Method, apparatus, system, and product for controlling industrial equipment

By employing layered authentication and two-way encryption mechanisms, the security threats and external access challenges of traditional industrial control systems are resolved, enabling secure and reliable industrial equipment control and convenient remote operation.

CN122268658APending Publication Date: 2026-06-23SIEMENS (CHINA) CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
SIEMENS (CHINA) CO LTD
Filing Date
2026-04-24
Publication Date
2026-06-23

AI Technical Summary

Technical Problem

Traditional industrial control systems face new security threats arising from the deep integration of information technology and operational technology. These threats include unauthorized access and intrusion risks, and external users cannot remotely operate internal network industrial equipment, making it difficult to meet cross-regional management needs.

Method used

Through a layered authentication mechanism, including multi-level authentication of industrial gateways, control servers, and edge nodes, and utilizing industrial security policies and bidirectional transport layer encryption, the trusted transmission and access control of client identity information are ensured.

Benefits of technology

It improves the safety of industrial environments, reduces the risk of unknown control interruptions, enhances accessibility, and enables secure and reliable control of industrial equipment and remote operation capabilities for external users.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122268658A_ABST
    Figure CN122268658A_ABST
Patent Text Reader

Abstract

Embodiments of the present disclosure relate to a method, apparatus, system and product for controlling industrial equipment. The method comprises obtaining a first request from an industrial gateway, the first request comprising an industrial interaction of a client with the industrial equipment and first identity information of the client, the client having passed a first identity authentication process performed by the industrial gateway. The method further comprises performing, by a control server, a second identity authentication process for the client based on the first identity information. The method further comprises in response to the client passing the second identity authentication process, sending a second request to an edge node corresponding to the industrial equipment, the second request comprising the industrial interaction and the first identity information, and the second request being used by the edge node to control the industrial equipment based on the industrial interaction and the first identity information. By implementing embodiments of the present disclosure, multi-layer identity authentication of the industrial interaction of the client with the industrial equipment can be achieved to improve the security of the industrial environment.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] Embodiments of this disclosure generally relate to the field of industrial control, and more specifically to methods, apparatus, systems and products for controlling industrial equipment. Background Technology

[0002] With the rapid development of industrial automation and intelligent manufacturing technologies, industrial control systems have been widely applied in various industrial fields, becoming the core support for realizing automated operation of industrial equipment and centralized control of production processes. Traditional industrial control systems typically consist of a programmable logic controller (PLC), remote terminal units, data acquisition and monitoring networks, actuators, human-machine interface terminals, and a monitoring platform. The various devices in an industrial control system interact and transmit commands via bus or industrial Ethernet to achieve real-time control, status monitoring, fault protection, and production scheduling of industrial equipment. Summary of the Invention

[0003] Embodiments of this disclosure provide a method, apparatus, system, and product for controlling industrial equipment.

[0004] According to a first aspect of this disclosure, a method for controlling industrial equipment is provided. The method includes obtaining a first request from an industrial gateway, the first request including an industrial interaction between a client and the industrial equipment and first identity information of the client, the client having passed a first authentication process performed by the industrial gateway. The method further includes a control server performing a second authentication process on the client based on the first identity information. The method further includes, in response to the client passing the second authentication process, sending a second request to an edge node corresponding to the industrial equipment, the second request including the industrial interaction and the first identity information, and the second request being used by the edge node to control the industrial equipment based on the industrial interaction and the first identity information.

[0005] In this way, embodiments of this disclosure can perform layer-by-layer authentication for clients, enabling only authenticated clients to transmit industrial interactions with industrial equipment further down the chain. This allows edge nodes to achieve secure and reliable control of industrial equipment based on industrial interactions and primary identity information, further improving the security of the industrial environment and reducing the risk of industrial production being interrupted by unknown controls. Furthermore, clients can access industrial equipment without needing to connect to an intranet, enhancing access convenience.

[0006] In some embodiments of the first aspect, the edge node includes an industrial service container for performing industrial services, the industrial service container being determined based on the industrial equipment corresponding to the edge node. In this way, the edge node performs industrial services based on a centralized industrial service container, enabling the integration of traditional industrial equipment into the industrial control system without modifying the traditional industrial equipment itself. Furthermore, determining the industrial service container included in the edge node based on the industrial equipment associated with it improves the adaptability of the edge node to the industrial equipment.

[0007] In some embodiments of the first aspect, the second request is used by the edge node to perform an additional authentication process on the client based on the first identity information. Upon successful authentication by the client, the edge node invokes an industrial service container based on industrial interaction to execute industrial services corresponding to the industrial service container for the industrial equipment. In this way, the industrial control system also authenticates the client based on identity information at the edge node, further realizing layer-by-layer authentication of the client and providing further protection for the secure control of industrial equipment.

[0008] In some embodiments of the first aspect, the industrial service includes at least one of data acquisition, protocol conversion, data preprocessing, data caching, or execution of control commands. In this way, an edge node can control the industrial equipment corresponding to the edge node to perform at least one of the industrial services of data acquisition, protocol conversion, data preprocessing, data caching, or execution of control commands by invoking the industrial service container, thereby enabling industrial interaction with the client.

[0009] In some embodiments of the first aspect, the control server performs a second identity authentication process on the client based on the first identity information, including: utilizing an industrial security policy, the control server performs the second identity authentication process on the client based on the first identity information. In this way, the control server utilizes the industrial security policy to perform the identity authentication process on the client based on the identity information, ensuring that the identity authentication process conforms to the industrial security policy, thereby enabling the identity authentication process to further match industrial application scenarios.

[0010] In some embodiments of the first aspect, the method further includes configuring identity credentials for each client, wherein first identity information is determined based on the client's identity credentials. In this way, the control server issues identity credentials to each client, so that when a client sends an industrial interaction, the identity information associated with the client's identity is also transmitted for authentication by various layers of the industrial equipment, thereby determining whether the client's identity meets the requirements.

[0011] In some embodiments of the first aspect, the industrial gateway and edge nodes are deployed in a distributed manner. In this way, the industrial gateway and edge nodes can be adapted to a wide distribution of clients and industrial equipment, and single points of failure can be avoided; the failure of some nodes does not affect the overall system operation, thus improving system stability and reliability.

[0012] In some embodiments of the first aspect, the industrial gateway and edge node support industrial communication protocols. In this way, the industrial gateway and edge node can be integrated into the industrial control system and transmit data via industrial communication protocols to adapt to industrial application scenarios.

[0013] In some embodiments of the first aspect, the method further includes: acquiring feedback data from an edge node corresponding to the industrial equipment and second identity information of the edge node. The method further includes performing an authentication process on the edge node based on the second identity information. The method further includes sending feedback data to the client in response to the edge node passing the authentication process. In this way, the control server can not only authenticate the client but also authenticate the industrial equipment when it transmits feedback data to the client, achieving bidirectional zero-trust authentication and further improving the communication security of the industrial control system.

[0014] In some embodiments of the first aspect, the first request, the second request, and the feedback data are transmitted encrypted using bidirectional transport layer encryption. In this way, multiple requests are transmitted encrypted using bidirectional transport layer encryption to ensure the confidentiality of multi-layer data transmission, resist various attacks on the transport layer, and thus further improve the security of the industrial control system.

[0015] According to a second aspect of this disclosure, an apparatus for controlling industrial equipment is provided. The apparatus includes a first acquisition module configured to acquire a first request from an industrial gateway, the first request including an industrial interaction between a client and the industrial equipment, and first identity information of the client, the client having passed a first authentication process performed by the industrial gateway. The apparatus also includes a first authentication module configured to have a control server perform a second authentication process on the client based on the first identity information. The apparatus further includes a first sending module configured to, in response to the client passing the second authentication process, send a second request to an edge node corresponding to the industrial equipment, the second request including the industrial interaction and the first identity information, and the second request being used by the edge node to control the industrial equipment based on the industrial interaction and the first identity information. The technical effects of the first aspect of this disclosure also apply to the second aspect.

