054] It is important to note that the phrase "verifying company data" refers to the process of verifying the accuracy, completeness, and legality of information related to the company. This may involve ensuring that the data is accurate, comes from a reliable source, and has not been tampered with. It is a method of confirming that the data is authentic, reliable, and representative.

[0055] Therefore, IT security measures can be applied according to the specific circumstances.

[0056] According to several examples of this disclosure, the computing module may include at least one of the following

[0057] -algorithm,

[0058] - Artificial intelligence / machine learning (AI / ML) models,

[0059] - Mathematical model, and

[0060] -Physical model.

[0061] Therefore, IT security measures can be applied according to the specific circumstances.

[0062] According to several examples of this disclosure, one or more predetermined posterior methods may be associated with one or more corresponding predetermined KPI thresholds, and the method may further include using one or more predetermined posterior methods based on the determined corresponding one or more predetermined KPI thresholds.

[0063] According to several examples of this disclosure, one or more predetermined prior methods may be associated with one or more corresponding predetermined KPI thresholds, and the method may further include using one or more predetermined prior methods based on the determined corresponding one or more predetermined KPI thresholds.

[0064] For example, based on the determined violated KPI threshold, i.e., based on the "trap" being determined to be hit, one or more predetermined posterior methods and / or one or more predetermined prior methods can be triggered. In other words, there can be a "1 to n" correlation between a violated threshold and n (n is 1 or greater) triggered processes. Furthermore, there can be an "m to 1" correlation between m (m is 1 or greater) violated thresholds and 1 triggered process.

[0065] Therefore, in other words, switching and / or application can be based on a predetermined threshold being violated, i.e., based on a "trap" being triggered. For example, if a first predetermined threshold is likely to be violated, the computation module can switch to a second state; and if a second predetermined threshold is likely to be violated, the computation module can switch to a third state. Accessibility to company data and / or additional company data may vary depending on the state of the computation module. The available computation methods may also vary depending on the state of the computation module. In other words, based on the specific "trap" triggered, the computation module may have access to different amounts of additional data, and / or the computation module may be able to use different computation methods.

[0066] Therefore, insights into data bias can be appropriately personalized.

[0067] According to several examples of this disclosure, the method may also include providing a computing module on the platform; and receiving company data and / or additional company data at the platform.

[0068] It is important to note that, generally, the platform can be provided by a first company or a second company. However, the platform can also be provided by a third company representing the platform provider.

[0069] Therefore, even in situations involving three parties—data providers, application providers, and platform providers—data can remain confidential.

[0070] According to a second aspect, a data processing apparatus is provided for providing insights into confidential corporate data in the event of data discrepancies in the context of an industrial plant, the data processing apparatus including a processor configured to perform the method of the first aspect.

[0071] The advantage of the data processing device according to the second aspect lies in its ability to contribute to enhancing the traceability of information flow and algorithmic decision-making, at least for post-hoc verification, and providing verifiable results in the case of prior verification. It also allows for the prevention of leakage of IP knowledge or confidential data when the process is operating normally (i.e., the process does not violate predetermined key performance indicators), and also prevents leakage when performing analysis or limited analysis in the event of violations or deviations. Furthermore, it enables collaboration with third-party data providers to provide partial root cause analysis (e.g., post-hoc analysis) and to provide action recommendations based on confidential data from IP-protected applications.

[0072] According to a third aspect, a data processing system is provided for providing insights into confidential corporate data in the context of data discrepancies occurring in an industrial plant. The data processing system includes the data processing apparatus of the second aspect. Additionally or alternatively, the data processing system includes components for performing the method of the first aspect.

[0073] The advantages of the data processing system according to the third aspect are that it can contribute to enhancing the traceability of information flow and algorithmic decision-making, at least for post-hoc verification, and providing verifiable results in the case of prior verification. It can also prevent the leakage of IP knowledge or confidential data when the process is operating normally (i.e., the process does not violate predetermined key performance indicators), and also prevent leakage when performing analysis or limited analysis in the event of violations or deviations. Furthermore, it enables collaboration with third-party data providers to provide partial root cause analysis (e.g., post-hoc analysis) and to provide action recommendations based on confidential data from IP-protected applications.

[0074] According to the fourth aspect, an industrial plant is provided, which includes the data processing apparatus of the second aspect and / or the data processing system of the third aspect.

