Method for configuring system configuration of industrial control system of industrial plant
By employing automated configuration methods and leveraging generative artificial intelligence and retrieval-enhanced generation technology, the time-consuming and error-prone aspects of industrial control system configuration are resolved, enabling efficient and secure system configuration. This approach is suitable for distributed control systems (DCS) and edge devices in industrial plants.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- ABB (SCHWEIZ) AG
- Filing Date
- 2025-11-06
- Publication Date
- 2026-05-12
AI Technical Summary
The configuration process of existing industrial control systems is time-consuming and error-prone, especially in applications with expanded configuration requirements and the NAMUR open architecture NOA, which necessitates effective engineering design for dedicated read/write channels in the DCS.
By acquiring trigger data, configuration data, and approval data, and utilizing generative artificial intelligence (GAI) models and retrieval-enhanced generative intelligence (RAG) technology, the system configuration of industrial control systems (ICS) is automatically configured. This includes selecting script templates and parameterized actions, performing syntax checks and compatibility verification, and ensuring the security and accuracy of the configuration data.
It significantly reduces the risk of configuration errors, improves configuration efficiency, ensures the security and consistency of system configuration, reduces manual intervention, and is suitable for different levels and equipment in industrial plants.
Smart Images

Figure CN122018382A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to a computer implementation method for configuring an industrial control system for configuring an industrial plant, one or more computer program products, and a data processing system. Background Technology
[0002] Industrial control systems (ICS) comprise a combination of hardware and software for a wide range of applications in industrial plants. These applications include, but are not limited to, mining, transportation and processing, chemical manufacturing plants, water and wastewater treatment, power plants, and pharmaceutical plants. ICS are engineered to monitor and manage industrial equipment and processes for specific applications.
[0003] ICS typically encompasses a Distributed Control System (DCS), which is usually comprised of software running on one or more computers. In other words, it's a computerized system that automates existing industrial equipment in an industrial plant, typically used in continuous and / or batch processing. Furthermore, ICS often includes several devices, such as, but not limited to, field devices or industrial equipment (e.g., sensor-actuator-machine, machine controllers, etc.), edge devices (e.g., unified architecture-based user interface devices), and cloud servers. These diverse devices, together with the DCS, constitute the ICS for monitoring and managing the industrial plant. Typically, ICS can include software and hardware from some or all levels of the automation pyramid, including the Information Technology (IT) level and the Operational Technology (OT) level.
[0004] Currently, the configuration of ICS (Integrated Systems and Access Control) systems, including DCS and surrounding systems or devices such as industrial edge devices and field devices, is done manually and on an individual basis for each system or device. This is not only time-consuming but also prone to errors. In addition to improving efficiency in process-related DCS configurations, such as generating control applications, defining function blocks, and managing alarms, it is also necessary to automate the system configuration of the ICS itself. This includes tasks such as exposing signals from the DCS to higher levels of the automation pyramid, asset management tasks, setting appropriate access rights for users within the system, and updating software versions within DCS components.
[0005] The driving force behind this need for extended configuration is the emergence of the NAMUR Open Architecture (NOA), which defines a dedicated read / write channel for the DCS and requires effective engineering in addition to existing control applications (e.g., written in some languages defined in IEC 61131-3). Summary of the Invention
[0006] The subject matter of the independent claims of this disclosure addresses or alleviates at least part of the aforementioned problems or needs, with further examples incorporated in the dependent claims.
[0007] According to one aspect of this disclosure, a computer-implemented method for configuring an industrial control system (ICS) in an industrial plant is provided, the method comprising:
[0008] - Obtain trigger data that indicates a request and / or requirement to configure the ICS system;
[0009] - Obtain configuration data that indicates instructions for configuring the ICS system, which is obtained based on trigger data;
[0010] - Obtain approval data indicating that at least one approved user of the ICS has approved the configuration data; and
[0011] - Configure the ICS system based on configuration data and approval data.
[0012] Therefore, this method can first be triggered by obtaining trigger data. For example, trigger data can be obtained when there is a request to configure the ICS system configuration. This request can come from an ICS user, for example, the user provides user input indicating a request to configure the ICS system configuration using the ICS's hardware input components, such as a computer mouse, keyboard, or similar components. In this regard, "configuring the ICS system configuration" can have several meanings, such as, but not limited to, writing, deleting, and overwriting data. In particular, configuring the ICS system configuration can be used to update, reconfigure, or reconfigure it. For example, a user might be an administrator, or typically a user with the right to grant certain access rights to other users. In this case, such a user might want to change or set the access rights of other users in the ICS, which is why they need to configure or reconfigure the ICS system configuration. Specifically, they might need to add new users and their data and access rights to the ICS system configuration, which may specifically include writing new data at several levels of the ICS system configuration or to its system or device. Alternatively or additionally, trigger data can be obtained when the ICS system configuration needs to be configured. For example, this requirement may occur when the system configuration is in some abnormal state, such as an error state. For example, this state can include, but is not limited to, outdated software components, ICS updates, or hardware changes. In these cases, to resolve abnormal or erroneous system configuration states, trigger data can be generated indicating that the state needs to be resolved. Of course, the trigger data can also indicate or include the state; for example, in addition to indicating that the state should be resolved, it can specify an error or abnormal state. In other words, it may be necessary to reconfigure or reconfigure the ICS system configuration.
