Modular and dynamic control of machines in a network

A software-defined edge device with a hypervisor on IPCs forms a modular, scalable, and secure network for beverage and food technology machine lines, addressing complexity, cost, and security issues by distributing workloads and eliminating hardware redundancy.

DE102024107971A1Pending Publication Date: 2025-09-25KRONES AG
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
DE102024107971
Authority / Receiving Office
DE · DE
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-03-20
Publication Date
2025-09-25

AI Technical Summary

Technical Problem

Existing machine installations in beverage and food technology machine lines face increased complexity and cost in network management due to dedicated switches and hardware routers per line, lack of scalability and flexibility, and security vulnerabilities, particularly in 'Bare-2 Metal' configurations.

Method used

Implementing a software-defined edge device on an industrial PC (IPC) with a hypervisor to create a modular, scalable, and secure network architecture, using a honeycomb structure with virtual operating platforms and demilitarized zones, enabling decentralized expansion and dynamic workload distribution among machines.

Benefits of technology

This approach simplifies network management, reduces physical components, enhances security, and lowers costs by eliminating the need for additional hardware, while ensuring flexibility and scalability, and provides robust cybersecurity measures.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

The invention relates to a machine line and a machine in the machine line, in particular in a machine line for filling and packaging food and / or beverages. The machine comprises an industrial PC (IPC) that implements a software-defined edge device for the machine and comprises a hypervisor. The hypervisor provides a virtual operating platform for hosting and / or operating corresponding services for operating the machine line. According to embodiments, the IPC or hypervisor implements a demilitarized zone (DMZ) with its own network segments in which the virtual operating platform is implemented. Furthermore, the IPC can establish a connection to a network of the machine line that interconnects a plurality of machines, each of which comprises an IPC.The IPC is further designed to distribute workloads among the machine and at least one other machine in the machine line network.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] The invention relates to a machine, a machine line and a computer program, a computer-readable storage medium for the modular and dynamic control of machines, in particular machines in a machine line for filling and packaging food and / or beverages.

[0002] In the field of industrial manufacturing, and particularly in the area of ​​beverage and food technology machinery, the integration of network capabilities into these machinery lines has led to significant advances. This development enables improved monitoring, efficiency, and automation of production, packaging, and filling processes. However, the current technology has some significant drawbacks, for example, affecting both operating costs and safety.

[0003] Currently, in practice, most machine systems are equipped with dedicated network switches at the line level. These switches are responsible for facilitating communication within individual production lines. While this solution ensures efficient data transmission within the lines, it leads to increased complexity in network management. Each line requires its own switch, which complicates network maintenance and scaling. This becomes particularly problematic when adjustments or expansions to the system are necessary, as each change must be implemented individually on each line.

[0004] In addition to the switches, each line or system is connected to the central corporate network via its own hardware router (i.e., one line switch across each line). This requires a central location / network cabinet and is therefore costly and complex. It is also not very modular and cannot be expanded in a decentralized manner. This separate network infrastructure per line not only increases administrative complexity but also increases hardware and maintenance costs. Particularly for systems with multiple machines, this requires the provision of a central network cabinet, which entails significant investment. The cost of such a setup, including the necessary engineering services, can easily exceed €10,000, which represents a significant financial burden, especially for smaller companies.

[0005] Another critical aspect is so-called "bare-to-metal" installations, where software is installed directly on the hardware, without an intermediate layer such as an operating system. While this configuration offers performance advantages, it limits the flexibility and scalability of the systems.

[0006] Further disadvantages arise from the lack of security in these network configurations. Many facilities lack basic security measures such as firewalls. This neglect of network security and non-compliance with the ISA95 standard, a key industry standard for the integration of enterprise and control systems, makes the facilities vulnerable to cyberattacks and data leaks. This can lead to serious consequences, including business interruptions, data loss, and even physical damage to equipment.

[0007] There is therefore a need for a solution that overcomes these disadvantages in the state of the art and thus provides a modular and dynamic control of machines in a network of machines for filling and packaging machines, lines and plants.

[0008] The object is achieved according to the invention by a machine according to claim 1, a computer-readable storage medium according to claim 9, and a machine line according to claim 10. Embodiments and further developments are covered in the subclaims.

