SECURE REMOTE ACCESS FOR CLOUD-BASED INDUSTRIAL AUTOMATION

The cloud-based system addresses the challenges of remote access to industrial automation devices by using MQTT and VPN tunnels for secure connections, ensuring safety and efficiency while supporting legacy systems without costly hardware upgrades.

DE102023210561B4Active Publication Date: 2025-05-08SOFTWARE DEFINED AUTOMATION GMBH
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
DE102023210561
Authority / Receiving Office
DE · DE
Patent Type
Patents
Current Assignee / Owner
Filing Date
2023-10-25
Publication Date
2025-05-08
Estimated Expiration
2043-10-25

AI Technical Summary

Technical Problem

Enabling remote access to industrial automation devices poses challenges due to safety concerns, compatibility with legacy devices, complex network architectures, proprietary communication protocols, and unreliable connectivity, especially in areas with poor network coverage.

Method used

A cloud-based system that uses machine-to-machine communications, such as MQTT, to establish device-specific secure remote access connections via VPN tunnels, allowing manufacturers and engineers to connect securely from a distance without requiring open input ports on industrial automation systems.

Benefits of technology

This solution provides secure, reliable, and efficient remote access to industrial automation devices, including legacy systems, without compromising device safety or production processes, and minimizes the need for expensive hardware upgrades.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000009_0000
    Figure 00000009_0000
  • Figure 00000010_0000
    Figure 00000010_0000
  • Figure 00000011_0000
    Figure 00000011_0000
Patent Text Reader

Abstract

The present disclosure relates to a method for establishing a secure remote access (SRA) connection between a cloud computing system (CCS) and an industrial automation system (IAS), the method comprising: receiving, by an SRA server component of the CCS, a first SRA connection establishment message from a first SRA client of the CCS or from a second SRA client of a user device connected to the CCS;Receiving, by a connection orchestrator component of the CCS, a specification for establishing the SRA connection between the CCS and the IAS; sending, by the connection orchestrator component and based at least in part on the specification, a machine-to-machine network protocol message to a third SRA client of the IAS, which includes information for establishing the SRA connection between the IAS and the CCS; receiving, by the SRA server component of the CCS, a second SRA connection establishment message from the second SRA client of the IAS; and establishing, via the SRA server component, the secure SRA connection between the first SRA client of the CCS and the third SRA client of the IAS, or between the second SRA client of the user device and the third SRA client of the IAS. The present disclosure also relates to a corresponding computer system and a computer program.
Need to check novelty before this filing date? Find Prior Art

Description

1. Technical area

[0001] The present disclosure relates to systems, methods, and software for establishing a secure remote access (SRA) connection between a cloud computing system (CCS) and an industrial automation system (IAS). Such an SRA connection can be used to securely configure industrial controllers of the IAS from the cloud, e.g., via an integrated development environment (IDE) hosted in the cloud and accessible via a web interface. 2. Background

[0002] In today's rapidly evolving manufacturing industry, automation plays a critical role in increasing efficiency and productivity while reducing downtime. To achieve this, remote access to industrial automation equipment is essential, allowing manufacturers to control and update their equipment from anywhere, anytime. However, enabling remote access to automation equipment is often challenging due to various factors, including stringent cybersecurity requirements, proprietary third-party communication protocols, and complex network architectures.

[0003] In this context, US 2021 / 0356944 A1 relates to a system and method for providing centralized management of a software-defined automation (SDA) system. The described SDA system comprises a collection of control nodes and a logically centralized yet physically distributed collection of compute nodes. Furthermore, O. Givehchi, J. Imtiaz, H. Trsek, and J. Jasperneite, "Control-as-a-service from the cloud: A case study for using virtualized PLCs" in 10th IEEE Workshop on Factory Communication Systems, 2014, refer to the concept of implementing a programmable logic control (PLC) as a service within a cloud-based infrastructure and discuss the performance of such cloud-based PLCs relative to legacy PLCs.

[0004] Applicant's WO2023 / 198280 A1 discloses a cloud computing system and an associated method and computer program for configuring and optimizing the performance of industrial automation systems from the cloud.