[0013] Therefore, in this method, configuration data can be obtained, which indicates instructions for configuring the ICS system configuration. These instructions can accordingly specify how or how to configure, for example, reconfigure the ICS system configuration. Since the configuration data is obtained based on trigger data, it is specifically obtained to configure the ICS system configuration in a manner that addresses requests and / or requirements. In other words, the configuration data is obtained so that it can respond to user requests and / or requirements, for example, by granting requested access in the ICS system configuration, particularly by addressing abnormal or erroneous states of the system configuration, for example, by updating or replacing outdated software. The configuration data can be obtained partially or entirely automatically based on trigger data. This means that obtaining the configuration data may require little or no manual intervention. Conversely, based on trigger data, the method can at least partially or entirely automatically obtain the configuration data, which can address the requests and / or requirements indicated by the trigger data.
[0014] Therefore, in this method, approval data can be obtained, which instructs the ICS's approved users to approve configuration data. To this end, the obtained configuration data can be indicated to one or more ICS approved users, for example, on a computer display or any other user interface of the ICS. For example, a prompt to approve or deny the configuration data can be displayed on the DCS user's computer. User approval means that the user has at least access to the ICS and / or the right to approve the configuration of the ICS system. For this purpose, for example, it may be necessary for the user to authenticate on the ICS, for example, by using login data (e.g., username and password) or any other authentication means, such as, but not limited to, fingerprint authentication, facial recognition, iris recognition, mobile phone, smart card, or similar methods. Specifically, users can be approved, giving them the right to approve the application of configuration data to the configuration of the ICS system. For example, the user can be a control engineer or technician in an industrial plant.
[0015] In all cases, at least one ICS-approved user approves the configuration data, thus generating the obtained approved data in this method. This ensures that only user-approved configuration data is executed to configure the ICS system. While configuration data can be automatically obtained based on trigger data, it will not be executed unless approved by at least one approved user. Therefore, the approval of configuration data adds an additional layer of security before it is applied. Through approval, at least one approved user can verify the correctness of the configuration data before execution. This prevents or at least reduces situations where the way the ICS system configuration is configured, or in other words, modified, could negatively impact the ICS. This is particularly important in industrial plants, where incorrect or faulty configuration can lead to safety risks or errors, which could cause partial or complete shutdowns of the industrial plant with significant consequences.
[0016] Therefore, ICS system configuration is only performed if approval data is obtained and indicates that at least one approving user has approved it. Specifically, approval data is only obtained when at least one or more approving users have approved the configuration data based on the approval rights required by the configuration data and / or ICS, which can be indicated by the configuration data and / or ICS. Otherwise, no approval data will be generated. Instead, disapproval or error data can be generated and displayed to users attempting to approve the configuration data, indicating that the user does not have the approval rights required to approve the configuration data and / or does not have the approval rights or approving user required to approve that particular configuration data. Therefore, if an approving user attempts to approve the configuration data without the required approval rights, disapproval data will be generated instead of approval data.
[0017] Furthermore, the configuration of the ICS system is based on configuration data, meaning that the obtained configuration data is used to configure the ICS configuration system. Configuration of the ICS configuration system typically includes any modifications, deletions, and / or additions to the ICS configuration system at the software and / or hardware levels.
[0018] Using the method of the first aspect of this disclosure, the system configuration of ICS can be performed without requiring users to manually provide instructions to configure different components of ICS individually, thus significantly reducing the risk of errors. Instead, configuration data can be obtained based on trigger data, which allows for system configuration, particularly in a manner at least partially automated, without requiring control engineers or technicians to manually provide system configuration instructions. Nevertheless, these instructions still require review before approval to ensure they do not negatively impact ICS.
[0019] The method of the first aspect is particularly capable of being at least partially or entirely implemented by a computer. This means that at least one, several, or all steps of the method can be performed by a data processing system, which may include one or more data processing devices, which may be in the form of a computer or computing unit and may include one or more processors and data storage devices or memories. Different steps may be performed by the same or different data processing devices of the data processing system. For example, steps such as obtaining trigger data, obtaining configuration data, obtaining approval data, and configuring the system can all be performed by an industrial control system, particularly its data processing system. The data processing system may be a distributed control system (DCS), which, for example, may include one or more data processing devices.
[0020] Typically, an Industrial Automation System (ICS) can include a Data Processing System (DCS), which can be formed by software running on a data processing system; in other words, it is itself a data processing system on which software is executed. The software running on the data processing system enables the automation of industrial equipment in an industrial plant, particularly for industrial equipment used in one or more continuous and / or batch processes. Furthermore, an ICS can also include several types of devices, such as, but not limited to, field devices or industrial equipment (e.g., sensor-actuator-machine, machine controllers, etc.), edge devices, cloud servers (e.g., unified architecture UA servers), and / or similar devices. These diverse devices, together with the DCS, form the ICS for use by users such as control engineers and technicians to supervise and manage the industrial plant. Typically, an ICS can include some or all of the software and hardware at different levels of the automation pyramid.
