COMMUNICATION SYSTEM AND INDUSTRIAL AUTOMATION DEVICE FOR PROCESSING A WEB REQUEST FROM A CLIENT
Patent Information
- Application Number
- DE502023002041
- Authority / Receiving Office
- DE · DE
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2023-07-17
- Publication Date
- 2025-11-13
- Estimated Expiration
- 2043-07-17
AI Technical Summary
Existing web integration solutions for automation systems fail to provide a unified access point and content harmonization, leading to fragmented user experiences and security vulnerabilities due to misconfigurations and complex management of reverse proxies.
Reversing the conventional proxy-server arrangement by positioning the web server upstream of the proxy unit, allowing the web server to transform requests and responses, thereby eliminating the need for the proxy unit in the first management domain and enhancing security and performance.
This arrangement provides a unified access point, reduces misconfiguration risks, enhances troubleshooting, improves security by maintaining client IP visibility, and eliminates the need for TLS tunnel termination, thus increasing system reliability and performance.
Description
[0001] The invention relates to a communication system and an industrial automation device for processing a web request from a client as described in the independent claims. Further embodiments are described in the dependent claims.
[0002] Today, attempts are being made to transform the concept of open application systems ("apps") into the world of automation. One aspect of the transformation to the Industry 4.0 world are web solutions, which are used for commissioning, parameterization, and diagnostics, for example, and which also provide interfaces for operator control and monitoring. When using web technology in open systems, a challenge quickly arises as soon as several subsystems of a device have their own web servers or web solutions. These independent web servers must be integrated so that they offer the end user only one web access point per device, as is customary with both existing automation devices and a specific network such as the Internet.
[0003] Existing web integration solutions, known as reverse proxies (proxy units), manage to provide a single access point to the device (e.g., on the well-known web ports 80 or 443), but do not support integration on the content side (i.e., the web pages themselves). Thus, each subsystem developer follows their own ideas regarding content presentation in the web environment. This makes such automation solutions appear fragmented to the outside world, rather than a unified, integrated solution.
[0004] A sensible path from the integration of various independent web solutions to a solution with support for content harmonization is a so-called portal web server. The portal web server is, in itself, the unified access point to the device for the user. System-compliant web solutions of individual components can be integrated into the portal web server, thus helping to create a unified solution for end users. With compliant integration, subcomponent websites look like "system websites" for managing the system and platform. The end user thus gets the impression of a unified system.
[0005] The publication US 2016 / 0234330 A1 - "SYSTEM AND METHOD FOR MOBILE APPLICATION DEEP LINKING" proposes that deep linking involves modifying the content of the provided web pages with regard to the embedded addresses.
[0006] The publication US 2015 / 0229628 A1 - Kosim-Satyaputra et al. "SYSTEM, METHOD AND ARCHITECTURE FOR PROVIDING INTEGRATED APPLICATIONS" shows a multi-tenant arrangement in which an authorization server is used for access by remote applications.
[0007] Fig. 1 shows a state-of-the-art web platform with the following architectural features: An Industrial Appstore Runtime (IAR) enables apps from a central (official) industrial app store to run. This runtime ensures that the app store operator can only run apps for which the appropriate rights have been acquired.
[0008] A Local App Runtime (LAR) allows users to run additional apps with different features. Such apps include, for example, user-created apps that they do not want to include in the central industrial app store.
[0009] While the current IAR implements a centralized management pattern (i.e., apps are pushed from a central device management system to the devices (or their IARs)), a LAR, in conjunction with a primary platform, can enable decentralized app management. This means that apps are pulled from an app store on the device itself, as is common practice today for consumer devices such as smartphones. In both cases, management in the runtimes is usually performed via web servers and / or via web APIs of web services. Even in such a simple configuration, two independent management web servers already interact: a first web server unit (first management web server) for the LAR and a second web server unit (second management web server) for the IAR.
[0010] According to the state of the art, these two management web servers are to be integrated via an upstream proxy unit.