[0016] According to a third aspect of this disclosure, a system for controlling industrial equipment is provided. The system includes an industrial gateway configured to send a first request, the first request including an industrial interaction between a client and the industrial equipment, and first identity information of the client, the client having passed a first authentication process performed by the industrial gateway. The system also includes a control server configured to receive the first request from the industrial gateway. The control server is further configured to perform a second authentication process on the client based on the first identity information. The control server is also configured to, in response to the client passing the second authentication process, send a second request to an edge node corresponding to the industrial equipment, the second request including the industrial interaction and the first identity information. The system also includes an edge node configured to control the industrial equipment based on the industrial interaction and the first identity information. The technical effects of the first aspect of this disclosure also apply to the third aspect.

[0017] In a fourth aspect of this disclosure, an electronic device is provided, including at least one processor; and a storage device for storing at least one program, which, when executed by the at least one processor, causes the at least one processor to implement the method according to any one of the first aspects of this disclosure. The technical effects of the first aspect of this disclosure also apply to the fourth aspect.

[0018] In a fifth aspect of this disclosure, a computer-readable storage medium is provided having a computer program stored thereon that, when executed by a processor, implements the method according to any one of the first aspects of this disclosure. The technical effects of the first aspect of this disclosure also apply to the fifth aspect.

[0019] In a sixth aspect of this disclosure, a computer program product is provided. This computer program product includes a computer program that, when executed by a processor, implements the method described according to any one of the first aspects of this disclosure. The technical effects of the first aspect of this disclosure also apply to the sixth aspect.

[0020] It should be understood that the content described in this section is not intended to limit the key or essential features of the embodiments of this disclosure, nor is it intended to restrict the scope of this disclosure. Other features of this disclosure will become readily apparent from the following description. Attached Figure Description

[0021] The above and other objects, features and advantages of this disclosure will become more apparent from the accompanying drawings, in which like reference numerals generally denote like parts.

[0022] Figure 1 A schematic diagram illustrating an example environment in which the devices and / or methods of embodiments of the present disclosure may be implemented;

[0023] Figure 2 A flowchart illustrating an example method for controlling industrial equipment according to an embodiment of the present disclosure is shown;

[0024] Figure 3 A schematic diagram of an example of an industrial control system for controlling industrial equipment according to an embodiment of the present disclosure is shown;

[0025] Figure 4 A schematic diagram of an example of an industrial gateway according to an embodiment of the present disclosure is shown;

[0026] Figure 5 A schematic diagram illustrating an example of a transmission request according to an embodiment of the present disclosure is shown;

[0027] Figure 6 A schematic diagram illustrating an example of an edge node according to an embodiment of the present disclosure is shown;

[0028] Figure 7 A schematic block diagram of an apparatus for controlling industrial equipment according to an embodiment of the present disclosure is shown;

[0029] Figure 8 A schematic block diagram of a system for controlling industrial equipment according to an embodiment of the present disclosure is shown;

[0030] Figure 9 A schematic block diagram of an example device suitable for implementing embodiments of the present disclosure is shown.

[0031] In the various figures, the same or corresponding reference numerals indicate the same or corresponding parts.

[0032] List of reference numerals in the attached diagram:

[0033] 102: Control Server

[0034] 104: Industrial Gateway

[0035] 106: First Request

[0036] 108: Client

[0037] 110: Industrial Equipment

[0038] 112: Industrial Interaction

[0039] 114: First Identity Information

[0040] 116: First Identity Authentication Process

[0041] 118: Second Identity Authentication Process

[0042] 120: Edge node

[0043] 122: Second Request

[0044] 202: Receive the first request from the industrial gateway

[0045] 204: The control server performs a second authentication process on the client based on the first identity information.

[0046] 206: In response to the client completing the second authentication process, a second request is sent to the edge node corresponding to the industrial equipment.

[0047] 302: Client

[0048] 304: Client

[0049] 306: Client

[0050] 308: Industrial Gateway

[0051] 310: Industrial Gateway

[0052] 312: Control Server

[0053] 314: Edge Node

[0054] 316: Edge Node

[0055] 318: Edge Node

[0056] 320: Programmable Logic Controller

[0057] 322: Electric motor

[0058] 324: Pressure sensor

[0059] 326: Switch Detector

[0060] 328: Camera

[0061] 402: Industrial Gateway

[0062] 404: Identity Verification

[0063] 406: Policy-based routing

[0064] 408: Load Balancing

[0065] 410: Fault Tolerance and Failover

[0066] 412: Supports multi-region / multi-location deployment

[0067] 414: Centralized Configuration Management

[0068] 416: Control Server

[0069] 502: Client

[0070] 504: Industrial Gateway

[0071] 506: Industrial Control Plane

[0072] 508: Service Mesh Ingress Gateway

[0073] 510: Identity Authentication Module

[0074] 512: Identity Issuance Server

[0075] 514: Core Components for Container Cluster Management

[0076] 516: Industrial Edge Node

[0077] 518: Industrial Equipment

[0078] 602: Industrial Service Containers

[0079] 604: Protocol Conversion Module

[0080] 606: Data Storage and Caching Module

[0081] 608: Real-time Data Acquisition and Monitoring Module

[0082] 610: Data Preprocessing and Edge Computing Module

[0083] 612: Equipment Control and Automation Module

[0084] 614: Equipment Health and Diagnostics Module

[0085] 616: Identity Proxy

[0086] 618: Service Grid Sidecar Agent

[0087] 702: First Acquisition Module

[0088] 704: First Authentication Module

[0089] 706: First Sending Module

[0090] 802: Industrial Gateway

[0091] 804: Control Plane

[0092] 806: Edge node

[0093] 902: CPU

[0094] 904: ROM

[0095] 906: RAM

[0096] 908: Bus

[0097] 910: I / O Interface

[0098] 912: Input Unit

[0099] 914: Output Unit

[0100] 916: Storage unit

[0101] 918: Communication Unit Detailed Implementation

[0102] Embodiments of this disclosure will now be described in more detail with reference to the accompanying drawings. While some embodiments of this disclosure are shown in the drawings, it should be understood that this disclosure can be implemented in various forms and should not be construed as limited to the embodiments set forth herein. Rather, these embodiments are provided to provide a more thorough and complete understanding of this disclosure. It should be understood that the accompanying drawings and embodiments of this disclosure are for illustrative purposes only and are not intended to limit the scope of protection of this disclosure.

[0103] In the description of embodiments of this disclosure, the term "comprising" and similar terms should be understood as open-ended inclusion, i.e., "including but not limited to". The term "based on" should be understood as "at least partially based on". The term "one embodiment" or "the embodiment" should be understood as "at least one embodiment". The terms "first", "second", etc., may refer to different or the same objects. Other explicit and implicit definitions may also be included below.

[0104] As mentioned above, industrial control systems have been widely applied in various industrial sectors, becoming the core technological support for driving the automated operation of industrial equipment and realizing centralized control of production processes. However, with the deep integration of information technology (IT) and operational technology (OT), and the widespread application of remote monitoring, remote maintenance, and distributed edge computing, traditional industrial control systems face increasingly prominent new security threats. These include unauthorized access to industrial services, lateral movement across operational technology networks, and intrusion into industrial equipment.

[0105] To address these issues, some solutions employ firewalls or Virtual Private Networks (VPNs) to build network boundary-based security models, filtering client access requests. However, such solutions have significant drawbacks: once a client bypasses boundary protection and enters the internal network, it is considered a trusted entity and often gains excessive trust and privileges, potentially enabling it to initiate unintended control operations or unauthorized access to industrial control systems, thus posing security risks.

[0106] In addition, some related solutions configure access policies for the internal network, requiring clients or external devices to connect to a designated internal network environment in order to access or control industrial equipment within that environment. However, if the client is located in an external network environment, it cannot directly access, manage, or maintain the industrial equipment from the outside, making it difficult to meet the needs of external users, such as external service providers, for remote operation and cross-regional management of industrial equipment within the internal network.