[0021] In the example, configuration data may include a playbook instance, which may include instructions for configuring the ICS system configuration as actions, or in other words, as tasks, specifically at the IT and OT levels of the ICS. Generally, a playbook can be understood as a repeatable, reusable configuration management software. Such a playbook can be configured with actions or tasks for configuring the IT-level system on multiple devices within the IT-level system. Therefore, if a task needs to be executed more than once, such as granting access to several users over time, a playbook can be used advantageously each time. In particular, a playbook can be used to push new configurations or confirm the configuration of several devices within the system. Typically, a playbook instance refers to an instance of a playbook that is subsequently executed to configure the ICS system. Typically, a playbook or playbook instance can have several "scenes," which may correspond to actions or tasks to be performed on the system. A playbook or playbook instance may also include the order or sequence of these scenes, actions, or tasks. In the current context, a playbook instance can be used to configure the ICS system, where the playbook instance contains instructions for configuring the ICS system as scenes, actions, or tasks. Advantageously, playbook instances are not limited to the IT tier of ICS but can perform actions or tasks at the OT tier to configure ICS. For example, this means that a playbook instance can configure the ICS DCS at the IT tier and also configure one or more field devices, one or more edge devices, and / or one or more cloud servers at the ICS OT tier. Therefore, playbook instances allow the configuration of the entire ICS system across all systems and devices in both the IT and OT tiers / domains of ICS. This eliminates the need to manually configure every system and device of the entire ICS system at each tier / domain.
[0022] In the example, a script template for a script instance can be selected from a script template repository based on trigger data. This repository includes multiple predefined script templates. Therefore, the repository can contain several predefined or previously generated script templates available for selection by the method. Typically, a script template is a reusable template for a scene of a script instance, used to address a request and / or requirement to configure the ICS system at a specific event or point in time. In other words, a template is a reusable part of a script that can be specifically configured to address a specific request and / or requirement to configure the ICS system. On the other hand, a script instance is an instance of a script based on a template and used to configure the ICS system. Specifically, the method may include the step of selecting a script instance from the repository based on trigger data. The step of selecting a script template may precede the step of obtaining the configuration data. This allows script instances to be obtained specifically from a large number of script templates capable of addressing requests and / or requirements for ICS system configuration (e.g., changing user access rights), and many different script templates can be used to perform different actions, such as changing user access rights, updating software, configuring new hardware, etc. Furthermore, this allows for the relatively quick acquisition of optimal template instances, which is particularly advantageous when ICS system configuration needs to be adjusted due to misconfigurations or abnormal states. Moreover, there is no need to manually determine the instructions or actions for configuring the ICS system separately. Instead, these instructions or actions are included as predefined scenes or actions in the script template.
[0023] In the example, a generative artificial intelligence (GAI) model can be used to select a playbook template, specifically employing retrieval-enhanced generative (RAG) techniques. Typically, the GAI model can be pre-trained to select playbook templates from a repository, and / or can be trained at runtime or during use. Generally, the GAI model allows for the rapid selection of a desired or optimal playbook template from available predefined playbook templates based on trigger data. A particularly advantageous approach to playbook template selection is the application of RAG techniques or patterns. Here, a user, such as an ICS, particularly an approved DCS user, or any other user, can chat with the GAI model to select or retrieve the optimal playbook template based on their request and / or requirement, or trigger data. An exemplary process using RAG techniques can begin with an interactive user chat where an ICS user is asked to describe a problem they are encountering. For example, a user could type, "I want to check if all software components in my DCS are the latest version" or "I want to expose the reactor R11 settings via an edge device." Suppose the user enters, "I want to expose the reactor R11 settings via an edge device." Based on the user input and predefined playbooks from the repository, the GAI model can select the most suitable playbook. Furthermore, the GAI model can also consider historical logs of certain scripts' "successful" or "unsuccessful" applications under specific ICS conditions. For example, users can enter "Was this script able to solve a similar problem?" or observe previous system configurations. Additionally, further user input can be extracted via chat functionality. Alternatively, selecting script templates entirely manually from the repository is also possible.
[0024] In the example, a play instance can be based on a selected play template that loads play parameters for ICS system configuration, and actions used to configure the ICS system configuration are parameterized based on these play parameters. Specifically, after selecting a play template, the method can load the play parameters of that play template to generate a play instance from the selected play template and the play parameters. Actions (or scenes or tasks) included in the selected play template are parameterized using play parameters of the ICS system configuration, which may depend on the triggering data and / or on the (current) ICS system configuration. For example, a play template can be a series of actions, specifically parameterized actions. For example, such parameterized actions could be "connect to the OPC UA server at endpoint {opc_ua_endpoint}" or "write the value {value} to the variable node with ID {opc_ua_node_id}". In this example, actions are specified in markup language as an example. Now, the parameterized actions need to be loaded with play parameters, specifically play parameter values. In the example above, the script parameter loaded in the action could be [opc_ua_endpoint="tcp.opc: / / 192.168.1.1:62541"]. In this example, the script template populated with parameters or values is a script instance. The workflow engine can parse this script instance. The workflow engine can execute this script instance to configure the ICS system.