[0011] In the proxy unit, each underlying sub-web server is assigned a sub-URL (URL prefix) under which this web server can be accessed from outside via the proxy unit. In the current state of the art, the proxy unit is therefore always the central entry point into the web server "application cluster." This is responsible for distributing incoming requests to the sub-web servers. This "splitting" is performed based on the URL prefixes that are specifically assigned to the downstream web servers.
[0012] The proxy unit has a configuration file that defines, among other things, the intended URLs for the downstream web servers and their IP addresses. At this configuration point, management requests from the IAR and the LAR converge in an uncoordinated manner.
[0013] In summary, the state-of-the-art proxy unit presents a number of problems, in addition to the obvious issues in terms of user interface and operating philosophy, compared to a portal web server approach: The first web server unit in the first management domain is used to configure the system and thus usually also to configure the system's associated reverse proxy. In the event of an automatic or manual misconfiguration of the reverse proxy, the device's first web server unit is no longer accessible. This misconfiguration cannot be corrected using this first web server unit.
[0014] The reverse proxy must be fully managed, meaning the configuration in the reverse proxy must be updated for each new root website in the portal web server and also in the app store runtime. Any manual configuration of communication paths is a potential source of errors and vulnerabilities.
[0015] Many existing web applications are not designed for reverse proxies. Such web applications on different web servers cannot easily check whether they are running behind a reverse proxy or not. For example, cookies from one web application can overwrite each other in the browser. For example, if a web server of a programmable logic controller is run behind a reverse proxy, this leads, among other things, to the mutual overwriting of login cookies. Thus, a user must log in again every time they change web servers.
[0016] The client's IP address is no longer visible in the IP packet reaching the first web server behind the reverse proxy (it always recognizes the reverse proxy's IP address as the source address). This significantly reduces the value of logging, especially in the first web server. Such limited visibility of client requests passing through the reverse proxy complicates troubleshooting and compromises system security.
[0017] The system-imposed termination of TLS tunnels at the reverse proxy results in a security degradation. By design, a reverse proxy operates as a man-in-the-middle "attacker" because, as an ISO Layer 7 gateway, it interrupts secure tunnels to the destination web server (e.g., the first web server unit). Compromising the reverse proxy thus allows attackers access to unencrypted data traffic. In addition to this breach of end-to-end security, further problems exist regarding certificate handling between the reverse proxy and the destination web server. The reverse proxy must trust all web servers located behind it (i.e., their (various) certificates) so that, after the tunnels on the inbound side are interrupted, it can at least re-establish secure tunnels on the other side (to the endpoint web servers).Due to the complexity of handling these connections, the connections between reverse proxies and the destination web servers are often even unsecured. This makes these connections directly vulnerable to attack, which can pose a problem depending on the security policy.
[0018] Against this background, one object of the present invention is to improve the management of web services that are accessible via a web server.
[0019] According to a first aspect, a communication system, in particular an automation system, is proposed for processing a web request from a client to retrieve a web service in a specific network. The communication system comprises: a web server for receiving the web request from the client and for transmitting a web response transformed on the basis of the web request back to the client, a proxy unit which is arranged separately from the web server and downstream of the web server in the communication system and which is coupled to the web service, wherein the web server has a proxy adapter which is configured to couple the web server to the proxy unit which is arranged separately and downstream of the web server, wherein the proxy adapter is further configured to transform the web request into the web response as a function of the proxy unit which is arranged separately and downstream of the web server and the web service.
[0020] According to the communication system according to the first aspect, the management of web services accessible via a web server is improved by the fact that the web server is no longer located behind the proxy unit, but rather in front of the proxy unit. In other words, the proxy unit is located downstream of the web server. This means that, thanks to this special arrangement, the web server now transforms from a backend server to a frontend server, thereby assuming the primary role previously assigned to the proxy unit. Thus, the web server receives all web requests to a device of the communication system as a central web server, transforming it into a portal web server.
[0021] To continue to enable access to the web solutions of the applications running on the additional local, decentralized application runtime environment (IAR), the proxy unit is appropriately connected to the (portal) web server via the proxy adapter. The proxy unit is now located behind the web server and is now uniquely and exclusively assigned to the IAR.