[0107] Therefore, embodiments of this disclosure propose a method for controlling industrial equipment. The method includes obtaining a first request from an industrial gateway, the first request including an industrial interaction between a client and the industrial equipment, and the client's first identity information, the client having passed a first authentication process performed by the industrial gateway. The method further includes a control server performing a second authentication process on the client based on the first identity information. The method also includes, in response to the client passing the second authentication process, sending a second request to an edge node corresponding to the industrial equipment, the second request including the industrial interaction and the first identity information, and the second request being used by the edge node to control the industrial equipment based on the industrial interaction and the first identity information.

[0108] In this way, embodiments of this disclosure can perform layer-by-layer authentication for clients, enabling only authenticated clients to transmit industrial interactions with industrial equipment further down the chain. This allows edge nodes to achieve secure and reliable control of industrial equipment based on industrial interactions and primary identity information, further improving the security of the industrial environment and reducing the risk of industrial production being interrupted by unknown controls. Furthermore, clients can access industrial equipment without needing to connect to an intranet, enhancing access convenience.

[0109] The embodiments of this disclosure will now be described in further detail with reference to the accompanying drawings. Figure 1 The illustration shows an example environment in which the devices and / or methods of embodiments of the present disclosure may be implemented. In environment 100, the methods of embodiments of the present disclosure may be implemented by a control server 102. Examples of control servers 102 include, but are not limited to, physical servers, industrial computers, embedded control devices, or cloud virtual servers.

[0110] like Figure 1As shown, control server 102 receives a first request 106 from industrial gateway 104. The first request 106 includes an industrial interaction 112 between client 108 and industrial equipment 110, and first identity information 114 of client 108. Industrial interaction 112 instructs client 108 to request control of industrial equipment 110 to perform industrial services. For example, industrial services may include acquiring readings from industrial equipment 110 such as sensors, or controlling industrial equipment 110 such as cameras, motors, or robotic arms to perform corresponding actions. Client 108 includes a client computer or client program. In some embodiments, client 108 has unique credentials, and the first identity information 114 is determined based on client 108's credentials. For example, industrial equipment 110 may include a Programmable Logic Controller (PLC), a Remote Terminal Unit (RTU), a switch detector, a pressure sensor, a camera, a motor, etc. Industrial services include at least one of data acquisition, protocol conversion, data preprocessing, data caching, or execution of control commands. For example, industrial interaction 112 can instruct client 108 to request the pressure sensor to acquire sensor data.

[0111] In some embodiments, the industrial gateway 104 performs a first identity authentication process 116 on the client 108 based on the first identity information 114. For example, the industrial gateway 104 compares the first identity information 114 with a preset list. If it determines that the client 108 belongs to a client included in the preset list, the industrial gateway 104 determines that the client 108 has passed the first identity authentication process 116. Further, if the client 108 has passed the first identity authentication process 116, the industrial gateway 104 sends a first request message to the control server 102. Further, if the client 108 has passed the first identity authentication process 116, the industrial gateway 104 performs authorization verification on the client 108, and only if the authorization verification is successful will the industrial gateway 104 authorize further data transmission. The authorization verification includes determining whether the first identity information 114 conforms to the list of those authorized to access the corresponding industrial services or industrial equipment.

[0112] like Figure 1 As shown, the control server 102 performs a second identity authentication process 118 on the client 108 based on the first identity information 114. In some embodiments, the control server 102 determines the route of the industrial interaction 112 based on the first request 106, and performs the second identity authentication process 118 on the client 108 based on the route. Further, the control server 102 may perform the second identity authentication process 118 on the client 108 based on a predetermined industrial security policy.

[0113] like Figure 1 As shown, in response to client 108 passing the second authentication process 118, control server 102 sends a second request 122 to the edge node 120 corresponding to industrial equipment 110. That is, control server 102 only authorizes further data transmission after confirming that client 108 has passed the second authentication process 118, achieving fine-grained access control over the client. The second request 122 includes industrial interaction 112 and first identity information 114. Furthermore, after client 108 passes the second authentication process 118, control server 102 performs secondary authorization verification on client 108, and only authorizes further data transmission if the authorization verification is successful. The industrial control system can further improve security by performing dual authentication (identity authentication and authorization authentication) at each layer.

[0114] In some embodiments, edge node 120 can control industrial equipment based on industrial interaction 112 and first identity information 114. For example, the industrial interaction instructs client 108 to request to turn on the camera, and client 108 has already passed the first authentication process 116 performed by industrial gateway 104. Control server 102 determines the route of industrial interaction 112 based on the first request 106, and performs a second authentication process 118 on client 108 based on the route and the first identity information 114 to authenticate whether client 108 meets the requirements for allowing camera to be turned on. If client 108 meets the requirements for allowing camera to be turned on, client 108 passes the second authentication process 118. At this time, control server 102 sends a second request 122 to the edge node 120 corresponding to the camera, and the edge node turns on the camera based on the industrial interaction 112 and the first identity information 114 of the second request 122 to perform the industrial service corresponding to industrial interaction 122.

[0115] In industrial environments, access control for client 108 is crucial, as any unauthorized or misrouted operation commands could directly disrupt the physical production process. By performing layer-by-layer identity authentication and authorization for client 108, the risk of industrial production being interrupted by unknown controls can be reduced.

[0116] In this way, embodiments of this disclosure can perform layer-by-layer authentication for client 108, enabling authenticated client 108 to further transmit industrial interactions 112 with industrial equipment 110. This allows edge node 120 to achieve secure and reliable control of industrial equipment 110 based on industrial interactions 112 and first identity information 114, further improving the security of the industrial environment and reducing the risk of industrial production being interrupted by unknown controls. Furthermore, client 108 can access industrial equipment 110 without accessing an intranet, improving access convenience.

[0117] Figure 2 A flowchart of an example method 200 for controlling industrial equipment according to an embodiment of the present disclosure is shown. Figure 2 The process of method 200 shown can be performed in Figure 1 This can be implemented in environment 100 or any other suitable environment. Method 200 can be implemented by... Figure 1 The control server 102 shown is executing.

[0118] In box 202, the control server receives the first request from the industrial gateway. Figure 1 In the illustrated environment, control server 102 receives a first request 106 from industrial gateway 104. The first request 106 includes an industrial interaction 112 between client 108 and industrial equipment 110, and first identity information 114 of client 108. Industrial interaction 112 instructs client 108 to request control of industrial equipment 110 to perform industrial services. Client 108 includes a client computer or client program. In some embodiments, client 108 has unique credentials, and the first identity information 114 is determined based on client 108's credentials. Furthermore, industrial equipment 110 includes a programmable logic controller, a switch detector, a pressure sensor, a camera, a motor, etc. Industrial services include at least one of data acquisition, protocol conversion, data preprocessing, data caching, or execution of control commands. For example, industrial interaction 112 may instruct client 108 to request a pressure sensor to acquire sensor data.

[0119] In some embodiments, the industrial gateway 104 performs a first identity authentication process 116 on the client 108 based on the first identity information 114. For example, the industrial gateway 104 compares the first identity information 114 with a preset list. If it determines that the client 108 belongs to a client included in the preset list, the industrial gateway 104 determines that the client 108 has passed the first identity authentication process 116. Further, if the client 108 has passed the first identity authentication process 116, the industrial gateway 104 sends a first request message to the control server 102. Further, if the client 108 has passed the first identity authentication process 116, the industrial gateway 104 performs authorization verification on the client 108, and only if the authorization verification is successful will the industrial gateway 104 authorize further data transmission. The authorization verification includes determining whether the first identity information 114 conforms to the list of those authorized to access the corresponding industrial services or industrial equipment.

[0120] In box 204, the control server performs a second identity authentication process on the client based on the first identity information. Figure 1 In the illustrated environment, in some embodiments, the control server 102 determines the route for the industrial interaction 112 based on the first request 106, and performs a second authentication process 118 on the client 108 based on the route. Further, the control server 102 may perform the second authentication process 118 on the client 108 based on a predetermined industrial security policy.