[0009] One embodiment of the invention relates to a machine in a machine line, in particular in a machine line for filling and packaging food and / or beverages. The machine comprises an industrial PC (IPC) that implements a software-defined edge device for the machine and includes a hypervisor. The hypervisor provides a virtual operating platform for hosting and / or operating services for the operation of the machine line. According to the implementing regulations, the IPC has the virtual operating platform or hypervisor installed "bare-to-metal."

[0010] Further embodiments relate to a computer-readable storage medium and a machine line.

[0011] Exemplary aspects of the invention are illustrated in the drawings. They show: Fig. 1: a diagram showing a honeycomb arrangement of cells in a network according to embodiments of the invention; Fig. 2: an example machine showing an IPC and several virtualized network layers; Fig. 3: an exemplary system configuration for PET containers and adhesive containers; Fig. 4: an exemplary system configuration for PET containers and shrink packers; Fig. 5: an example system configuration for cans or glass bottles; and Fig. 6: an example system configuration for cans.

[0012] The invention provides an approach to overcome the disadvantages described above by implementing a "software-defined" edge device for each machine in a machine line. According to embodiments, this can be implemented on an industrial PC (IPC). This allows the organization of the standalone edge devices to be modularized so that each machine functions like a cell that can be added modularly, like a honeycomb concept. This concept is described in Fig. 1, which shows an example arrangement of machines organized in a honeycomb structure. Each of the example machines has a corresponding IPC that implements an operating platform or hypervisor. Such an operating platform can provide a variety of services for the operation of the machine line. The hypervisor can be implemented bare-to-metal on the IPC and provide a virtualization environment that enables the simultaneous execution of multiple operating systems or virtual machines on a single physical IPC. This can make it possible to run different services on the same IPC without them affecting each other or causing conflicts. Furthermore, services can be moved or duplicated between different IPCs using the hypervisor to ensure flexible scalability and fault tolerance, as explained further below.

[0013] The more machines in a line are organized in this way, the more robust the given infrastructure is, since loads can be distributed using different implementations. Examples of loads to be distributed include services of various edge device functionalities or line management, each of which runs on this IPC.

[0014] The use of software-defined networking technology, as demonstrated in the embodiments described herein, enables high flexibility and simplifies network management. In the exemplary network architecture, this can be used to virtualize network components. This leads to a reduction in physical network components and facilitates the modular and scalable design of the machine line.

[0015] According to embodiments, the IPC is configured to implement a software-defined edge device for the machine and includes a hypervisor. The hypervisor provides a virtual operating platform for hosting and / or operating appropriate services for operating the machine line.

[0016] The hypervisor can further implement a demilitarized zone (DMZ) with its own network segments, in which at least part of the virtual operating platform is implemented. For example, the DMZ hosts services that publicly expose a service to the internet and / or exchange data with other cloud platforms. The DMZ is a zone or an exemplary network segment. The DMZ is primarily for services hosted publicly on the internet. There may be other network zones / segments, depending on how deeply the services should / need to be segmented.

[0017] According to embodiments, the machines, or the IPCs of the machines, can connect to each other and establish a connection to a machine line network. The machine line network thus connects a plurality of machines, each of which also includes an IPC as a software-defined edge device configured according to embodiments. The modular composition of these "cells" (a cell means a machine with an IPC on which a hypervisor / operating platform is implemented) allows the workloads to be distributed among the machines in the machine line network.

[0018] The cells according to embodiments each form a communicatively independent unit within the machine line. By means of authorization, a cell can automatically connect to the machine line network, i.e., to the other cells. The IPC within the cell can serve as an entry / connection point for the cell and provide a firewall container for incoming and outgoing communication.

[0019] When connecting a machine / cell to the network, the connection can be automatically detected and the correct assignment of the corresponding zone / VLAN for the devices can be carried out as soon as they are connected to a switch, for example.

[0020] For example, a central network management service can automatically connect connected (known / verified) devices to the correct network.

[0021] As in Fig. 1, machines without the appropriate authorization (“foreign machines”) can also be connected to the network. Visually marked in Fig. 1, the pallet wrapping machine is such a remote machine in this example. If it is determined that a machine / cell in the machine line is unauthorised (trusted), limited communication with the unauthorised machine can still be established or maintained. The limited communication can, for example, allow the remote machine to access network resources and / or network segments within the network. Alternatively or additionally, the limited communication with the remote machine can be monitored and logged.