[0022] This has the technical effect that the proxy unit is no longer used for web access to the first management domain and is no longer managed from the first management domain.
[0023] This has the advantage of creating a logical separation between the first management domain and the second management domain. The first management domain contains the portal web server and the proxy adapter. The second management domain begins with the proxy unit. Conflicts associated with managing the proxy unit from multiple sites are thus eliminated.
[0024] Automatic or manual misconfigurations, even if they still occur after the aforementioned management conflict has been resolved, now only affect the second management domain. A no longer functional web access from the second management domain can advantageously be restored to a functional initial state by the first management domain. In the event of an automatic or manual misconfiguration of the proxy unit, at least the first management domain and the web server are still accessible, and only apps in the second management domain may no longer be accessible. This allows the first management domain and the web server to operate independently of the proxy unit.
[0025] Another advantage of placing the web server upstream is that the client's IP address is now visible in the IP packet that reaches the web server. This facilitates troubleshooting and increases the security of the communications system.
[0026] Since the proxy unit is now located downstream of the web server, there is no longer any need for system-related termination of TLS tunnels at the proxy unit, which also increases the security of the communication system.
[0027] In addition, the performance and latency (transaction latency) of the communication system increases because the downstream proxy unit no longer has to act as a Layer 7 converter and does not have to terminate TCP and TLS connections on one side and re-establish them on the other.
[0028] The communication system can be implemented, in particular, within an automation system or as an automation system. The automation system can be a system from the process industry, the chemical industry, the pharmaceutical industry, the petrochemical industry, or a system from the food and beverage industry. This also includes any system from the manufacturing and production industry and systems in which, for example, cars or goods of any kind are produced. Furthermore, the automation system can also be designed as an energy generation system, such as a wind turbine, a solar system, or a power plant, and / or as an energy distribution system.
[0029] A web request is a request made by a client, such as a web browser, to a web server to retrieve a web service. Web requests are typically sent via the Hypertext Transfer Protocol (HTTP), which is why the web request can also be referred to as an HTTP request.
[0030] A web response is a response to the transmitted web request from the web server, which processes the transmitted web request and converts the web response, and then returns it to the client. The web response is, in particular, an HTTP response.
[0031] A client—also known as a client-side application, client application, or client program—is a computer program that runs on a device on a network and communicates with a server or web server. Preferably, the device itself, which requests services from a server, is a client.
[0032] A web service is any service located on or connected to a specific network, such as a local area network or the Internet, such as a website, a web application, an application, or a service, especially a microservice. Web services are identified using Uniform Resource Identifiers (URIs).
[0033] A specific network is, in particular, a local area network or the Internet. The local area network can be configured as an enterprise network or as a closed computer network.
[0034] A web server is, in particular, a server that transmits documents to clients, such as a web browser. A web server refers to the computer with web server software or simply the web server software itself. The web server is preferably configured as a portal web server. A portal web server is a central server that receives all web requests to a device in the communications system, then selects them and forwards them to the appropriate location.
[0035] The term "downstream" specifically means that the web server is positioned before the proxy unit, and the proxy unit is positioned after the web server. In other words, the proxy unit does not receive the web request first, but rather the web server, which can then forward the web request to the proxy unit via the proxy adapter.
[0036] Preferably, the term "separately located" means that the web server and the proxy unit are logically separated from each other. "Logical separation" specifically means that the web server has a first assigned logical address, for example, a TCP / IP address, in the communications system, whereas the proxy unit has a second assigned logical address in the communications system.
[0037] A proxy unit is a communication interface in a communications system. The proxy unit operates primarily as an intermediary, accepting web requests on one side and then establishing a connection to another side via its own address. The proxy unit is specifically designed as a reverse proxy.
[0038] In particular, the proxy adapter receives the web request. The proxy adapter serves to connect or link the downstream proxy unit. Preferably, a web request that is not processed in the upstream components, i.e., the URL handler chain, is forwarded by the proxy adapter to the proxy unit of a second management domain.