[0075] According to several examples, "industrial plant" can refer to an industrial factory, industrial production plant, or industrial resource plant, such as a mine, which includes one or more pipelines, production lines, and / or assembly lines for transforming one or more effluents into products and / or for assembling one or more components into a final product. According to several examples, it can refer to an industrial plant that processes data from third parties for transformation and / or assembly. According to several examples, it can refer to an industrial plant in the oil and gas industry, mining industry, chemical industry, wind and electricity industry, or food and beverage industry.

[0076] The advantages of the industrial plant according to the fourth aspect are that it can participate in providing enhanced traceability of information flow and algorithmic decision-making, at least for post-hoc verification, and providing verifiable results in the case of prior verification. It can also prevent the leakage of IP knowledge or confidential data when the process is operating normally (i.e., the process does not violate predetermined key performance indicators), and also prevent leakage when performing analysis or limited analysis in the event of violations or deviations. Furthermore, it enables collaboration with third-party data providers to provide partial root cause analysis (e.g., post-hoc analysis) and to provide action recommendations based on confidential data from IP-protected applications.

[0077] According to a fifth aspect, a computer-readable medium including instructions that, when executed by a computing system, cause the computing system to perform the method of the first aspect. The computer-readable medium may be transient or non-transient, volatile or non-volatile.

[0078] A computing system can typically be a processor, such as a processor that is part of a computer.

[0079] The advantages of computer-readable media according to the fifth aspect are that it can contribute to providing enhanced traceability of information flow and algorithmic decision-making, at least for post-hoc verification, and providing verifiable results in the case of prior verification. It can also prevent the leakage of IP knowledge or confidential data when the process is operating normally (i.e., the process does not violate predetermined key performance indicators), and also prevent leakage when analysis or limited analysis is performed in the event of violations or deviations. Furthermore, it enables collaboration with third-party data providers to provide partial root cause analysis (e.g., post-hoc analysis) and to provide action recommendations based on confidential data from IP-protected applications.

[0080] According to a sixth aspect, a computer program product including instructions that, when executed by a computing system, cause or enable the computing system to perform the method of the first aspect. The computer program product may include a computer-readable medium containing the instructions of the computer program product.

[0081] The advantages of the computer program product according to the sixth aspect are that it can contribute to providing enhanced traceability of information flow and algorithmic decision-making, at least for post-hoc verification, and providing verifiable results in the case of prior verification. It can also prevent the leakage of IP knowledge or confidential data when the process is operating normally (i.e., the process does not violate predetermined key performance indicators), and also prevent leakage when performing analysis or limited analysis in the event of violations or deviations. Furthermore, it enables collaboration with third-party data providers to provide partial root cause analysis (e.g., post-hoc analysis) and to provide action recommendations based on confidential data from IP-protected applications.

[0082] According to the seventh aspect, there is use for at least one of the data processing apparatus of the second aspect, the data processing system of the third aspect, the industrial plant of the fourth aspect, the computer-readable medium of the fifth aspect, and the computer program product of the sixth aspect.

[0083] The advantage of the seventh application is that it can contribute to providing enhanced traceability of information flow and algorithmic decision-making, at least for post-hoc verification, and providing verifiable results in the case of prior verification. It can also prevent the leakage of IP knowledge or confidential data when the process is operating normally (i.e., the process does not violate predetermined key performance indicators), and also prevent leakage when performing analysis or limited analysis in the event of violations or deviations. Furthermore, it enables collaboration with third-party data providers to provide partial root cause analysis (e.g., post-hoc analysis) and to provide action recommendations based on confidential data from IP-protected applications.

[0084] The optional features of the first aspect can form part of any one of the second to seventh aspects, with necessary modifications.

[0085] The method of the first aspect can be implemented at least in part by a computer. Preferably, the method of the first aspect is implemented by a computer.

[0086] The fifth aspect is a computer-readable medium on which the computer program product of the sixth aspect can be stored.

[0087] As used herein, the term “acquisition” can include, for example, receiving from another system, device, or process; receiving via interaction with a user; loading or retrieving from a storage device or memory; or measuring or capturing using a sensor or other data acquisition device.

[0088] The indefinite article “a” or “one” does not exclude the plural. Furthermore, the article “a” or “one” as used in this text should generally be interpreted as “one or more” unless otherwise specified or clearly indicated from the context to be in the singular form.