[0025] In this example, a generative artificial intelligence (GAI) model can be used to determine script parameters, specifically employing retrieval-enhanced generative RAG techniques. Typically, the GAI model can be pre-trained to select script templates from a repository and / or can be trained at runtime or during use. Generally, the GAI model allows for the determination of script parameters needed to resolve requests and / or requirements. A particularly advantageous method for determining script parameters is by applying RAG techniques or patterns. Here, a user, such as an ICS, particularly an approved DCS user, or any other user, can chat with the GAI model to determine script parameters. In this case, the user can use a query to the GAI model based on a large language model (LLM) to determine script parameters or their values. The GAI model can be the same as or different from the GAI model used to select the script template. For example, a scene or action in the script template could be “exposing {parameter} of DCS via an edge device.” To configure the ICS system configuration, the correct parameterization of the script template in this example needs to be known. Therefore, the names of the variables to be exposed in the ICS system configuration need to be known. For example, to determine or retrieve this script parameter (value), the LLM-based GAI model can be prompted to perform several application programming interface (API) calls to the ICS system configuration. For example, you could request the GAI model to suggest a list of available tag names, select a tag name from it, and recommend it to the user. Alternatively, you could determine the playbook parameters entirely manually.
[0026] In the example, a generative artificial intelligence (GAI) model can be used to generate script templates for script instances based on trigger data. This GAI model specifically utilizes retrieval-enhanced generative RAG techniques. This GAI model may be the same as or different from other GAI models mentioned in this paper. Therefore, script templates can also be generated specifically based on trigger data, thereby targeting requests and / or requests for configuring the ICS system. This approach can be advantageous when there are no predefined script templates in the repository that can resolve requests and / or requests. However, it can also be advantageous to generate script templates in the repository using a GAI model. For example, entirely new script templates can be proposed based on available primitives (or application goals) on which scripts can operate. For example, troubleshooting some network problems within a DCS node can be performed. Here, an LLM-based GAI model can determine possible solutions from its pre-trained knowledge, such as "reacquire a DHCP lease from the DHCP server". Then, by scanning the scripts and their documents for publicly available actions, a suitable script action is found based on RAG techniques, for example, invoking the task: network.host_re-aquire-dhcp({dhcp_server_hostname}). Under user supervision, a playbook template containing this primitive was created. Additionally, this step can be performed to locate the actual "dhcp_server_hostname" corresponding to the DHCP server in the current ICS system configuration to execute the playbook instance.
[0027] In the example, the method may also include checking the playbook instance before configuring the ICS system configuration. The checks may include one or more of the following: a syntax check of the playbook instance; a predefined set of rules to which one or more checks are applied; and a compatibility check of the playbook instance with one or more constraints and / or one or more states of the ICS system configuration. Advantageously, performing such checks or pre-checks before configuring the ICS system configuration ensures, in addition to approving data, that the ICS system configuration is not configured incorrectly or erroneously. For example, by checking the syntax of the playbook instance, its correctness can be checked before errors occur during the ICS system configuration process. Furthermore, a predefined set of rules can be applied, which may include, for example, more granular checks, such as manual approval that might be required when writing to some Open Platform Communication Unified Architecture (OPC UA) server or device. Additionally, the entire playbook instance may be rejected due to violations of some predefined constraints of the ICS system configuration, such as writing node variables outside a specific allowed range. Alternatively or additionally, script instances may also be rejected based on the current state of the system; for example, operating software (OS) updates may not be applicable when a critical process is running within an industrial plant. Therefore, checking compatibility with the ICS system configuration or the constraints and / or state of the industrial plant before the configuration step allows such rejection to be avoided, and compatible script instances are applied only during acceptable periods for the industrial plant or ICS. Typically, GAI models can also be used to recommend approving users or user approval permissions, such as different approval roles, and can be used to recommend predefined rule sets.
[0028] For example, the system configuration of an ICS can be configured across a distributed control system (DCS) and one or more of the following: at least one field device, at least one edge device, and at least one cloud server. Specifically, the system configuration of an ICS can be configured across three or more or all of the aforementioned components or parts of the ICS. To this end, configuration data can be configured using specific instructions for all these systems or devices within the ICS. In particular, a playbook instance can have actions for all these systems or devices within the ICS. This greatly simplifies the system configuration process because it eliminates the need to manually configure all the different systems or devices within the ICS. For example, when updating the system configuration of an ICS or creating a new user for the ICS, the instructions can be used to update the ICS and / or create the user on all field devices, edge devices, the cloud server, and the DCS. Specifically, configuration can be performed at all levels of the automation pyramid. Furthermore, configuration can also be performed for both information technology (IT) and operational technology (OT) systems or devices.