[0005] US 2022 / 0 103 517 A1 relates to a method for establishing a secure remote connection between a user device and a target device, wherein the target device does not have a direct internet connection. A first gateway receives a first connection request from the user device, wherein the first connection request contains an access token. The access token is validated in an identity and access management service, and after successful validation, a first tunnel is established between the user device and the target device via one or more intermediate gateways. The target device receives a second connection request from the user device, wherein the second connection request contains the access token.A second tunnel is established between the target device and an identity and access management service through the one or more intermediate gateways, and the access token is validated in the identity and access management service through the second tunnel.

[0006] EP 4 366 238 A1 relates to a device that receives a login request from a web browser executed by a client endpoint in a first network. The device provides the web browser with a one-time password that causes the client endpoint to invoke a local handler process associated with an access service executed by the client endpoint or to invoke the web browser's access to a specific uniform resource locator on the device. The device receives a remote connection request from the access service containing the one-time password for accessing a target endpoint in a second network. Based on the remote connection request, the device configures a remote access connection between the client endpoint in the first network and the target endpoint in the second network.

[0007] US 2022 / 0 353 244 A1 concerns systems and methods for privileged remote access to the operational technology (OT) / Internet of Things (IOT) / Industrial IOT (IIOT) / Industrial Control System (ICS) infrastructure implemented in a cloud-based system.The method comprises the following steps: determining the user's security and access policies and creating a session for the user in response to determining that a user can access an application connected to the OT / IOT / IIOT / ICS infrastructure; establishing a secure connection to the application via a lightweight connector connected to the application; and mediating a connection between the user's device and the application via the lightweight connector, thereby enabling the user to interact with the application for the OT / IOT / IIOT / ICS infrastructure based on the user's security and access policies.

[0008] EP 4 369 659 A1 relates to a method that may include receiving configuration data associated with an industrial device via a secure deployment management (SDM) system, identifying a secure deployment management (SDM) node associated with the industrial device via the SDM system, and establishing a secure communication channel between the SDM system and the SDM node using one or more security protocols via the SDM system. The method may also include sending the configuration data via the SDM system to the industrial device via the secure communication channel. The industrial device may receive the configuration data without performing one or more security operations on the configuration data.

[0009] US 2019 / 0 089 741 A1 concerns techniques for a network orchestration and security platform for a network, such as an industrial control system (ICS). These techniques include, for example, methods for characterizing and classifying networked industrial devices based on conversation patterns, generating security zones for networked ICS devices based on conversation characteristics and patterns, identifying and recording networked ICS devices in a non-intrusive manner, and creating secure lines between security zones for networked ICS devices without impacting the endpoint devices and systems therefor. 3. Summary

[0010] The manufacturing industry has undergone significant transformation in recent years, with automation playing a critical role in driving growth and efficiency. Industrial automation devices such as programmable logic controllers (PLCs), sensors, and human-machine interfaces (HMIs) have become increasingly sophisticated and complex, requiring manufacturers to monitor, control, and adjust their production processes in real time. However, with the increasing complexity of the programs running on these devices, the need to connect to them remotely has become essential. Remote access allows manufacturers to troubleshoot issues, perform maintenance, and make adjustments to their equipment from anywhere, anytime. This results in significant cost savings, increased uptime, and improved overall efficiency.

[0011] For example, system integrators working with manufacturers don't have to have their experienced engineer travel on-site. Instead, they can assist their customers remotely, saving costs and reducing their carbon footprint. As a result, manufacturers with their own automation engineering teams can increasingly source PLC engineers worldwide to work remotely, helping them attract rare talent and reduce their own costs. Despite these advantages, enabling remote access to industrial automation equipment can be challenging, requiring secure and reliable connections that don't compromise the safety of equipment or production processes.The connectivity services / systems / methods disclosed herein address such challenges and provide a secure and efficient solution for PLC operators such as manufacturers and machine builders seeking to enable remote access to their industrial automation equipment.

[0012] Enabling remote access to industrial automation equipment presents several challenges for manufacturers. Some of these challenges include: Security concerns: Industrial automation equipment often controls critical production processes, so security is a major concern. Remote access must be secure and not compromise the integrity of the equipment or the production process. Legacy equipment: Many manufacturers have legacy equipment that is not designed to support remote access, making it difficult to enable this functionality without expensive hardware upgrades. Furthermore, these legacy equipment is often unpatched. Network architecture complexity: The architecture of typical operational technology (OT) networks is quite complex due to their specialized nature and unique requirements.Devices are often divided into multiple subnets, and the OT network is separated from the corporate network via a demilitarized zone (DMZ). Proprietary network communication protocols: Many industrial automation devices rely on proprietary software (e.g., Siemens TIA Portal) with proprietary communication protocols, which can make it difficult to establish secure remote connections to all devices using a single solution. Connectivity reliability: Remote access requires reliable and secure connections, which is challenging in areas with poor network coverage or unreliable internet connections. The connectivity services / systems and methods disclosed herein address these challenges by providing a secure solution that enables remote access to industrial automation devices, including legacy devices.The present disclosure enables the use of third-party communication protocols and works with existing devices that meet minimum system requirements to minimize the need for expensive hardware upgrades.