[0089] Unless otherwise specified or clearly stated from the context, the phrases “one or more of A, B, and C,” “at least one of A, B, and C,” and “A, B, and / or C” as used herein are intended to refer to all possible permutations of one or more of the listed items. That is, the phrase “A and / or B” means (A), (B), or (A and B), while the phrase “A, B, and / or C” means (A), (B), (C), (A and B), (A and C), (B and C), or (A and B and C).

[0090] The term "comprising" does not exclude other elements or steps. Furthermore, the terms "comprising," "including," and "having," etc., are used interchangeably herein.

[0091] This invention may include one or more aspects, examples, or features, either individually or in combination, whether specifically disclosed in the combination or individually. Any optional feature or sub-aspect of one of the foregoing aspects is applicable to any other aspect.

[0092] The above aspects will become apparent from the detailed description provided below, and will be clarified by reference. Attached Figure Description

[0093] A detailed description will now be given with reference to the accompanying drawings, by way of example only, in which:

[0094] - Figure 1 The diagram illustrates, according to several examples of this disclosure, the architecture of how a confidential algorithm processes confidential data from multiple products from different suppliers in a trusted execution environment.

[0095] - Figure 2 The diagram illustrates a possible sequence of events that may occur when deviations occur;

[0096] - Figure 3 The illustrations depict process diagrams indicating methods according to several examples of this disclosure; and

[0097] - Figure 4 A schematic diagram illustrating a block diagram of a data processing apparatus according to several examples of this disclosure is shown. Detailed Implementation

[0098] To enable traceability and root cause analysis, this disclosure provides partial insights into applications and data protected by confidentiality measures such as trusted execution environments or other IT security mechanisms. This allows for the interpretation or understanding of specific application behaviors or outcomes (especially in cases of deviations from expected behavior or outcomes) and the implementation of appropriate corrective actions in industrial processes, even when data is stored in an encrypted state and the original plaintext data is not exposed. Because the original data may not be exposed, the insights may be limited to a certain extent.

[0099] According to several examples of this disclosure, measures to achieve such traceability can be integrated into applications, such as fleet management computation modules, which may be at least one of fleet management algorithms, fleet management mathematical models, fleet management physical models, and fleet management machine learning / artificial intelligence (ML / AI) models, as (1) prior verification or allowing (2) post-verification. For example, through the former (i.e., prior verification), the partners involved can verify the legitimacy of the model used by the application (e.g., AI / ML, mathematical, or physical models). Through the latter (i.e., post-verification), additional information and insights, such as decomposed values ​​or the most significant outliers, can be shared if specific “trap conditions” are met (such as key performance indicators (KPIs) exceeding predefined ranges, i.e., violations of predefined ranges (at the first or second end of the range) or asset failures). Such mechanisms may need to be pre-engineered and do not simply expose raw data. With this additional information and insights, industrial processes can be restored to normal behavior while protecting the confidentiality of the data.

[0100] For example, IT security measures can be applied to encrypt data or sign algorithms to ensure the integrity of the executed application.

[0101] It is important to note that this disclosure is not limited to confidential computing applications, but also applies to all situations where raw data is kept confidential and protected to the data owner, while aggregated or selected data items are made available to higher-level users. For example, this applies to the digital twin / Industry 4.0 domain, where parts of the model are confidential and accessible only to the owner, while access to aggregated or selected data is provided to other parts of the model or lifecycle roles.

[0102] Based on several examples from this disclosure, one application area is a sustainability dashboard that displays aggregated values ​​to the end customer, such as the use of RoHS-compliant materials or the CO2 consumption of an entire automated system. This is built upon a potentially long supply chain of information, broken down to individual materials or every manufacturing step from materials to the fully automated system. Other examples might be CO2 emissions tracking, which could be based, for instance, on a digital twin model. Finally, data processing tools, such as streaming engines like ABB's Edgenius streaming engine, are just one example, but not limited to. For instance, it might also be possible to provide algorithms or applications that benefit from aggregated data without exposing the raw data, such as fleet management applications for heterogeneous mobile mining equipment to optimally manage energy, but where the application provider or computing module provider does not allow viewing the supplier's battery status or battery model. Therefore, for example, a problem might arise: what if the battery model is defective / faulty, leading to poor power management decisions and causing trucks in the fleet to break down due to depleted batteries? In all these examples, the algorithms and / or models can be protected, meaning that confidentiality must be maintained in addition to the data. This implies that multiple parties can rely on confidentiality guarantees while still focusing on additional traceability and root cause analysis in the event of deviations from expected behavior.