[0022] For unknown devices (foreign machines), a user can be asked in an HMI dialog box whether the device is trusted, what type of device it is, which group it belongs to, etc. The network management service can then move the device to the correct zone and, if necessary, equip it with limited communication capability.

[0023] According to embodiments, if it is determined that a machine in the machine line is infected with malware, communication with the infected machine can be terminated. This is particularly efficient because each IPC, or rather the software-defined firewall of each IPC, performs appropriate data packet monitoring on incoming and / or outgoing messages.

[0024] Distributing workloads among the machines / cells in the machine line network involves distributing tasks necessary for the network itself. For example, distributing tasks refers to software-defined network services, from a list of services required for the network, such as an APN service, a DHCP service, a DNS service, an MQTT service, and so on. Further examples are described in Fig. Figure 2 shows an example machine on which a virtual DMZ is implemented on the IPC. The IPC can execute various services (e.g., in the DMZ and / or a virtual business function zone), or only a portion of them, so that the tasks are distributed among the cells in the network.

[0025] For example, some IPCs can handle dial-up to a network (e.g., Internet, VPN, etc.), other IPCs can handle a DHCP service, others a DNS service, and yet others can handle product workloads. This enables a high level of flexibility and security while conserving resources.

[0026] The allocation of tasks among the cells can encompass a number of other exemplary tasks and aspects. For example, a cell can be responsible for dynamic packet distribution for the lifecycle of at least one IPC. Furthermore, a cell can be responsible for controlling the communication of administration commands via a mobile data connection (such as via 5G) and controlling the download of packets and / or artifacts via a fiber / DSL connection. This can achieve even faster commissioning of the system. Furthermore, the cell can also use the mobile 5G data connection to download required data for faster commissioning if a fiber / DSL connection is not yet available.

[0027] For example, in Fig. As shown in Figure 2, the virtual access zone can be executed in a different kernel than the DMZ. The virtual access zone controls and receives data from the machine's IPCs 205 and from sensors 206 that collect data on the machine. Communication with the virtual access zone can be achieved, for example, via a trunk port and a Profinet-compatible managed switch. Direct access to HMIs or mobile devices can also be achieved via a data connection 207.

[0028] Embodiments of the invention thus provide a network technology concept that is highly software-defined, eliminating the need for additional network hardware between the machines or lines. This enables a simple, modular, and scalable design of the machines and their networks.

[0029] According to embodiments, the IPC, or rather the software-defined edge device or the corresponding hypervisor of an IPC, can connect to, for example, a backend service on which various additional services are available, which can either be transferred to the IPC or executed on the backend server. Furthermore, a connection can also be established to a data center on which additional, for example, company-specific data can be made available for the services.

[0030] The invention can be implemented on a computer configured to execute specific program instructions that enable the functionality of the invention. The basic architecture of this computer includes several core components, such as a central processing unit (CPU), memory, input / output systems, network connectivity, a bus, etc. The CPU is responsible for executing the program instructions. It processes data and controls other components of the system. Memory can include both volatile memory (RAM) and non-volatile memory (such as hard drives or SSDs). RAM provides temporary storage for running processes and data, while non-volatile memory enables permanent data storage. The input / output systems enable the computer's interaction with the outside world, including input devices such as the keyboard and mouse, and output devices such as monitors and printers.Network connectivity allows the computer to connect to other computers and networks, enabling data exchange and remote access. Components can be connected via a bus system.

[0031] The computer-readable storage medium contains program instructions that, when executed by the computing device, configure the device to implement the specific functions and processes of the invention. These instructions may be in the form of software code written in a programming language and stored on the storage medium. When executed by the CPU, this code enables the computer to implement the invention by performing specific algorithms and processing steps.

[0032] In the following Fig. 3 to 6, various exemplary plant configurations for various bottle filling plants are described in which the invention or at least parts and aspects of the invention can be implemented. The description of the Fig. 3 to 6 are intended only to provide a general overview of machines for which status data can be collected, on the basis of which the LLM can process user requests.

[0033] Fig. Figure 3 shows an example system configuration 1000 for PET bottles or PET containers and adhesive packs. As in Fig. As can be seen in Figure 3, the system configuration comprises 1,000 different modules that form a line at the end of which finished PET containers are dispensed in the form of a bundle on pallets. Some of the modules and machines may be optional, and the invention is not limited to the exact shape and arrangement of the system configurations.