[0013] To address these and similar challenges discussed above, the present disclosure generally provides secure remote access connectivity from cloud-hosted services / applications to factory-level industrial automation devices such as programmable logic controllers (PLCs). The service leverages machine-to-machine communications such as MQTT communications and establishes device-specific secure remote access connections such as VPN tunnels on demand, enabling manufacturers, machine builders, and system integrators to securely connect remotely. All communications can be fully encrypted, and different manufacturers are completely isolated from each other via tenant-specific connectivity host servers. Furthermore, manufacturers can use a dedicated connectivity client on existing gateway devices, minimizing the need to install new and expensive hardware.

[0014] More particularly, in a first aspect, the present disclosure provides a method for establishing a secure remote access (SRA) connection between a cloud computing system (CCS) and an industrial automation system (IAS). The method comprises receiving, by an SRA server component of the CCS, a first SRA connection establishment message from a first SRA client of the CCS or from a second SRA client of a user device connected to the CCS; receiving, by an SRA orchestrator component of the CCS, an indication to establish the SRA connection between the CCS and the IAS; sending, by the SRA orchestrator component and based at least in part on the indication, a machine-to-machine network protocol message to a third SRA client of the IAS comprising information to establish the SRA connection between the IAS and the CCS; receiving, by the SRA server component of the CCS,a second SRA connection establishment message from the third SRA client of the IAS; and establishing, via the SRA server component, the secure SRA connection between the first SRA client of the CCS and the third SRA client of the IAS or between the second SRA client of the user device and the third SRA client of the IAS.

[0015] In this way, the CCS and the IAS can exchange sensitive information such as new or updated PLC code or configurations in a secure and efficient manner without the need for an open input port on the IAS.

[0016] In another aspect, the present disclosure provides a method for configuring an industrial controller of an industrial automation system (IAS) via a cloud computing system (CCS), comprising: generating a control program and / or a control configuration for the industrial controller, establishing a secure remote access (SRA) connection between the CCS and the IAS using the method described above (and in more detail below), and sending, using the established SRA connection, the generated control program and / or the control configuration to the industrial controller.

[0017] In this way, an industrial automation engineer can remotely reconfigure industrial controllers or even remotely complete industrial automation systems without compromising the security of the industrial automation system.

[0018] The present disclosure also relates to a corresponding computer program and a corresponding cloud computing system. Further details and technical advantages are discussed below with reference to the drawings. 4. Brief description of the drawings

[0019] Various aspects and implementation details of the present disclosure are described in more detail below with reference to the accompanying drawings. These drawings show: Fig. 1: a functional block diagram of a cloud computing system for configuring industrial controllers via an SRA connection as disclosed herein. Fig. 2: a functional block diagram of an implementation of a computing system configured to establish an SRA connection with an industrial automation system as disclosed herein. Fig. 3: a process flow diagram of a method for establishing an SRA connection between a CCS and an IAS as disclosed herein. Fig. 4: a process flow diagram of a method for configuring an industrial controller of an IAS using an SRA connection as disclosed herein. Fig. 5: illustrates various options for arranging multiple connectivity clients within a local network. 5. Description of exemplary embodiments

[0020] Below, some example embodiments of the present disclosure are described in more detail with reference to example processes and computer systems. Of course, the computer systems provided by the present disclosure may employ standard hardware components (e.g., cloud computing nodes or servers interconnected via conventional wired or wireless network technology). In some implementations, application-specific hardware may also be employed. Further, such computer systems are configured to execute software instructions (e.g., retrieved from collocated or remote non-volatile memory circuitry) to perform the computer-implemented methods disclosed herein.