[0103] Furthermore, according to several examples of this disclosure, the present disclosure is built upon the idea of ​​embedding predetermined thresholds or “traps” (hereinafter referred to as “traps”) within algorithms or platforms that run models (such as AI / ML, mathematical, or physical models). The algorithms, platforms, or models themselves are designed to provide additional insights into the data when a trap is hit (e.g., when some KPIs exceed predefined ranges). These additional insights may need to be sophisticated enough to enable further action in the sense of guiding the technical process back to normal behavior. However, they require sufficient protection to prevent the disclosure of the original data, which may in any case need to remain confidential.

[0104] While trapping methods can allow for posterior root cause analysis or action recommendations—that is, after the bias has occurred—these methods can be combined with other prior methods to ensure a higher level of trust in the information, such as zero-knowledge proofs or remote verification methods, to verify the validity of the model used by the sub-supplier or partner without the sub-supplier or partner revealing the model itself.

[0105] According to several examples in this disclosure, an example of a trap or predetermined KPI threshold could be an excessively high CO2 emissions KPI in a production process sustainability dashboard. This trap can be triggered in two ways: first, using a priori methods; second, using post-hoc methods. For example, in the case of using a priori methods (e.g., utilizing zero-knowledge proofs), any sensor in the platform that uses an invalid model or requires recalibration or recalibration could be flagged. Similarly, remote verification can be used to verify the source of data, the integrity of assets, and the platform processing the data.

[0106] In posterior-based approaches, traps may be triggered or become activated, prompting the algorithm (or more generally, the computational module) to provide insights into further directions for investigation. There are various examples of such traps. The following lists and briefly explains some of them as examples, but is not limited to these.

[0107] According to several examples in this disclosure, selected traps may be applied depending on the individual protection requirements and characteristics of the computing module, algorithm, or data. For example, which trap is applied may depend on the pre-configuration of the confidentiality protection execution environment, such as a trusted execution environment or encryption. The pre-configuration may include the boundaries for triggering the trap and the aggregated data that is allowed to be disclosed if the trap is triggered.

[0108] Examples of “trap boundaries” or predetermined thresholds are as follows:

[0109] • Specific values ​​(e.g., CO2 emissions KPIs in a product process sustainability dashboard) may statistically deviate from previous values ​​by a certain amount, such as 10% from the average of the past 24 hours.

[0110] • Specific values ​​may be higher or lower than predefined boundary values ​​or (upper / lower) thresholds, for example, boiler temperature rising above 80°C or falling below 30°C.

[0111] • Time series data analysis used to detect outliers. For example, missing data or excessively frequent data may indicate a problem with sensors or actuators (e.g., on a platform).

[0112] • Anomaly detection, where correlations between multiple values ​​(e.g., multiple values ​​for the same KPI or different KPIs) may indicate a problem. For example, temperature and pressure values ​​typically rise and fall simultaneously. A trap might be triggered when temperature rises while pressure falls, and vice versa.

[0113] Examples of "trap actions" or processes triggered by a violation of a predetermined threshold are as follows:

[0114] • Reveal the process phase that contributed the most to triggering the trap, such as revealing the process phase that consumed the most carbon dioxide in the past hour if the carbon dioxide emissions tracking triggers the trap.

[0115] • Reveal the process lifecycle phases that contribute the most to triggering traps, such as the lifecycle phases with the most failures in sustainability key performance indicators (KPIs).

[0116] • Reveal the three least sustainable process components or products that contribute the most to triggering the trap within the production process.

[0117] • In the event of an alert, reveal the top ten (aggregated) data points that deviate most from the average value monitored last week.

[0118] • Reveal the identities of those devices that were associated with triggering the alarm and that had the greatest spread in the measured data.

[0119] • After a battery-related problem occurs, disclose the battery status at discrete time points in the battery model so that these values ​​can be roughly verified against expected data, such as in the case of energy management of mobile mining equipment.

[0120] • In case of problems, reveal, for example, the five most influential layers in the ML model, such as energy management that has predicted the last charging decision.

[0121] Such “trap operations” can allow for some initial insight into the biases of conventional “black box” monitoring, enabling further action to be taken depending on the granularity of the information released by the trap.