[0039] The respective unit, for example, the proxy unit, can be implemented in hardware and / or software. In a hardware implementation, the respective unit can be embodied as a device or as part of a device, for example, as a computer or a microprocessor. In a software implementation, the respective unit can be embodied as a computer program product, as a function, as a routine, as part of a program code, or as an executable object.
[0040] According to one embodiment, the web server is arranged in a first management domain and the proxy unit arranged separately and downstream of the web server is arranged in a second management domain, wherein the first management domain and the second management domain are logically separated from each other.
[0041] The above explanation of the term "logical separation" also applies analogously to this embodiment.
[0042] In particular, in the communication system according to the first aspect, the first management domain and the second management domain can be arranged spatially separated from one another at different locations and / or devices.
[0043] According to the invention, the first management domain is designed as a local decentralized application runtime environment which has a local or remote APP store with at least one local application, and the second management domain is designed as a further local decentralized application runtime environment which has a central APP store with at least one centrally stored application.
[0044] The first management domain is a "Local App Runtime," or "LAR" for short. A local application is, in particular, an application that is not hosted in the central app store.
[0045] The second management domain is specifically an "Industrial Appstore Runtime" or "IAR" for short.
[0046] In particular, the term "remote APP Store" means that this APP Store is not located in the first management domain, but is connected to the first management domain to enable access to applications of this APP Store.
[0047] According to a further embodiment, the web server has a Uniform Resource Locator handler chain with a plurality of Uniform Resource Locator handlers, wherein the proxy adapter is arranged in the web server at the end of the Uniform Resource Locator handler chain.
[0048] According to a further embodiment, the plurality of Uniform Resource Locator handlers of the Uniform Resource Locator handler chain are arranged in series one after the other in the web server, wherein each Uniform Resource Locator handler of the Uniform Resource Locator handler chain is configured to forward the received web request to the next Uniform Resource Locator handler in the series, wherein the last Uniform Resource Locator handler in the series is configured to transmit the forwarded received web request to the proxy adapter and to receive the transformed web response from the proxy adapter.
[0049] The arrangement of the proxy adapter at the end of the URL handler chain according to this embodiment has the following advantages: This particular arrangement of the proxy adapter results in all web requests not handled in the first management domain, in particular URL requests, being received by the proxy adapter, whereas in the prior art without this particular arrangement, an HTTP error 404 message would be returned for each unhandled web request.
[0050] In addition, the URL handlers of the URL handler chain, and thus the websites of the first management domain, have a higher priority than the proxy unit and thus also the underlying web servers in the IAR and its apps. This is particularly desirable for the management websites for the first management domain, since the IAR is merely a downstream subsystem after the first management domain.
[0051] In addition, placing the proxy adapter as the last URL handler in the URL handler chain prevents the high latencies inevitably associated with the proxy unit from negatively impacting the URL handlers in the URL handler chain and thus the websites of the first management domain.
[0052] In particular, the last Uniform Resource Locator handler in the chain is configured to transmit the forwarded received web request to the proxy adapter and to receive the transformed web response as part of a response chain from the proxy adapter.
[0053] Preferably, the plurality of Uniform Resource Locator handlers in the handler chain comprise a first URL handler and a second URL handler, wherein the second URL handler may also be referred to as the next URL handler. In particular, the first and second URL handlers are implemented by a backend web framework. An example of such a web framework is the Node.js-based Express.js.
[0054] In addition, the first URL handler can be responsible for static web pages, while the second URL handler can be responsible for dynamically generated web pages.
[0055] According to a further embodiment, the proxy adapter for transforming the web request into the web response is configured to convert the web request into a network request, in particular into an HTTP request, to transmit the network request to the proxy unit arranged separately and downstream of the web server, to receive a network response, in particular an HTTP response, from the proxy unit arranged separately and downstream of the web server as a function of the web service and on the basis of the network request, and to convert the received network response into the web response.