[0021] While specific feature combinations are described in the following paragraphs with respect to exemplary embodiments of the present disclosure, it should be understood that not all features of the discussed embodiments need to be present to practice the disclosure defined by the subject matter of the claims. The disclosed embodiments may be modified by combining certain features of one exemplary embodiment with one or more technically and functionally compatible features of other exemplary embodiments.In particular, those skilled in the art will understand that features, components, processing steps, and / or functional elements of an exemplary embodiment may be combined with technically compatible features, processing steps, components, and / or functional elements of any other exemplary embodiment of the present disclosure, as long as they are covered by the specifications as provided by the appended claims.

[0022] Furthermore, the various embodiments discussed herein may be implemented in hardware, software, or a combination thereof. For example, the various components, elements, subsystems, modules, etc., of the systems disclosed herein may also be implemented via application-specific software executing on general-purpose data and signal processing devices such as servers, compute nodes, CPUs, DSPs, and / or systems on a chip, SOCs, or similar components, or any combination thereof. Some implementations also employ application-specific hardware components such as application-specific integrated circuits, ASICs, and / or field-programmable gate arrays, FPGAs, and / or similar components, and / or any combination thereof.For example, the various computing (sub)systems discussed herein may be implemented, at least in part, on general-purpose computing devices such as cloud and / or edge computing servers.

[0023] Fig. 1 shows a functional block diagram illustrating the system architecture, functions, and operation of a cloud computing system (CCS) 110 according to one aspect of the present disclosure. As discussed herein, the cloud computing system 110 may include one or more cloud computing nodes 112, each providing (e.g., virtualized) processing resources 114, storage resources 116, and network resources 118 for cloud-based distributed execution of cloud computing software (not shown). The cloud computing nodes 112 are configured to receive and transmit data from and to controllers 132 of an industrial automation system 130 and, optionally, from and to one or more sensors (not shown) that monitor the operation of the industrial automation system 130, over a network 120 (e.g., an IP-based network such as the Internet). The industrial automation system 130 may also include edge computing devices 134 (e.g.The industrial automation system 130 may include (or be connected to) one or more edge computing nodes executing edge computing software, which may be configured to host virtualized and preferably containerized virtual industrial controllers, as discussed in WO2023 / 198280 A1, which is incorporated herein in its entirety. The industrial automation system 130 may also include hardware-based industrial controllers 132, such as PLCs.

[0024] The virtual and hardware-based controllers of the industrial automation system 130 may be connected to actuators 138 and sensors (not shown) of the industrial automation system 130 via real-time capable industrial automation network technology 136. As also discussed herein, the cloud computing nodes 112 are configured to execute cloud computing software to configure the controllers of the industrial automation system 130 via the network 120 by performing methods as discussed herein. In particular, the network 120 may be used to establish a secure remote access (SRA) connection from the CCS 110 to the IAS 130, as described below with reference to Fig. 3, and to securely (re)configure the IAS using the established SRA connection, as described below with reference to Fig. 4 discussed.

[0025] Fig. 2 illustrates a functional block diagram of an implementation of a computing system configured to establish an SRA connection 205 between a CCS 110 to an IAS 130, e.g., an IAS 130 of a factory or manufacturing facility, as disclosed herein. In a typical use case scenario, a user device 240 remotely operates (e.g., via a web browser 225) a cloud-hosted application software component 215 (e.g., an IDE as a service application), which may include or be operatively coupled to a first SRA client component 220, which in turn may exchange data with an SRA server component 210, as discussed below. Alternatively or additionally, the SRA server component 210 may also exchange data with a second SRA client component 230 on the user device 240.

[0026] The CCS 110 may further include a connection orchestrator component 250 that can exchange data with the application software component 215 and, as discussed below, with a third SRA client component 260 of the IAS, e.g., via a machine-to-machine interface 207 such as an MQTT connection. Alternatively or additionally, the connection orchestrator component 250 may also exchange data with the user device 240, e.g., with a user connectivity service client 270. The IAS 130 may further include a factory connectivity service client 255 (e.g., running on edge computing hardware) and industrial controllers 138 (robot controllers, PLCs, virtual PLCs, etc.). The CCS 110 may thus include means (e.g., implemented in hardware or software, or a combination thereof) to perform methods, as discussed below with reference to Fig. 3 and Fig. 4 discussed.