[0122] Posterior traps can not only provide further data insights, but also offer action recommendations based on confidential ML models. This means that confidential ML models do not reveal any confidential data, while allowing for corrective actions based on previously learned patterns in the event of similar biases.

[0123] See now Figure 1 , Figure 1An architecture diagram or system 100 including a KPI engine 110 is schematically shown. The KPI engine 110 includes a supplier 1 core 120, a supplier 2 core 130, and a company core 140. The KPI engine 110 may include more or fewer supplier cores. For example, supplier 1 core 120 may include company data or first company data associated with a first company (first supplier). The first company data may be protected by a first IT security measure. Company core 140 may include an application or computing module provided by a second company (e.g., an application provider or a computing module provider). This computing module may be protected by a second IT security measure. The computing module from company core 140 may obtain (e.g., access) at least a portion of the first company data to process that portion of the first company data. Sustainability KPIs 150 may be output by the computing module and KPI engine 110 as processing results.

[0124] The data from the first company can be provided by the first company representing the first data provider. For example, such as... Figure 1 As indicated, the first company (the first supplier) can input CO2 data for product X 160 into Supplier 1 Core 120, and can also input CO2 data for product Y 170 into Supplier 1 Core 120. Therefore, the first company's data can include CO2 data for both product X 160 and product Y 170. The calculation module can calculate, for example, KPIs for CO2 emissions for product X and product Y covering several processing steps in the product manufacturing process or product supply chain.

[0125] The KPI engine 110 can represent a platform, or can be provided on a platform. The KPI engine 110 can be provided by a third-party company that can represent the platform provider. The KPI engine 110 can feed KPIs 150 to the customer dashboard.

[0126] Supplier 2 core 130 may include second company data associated with a fourth company (i.e., the second supplier). The second company data may be protected using the same or different IT security measures as the first company.

[0127] See now Figure 2 , Figure 2 The diagram illustrates a series of events that may occur when there is a deviation from the calculated KPI value, such as issuing a problem or alarm for the monitored KPI, or deviating from a predefined trap boundary or reference KPI value. This process, even when using an application or calculation module (e.g., based on...), Figure 1 The second company in the illustrated core 140 processes data provided by a data provider (e.g., according to...). Figure 1Data 160 and 170 provided by the first company illustrated, or according to Figure 1 The data (180) provided by the fourth company illustrated can operate in normal mode with full data protection. Normal mode can also be understood as the initial mode or the first state. Figure 2 In this system, different levels of data confidentiality are indicated by different diamonds: a plain diamond 210 represents full data protection, a tiled diamond 220 represents a lower level of data protection compared to the plain diamond 210, a striped diamond 230 represents a lower level of data protection compared to the tiled diamond 220, and a black diamond 240 represents no data protection. In normal mode, for example, key performance indicator (KPI) data can be calculated with full or maximum data protection based on confidential data provided by different companies or suppliers. During normal mode, predefined thresholds, trap boundaries, or trigger conditions are continuously checked, and if a threshold is violated, a trap boundary is reached, or a trigger criterion is met (e.g., an alarm is issued, or a value is determined to deviate from the average value, including a predetermined number of previous values, by 10% or more), the corresponding trap is triggered or activated. The calculation module can then access additional data, such as... Figure 1 As illustrated, Supplier 1 Core 120 or Supplier 2 Core 130 provides additional data, or the computing module in Company Core 140 switches to a trap mode. This mode can represent a second mode or a second state using the additional data (i.e., the computing module can switch from a first state to a second state, where the first state can be understood as the initial mode or normal mode, and the second state can be understood as a trap mode or a mode that performs more detailed data processing by using data with a lower aggregation level / using data with a higher data exposure level). In this case, as... Figure 2 As indicated by diamonds 220 and 230, most of the supplier data, including all raw data, remains protected, while the data exposure level of the compute module increases slightly due to access to additional data. Depending on the specific trap, the data exposure level of the compute module may vary, meaning that more or less additional data may be provided to the company core 140.

[0128] Therefore, according to several examples of this disclosure, the amount and / or granularity and / or level of data exposure of the additional data are based on traps (the configuration of the traps) or triggering modules (the configuration of the triggering modules). It should be noted that all data (i.e., the original data and the additional data) remains protected, and there is no situation that would lead to the exposure of all data or the lack of confidentiality data protection.