[0029] In the example, approval data is obtained after checking the approval requirements of the configuration data and / or ICS system configuration against the approval permissions of at least one approving user. Typically, there can be several approving users. Each of these approving users may have the same, similar, or different approval permissions for approving the configuration data that will therefore be executed on the ICS to configure its system configuration. Configuring different ICS system configurations may require different approval permissions. Furthermore, depending on the configuration to be executed on the ICS system configuration, approval from multiple or all users may be required. This approval from multiple users may vary depending on the configuration data. For example, for large, special, specific, or sensitive configurations, approval from two or more users or one or more users with specific approval permissions may be required. On the other hand, for small, ordinary, or non-sensitive configurations, approval from one user or a user with ordinary approval permissions may be sufficient. Therefore, different approving users may have different approval permissions. For example, the approval permissions required to approve configuration data may be defined in the configuration data itself and / or within the ICS or ICS system configuration by approval requirements. By checking the approval requirements against the approval permissions of one or more approving users when receiving an approval request, it can be checked whether the given approval is sufficient to generate approval data, which is obtained in this method. If attempts to approve configuration data, such as template instances, by multiple approving users fail to meet approval requirements, erroneous or unapproved data may be generated instead of approved data. This ensures that significant changes to the ICS system configuration can only come from approving users with high approval authority and / or from multiple approving users, thus ensuring that industrial plants are not damaged or that industrial processes are not interrupted by erroneous configuration data approved by a single user with lower approval authority. Typically, approval requirements can be goal-based. For example, if modifications to the parameters of a proportional-integral-derivative (PID) controller within a DCS are required, approval from a group of "process engineers" with specific approval authority for a particular industrial plant may be necessary. Mandatory changes to the configuration of field devices may require approval from a number of "instrument engineers," etc. Furthermore, additional checks may be required based on the size or increment of the proposed change in the ICS system configuration associated with the configuration data, or approval authority may depend on the size or increment of the proposed change in the ICS system configuration associated with the configuration data. Smaller parameter deviations may require only a smaller list of approvers or often only lower approval requirements compared to large (numerical) or structural changes to the ICS system configuration. Another type of configuration data change can be context-based. Understanding the context in which changes occur is crucial. One example is the structural nature of the change's objective; for instance, changes to a safety subsystem may require different approval or verification procedures compared to changes to a human-machine interface (HMI), such as an operator's screen. Another example is the temporal context. For instance, some changes may not be permitted at night or outside of maintenance windows.These mechanisms can be encoded in proprietary databases or as vendor-specific properties of existing data sources, such as OPC UA servers and their attributes. Once the required list of approvers (the approver chain) or approver roles is determined, the actual approval mechanism may vary, such as sending an email to the on-duty user or operator in the industrial plant or sending a notification to their mobile device or HMI screen. Additionally, if a value needs to be changed during the process, a request verification mechanism in the DCS may be triggered.
[0030] In the example, configuration data can indicate declarative instructions for configuring the ICS system. Typically, these instructions can take any form, such as programming languages, scripting languages, markup languages, or anything else. For example, markup languages such as Extensible Markup Language (XML) or YAML (Ain't Markup Language), domain-specific languages such as Business Process Modeling and Markup (BPMN) or derivatives of IEC 61131 Structured Text Language, or scripting languages such as Python or JavaScript can be used. While imperative instructions or imperative languages are often possible, declarative instructions are more advantageous because they describe even complex goals or tasks in a way that is easy for users to read and understand. Therefore, users can easily inspect the instructions. Furthermore, declarative instructions define what the configuration must accomplish according to the problem domain, rather than describing how to accomplish the configuration of the ICS system. Unlike imperative instructions, such as "increment parameter x by 1", declarative instructions might be, for example, "parameter x should have a value of 4". Additionally, declarative instructions define configurations (e.g., conditions, settings, etc.) independent of the current ICS system configuration, while imperative instructions take the current configuration into account. This allows even complex configurations to be applied in a simple way, without considering the current configuration. No assumptions need to be made about the previous ICS system configuration state. For a playbook instance, the scenes or actions contained within can be expressed declaratively. Furthermore, instructions, scenes, or actions can be idempotent. In this way, instructions or actions describe the desired state of the system and always produce the same result.