[0121] In box 206, in response to the client passing the second authentication process, the control server sends a second request to the edge node corresponding to the industrial equipment. In response to the client 108 passing the second authentication process 118, the control server 102 sends a second request 122 to the edge node 120 corresponding to the industrial equipment 110. That is, the control server 102 only performs further data transmission after confirming that the client 108 has passed the second authentication process 118, achieving fine-grained access control over the client. The second request 122 includes industrial interaction 112 and first identity information 114. Further, after the client 108 passes the second authentication process 118, the control server 102 performs secondary authorization verification on the client 108, and only after successful authorization verification does the control server 102 continue transmitting data to the next node (e.g., the edge node associated with the industrial equipment). The industrial control system can further enhance security by performing dual authentication (identity authentication and authorization authentication) at each layer.

[0122] Edge node 120 can control industrial equipment based on industrial interaction 112 and first identity information 114. For example, industrial interaction 112 instructs client 108 to request to turn on the camera, and client 108 has already passed the first identity authentication process 116 performed by industrial gateway 104. Control server 102 determines the route of industrial interaction 112 based on the first request 106, and performs a second identity authentication process 118 on client 108 based on the route and the first identity information 114 to authenticate whether client 108 meets the requirements for allowing the camera to be turned on. If client 108 meets the requirements for allowing the camera to be turned on, client 108 passes the second identity authentication process 118. At this time, control server 102 sends a second request 122 to the edge node 120 corresponding to the camera. The edge node turns on the camera based on the industrial interaction 112 and the first identity information 114 of the second request 122 to perform the industrial service corresponding to industrial interaction 122.

[0123] In industrial environments, access control for client 108 is crucial, as any unauthorized or misrouted operation commands could directly disrupt the physical production process. By performing layer-by-layer identity authentication and authorization for client 108, the risk of industrial production being interrupted by unknown controls can be reduced.

[0124] In this way, the control server can perform layer-by-layer authentication of clients, ensuring that only authenticated clients can transmit industrial interactions with industrial equipment further down the chain. This allows edge nodes to securely and reliably control industrial equipment based on industrial interactions and initial identity information, further improving the security of the industrial environment and reducing the risk of industrial production being interrupted by unknown controls. Furthermore, clients can access industrial equipment without needing to connect to an intranet, enhancing access convenience.

[0125] In some embodiments, the control server performs a second identity authentication process on the client based on the first identity information, including: utilizing an industrial security policy, the control server performs the second identity authentication process on the client based on the first identity information. In this way, the control server utilizes the industrial security policy to perform the identity authentication process on the client based on the identity information, ensuring that the identity authentication process conforms to the industrial security policy, thereby enabling the identity authentication process to be further matched to industrial application scenarios.

[0126] In some embodiments, the industrial gateway and edge node support industrial communication protocols. In this way, the industrial gateway and edge node can be integrated into the industrial control system and transmit data via industrial communication protocols to adapt to industrial application scenarios.

[0127] In some embodiments, the control server is further configured to acquire feedback data from an edge node corresponding to the industrial equipment, as well as secondary identity information of the edge node. The control server is also configured to perform an authentication process on the edge node based on the secondary identity information. Furthermore, the control server is configured to send feedback data to the client in response to the edge node successfully completing the authentication process. In this way, the control server can not only authenticate the client but also authenticate the industrial equipment when it transmits feedback data to the client, achieving two-way zero-trust authentication and further improving the communication security of the industrial control system.

[0128] In some embodiments, the first request, the second request, and the feedback data are transmitted encrypted using bidirectional transport layer encryption. In this way, multiple requests are transmitted encrypted using bidirectional transport layer encryption to ensure the confidentiality of multi-layered data transmission, resist various attacks at the transport layer, and thus further improve the security of the industrial control system.

[0129] In some embodiments, the control server in an industrial control system can receive a first request from an industrial gateway. This first request includes the client's industrial interaction with the industrial equipment and the client's identity information, wherein the client has already completed the authentication and secure connection establishment process performed by the industrial gateway. The control server can also perform policy-based access control, continuous authentication, and authorization decisions for the client based on the identity information and preset access policies. In response to the client's successful authentication and authorization, the control server can generate a second request and send it to the edge node corresponding to the industrial equipment. This second request includes the industrial interaction and the client's identity information. The edge node can verify the second request based on workload identity mechanisms and secure communication mechanisms, and perform operation processing related to the industrial equipment according to the request. By implementing this approach, multi-layered, dynamic trust authentication and access control for industrial interactions are achieved, improving the security and reliability of the system in the industrial environment without modifying traditional industrial equipment.

[0130] Figure 3 A schematic diagram of an example 300 of an industrial control system for controlling industrial equipment according to an embodiment of the present disclosure is shown. Figure 3As shown, clients 302, 304, and 306 serve as the primary external interaction interfaces for the industrial control system. Industrial engineers, operators, or automated monitoring systems access industrial services or equipment through these interfaces. Clients 302, 304, and 306 can be client computers or client programs. For example, clients may include human-machine interfaces, data acquisition and monitoring applications, maintenance tools, etc. Clients may also include industrial control programs for observing industrial production processes, adjusting parameters, or issuing control commands.

[0131] like Figure 3 As shown, clients 302 and 304 are both connected to industrial gateway 308, and client 306 is connected to industrial gateway 310. In some embodiments, the clients operate outside the industrial control network, and can establish remote connections with the industrial gateways on public or professional networks via Virtual Private Network (VPN) or Transport Layer Security (TLS) encrypted channels. Furthermore, the clients can generate web-based traffic and industrial protocol communications to reflect common operational and monitoring practices in industrial environments. These industrial protocol communications include Modbus TCP, Message Queuing Telemetry Transport (MQTT), etc.

[0132] In some embodiments, industrial gateways 308 and 310 can be industrial Envoy gateways. Industrial gateways 308 and 310, as dedicated industrial access gateways, are deployed at the boundary of the industrial control system to mediate all external access requests to industrial services and industrial equipment within the industrial control system. Industrial gateways 308 and 310 are deployed on physical or virtual industrial edge gateway devices and are adapted to support industrial communication protocols and integrate with traditional gateway devices.

[0133] In some embodiments, the industrial gateways are deployed in a distributed manner. For example, industrial gateway 308 and industrial gateway 310 are deployed on different industrial edge gateway devices. In some embodiments, one industrial gateway can connect to multiple clients. For example, industrial gateway 308 connects to clients 302 and 304. This allows geographically proximate clients to communicate with the same industrial gateway, increasing the reusability of the industrial gateway. Furthermore, a client can connect to multiple industrial gateways. Redundancy in the configuration of multiple industrial gateways can back up client requests to prevent communication interruptions due to the failure of a single industrial gateway. By establishing a multi-layered separation between the client and industrial equipment, including the industrial gateway, control server 312, and edge nodes, the zero-trust industrial control system avoids direct connection between the client and industrial equipment, limiting the impact of compromised or misconfigured clients on the industrial equipment, reducing the likelihood of attacks, and establishing a clear boundary through the industrial gateway where client behavior, access patterns, and protocol usage can be detected and evaluated.

[0134] like Figure 3 As shown, both industrial gateways 308 and 310 are connected to control server 312. In some embodiments, the industrial gateway terminates client requests encrypted with VPN or TLS, and analyzes or decrypts the client requests to obtain client identity information and access request routes, etc. Subsequently, the industrial gateway authenticates the client. For example, industrial gateway 308 can authenticate client 302 and / or client 304. Industrial gateway 310 can authenticate client 306.