[0129] Based on several examples of this disclosure, and depending on the specific needs of the computing module (e.g., the relationship between the data owner and the supplier), it may be necessary to define in advance and agree upon by both parties (e.g., Company 1 and Company 2) traps that can be implemented or embedded in the computing module and / or KPI engine 110 for specific use cases. The definition of a “trap” can be expressed in natural language, or some machine-readable constraints can be used to simplify the logic following trap triggering. Furthermore, trap actions may need to be coordinated in advance in a technical (or possibly legal) “contract,” such as decrypting portions of the data provider’s (data owner’s) data in an automated or semi-automated (e.g., manually approved) step.

[0130] See now Figure 3 , Figure 3 The diagram illustrates flowcharts of methods according to several examples of this disclosure. These methods are used to provide insights into confidential company data in the context of data discrepancies within an industrial plant.

[0131] This method starts from S300.

[0132] In S310, the method includes processing company data by a computing module in a first processing state, and obtaining KPI values ​​from the processing in S320. The company data is protected by a first IT security measure and associated with processes related to the first company. The computing module is protected by a second IT security measure and associated with a second company. The company data, the first and second IT security measures, and the first and second companies can be as described above. Figure 1 and Figure 2 Overview of company data, first and second IT security measures, and first and second companies.

[0133] In S330, the method includes determining data bias by identifying whether the acquired data violates a predetermined KPI threshold (i.e., whether a predetermined trap has been hit). This determination may include, for example... Figure 2 The diagram shows the boundary of the inspection trap.

[0134] In S340, the method includes: based on a determined result, using a posteriori methods, including providing action recommendations for reducing data bias based on a confidential machine learning model and / or switching the computation module to a second processing state, wherein, compared to the first processing state, the second processing state enables the computation module to perform additional processing related to the company data and provide additional information related to the company data; and / or using a priori methods, including applying zero-knowledge proof methods and / or remote verification methods related to the company data. The use of this method may include, for example... Figure 2 The diagram illustrates the switching and attachment data acquisition.

[0135] The method ends at S350.

[0136] See now Figure 4 , Figure 4 A block diagram schematically illustrating a data processing apparatus 400 according to several examples of the present disclosure is shown. Specifically, according to several examples of the present disclosure, a data processing apparatus 400 is provided for providing insights into confidential corporate data in the context of data discrepancies occurring in an industrial plant. The data processing apparatus 400 includes components configured to perform operations from... Figure 2 Methods and / or exported from Figure 3 The processor 401 of the method. The data processing device 400 can be used as described above. Figures 1 to 3 Overview of the computational modules.

[0137] More specifically, based on various examples, it is configured to execute Figure 3 The data processing apparatus 400 of the method may include a processing circuitry, processing functions, processing components, processing units, or a processor 401, enabling the data processing apparatus 400 to provide insights into confidential corporate data in the context of data discrepancies within an industrial plant. The processor 401 may include one or more processing portions or functions, wherein the processing portions or functions may be provided as one or more physical or virtual entities. The data processing apparatus 400 may include one or more communication interfaces 402. The data processing apparatus 400 may also include a memory or storage unit 403 for storing data, programs, and / or instructions to be executed by the processor. The memory 403 may be internal to the data processing apparatus 400 or external to the data processing apparatus 400, such as in a cloud server. The processor 401 may include one or more portions enabling the data processing apparatus 400 to perform, for example... Figure 3 The method. According to several examples of this disclosure, the processing section 410 can be configured to perform according to Figure 3 This type of processing is performed by S310. Furthermore, the acquisition section 420 can be configured to perform processing based on... Figure 3 This type of acquisition of S320. Furthermore, the determination section 430 can be configured to perform based on... Figure 3 This determination of S330. Part 440 can be configured to perform according to... Figure 3 This type of use of the S340.

[0138] According to several examples of this disclosure, corresponding portions of the data processing apparatus 400 may also be understood as components for performing specific functions.

[0139] According to several examples of this disclosure, a data processing system is provided for providing insights into confidential corporate data in the context of data discrepancies occurring in an industrial plant. The data processing system includes, according to... Figure 4Data processing device 400 and / or for performing according to Figure 2 Export method and / or based on Figure 3 The method is a component. The data processing system can be, for example, as... Figure 1 The illustrated system 100 is of this type.

[0140] According to several examples of this disclosure, an industrial plant is provided, comprising, according to Figure 4 The data processing device 400 and / or the data processing system as described above.