[0031] In the example, the instructions for configuration data can be converted into computer-executable code using a generative artificial intelligence (GAI) model. Specifically, the method may include the step of converting instructions into computer-executable code. This step can be performed after obtaining the configuration data and / or after obtaining the approved data and before configuring the ICS system, and the computer-executable code can be used to configure the ICS system. As previously mentioned, the configuration data and its instructions do not necessarily need to be provided in the form of a computer-executable script or programming language, but can also be provided in other forms, such as markup languages, to achieve the advantages described above, such as ease of user understanding. In this case, the language or form of the configuration data can be converted into computer-executable code for execution by the ICS. Specifically, different codes may be required depending on the operating software or programming method of the DCS, field devices, edge devices, cloud servers, etc. Advantageously, particularly for each of the DCS, field devices, edge devices, cloud servers, or generally according to the requirements of the ICS system and devices and depending on the ICS system and devices to be configured within the ICS system configuration, a generative artificial intelligence (GAI) model, such as based on one or more LLMs, can be used to convert the language or form of the configuration data, such as markup languages, into computer-executable code or scripts. Therefore, the GAI model not only has the advantage of typically providing computer-executable code, but also has the advantage of being able to provide the specific scripting or code languages required at different systems or devices in ICS.
[0032] In the example, the method may also include logging the ICS system configuration before configuring the ICS system configuration based on configuration data and approval data. In other words, the ICS system configuration can be logged, specifically its current version before configuration based on configuration data and approval data. This means that at least information about the ICS system configuration that will be affected or changed by subsequent configuration of the ICS system configuration will be logged. Furthermore, the information about the ICS system configuration can be fully logged. For example, a snapshot of the current ICS system configuration can be taken for logging. Additionally, some or more data or information about the current ICS system configuration can be stored. Advantageously, a log of the ICS system configuration changing over time can be generated. Logging is particularly advantageous when using declarative directives because declarative directives cannot trace changes made to the ICS system configuration over time during configuration. Specifically, since the state of the ICS system configuration is often unknown, it is not possible to simply roll back an applied playbook instance; instead, it requires engineering on a case-by-case basis depending on the specific application or for dedicated playbooks. Therefore, when using a logging or auditing logging system, the previous state of the ICS system configuration can be restored. The logs allow viewing the state of the ICS system configuration before subsequent configuration steps. This allows ICS system configurations to be rolled back. This means that, especially when declarative directives, while advantageous, lack traceability, it's possible to configure an earlier ICS system configuration, or in other words, to revert to an earlier ICS system configuration. For example, this method can roll back an ICS system configuration based on logged ICS system configurations after configuring it based on configuration and approval data.
[0033] According to a second aspect of the invention, one or more computer program products including instructions are provided, which, when executed by one or more data processing devices, cause the one or more data processing devices to perform the method of the first aspect of the present disclosure.
[0034] The computer program product(s) may be one or more computer programs themselves, that is, computer programs consisting of or including program code that will be executed by a data processing device, particularly a computer.
[0035] Alternatively, the computer program product may be one or more products such as data storage devices (in particular, computer-readable data storage media) on which the computer program may be stored temporarily or permanently.
[0036] According to a third aspect of this disclosure, a data processing system is provided, configured to perform the methods of the first aspect of this disclosure. For example, the data processing system may be a DCS of an ICS or any other device or system, or a data processing system other than a DCS or an ICS in the general sense.
[0037] It should be noted that the above aspects, examples, and features can be combined with each other, regardless of the aspects involved.
[0038] The foregoing and other aspects of this disclosure will become apparent and will be illustrated with reference to the examples described below. Attached Figure Description
[0039] Reference Figure 1 Further description of exemplary embodiments, Figure 1 A method 100 for configuring the system configuration of an industrial control system 10 using a workflow engine 2 is shown.
[0040] The accompanying drawings are schematic only and are not drawn to scale. In principle, the same or similar parts, elements and / or steps in the drawings are provided with the same or similar reference figures. Detailed Implementation
[0041] Figure 1 An industrial control system ICS10 is schematically shown for controlling an industrial plant (not shown), which can execute one or more industrial processes.
[0042] like Figure 1 As shown, ICS 10 may include several systems and devices. For example, ICS 10 here includes a distributed control system DCS 11, which is a computerized system that automates industrial equipment used in an industrial plant. Such industrial equipment may be field devices 12. Figure 1 As shown, one or more field devices 12 may also be part of ICS 10. In addition, one or more edge devices 13 and / or cloud servers 14 may also be part of ICS 10.
[0043] ICS 10 may have a system configuration, according to which all or some of DCS 11, field devices 12, edge devices 13, and / or cloud servers 14 may currently be configured. Typically, edge devices 13 may be specific IT-based processing units, unlike cloud servers 14, which may be physically installed close to an industrial plant's OT system, for example, within the plant itself. Definitions such as user access rights, software versions, and asset management functions may be part of this system configuration 15. It may now be requested or required that the current system configuration of ICS 10 be configured on all systems and devices (including all or some of DCS 11, field devices 12, edge devices 13, and / or cloud servers 14).
[0044] For this purpose, a computer-implemented method 100 can be executed on a data processing system (not shown), which may have one or more data processing devices and may or may not be part of ICS 10, such as DCS 11. When executed, method 100 can configure or reconfigure the current system configuration 15 based on a request or requirement. Method 100 and the data processing system can use, for example, Figure 1 Workflow Engine 2 is shown. Additionally, as... Figure 1 Steps 101 to 105 and step 110 of method 100 shown can also be executed by a data processing system, for example, by another workflow engine or the same workflow engine 2.