[0135] In some embodiments, when the client is authenticated, the industrial gateway generates an encryption request based on the industrial interactions sent by the client and the client's identity information, and sends the encryption request to the server. For example, when client 306 is authenticated by industrial gateway 310, industrial gateway 310 determines the identity information of client 306 based on pre-issued identity credentials of client 306, and generates an encryption request based on the identity information of client 306 and data such as industrial interactions sent by client 306, and sends the encryption request to control server 312.

[0136] In some embodiments, the control server determines the client's identity information based on the encrypted request transmitted by the industrial gateway, and authenticates the client based on the identity information. For example, the control server 312 determines the client 306's identity information based on the encrypted request transmitted by the industrial gateway 310, and authenticates the client 306 based on the identity information.

[0137] like Figure 3As shown, control server 312 connects to edge nodes 314, 316, and 318. After the client sending the industrial interaction performs authentication through the control server, the control server can further send the encryption request to the edge nodes. In some embodiments, the control server can determine the route of the industrial interaction based on the industrial interaction and send the encryption request to the edge node associated with the route based on the route. For example, after client 302 performs authentication through control server 312, the encryption request associated with the industrial interaction sent by client 302 is sent to edge node 316 associated with the industrial interaction route.

[0138] In some embodiments, the control server 312 can also perform protocol-aware analysis on communication traffic to detect abnormal access or illegal communication behavior. In some embodiments, the control server 312 can also achieve secure communication between components within the industrial control system through a two-way authentication communication mechanism between services. In some embodiments, the control server 312 can also perform continuous trust assessment on the access behavior of clients, industrial equipment, and industrial services.

[0139] like Figure 3 As shown, edge node 314 connects to programmable logic controller 320 and motor 322, edge node 316 connects to pressure sensor 324 and switch quantity detector 326, and edge node 318 connects to camera 328. By setting up edge nodes as intermediaries in front of traditional industrial equipment, traditional industrial equipment can be integrated into a zero-trust industrial control system without modification. Each edge node includes multiple industrial service containers.

[0140] In some embodiments, industrial services are encapsulated within an industrial service container, allowing edge nodes to execute these services by invoking the container. Further, the industrial service container included in an edge node can be determined based on the industrial equipment associated with the edge node. For example, edge node 314 is connected to motor 322, so the industrial services encapsulated in the industrial service container of edge node 314 may include controlling the start and stop of the industrial equipment. Edge node 316 is connected to pressure sensor 324 and switch detector 326, so the industrial services encapsulated in the industrial service container of edge node 316 may include controlling the start and stop of the industrial equipment, acquiring data, etc.

[0141] In some embodiments, the edge node performs authentication on the client based on the client's identity information. When the client successfully completes the authentication performed by the edge node, the edge node invokes an industrial service container based on the client's industrial interaction with the industrial equipment to execute the industrial service associated with the control command. For example, if client 306 sends an industrial interaction to control camera 328 to turn on, and the edge node 318 receives an encrypted request from control server 312 containing the industrial interaction and client 306's identity information, it authenticates client 306 based on client 306's identity information. If client 306 successfully completes the authentication performed by edge node 318, edge node 318 invokes an industrial service container to execute the industrial service for controlling camera 328 to turn on.

[0142] Understandably, traffic can also be transmitted from industrial devices sequentially through edge nodes, control servers, and industrial gateways to the client, with authentication required at each layer (e.g., edge node, control server, or industrial gateway). In some embodiments, traffic data transmitted between edge nodes, control servers, and industrial gateways can be encrypted using bidirectional TLS (e.g., mTLS).

[0143] It should be understood that Figure 3 This disclosure merely illustrates the structure of some embodiments of the industrial control system proposed herein; the number and connection relationships of clients, industrial gateways, control servers, edge nodes, and industrial devices are not limited to these examples. Figure 3 limit.

[0144] Figure 4 A schematic diagram of an example 400 of an industrial gateway according to an embodiment of the present disclosure is shown. Figure 4 As shown, the industrial gateway 402 supports identity authentication 404, policy-based routing 406, load balancing 408, fault tolerance and failover 410, multi-region / multi-location deployment support 412, and centralized configuration management 414. In some embodiments, the industrial gateway 402 can determine whether a client's identity meets the requirements by performing identity authentication 404 based on the client's identity information, so as to allow industrial interactions only to clients that meet the requirements. That is to say, the industrial gateway 402 can serve as the main detection and monitoring point of the industrial control system.

[0145] Furthermore, the industrial gateway 402 can also identify unauthorized access attempts, abnormal protocol usage, and access patterns that deviate from expectations before industrial interactions reach the industrial services inside the industrial control system by inspecting connection metadata, client identity information, and industrial protocol characteristics, thereby achieving security detection of the industrial control system.

[0146] like Figure 4As shown, to support geographically distributed industrial deployments, the industrial gateway 402 can support multi-region / multi-site deployments 412. That is, the industrial gateway 402 can be deployed across different network regions or sites. Each industrial gateway 402 acts as a regional access point for nearby clients to achieve load balancing 408, fault tolerance, and network location optimization, while also eliminating single points of failure in remote industrial access.

[0147] In some embodiments, the industrial gateway 402 can support centralized configuration management 414 by integrating with Istio and being performed by the control server 416. For example, the industrial gateway 402 enables centralized configuration management 414 by defining and updating routing rules, authentication behaviors, security policies, and telemetry settings in a unified and declarative manner, ensuring policy consistency, auditability, and compliance with preset requirements across all deployment locations. Through a combination of functions such as industrial protocol conversion, legacy device protection, distributed deployment, and gateway-level authentication, the industrial gateway 402 enables zero-trust industrial control systems to achieve secure, resilient, and scalable access to the edge. Understandably, zero trust refers to requiring authentication before each forwarding of traffic.

[0148] In some embodiments, the method further includes configuring identity credentials for each client, wherein the first identity information is determined based on the client's identity credentials. In this way, the control server issues identity credentials to each client, so that when a client sends an industrial interaction, the identity information associated with the client's identity is also transmitted, allowing for authentication at each layer of the industrial equipment to determine whether the client's identity meets the requirements.

[0149] In some embodiments, the industrial gateway and edge nodes are deployed in a distributed manner. This approach allows the industrial gateway and edge nodes to be adapted to a wide range of clients and industrial devices, and avoids single points of failure; the failure of some nodes does not affect the overall system operation, thus improving system stability and reliability.

[0150] Figure 5 A schematic diagram of an example 500 of a transmission request according to an embodiment of the present disclosure is shown. Figure 5 As shown, client 502 sends a request containing industrial interaction to industrial gateway 504. The request sent by client 502 may be encrypted via VPN or TLS. Industrial gateway 504 authenticates client 502 based on the request, and if the client is successfully authenticated, industrial gateway 504 forwards the traffic containing the request to industrial control plane 506 (e.g., a control server). Further, the traffic forwarded by industrial gateway 504 includes client 502's SPIFFE identity information and industrial interaction.

[0151] likeFigure 5 As shown, the industrial control plane 506 includes a service mesh ingress (Istio) gateway 508, an identity authentication module 510 (e.g., AuthN / AuthZ service), an identity issuing server 512 (e.g., SPIRE server), and a container cluster management core component 514 (e.g., Kubernetes core component), etc. In some embodiments, the industrial control plane 506 includes a Kubernetes control plane. The industrial control plane 506 can serve as a centralized industrial control, security implementation, and management layer between the industrial gateway 504 and distributed industrial edge nodes 516. In addition to traditional container orchestration, the industrial control plane 506 can be adapted to industrial control system environments to serve as a policy decision center, identity authorization center, and coordination node for distributed industrial devices 518. The industrial control plane 506 supports identity-centric access implementation, continuous authentication, and coordination detection across the industrial gateway 504 and industrial edge nodes 516, providing unified resource management and high-availability operation for industrial services of the industrial control system.