[0056] The term "transform" describes in particular an information transformation, since the data content of the medium to be transformed changes, in this case the data content of the web request into a data content of the web response.
[0057] The term "conversion" primarily describes a format conversion, as it involves changing the format of the medium being transmitted or converted. For example, a web request in a computer format, such as source code or software code (programming code), is converted into a network request in HTTP format. The medium being transmitted or converted changes, in particular, from the computer format in the form of a web request to a network format, such as the HTTP format, in the form of a network request.
[0058] According to a further embodiment, the proxy unit is configured to check, on the basis of the received network request and depending on a configuration file of the proxy unit for obtaining a forwarding result, whether a specific web service requested by means of the network request is present in the second management domain for forwarding the network request to this specific web service or not, wherein the forwarding result is positive if the specific web service is present in the second management domain, wherein the forwarding result is negative if the specific web service is not present in the second management domain, wherein, if the obtained forwarding result is positive, the network response is designed as a positive message, wherein, if the obtained forwarding result is negative, the network response is designed as an error message, in particular an HTTP error message.
[0059] In other words, the proxy unit uses its configuration to check whether the converted network request can be forwarded to a specific web service assigned to it for processing. If the check result is positive (positive forwarding result), it performs the forwarding. The proxy unit then receives a positive message from the specific web service or a web server connected to the specific web service. The proxy unit, in turn, forwards the positive message in the form of a network response to the proxy adapter. If the specific web service is not present, either the proxy unit or one of its downstream web servers generates an error message (depending on the situation), specifically the HTTP error message (negative forwarding result).
[0060] If the forwarding result is negative because the specific web service is not present in the second management domain, it may be that the proxy unit is aware of the specific web service requested via the network request, but is not connected to it (for example, via a downstream web server in the second management domain), and therefore the error message is generated. In another case, the proxy unit is not aware of the specific web service requested via the network request, and therefore the error message is generated.
[0061] In particular, a response from a downstream web server (a positive message) located behind the proxy unit in the second management domain, or an error message, is returned to the proxy adapter as a response to the network request generated by the proxy adapter. On this return path, the proxy adapter converts the HTTP response (network response) received from the proxy unit into a web response for the web server components of the first management domain and feeds this web response into the response chain of the web server components. Finally, a base web server in the portal web server can deliver the corresponding web response to the requesting client, such as a web browser.
[0062] According to a further embodiment, the communication system further comprises a certificate store for storing digital certificates, wherein the stored digital certificates comprise a first digital certificate for the web server and a second digital certificate for the proxy unit, wherein the certificate store is configured to store the first digital certificate in dependence on the web server and to provide it to the web server and to store the second digital certificate in dependence on the proxy unit and to provide it to the proxy unit.
[0063] A certificate store is used to securely store digital certificates on a computer system. Since the first management domain and the second management domain use the shared certificate store, this advantageously simplifies the management of the digital certificates of both management domains.
[0064] In particular, the certificate store is linked to a certificate authority (CA). The certificate authority is preferably located external to the communications system. A certificate authority (CA) is an entity that stores, signs, and issues digital certificates. A digital certificate certifies the possession of a public key by the designated subject of the certificate. A digital certificate is a digital record, usually according to ITU-T or IETF standards, that confirms certain properties of persons or objects and whose authenticity and integrity can be verified using cryptographic methods.
[0065] According to a further embodiment, the web server and the proxy unit are configured, depending on the first digital certificate and the second digital certificate, to establish an encrypted channel between the proxy adapter and the proxy unit for the secure transmission of the network request and the network response between the proxy adapter and the proxy unit, wherein the encrypted channel is secured in particular by means of HTTPS.
[0066] The encrypted channel between the proxy adapter and the proxy unit increases the security of the communication system, as end-to-end security is now established between the first and second management domains using the encrypted channel. Furthermore, end-to-end security is no longer breached, as all communication between the proxy adapter and the proxy unit is now secured using HTTPS over the encrypted channel.