[0045] Specifically, in step 101 of method 100, trigger data can be obtained indicating a request and / or requirement to configure ICS system configuration 15. For example, the request can be provided by user 1 of ICS 10, for example, when they want to create a new user in system configuration 15; or it can be provided by ICS 10 itself, for example, due to an error in the industrial plant or generally due to an error returned by ICS 10, such as DCS 11 or field device 12.
[0046] Triggering data can be achieved in steps 102 and 103 of method 100 to obtain configuration data indicating instructions for configuring system configuration 15. This configuration data can be in the form of script instance 6. To obtain configuration data in the form of script instance 6, in step 102 of method 100, a script template 4 is selected from a script template repository 3, which includes multiple predefined script templates 4. Subsequently, in step 103 of method 100, the selected script template 4 is loaded with script parameters 5 for ICS system configuration 15 and instructions in the form of scenes or actions of script instance 6 to be executed for configuring system configuration 15. Here, script template 4 is parameterized based on script parameters 5. Thus, script instance 6 is obtained.
[0047] In step 104 of method 100, script instance 6 is thus supplied to workflow engine 2 for execution. For example, parameterized actions or instructions of script instance 6 may be provided in a declarative language or as a simple markup language. Therefore, at step 104, before or after this step, the instructions or actions of script instance 6 may be converted into computer-executable code, for example, through a generative artificial intelligence (GAI) model.
[0048] Workflow Engine 2 can execute several steps 105 to 109 of method 100. For example, in step 105, the instruction or action of script instance 6 can be syntax-checked before being applied to the system configuration 15 of ICS. Additionally, in step 106, approval from one or more approving users 1 of ICS 10 can be obtained. After approval, approval data indicating that script instance 6 has been approved can be obtained at step 106. Furthermore, at step 107, one or more predefined rule sets of checks can be applied to script instance 6. Alternatively, or as an alternative to step 107, a compatibility check of script instance 6 with one or more constraints and / or one or more states of ICS system configuration 15 can be performed. Furthermore, at step 108, ICS system configuration 15 can be logged before configuration based on script instance 6.
[0049] Therefore, particularly after steps 106 to 108, script instance 6 can be applied or executed to ICS system configuration 15 to resolve requests and / or requirements indicated by trigger data. For example, script instance 6 could be based on script template 4 to create new users with specific access rights in different systems and devices 11 to 14 of ICS 10, and loaded or parameterized with script parameters 5 to access the correct instances of systems and devices 11 to 14.
[0050] Usually, such as Figure 1As shown, script template 4 can be generated, for example, using the GAI model, via another method 200 or as part of method 100. This template can be stored in the repository 3 and thus used depending on requests and / or requirements for configuring the system configuration 15 of ICS 10.
[0051] While the invention has been illustrated and described in detail in the accompanying drawings and foregoing description, these illustrations and descriptions should be considered exemplary rather than limiting. The invention is not limited to the disclosed embodiments. By studying the drawings, the disclosure, and the claims, those skilled in the art can understand and implement other variations of the disclosed embodiments.
[0052] As used herein, the word “comprising” does not exclude other elements or steps, and the indefinite articles “a” or “an” do not exclude multiple. The fact that certain measures are referenced in mutually different dependent claims does not indicate that a combination of these measures cannot be advantageous. Furthermore, as used herein, when referring to a list of one or more entities, the phrase “at least one” or similar phrases (e.g., “one or more…”) should be understood to mean at least one entity selected from any one or more entities in the entity list, but not necessarily including at least one of every entity specifically listed in the entity list, and does not exclude any combination of entities in the entity list. This definition also allows such an entity to optionally exist outside of the entities specifically identified in the entity list referred to by the phrase “at least one” or similar phrase, regardless of whether it is related to those specifically identified entities. Therefore, as a non-restrictive example, in one example, "at least one of A and B" (or equivalent to "at least one of A or B" or equivalent to "at least one of A and / or B" or equivalent to "one or more of A and B", "one or more of A or B" or "one or more of A and / or B") can refer to at least one, optionally including multiple A's, but without B (and optionally including entities other than B); in another example, it can refer to at least one, optionally including more than one B's, without A's (and optionally including entities other than A's); in yet another example, it can refer to at least one, optionally including more than one A's, and can also refer to at least one, optionally including more than one B's (and optionally including other entities). In other words, the phrases "at least one", "one or more", and "and / or" are open-ended expressions, operationally functioning as both conjunctions and disjunctive words. For example, each of the expressions “at least one of A, B and C”, “at least one of A, B or C”, “one or more of A, B and C”, “one or more of A, B or C” and “A, C and / or B” can mean A alone, B alone, C alone, A and B together, A and C together, B and C together, A, B and C together, and optionally a combination of any of the above with at least one other entity.