[0152] In some embodiments, the Istio gateway 508 can serve as a controlled entry point within the industrial control plane 506, receiving traffic that has been securely terminated and forwarded by the industrial gateway 504. The Istio gateway 508 can perform operations such as protocol-aware routing, access path control, and service management policies. These service management policies include load balancing, rate limiting, and circuit interruption. By providing a unified access policy for web-based interactions and industrial applications, the Istio gateway 508 ensures that all external client requests adhere to consistent industrial security and traffic control requirements when entering the industrial control system, thereby achieving a controlled and secure transition from external access to internal industrial services.

[0153] like Figure 5 As shown, after traffic enters the industrial control plane 506, the industrial control plane 506 will, according to a preset industrial security policy, use the identity authentication module 510 to perform identity authentication and fine-grained access authorization control on the client 502 corresponding to the industrial interaction carried by the traffic. That is, the identity authentication module 510 is used to determine the true identity of the client and whether the client 502 has the right to access the specified industrial service or industrial equipment 518 (e.g., PLC data endpoint or control interface). In some embodiments, the policy decisions and access results of the industrial control plane 506 are recorded and stored in association, providing traceable data support for subsequent security analysis and abnormal access behavior detection.

[0154] like Figure 5As shown, the identity issuing server 512 can act as the identity authority for the workloads of the industrial control system, issuing encrypted identities and credentials (e.g., SPIFFE IDs and TLS credentials) to workloads including clients, industrial service containers, industrial services, and edge nodes according to the SPIFFE standard. By issuing identities to each node, the industrial control system can establish a zero-trust trust domain.

[0155] In some embodiments, the identity issuing server 512 can also provide security for omnidirectional (north-south and east-west) communication within the industrial control system through mTLS encryption with two-way authentication, ensuring the confidentiality and integrity of industrial data and control commands. Centralized identity management and policy-driven access control can eliminate large-scale manual configuration, reducing the long-term costs of secure operation and event response in industrial application environments. Simultaneously, the event streams generated by the identity issuance, update, and revocation of identities by the identity issuing server 512 also provide crucial data input for identity-based monitoring and threat detection mechanisms in the industrial control system.

[0156] like Figure 5 As shown, the container cluster management core component 514 provides cluster management capabilities for the industrial control plane 506, while adapting to the operational requirements of specific industrial sectors. In some embodiments, the container cluster management core component 514 includes an API server, a distributed key-value storage system (e.g., etcd), a scheduler, and a controller manager. In some embodiments, the container cluster management core component 514 performs resource scheduling and policy distribution for the industrial edge nodes 516.

[0157] In some embodiments, the API server serves as a unified interface to receive control commands, configuration update and policy management commands from operators or upper-level industrial control systems. etcd acts as a distributed consistent data store, used for unified management of cluster state to record industrial application deployments, device access policies, and security configurations, thus providing a foundation for reliable collaborative operation in multi-site environments. The scheduler can be used to allocate industrial service containers to the optimal industrial edge nodes 516 based on multi-dimensional resource constraints (e.g., CPU, memory, network bandwidth, GPU) and the characteristics of industrial equipment 518, to meet the performance requirements of industrial services such as data acquisition, real-time control, and edge analytics. The controller manager can be used to continuously monitor the operational status of industrial services and ensure the continuous availability and business continuity of the industrial control system through automated fault handling and abnormal state compensation mechanisms.

[0158] In some embodiments, without modifying traditional industrial equipment (e.g., PLC, RTU), the industrial control system uses SPIRE based on SPIFFE to assign identities to devices and workloads, implements mTLS encrypted communication between services and fine-grained traffic management through Istio sidecars, and forms a collaborative policy execution chain between industrial gateways, industrial edge nodes and industrial control plane 506 to provide dynamic authentication, end-to-end encrypted transmission, real-time anomaly detection and unified auditing capabilities for industrial protocols and data.

[0159] Furthermore, by deploying an industrial control plane 506 adapted to the industrial environment on the intranet, the industrial control system achieves seamless integration of OT devices and IT security mechanisms. While meeting industrial constraints such as real-time performance, protocol diversity, and business continuity, it provides centralized zero-trust protection across domains and sites, significantly improving the security of the industrial edge computing environment.

[0160] In some embodiments, the edge node includes an industrial service container for performing industrial services, the industrial service container being determined based on the industrial equipment corresponding to the edge node. In this way, the edge node performs industrial services based on a centralized industrial service container, enabling the integration of traditional industrial equipment into the industrial control system without modifying the traditional industrial equipment itself. Furthermore, determining the industrial service container contained in the edge node based on the industrial equipment associated with it improves the adaptability of the edge node to the industrial equipment.

[0161] In some embodiments, the second request is used by the edge node to perform an additional authentication process on the client based on the first identity information. If the client passes the additional authentication process, the edge node invokes an industrial service container based on industrial interaction to execute the industrial service corresponding to the industrial service container for the industrial equipment. In this way, the industrial control system also authenticates the client based on identity information at the edge node, achieving a three-layer authentication system performed by the industrial gateway, control server, and edge node on the client, providing further security for the control of industrial equipment.

[0162] In some embodiments, the industrial service includes at least one of data acquisition, protocol conversion, data preprocessing, data caching, or execution of control commands. In this way, an edge node can control the industrial equipment corresponding to the edge node to perform at least one of the industrial services, namely data acquisition, protocol conversion, data preprocessing, data caching, or execution of control commands, by invoking the industrial service container, thereby enabling industrial interaction with the client.

[0163] Figure 6 A schematic diagram of an example 600 of an edge node according to an embodiment of the present disclosure is shown. Figure 6As shown, the industrial edge node is the execution and implementation layer of the industrial control system. The industrial edge node includes at least one industrial service container 602. The industrial service container 602 acts as a logical interface between the Kubernetes environment and traditional industrial equipment.

[0164] In some embodiments, the industrial service container 602 encapsulates drivers and adapters for industrial protocols such as Modbus, OPC UA, Profinet, and MQTT to handle industrial services such as real-time data acquisition, protocol conversion, data preprocessing, caching, and control command execution. For example, the industrial service container 608 may include containers encapsulating industrial services such as a protocol conversion module 604, a data storage and caching module 606, a real-time data acquisition and monitoring module 608, a data preprocessing and edge computing module 610, an equipment control and automation module 612, and an equipment health and diagnostic module 614. By encapsulating industrial services, traditional industrial equipment can be securely connected to a zero-trust, cloud-native industrial control system without modification, achieving seamless integration of traditional industrial equipment with modern cloud-edge architecture.

[0165] like Figure 6 As shown, the industrial edge node also includes an identity agent 616, such as the SPIRE agent, running in the SPIFFE runtime environment. The identity agent 616 runs on each industrial edge node and is used to assign and manage identity credentials for industrial services or devices on the industrial edge node. By conforming to the SPIFFE standard, the identity agent 616 provides strong authentication and fine-grained access control for industrial services, ensuring that only authenticated services can communicate with other devices or services, thereby enhancing the security of the entire industrial control system.

[0166] Through the collaborative operation of industrial service containers, Istio sidecars, and SPIRE agents, industrial edge nodes provide real-time industrial data processing capabilities while implementing zero-trust security policies at locations closest to physical industrial equipment. This combination enables secure integration with traditional industrial equipment, supports scalable edge deployment, and introduces edge-level security detection and policy enforcement capabilities to industrial control systems that are not available in traditional Kubernetes-based industrial control systems.

[0167] like Figure 6As shown, the industrial edge node also includes a service mesh sidecar agent 618, such as the Istio sidecar. The Istio sidecar can be used to implement secure inter-service communication and fine-grained traffic management. In some embodiments, the Istio sidecar can implement mTLS encryption for all data exchanges between the edge service and the industrial control plane to ensure the confidentiality and integrity of industrial production data and control commands during transmission. In some embodiments, the Istio sidecar can also provide traffic routing, load balancing, and deep observability capabilities. These capabilities enable the industrial control system to detect abnormal communication patterns or policy violations on the edge side in real time, and to correlate and uniformly manage these security events with centralized global security policies, thereby building a transparent, highly secure, and auditable communication mesh in complex industrial heterogeneous environments.