[0027] Fig. 3 illustrates a process flow diagram of a method for establishing an SRA connection between a CCS 110 and an IAS 130, as discussed above. Step 310 includes receiving, by an SRA server component of the CCS, a first SRA connection establishment message from a first SRA client of the CCS or from a second SRA client of a user device connected to the CCS. Step 320 includes receiving, by a connection orchestrator component of the CCS, an indication to establish the SRA connection between the CCS and the IAS, and step 330 includes sending, by the connection orchestrator component and based at least in part on the indication, a machine-to-machine network protocol message to a third SRA client of the IAS comprising information to establish the SRA connection between the IAS and the CCS.Step 340 includes receiving, by the SRA server component of the CCS, a second SRA connection establishment message from the third SRA client of the IAS. Step 350 includes establishing, via the SRA server component, the secure SRA connection between the first SRA client of the CCS and the third SRA client of the IAS, or between the second SRA client of the user device and the third SRA client of the IAS. In this way, the IAS 130 does not need to include open input ports for establishing the SRA connection between the CCS and the IAS.

[0028] In some implementations, receiving, by the SRA orchestrator component of the CCS, the indication to establish the SRA connection between the CCS and the IAS may include receiving, via an application programming interface, the indication to establish the SRA connection from the user device connected to the CCS, or receiving the indication to establish the SRA connection from an application software component of the CCS used by the user device connected to the CCS. Further, the machine-to-machine network protocol message may include an MQTT message or a similar message.

[0029] Furthermore, the SRA connection may comprise a virtual private network (VPN) connection, and the first, second, and third SRA client components may comprise a VPN client component, and the SRA server component may comprise a VPN server component. In other implementations, the SRA connection may comprise a Secure Shell (SSH) port forwarding connection, and the first, second, and third SRA client components may comprise an SSH client component, and the SRA server component may comprise an SSH server component.In some implementations, the method disclosed herein may further comprise receiving, by the CCS, a request to establish the SRA connection between the CCS and the IAS, and optionally, the SRA server component may comprise a tenant-specific server component, and optionally, the method may further comprise instantiating the SRA server component in response to receiving the request to establish the SRA connection between the CCS and the IAS.

[0030] Fig. Figure 4 illustrates a process flow diagram of a method for configuring an industrial controller of an IAS using an SRA connection, as disclosed herein. Step 410 includes generating a control program and / or control configuration for the industrial controller, and step 420 includes establishing a secure remote access, SRA, connection between the CCS and the IAS using the method as described with reference to Fig. 3. Step 430 includes sending, using the established SRA connection, the generated control program and / or control configuration to the industrial controller (see Fig. 2 for an example system configuration). In some implementations, the method of Fig. 4 further comprise establishing a connection between a user device and an integrated development environment (IDE) of the CCS (e.g., for streaming the IDE in a web browser) and using the IDE to generate the control program and / or the control configuration.

[0031] The secure connectivity service / system / method provided herein enables secure remote access from cloud-hosted automation applications to industrial automation devices at the factory level. The service uses MQTT or similar protocols for basic communication and opens additional encrypted communication channels upon request, such as a device-specific VPN tunnel, for example, to enable remote deployment of program code and / or configurations for industrial controllers, such as PLCs or similar automation equipment. Some of the key features and benefits of the disclosed secure connectivity service include: (1) Secure connections: All communications can be fully encrypted and do not require open input ports. (2) Support for third-party legacy software: The disclosed services support third-party legacy software, allowing manufacturers to continue using their existing software tools. (3) Compatibility with existing gateway devices: Modules of the service disclosed herein can be installed on existing gateway devices, minimizing the need for expensive hardware upgrades. (4) Secure Tenant Isolation: The disclosed services and system architecture (see Fig. 2) enable strict separation of traffic between different tenants within their cloud architecture. A dedicated connectivity host server can be instantiated for each tenant, to which all traffic can be routed. (5) Comprehensive permission management: This disclosure allows manufacturers to have full control over which of their users can access which device. Furthermore, they can allow temporary access for third parties (e.g., system integrators) to make changes to specific devices (e.g., access to only one PLC for a maximum of 3 hours, etc.). (6) No connection from unsecured engineering workstations: The disclosed secure connectivity services / methods / systems allow connections to be restricted only between secure cloud servers and the manufacturer's automation devices. Direct access from unsecured engineering workstations (e.g., those of system integrators) to automation devices can thus be avoided. (7) Multi-protocol support: The connectivity services / methods / systems disclosed herein support multiple communication channels that are opened on demand. For example, multiple PLCs can be accessed and updated using port forwarding, eliminating the need to establish a VPN tunnel to remotely manage these devices. (8) State-of-the-art VPN tunnels on request only: If a VPN tunnel is required to communicate with a specific device, the service opens temporary, device-specific, and encrypted VPN tunnels only on request, so that no permanent VPN connections are established. The VPN technology may be based on WireGuard. (9) Nested Gateway Devices: The disclosed embodiments provide the ability to use nested gateway devices within the local network 136 for enhanced security. In this case, there may be a parent gateway with multiple sub-gateway devices.