[0034] The system configuration 1000 comprises an oven 1002 for preforms, a preform sorter with a feeding machine 1004, and a blow molding machine 1008. The modules 1002, 1004, and 1008 generally form a stretch blow molding machine in which PET containers are produced and formed from a starting material. The produced PET containers are forwarded to a filler 1010, where the bottles are filled. The filler can optionally include a rinser. Various particles such as dust, cardboard, or wooden pallet residue can settle in the preforms during storage or transport. These can be removed with the rinser. A closer can be arranged at the end of the filler, by means of which the PET containers are closed after filling.

[0035] Optionally, the system configuration 1000 can include a rotating device downstream of the filler 1010, which is used for hot filling of the PET containers. Via one or more conveyor belts 1016, which can also include a buffer 1018 for intermediate loading of filled containers, the filled PET containers are conveyed to a separator 1020 and then to a drying device 1024, in which the PET containers are dried.

[0036] After drying, the PET containers are conveyed to a labeling machine 1026. The labeling machine 1026 can be designed for various labeling techniques, such as labeling using hot melt, cold melt, self-adhesive labels, or sleeves. After the PET containers have been printed or labeled, they are conveyed through a second drying device 1028, a line distributor 1030, conveyor belts 1032, an adhesive pack production line 1034, and a curing section to a handle applicator. In the adhesive pack production line 1034, the PET containers are grouped into specific group sizes and packaged into a pack, such as a "six-pack." In the handle applicator, a carrying handle is attached to the pack, which allows for comfortable carrying of the pack.The finished containers are then arranged accordingly by a robot 1042 for layer production and packed on pallets by a palletizer 1044.

[0037] In system configuration 1000, so-called format trolleys or format racks can be arranged on various modules and machines to provide quickly interchangeable format sets for short changeover times and automatic tool changes. Examples of format trolleys are format trolley 1006 for blow molding machine 1008, format trolley 1012 for filler 1010, format trolley 1022 for labeling machine 1026, format trolley 1038 for adhesive pack production 1034, and format trolley 1046 for palletizer 1044.

[0038] Fig. Figure 4 shows another example system configuration 1100 for PET containers and shrink packers. The system 1100 from Fig. 4 includes many of the modules and machines from the plant configuration 1000 from Fig. 3, but there are some differences. The description of the modules already mentioned in connection with Fig. 3 are described, is therefore for Fig. 4 waived.

[0039] A key difference between the two exemplary system configurations 1000 and 1100 is that the labeling machine 1126 with the labeling modules 1127 can be installed downstream of the blow molding machine 1008 and upstream of the filler 1008. For this purpose, the system configuration 1100 can comprise six transport lanes 1150 into which the PET containers can be pushed. After the PET containers have pushed into one of the six lanes 1150, they are conveyed into the film wrapping module 1152 and then into the shrink tunnel 1154.

[0040] Fig. Figure 5 shows an example system configuration 1200 for cans or glass bottles. The example system configuration 1200 from Fig. 5 again has some similarities to the system configurations 1000 and 1100 from Fig. 3 and Fig. 4 and the description of the system configuration is therefore limited to the differences in the system configurations.

[0041] As in Fig. As shown in Figure 5, the exemplary system configuration can include two separate feeders. A first feeder, on the left in Fig. 5, shows a branch for cans or optionally a partial branch for reusable new bottles. The containers, ie cans or new bottles, are fed into the machine by a depalletizer 1302, where they are guided via conveyor belts to the filler 1010. A second feed, on the right in Fig. 5, shows a partial branch for reusable bottles that are fed into the system from a reusable sorting system (not shown).

[0042] In the case that the already used reusable bottles are introduced into the system 1200 via the sub-branch for reusable bottles, the reusable bottles first pass through the cleaning machine or washing machine 1304. Another possible difference in the exemplary system configuration 1200 is the transfer packer 1306 after the labeling machine 1026. The transfer packer can sort the bottles or cans into a carton clip application or into crates or both.

[0043] Fig.Figure 6 shows an exemplary system configuration 1300 for cans, in which the elements already described in the other system configurations are no longer described. The cans in system configuration 1300 are fed into the depalletizer 1302 from a magazine 1402 containing cans. After passing through the filler and being filled, the cans are closed by means of a closure magazine 1404 and transported further along the system 1400 via the conveyor belts, as described above.