[0168] In some embodiments, industrial edge nodes can be specifically designed based on Kubernetes nodes to adapt to the requirements of industrial control system application scenarios. Industrial edge nodes can not only carry containerized workloads but also directly connect to industrial equipment such as PLCs and RTUs, enabling real-time data acquisition, industrial protocol adaptation, and the issuance and execution of safety control commands, thus forming a key hub connecting the information world and physical control.

[0169] In some embodiments, industrial edge nodes are configured to act as intermediary agents for industrial equipment, communicating with the equipment. By setting up industrial edge nodes, industrial control systems can achieve secure access and control over traditional industrial equipment that does not support authentication or secure communication mechanisms, without requiring modifications to the industrial equipment.

[0170] Figure 7 A schematic block diagram of an apparatus 700 for controlling industrial equipment according to an embodiment of the present disclosure is shown. The apparatus 700 includes a first acquisition module 702 configured to acquire a first request from an industrial gateway. The first request includes an industrial interaction between a client and the industrial equipment, and first identity information of the client, which has passed a first authentication process performed by the industrial gateway. The apparatus 700 also includes a first authentication module 704 configured to have a control server perform a second authentication process on the client based on the first identity information. The apparatus 700 further includes a first sending module 706 configured to send a second request to an edge node corresponding to the industrial equipment in response to the client passing the second authentication process. The second request includes the industrial interaction and the first identity information, and is used by the edge node to control the industrial equipment based on the industrial interaction and the first identity information.

[0171] In this way, embodiments of this disclosure can perform layer-by-layer authentication for clients, enabling only authenticated clients to transmit industrial interactions with industrial equipment further down the chain. This allows edge nodes to achieve secure and reliable control of industrial equipment based on industrial interactions and primary identity information, further improving the security of the industrial environment and reducing the risk of industrial production being interrupted by unknown controls. Furthermore, clients can access industrial equipment without needing to connect to an intranet, enhancing access convenience.

[0172] In some embodiments, the edge node includes an industrial service container for performing industrial services, the industrial service container being determined based on the industrial equipment corresponding to the edge node. In this way, the edge node performs industrial services based on a centralized industrial service container, enabling the integration of traditional industrial equipment into the industrial control system without modifying the traditional industrial equipment itself. Furthermore, determining the industrial service container contained in the edge node based on the industrial equipment associated with it improves the adaptability of the edge node to the industrial equipment.

[0173] In some embodiments, the second request is used by the edge node to perform an additional authentication process on the client based on the first identity information. If the client passes the additional authentication process, the edge node invokes an industrial service container based on industrial interaction to execute industrial services corresponding to the industrial service container for the industrial equipment. In this way, the industrial control system also authenticates the client based on identity information at the edge node, further realizing layer-by-layer authentication of the client and providing further security for the control of industrial equipment.

[0174] In some embodiments, the industrial service includes at least one of data acquisition, protocol conversion, data preprocessing, data caching, or execution of control commands. In this way, an edge node can control the industrial equipment corresponding to the edge node to perform at least one of the industrial services, namely data acquisition, protocol conversion, data preprocessing, data caching, or execution of control commands, by invoking the industrial service container, thereby enabling industrial interaction with the client.

[0175] In some embodiments, the device 700 further includes a second authentication module configured to utilize industrial security policies, allowing the control server to perform a second identity authentication process on the client based on the first identity information. In this way, the control server utilizes industrial security policies to perform the identity authentication process on the client based on the identity information, ensuring that the identity authentication process conforms to the industrial security policies, thereby enabling the identity authentication process to further match industrial application scenarios.

[0176] In some embodiments, the device 700 further includes an identity configuration module configured to configure identity credentials for each client, wherein first identity information is determined based on the client's identity credentials. In this way, the control server issues identity credentials to each client, so that when a client sends an industrial interaction, the identity information associated with the client's identity is also transmitted for authentication by various layers of the industrial equipment, thereby determining whether the client's identity meets the requirements.

[0177] In some embodiments, the industrial gateway and edge nodes are deployed in a distributed manner. This approach allows the industrial gateway and edge nodes to be adapted to a wide range of clients and industrial devices, and avoids single points of failure; the failure of some nodes does not affect the overall system operation, thus improving system stability and reliability.

[0178] In some embodiments, the industrial gateway and edge node support industrial communication protocols. In this way, the industrial gateway and edge node can be integrated into the industrial control system and transmit data via industrial communication protocols to adapt to industrial application scenarios.

[0179] In some embodiments, the device 700 further includes a second acquisition module configured to acquire feedback data from an edge node corresponding to the industrial equipment and second identity information of the edge node. The device 700 also includes a third authentication module configured to perform an authentication process on the edge node based on the second identity information. The device 700 further includes a second sending module configured to send the feedback data to the client in response to the edge node passing the authentication process. In this way, the control server can not only authenticate the client but also authenticate the industrial equipment when it transmits feedback data to the client, achieving bidirectional zero-trust authentication and further improving the communication security of the industrial control system.

[0180] In some embodiments, the first request, the second request, and the feedback data are transmitted encrypted using bidirectional transport layer encryption. In this way, multiple requests are transmitted encrypted using bidirectional transport layer encryption to ensure the confidentiality of multi-layered data transmission, resist various attacks at the transport layer, and thus further improve the security of the industrial control system.

[0181] Figure 8A schematic block diagram of a system 800 for controlling industrial equipment according to an embodiment of the present disclosure is shown. System 800 includes an industrial gateway 802 configured to send a first request, the first request including an industrial interaction between a client and the industrial equipment and first identity information of the client, the client having passed a first authentication process performed by the industrial gateway. The system also includes a control server 804 configured to receive the first request from the industrial gateway. The control server is further configured to perform a second authentication process on the client based on the first identity information. The control server 804 is also configured to send a second request to an edge node corresponding to the industrial equipment in response to the client passing the second authentication process, the second request including the industrial interaction and the first identity information. The system also includes an edge node 806 configured to control the industrial equipment based on the industrial interaction and the first identity information.

[0182] In this way, embodiments of this disclosure can perform layer-by-layer authentication for clients, enabling only authenticated clients to transmit industrial interactions with industrial equipment further down the chain. This allows edge nodes to achieve secure and reliable control of industrial equipment based on industrial interactions and primary identity information, further improving the security of the industrial environment and reducing the risk of industrial production being interrupted by unknown controls. Furthermore, clients can access industrial equipment without needing to connect to an intranet, enhancing access convenience.

[0183] Figure 9 A schematic block diagram of an example device 900 suitable for implementing embodiments of the present disclosure is shown. Figure 1 The control server 102 can be implemented using device 900. As shown, device 900 includes a central processing unit (CPU) 902, which can perform various appropriate actions and processes based on computer program instructions stored in read-only memory (ROM) 904 or loaded from storage unit 916 into random access memory (RAM) 906. RAM 906 can also store various programs and data required for the operation of device 900. CPU 902, ROM 904, and RAM 906 are interconnected via bus 908. Input / output (I / O) interface 910 is also connected to bus 908.

[0184] Multiple components in device 900 are connected to I / O interface 910, including: input unit 912, such as keyboard, mouse, etc.; output unit 914, such as various types of monitors, speakers, etc.; storage unit 916, such as disk, optical disk, etc.; and communication unit 918, such as network card, modem, wireless transceiver, etc. Communication unit 918 allows device 900 to exchange information / data with other devices through computer networks such as the Internet and / or various telecommunications networks.

[0185] The various processes and handling described above, such as method 200, can be executed by processing unit 902. For example, in some embodiments, method 200 can be implemented as a computer software program tangibly contained in a machine-readable medium, such as storage unit 916. In some embodiments, part or all of the computer program can be loaded and / or installed on device 900 via ROM 904 and / or communication unit 918. When the computer program is loaded into RAM 906 and executed by CPU 902, one or more actions of method 200 described above can be performed.