[0053] As used herein, the phrase “indicate” can mean, for example, “reflect” and / or “include”. Therefore, an entity, element, and / or step referred to herein as “indicates…” can be used synonymously or interchangeably with one, two, or all of the entities, elements, or steps described as “including…” and “reflecting…”. Furthermore, as used herein, unless otherwise stated, phrases such as “based on,” “related to,” “affected by,” “associated with,” and similar terms should not be limited to the entities, elements, and / or steps they refer to. Rather, unless otherwise stated, these phrases should be understood as inclusive, because, for example, an entity, element, or step referenced by any of these phrases or similar phrases (e.g., “based on” one or another entity, element, or step) does not exclude that the corresponding entity, element, or step may also be or also “based on” any other entity, element, or step besides the one it references.
[0054] As provided herein, the designation of methods and steps as first, second, etc., is intended only to make these methods and their steps refer to and distinguish them from each other. The designation of methods and steps in no way constitutes a limitation on the scope of this disclosure. For example, when this disclosure describes a third step of a method, the first or second step of the method need not be present, nor need to be performed separately before the third step, unless expressly stated that they are essential on their own or precede the third step. Furthermore, the presentation of methods or steps in a particular order is merely intended to facilitate one example of this disclosure and in no way constitutes a limitation on the scope of this disclosure. Generally, these methods and steps can be performed in any feasible order unless an expressly required order is mentioned. Specifically, the terms first, second, third, or (a), (b), (c), etc., in the specification and claims are used to distinguish similar elements and are not necessarily used to describe an order or chronological sequence. It should be understood that the terms thus used are interchangeable where appropriate, and embodiments of the invention described herein can operate in orders other than those described or illustrated herein.
[0055] Any reference symbols in the claims should not be construed as limiting the scope of the claims.
Claims
1. A computer-implemented method (100) for configuring the industrial control system (ICS) system configuration (15) of an industrial control system (ICS) (10) in an industrial plant, the method (100) comprising: - Obtain trigger data, which indicates a request and / or requirement to configure the ICS system configuration (15); - Obtain configuration data, which indicates instructions for configuring the ICS system configuration (15), and the configuration data is obtained based on the trigger data; - Obtain approval data, which indicates the approval of the configuration data by at least one approving user (1) of the ICS (10); as well as - Configure the ICS system configuration (15) based on the configuration data and the approval data.
2. The method (100) according to claim 1, wherein the configuration data includes a script instance (6), the script instance including instructions for configuring the ICS system configuration (15) as an action at the information technology (IT) level and the operational technology (OT) level of the ICS (10).
3. The method (100) according to claim 2, wherein a script template (4) for the script instance (6) is selected from the script template store (3) based on the trigger data, wherein the script template store (3) includes a plurality of predefined script templates (4).
4. The method (100) of claim 3, wherein a generative artificial intelligence (GAI) model is used to select the script template (4), the GAI model specifically employing retrieval-enhanced generative RAG techniques.
5. The method (100) according to claim 3 or 4, wherein the script instance (6) is based on the selected script template (4) which loads script parameters (5) for the ICS system configuration (15), and the action for configuring the ICS system configuration (15) is parameterized based on the script parameters (5).
6. The method (100) according to claim 5, wherein the script parameter (5) is determined using a generative artificial intelligence (GAI) model, wherein the GAI model specifically uses retrieval-enhanced generative RAG technology.
7. The method (100) according to any one of claims 2 to 6, wherein the script template (4) for the script instance (6) is generated based on the trigger data using a generative artificial intelligence (GAI) model, wherein the GAI model specifically uses retrieval-enhanced generative RAG technology.
8. The method (100) according to any one of claims 2 to 7, wherein the method (100) further comprises checking the play instance (6) before configuring the ICS system configuration (15), the check comprising one or more of the following: a syntax check of the play instance (6); a predefined set of rules on which one or more checks are applied to the play instance (6); and a compatibility check of the play instance (6) with one or more constraints and / or one or more states of the ICS system configuration (15).
9. The method (100) according to any one of the preceding claims, wherein the ICS system configuration (15) is configured as a distributed control system (11), DCS, and one or more of the following across the ICS (10): at least one field device (12), at least one edge device (13), and at least one cloud server (14) of the ICS (10).
10. The method (100) according to any one of the preceding claims, wherein the approval data is obtained after checking the approval requirements of the configuration data and / or ICS system configuration (15) against the approval authority of the at least one approving user (1).
11. The method (100) according to any one of the preceding claims, wherein the configuration data indicates declarative instructions for configuring the system configuration (15) of the ICS (10).
12. The method (100) according to any one of the preceding claims, wherein the instructions of the configuration data are converted into computer-executable code by a generative artificial intelligence (GAI) model.
13. The method (100) according to any one of the preceding claims, wherein the method further comprises: Before configuring the ICS system configuration (15) based on the configuration data and the approval data, the ICS system configuration (15) is logged.
14. A computer program product comprising instructions which, when executed by a data processing apparatus, cause the data processing apparatus to perform the method (100) according to any one of the preceding claims.
15. A data processing system configured to perform the method (100) according to any one of claims 1 to 13.