[0044] The optional Pasteurizer 1408 can be bypassed via the Bypass 1412 if not required. Freshly filled products can be pasteurized in the Pasteurizer 1408 for preservation.

[0045] In contrast to plant configurations 1000, 1100, and 1200, the exemplary plant configuration 1300 shows various tanks for corresponding consumables, such as tanks 1410 with rinsing liquid and / or the filling product and tanks 1406 with belt lubricant. These tanks can also be included in the exemplary plant configurations described above. For example, the chemical products 106 that are fed from the mixer 110 to the machines can be stored in tanks 1406 and 1410.

Claims

[1] Machine in a machine line, in particular in a machine line for filling and packaging food and / or beverages, the machine comprising: an industrial PC, IPC, implementing a software-defined edge device for the machine and comprising a hypervisor, wherein the hypervisor is designed to: Providing a virtual operating platform to host and / or operate appropriate services for the operation of the machine line. [2] The machine of claim 1, wherein the hypervisor is further configured to: Implementing a demilitarized zone, DMZ, with its own network segments in which at least part of the virtual operating platform is implemented, wherein services are hosted in the DMZ that make a service publicly available to the Internet and / or exchange data with other cloud platforms. [3] A machine according to any one of claims 1 or 2, wherein the hypervisor is further configured to: Establishing a connection to a machine line network, wherein the machine line network interconnects a plurality of machines, each of the plurality of machines implementing an IPC as a software-defined edge device for the respective machine and comprising a respective hypervisor; and Distributing workloads among the machine and at least one second machine in the machine line network; Where, if an IPC of a machine on the network fails, the hypervisor is designed to redistribute and / or take over a workload of the failed IPC. [4] Machine according to one of claims 1 to 3, wherein: the machine forms a communicatively independent cell in the machine line; the machine automatically connects to the machine line network by means of an authorization; and the IPC within the cell is an entry / connection point for the cell and provides a firewall container for inbound and outbound communication. [5] Machine according to one of claims 1 to 4, wherein the IPC is further equipped with WAN, 5G and / or LTE communication means and can independently connect to the Internet via the WAN, 5G and / or LTE communication means. [6] A machine according to any one of claims 3 to 5, wherein the hypervisor is further configured to: Determine that a machine in the machine line is an unauthorised machine; and Establishing limited communication with the machine without authorization, wherein the limited communication enables limited access of the machine without authorization to network resources and / or network segments in the network and / or wherein the limited communication with the machine without authorization is monitored and logged; and / or Determine that an IPC of a machine in the machine line is infected with malware and terminate communication with the infected machine. [7] A machine according to any one of claims 3 to 6, wherein the distributing workloads among the machine and at least one second machine in the network of the machine line comprises: Allocating tasks related to a software-defined network service from a list of services required for the network, in particular an APN service, a DHCP service, a DNS service, and / or an MQTT service; and / or dynamic package distribution for a lifecycle of at least one IPC; and / or Control or communication of administration commands over a mobile data connection and download of packages and / or artifacts over a fiber / DSL connection; and / or Additional use of a mobile 5G data connection for faster commissioning if a fiber / DSL connection is not yet available. [8] A machine according to any one of claims 1 to 7, wherein the hypervisor is further configured to: Virtualizing a firewall and / or router functionality as software-defined functions so that the access layer and core layer are integrated in one hardware unit of the IPC. [9] A computer-readable storage medium having recorded thereon program instructions which, when executed by at least one computing device, configure the at least one computing device to: Implementing a hypervisor for a software-defined edge device for a machine, the hypervisor being configured to: Providing a virtual operating platform to host and / or operate appropriate services for the operation of the machine line. wherein the machine is part of a machine line, in particular in a machine line for filling and packaging food and / or beverages. [10] Machine line, in particular a machine line for filling and packaging food and / or beverages, the machine line comprising: a plurality of machines connected to each other via a network, each of the machines comprising an industrial PC, IPC, implementing a software-defined edge device for the machine and comprising a hypervisor, the hypervisor being designed to: Providing a virtual operating platform to host and / or operate appropriate services for the operation of the machine line.

Citation Information

Patent Citations

  • Distributed software-defined industrial systems

    DE112018005879T5

  • Control system for controlling and monitoring an industrial plant, industrial plant, external control device and externally controlled industrial plant system

    DE202023105695U1