[0032] In some implementations, there are multiple options for placing connectivity clients within a given network infrastructure. Important constraints include the ability of the gateway to communicate with the respective automation devices using their proprietary protocols and to have outbound Internet access to selected domains associated with the CCS. For example, a connectivity client can be placed within a demilitarized zone (see Fig.5). In other implementations, the connectivity client can be placed within an OT (sub)network. Users can also deploy multiple gateway instances within their networks (e.g., across different OT subnets to enable nested gateway setups—e.g., a parent client within the DMZ and nested clients within the OT subnets).

Claims

[1] A method for establishing a secure remote access (SRA) connection between a cloud computing system (CCS) (110) and an industrial automation system (IAS) (130), the method comprising: Receiving (310), by an SRA server component (210) of the CCS, a first SRA connection establishment message from a first SRA client (220) of the CCS or from a second SRA client (230) of a user device (240) connected to the CCS; Receiving (320), by a connection orchestrator component (250) of the CCS, an indication to establish the SRA connection between the CCS and the IAS; Sending (330), by the connection orchestrator component and based at least in part on the indication, a machine-to-machine network protocol message to a third SRA client (260) of the IAS comprising information for establishing the SRA connection between the IAS and the CCS; and Receiving (340), by the SRA server component of the CCS, a second SRA connection establishment message from the third SRA client of the IAS; and Establishing (350), via the SRA server component, the secure SRA connection between the first SRA client of the CCS and the third SRA client of the IAS or between the second SRA client of the user device and the third SRA client of the IAS. [2] The method of claim 1, wherein receiving, by the SRA orchestrator component of the CCS, the indication for establishing the SRA connection between the CCS and the IAS comprises: Receiving, via an application programming interface, the indication to establish the SRA connection from the user device connected to the CCS; or Receiving the indication to establish the SRA connection from an application software component of the CCS used by the user device connected to the CCS. [3] The method of claim 1 or 2, wherein the machine-to-machine network protocol message comprises an MQTT message. [4] The method of any one of the preceding claims 1 to 3, wherein the SRA connection comprises a virtual private network (VPN) connection; and wherein the first, second, and third SRA clients comprise a VPN client, and wherein the SRA server component comprises a VPN server component. [5] The method of any one of the preceding claims 1 to 3, wherein the SRA connection comprises a Secure Shell, SSH, port forwarding connection; and wherein the first, second, and third SRA clients comprise an SSH client, and wherein the SRA server component comprises an SSH server component. [6] A method for configuring an industrial controller (132, 134) of an industrial automation system, IAS, (130) via a cloud computing system, CCS, (110), comprising: Generating (410) a control program and / or a control configuration for the industrial control system; Establishing (420) a secure remote access, SRA, connection between the CCS and the IAS using the method according to any one of the preceding claims 1 to 5; and Sending (430), using the established SRA connection, the generated control program and / or the control configuration to the industrial controller. [7] The method of claim 6, further comprising Establishing a connection between a user device and an integrated development environment of the CCS; and Use the integrated development environment to create the control program and / or control configuration. [8] Cloud computing system comprising means for carrying out the method according to any one of the preceding claims 1 to 7. [9] A computer program comprising instructions for carrying out the steps of the method according to any one of the preceding claims 1 to 7 when executed by a cloud computing system.

Citation Information

Patent Citations

  • Web browser-based secure equipment access

    EP4366238A1

  • Facilitating direct device-to-cloud communications within a secure deployment management system

    EP4369659A1

  • Network asset characterization, classification, grouping and control

    US20190089741A1

  • Secure Remote Connections In Industrial Internet Of Things

    US20220103517A1

  • Privileged remote access for OT / IOT / IIOT / ICS infrastructure

    US20220353244A1