[0141] According to several examples of this disclosure, a computer-readable medium including instructions that, when executed by a computing system, cause the computing system to perform actions from... Figure 2 The method of derivation or based on Figure 3 The method. The computer-readable medium may be temporary or non-temporary, volatile or non-volatile.

[0142] According to several examples of this disclosure, a computer program product including instructions is provided that, when executed by a computing system, cause the computing system to perform actions from... Figure 2 The method or based on the exported from the middle Figure 3 The method. The computer program product may include a computer-readable medium that includes the instructions of the computer program product. The computer-readable medium as mentioned above may store the computer program product thereon.

[0143] According to several examples of this disclosure, there is a use for a data processing apparatus 400, a data processing system as outlined above, an industrial plant as outlined above, a computer-readable medium as outlined above, and / or a computer program product as outlined above.

[0144] according to Figure 3 The method can be implemented, at least in part, by a computer. According to several examples of this disclosure, preferably, according to... Figure 3 The method is implemented by computer.

[0145] according to Figure 3 The optional features of the method may form part of the data processing apparatus 400, the data processing system, the industrial plant, the computer-readable medium, the computer program product and its uses, but necessary modifications are required.

[0146] Any unit, module, circuit system, or method described herein may be implemented using hardware, software, and / or firmware configured to perform any of the operations described herein. Hardware may include one or more processor cores, field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), system-on-a-chip (SoCs), complex programmable logic devices (CPLDs), etc. Software may be embodied as software packages, code, instructions, instruction sets, and / or data recorded on at least one transient or non-transitory computer-readable storage medium. Firmware may be embodied as code, instructions, or instruction sets and / or data hard-coded in a memory device (e.g., a non-volatile memory device).

[0147] If implemented in software, the functionality can be stored on or transmitted through a computer-readable medium as one or more instructions or code. Computer-readable media includes computer-readable storage media. A computer-readable storage medium can be any available storage medium accessible to a computer. For example, and not limitingly, such computer-readable storage media can include FLASH storage media, RAM, ROM, EEPROM, CD-ROM or other optical disc storage devices, disk storage devices or other magnetic storage devices, or any other medium that can be used to carry or store desired program code in the form of instructions or data structures and is accessible to a computer. As used herein, “disk” and “optical disc” include compact optical discs (CDs), laser optical discs, optical discs, digital versatile optical discs (DVDs), floppy disks, and Blu-ray discs (BDs), where disks typically copy data magnetically and optical discs typically copy data optically using lasers. Furthermore, the propagation of signals can also be included within the scope of computer-readable storage media. Computer-readable media also includes communication media, which includes any medium that facilitates the transfer of a computer program from one place to another. For example, a connection can be a communication medium. For example, if software is transmitted from a website, server, or other remote source using coaxial cable, fiber optic cable, twisted pair, digital subscriber line (DSL), or wireless technologies such as infrared, radio, and microwave, then coaxial cable, fiber optic cable, twisted pair, DSL, or wireless technologies such as infrared, radio, and microwave are all included in the definition of communication media. Combinations of the above should also be included within the scope of computer-readable media.

[0148] The applicant hereby individually discloses each individual feature described herein, as well as any combination of two or more such features, provided that such features or combinations can be implemented based on the entire specification and in view of common general knowledge of those skilled in the art, regardless of whether such features or combinations of features solve any problem disclosed herein, and without limiting the scope of the claims. The applicant notes that aspects of the invention can consist of any such individual features or combinations of features.

[0149] It should be noted that embodiments of the present invention are described with reference to different categories. Specifically, some examples are described with reference to methods, while others are described with reference to apparatus. However, those skilled in the art will understand from the specification that, unless otherwise stated, any combination of features related to different categories, in addition to any combination of features belonging to the same category, is also considered to be disclosed in this application. However, all features can be combined to provide a synergistic effect greater than the simple sum of the features.

[0150] While the invention has been detailed and described in the accompanying drawings and foregoing description, these illustrations and descriptions should be considered exemplary rather than limiting. The invention is not limited to the disclosed embodiments. Those skilled in the art will understand and implement other variations of the disclosed embodiments by studying the drawings, the disclosure, and the appended claims.

[0151] The fact that certain measures are stated in mutually different dependent claims does not indicate that a combination of these measures cannot be used advantageously.

[0152] Any reference symbols in the claims should not be construed as limiting the scope.