[0186] This disclosure can be a method, apparatus, system, and / or computer program product. A computer program product may include a computer-readable storage medium having computer-readable program instructions loaded thereon for performing various aspects of this disclosure.

[0187] Computer-readable storage media can be tangible devices capable of holding and storing instructions for use by an instruction execution device. Computer-readable storage media can be, for example—but not limited to—electrical storage devices, magnetic storage devices, optical storage devices, electromagnetic storage devices, semiconductor storage devices, or any suitable combination of the foregoing. More specific examples (a non-exhaustive list) of computer-readable storage media include: portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), static random access memory (SRAM), portable compact disc read-only memory (CD-ROM), digital multifunction disc (DVD), memory sticks, floppy disks, mechanical encoding devices, such as punch cards or recessed protrusions storing instructions thereon, and any suitable combination of the foregoing. The computer-readable storage media used herein are not to be construed as transient signals themselves, such as radio waves or other freely propagating electromagnetic waves, electromagnetic waves propagating through waveguides or other transmission media (e.g., light pulses through fiber optic cables), or electrical signals transmitted through wires.

[0188] The computer-readable program instructions described herein can be downloaded from computer-readable storage media to various computing / processing devices, or downloaded via a network, such as the Internet, local area network, wide area network, and / or wireless network, to an external computer or external storage device. The network may include copper transmission cables, fiber optic transmission, wireless transmission, routers, firewalls, switches, gateway computers, and / or edge servers. A network adapter card or network interface in each computing / processing device receives the computer-readable program instructions from the network and forwards them to the computer-readable storage media in the respective computing / processing device.

[0189] Computer program instructions used to perform the operations of this disclosure may be assembly instructions, instruction set architecture (ISA) instructions, machine instructions, machine-dependent instructions, microcode, firmware instructions, status setting data, or source code or object code written in any combination of one or more programming languages, including object-oriented programming languages ​​such as Smalltalk, C++, etc., and conventional procedural programming languages ​​such as the "C" language or similar programming languages. The computer-readable program instructions may execute entirely on the user's computer, partially on the user's computer, as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving a remote computer, the remote computer may be connected to the user's computer via any type of network—including a local area network (LAN) or a wide area network (WAN)—or may be connected to an external computer (e.g., via the Internet using an Internet service provider). In some embodiments, electronic circuitry, such as programmable logic circuitry, field-programmable gate arrays (FPGAs), or programmable logic arrays (PLAs), is personalized by utilizing the status information of the computer-readable program instructions to implement various aspects of this disclosure.

[0190] Various aspects of this disclosure are described herein with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this disclosure. It should be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer-readable program instructions.

[0191] These computer-readable program instructions can be provided to a processing unit of a general-purpose computer, a special-purpose computer, or other programmable data processing apparatus to produce a machine such that, when executed by the processing unit of the computer or other programmable data processing apparatus, they create means for implementing the functions / actions specified in one or more blocks of the flowchart and / or block diagram. These computer-readable program instructions can also be stored in a computer-readable storage medium that causes a computer, programmable data processing apparatus, and / or other device to operate in a particular manner. Thus, the computer-readable medium storing the instructions comprises an article of manufacture that includes instructions for implementing aspects of the functions / actions specified in one or more blocks of the flowchart and / or block diagram.

[0192] Computer-readable program instructions may also be loaded onto a computer, other programmable data processing apparatus, or other device to cause a series of operational steps to be performed on the computer, other programmable data processing apparatus, or other device to produce a computer-implemented process, thereby causing the instructions executed on the computer, other programmable data processing apparatus, or other device to perform the functions / actions specified in one or more boxes of a flowchart and / or block diagram.

[0193] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of the present disclosure. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of an instruction containing one or more executable instructions for implementing a specified logical function. In some alternative implementations, the functions marked in the blocks may occur in a different order than those shown in the drawings. For example, two consecutive blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, may be implemented using a dedicated hardware-based system that performs the specified function or action, or using a combination of dedicated hardware and computer instructions.

[0194] The various embodiments of this disclosure have been described above. These descriptions are exemplary and not exhaustive, nor are they limited to the disclosed embodiments. Many modifications and variations will be apparent to those skilled in the art without departing from the scope and spirit of the described embodiments. The terminology used in this disclosure is chosen to best explain the principles, practical application, or technical improvement of the embodiments in the market, or to enable others skilled in the art to understand the embodiments disclosed herein. Nouns and pronouns relating to persons in this patent application are not limited to specific genders.

Claims

1. A method (200) for controlling industrial equipment, comprising: Obtain a first request (202) from the industrial gateway, the first request including industrial interaction between the client and the industrial equipment and the first identity information of the client, the client having passed the first identity authentication process performed by the industrial gateway; The control server performs a second identity authentication process on the client based on the first identity information (204). as well as In response to the client sending a second request (206) to the edge node corresponding to the industrial equipment through the second identity authentication process, the second request includes the industrial interaction and the first identity information, and the second request is used by the edge node to control the industrial equipment based on the industrial interaction and the first identity information.

2. The method (200) according to claim 1, wherein the edge node includes an industrial service container for performing industrial services, the industrial service container being determined based on industrial equipment corresponding to the edge node.

3. The method (200) according to claim 2, wherein the second request is performed by the edge node to perform an additional identity authentication process on the client based on the first identity information, and if the client passes the additional identity authentication process, the edge node invokes the industrial service container based on the industrial interaction to perform industrial services corresponding to the industrial service container for the industrial equipment.

4. The method (200) according to claim 2, wherein the industrial service includes at least one of data acquisition, protocol conversion, data preprocessing, data caching, or execution of control commands.

5. The method (200) according to claim 1, wherein performing the second identity authentication process (204) on the client based on the first identity information includes: Using industrial security strategies, the second identity authentication process is performed on the client based on the first identity information.

6. The method (200) according to claim 1, further comprising: Each client is configured with identity credentials, and the first identity information is determined based on the client's identity credentials.

7. The method (200) according to claim 1, wherein the industrial gateway and the edge node are deployed in a distributed manner.

8. The method (200) according to claim 1, wherein the industrial gateway and the edge node support industrial communication protocols.

9. The method (200) according to claim 1, further comprising: Obtain feedback data from the edge node corresponding to the industrial equipment and the second identity information of the edge node; The edge node is authenticated based on the second identity information. as well as In response to the edge node completing the authentication process, the feedback data is sent to the client.

10. The method (200) of claim 9, wherein the first request, the second request, and the feedback data are transmitted encrypted using bidirectional transport layer encryption.

11. A device (700) for controlling industrial equipment, comprising: The first acquisition module (702) is configured to acquire a first request from an industrial gateway, the first request including industrial interaction between the client and the industrial equipment and the first identity information of the client, the client having passed the first identity authentication process performed by the industrial gateway; The first authentication module (704) is configured to have the control server perform a second identity authentication process on the client based on the first identity information; as well as The first sending module (706) is configured to send a second request to an edge node corresponding to the industrial equipment in response to the client passing the second identity authentication process. The second request includes the industrial interaction and the first identity information, and the second request is used by the edge node to control the industrial equipment based on the industrial interaction and the first identity information.

12. A system (800) for controlling industrial equipment, comprising: One or more industrial gateways (802) are configured to send a first request, the first request including industrial interaction between one or more clients and one or more industrial devices and first identity information of the one or more clients, the one or more clients having passed a first identity authentication process performed by the one or more industrial gateways; The control server (804) is configured as follows: Obtain the first request from the one or more industrial gateways. A second identity authentication process is performed on the one or more clients based on the first identity information; as well as In response to the one or more clients passing the second identity authentication process, a second request is sent to one or more edge nodes corresponding to the one or more industrial devices, the second request including the industrial interaction and the first identity information; The one or more edge nodes (806) are configured to control the one or more industrial devices based on the industrial interaction and the first identity information.

13. A computer program product comprising computer-executable instructions, wherein the computer-executable instructions are executed by a processor (902) to implement the method according to any one of claims 1 to 10.