Claims

1. A method for providing insights into confidential corporate data in the context of data bias within an industrial plant, the method comprising: The company data is processed by the computing module in the first processing state (S310), and the key performance indicator (KPI) values ​​are obtained from the processing (S320). The company data mentioned therein is protected by a first IT security measure and is associated with processes related to the first company; The computing module is protected by a second IT security measure and is associated with a second company; Data deviation is determined (S330) by determining whether the acquired KPI value violates a predetermined KPI threshold; and Based on the determined results Using a (S340) posterior method, the posterior method includes providing action recommendations for reducing data bias based on a confidential machine learning model and / or switching the computing module to a second processing state, wherein, compared to the first processing state, the second processing state enables the computing module to perform additional processing related to the company data and to provide additional information related to the company data; and / or Using (S340) a priori methods, said a priori methods include applying zero-knowledge proof methods and / or remote verification methods related to the company data.

2. The method according to claim 1, further comprising: Embed one or more predetermined KPI thresholds into the calculation module; and Whether the predetermined KPI threshold has been violated is determined based on whether the embedded predetermined KPI threshold has been violated.

3. The method according to claim 1 or 2, further comprising: In the event that the predetermined KPI threshold is determined to be violated The computing module is triggered to execute the switching and / or the application.

4. The method according to any one of claims 1 to 3, wherein switching the computing module to the second processing state comprises: Make additional company data accessible to the computing module, wherein the additional company data is associated with the process related to the first company; as well as The additional company data is processed by the computing module.

5. The method of claim 4, wherein at least a portion of the additional company data is included in the company data, and making the additional company data accessible to the computing module comprises: Transmit at least a portion of the additional company data to the computing module, and / or This enables the computing module to access at least a portion of the additional company data included in the company data.

6. The method of claim 4 or 5, wherein at least a portion of the additional company data is not included in the company data and is protected by a third IT security measure, and making the additional company data accessible to the computing module comprises: Transmit at least a portion of the additional company data to the computing module, and / or This enables the computing module to access at least a portion of the additional company data that is protected by the third IT security means.

7. The method according to any one of claims 1 to 6, wherein switching the computing module to the second processing state comprises: This enables the computing module to execute additional computing methods; as well as The company data and / or the additional company data are processed by using one or more of the additional calculation methods.

8. The method of claim 7, wherein enabling the computing module to perform the additional computing method comprises: This enables the computing module to process the company data and / or the additional company data, and to obtain values ​​for the additional KPIs from the processing.

9. The method according to any one of claims 1 to 8, Wherein at least two of the first IT security measure, the second IT security measure, and the third IT security measure are different from each other, or The first IT security measure, the second IT security measure, and the third IT security measure are the same IT security measures.

10. The method according to any one of claims 1 to 9, wherein protection by at least one of the first IT security means, the second IT security means, and the third IT security means includes at least one of the following: The computing module, the company data, and / or the additional company data are provided in a Trusted Execution Environment (TEE). The company data and / or the additional company data are encrypted; Distributed ledger technology is used to protect the company data and / or the additional company data; Use homomorphic encryption to perform computations on encrypted and / or additional company data without decrypting it; The state of the company data and / or the additional company data is proved using zero-knowledge proofs. Anonymize the company data and / or the additional company data; Obfuscate the company data and / or the additional company data; Authenticate the company data and / or the additional company data; Access control is enforced on the company data and / or the additional company data through attribute-based, role-based, and / or context-based authorization.

11. The method according to any one of claims 1 to 10, One or more of the predetermined posterior methods are associated with one or more corresponding predetermined KPI thresholds, and said methods further include: One or more pre-defined posterior methods are used based on the determined corresponding one or more pre-defined KPI thresholds; and / or One or more predetermined prior methods are associated with one or more corresponding predetermined KPI thresholds, and the method further includes: using one or more predetermined prior methods based on the determined corresponding one or more predetermined KPI thresholds.

12. The method according to any one of claims 1 to 11, further comprising: The computing module is provided on the platform; as well as Receive the company data and / or the additional company data at the platform.

13. A data processing apparatus for providing insights into confidential corporate data in the event of data discrepancies in the context of an industrial plant, the data processing apparatus comprising a processor configured to perform the method according to any one of claims 1 to 12.

14. A computer program product comprising instructions that, when executed by a computing system, cause and / or cause the computing system to perform the method according to any one of claims 1 to 12.

15. A computer-readable medium having a computer program product according to claim 14 stored thereon.