[0067] Overall, the first and second digital certificates are signed by a jointly trusted certification authority (i.e., by the first and second management domains). This ensures mutual trust between the proxy adapter of the portal web server of the first management domain and the proxy unit for the second management domain. On this basis, the above-mentioned encrypted channel between the two can also be implemented. Preferably, authentication of the proxy adapter to the proxy unit is not required, since the proxy adapter acts as an additional client here. The client's login credentials can be relevant for access rights to another web server in the second management domain. These credentials are forwarded from the proxy adapter to the proxy unit.
[0068] The encrypted channel is set up as follows: First, the first certificate is signed by a higher-level certification authority external to the communication system. The first certificate is specifically designed as a CA certificate.
[0069] The proxy then retrieves the second certificate and the associated private key from the certificate store. The second certificate is specifically designed as a server certificate. Furthermore, the second certificate is preferably signed with the first certificate.
[0070] The proxy unit then authenticates itself to the proxy adapter or web server with its signed second certificate. Specifically, the proxy adapter checks the signed first certificate, which was used to sign the second certificate, against the certificates contained in the certificate store. The certificate store contains all trusted certificates, such as the CA certificate.
[0071] Since both the proxy unit and the proxy adapter trust the same certificate authority and therefore the signed first certificate is trusted, the authentication is successful.
[0072] Preferably, the proxy unit and the proxy adapter then negotiate session keys with each other in order to then establish the encrypted channel.
[0073] According to a second aspect, an industrial automation device, in particular a process control device, is proposed for processing a web request from a client to retrieve a web service in a specific network. The industrial automation device comprises: a web server for receiving the web request from the client and for transmitting a web response transformed on the basis of the web request back to the client, a proxy unit which is arranged separately from the web server and downstream of the web server on the industrial automation device and which is coupled to the web service, wherein the web server has a proxy adapter which is configured to couple the web server to the proxy unit arranged separately and downstream of the web server, wherein the proxy adapter is further configured to transform the web request into the web response depending on the proxy unit arranged separately and downstream of the web server and the web service.
[0074] The process control device is, in particular, an IoT device or an edge device. It can be implemented as a programmable logic controller (PLC). In particular, the process control device can be implemented in software, or parts of the process control device can be implemented as software. Furthermore, other parts of the process control device can also be implemented in hardware at the same time.
[0075] According to the second aspect, the first management domain and the second management domain are not spatially separated from each other, but are implemented on a single device, namely the industrial automation device.
[0076] The technical effects and advantages described for the communication system according to the first aspect apply equally to the industrial automation device according to the second aspect.
[0077] Furthermore, the embodiments and features described with reference to the communication system according to the first aspect equally apply to the industrial automation device according to the second aspect.
[0078] According to an embodiment of the second aspect, the web server is arranged in a first management domain and the proxy unit arranged separately and downstream of the web server is arranged in a second management domain, wherein the first management domain and the second management domain are logically separated from one another.
[0079] According to a further embodiment of the second aspect, the first management domain is designed as a local decentralized application runtime environment, which has a local or remote APP store with at least one local application, and the second management domain is designed as a further local decentralized application runtime environment, which has a central APP store with at least one centrally stored application.
[0080] According to a further embodiment of the second aspect, the local decentralized application runtime environment is configured to drag the local application onto the industrial automation device depending on the received web request, wherein the further local decentralized application runtime environment is configured to load the web service depending on a network request received via the proxy unit and to make it available to the proxy unit for provision to the client.
[0081] The term "pulling a local application" can also be referred to as "pulling" a local application. The process of configuring the additional local, decentralized application runtime environment to load the web service based on a network request received via the proxy unit and making it available to the proxy unit for delivery to the client can also be referred to as "pushing" or "pushing" the web service or a centrally stored application to the proxy unit.
[0082] According to a further embodiment of the second aspect, the proxy adapter for transforming the web request into the web response is configured to convert the web request into a network request, in particular into an HTTP request, to transmit the network request to the proxy unit arranged separately and downstream of the web server, to receive a network response, in particular an HTTP response, from the proxy unit arranged separately and downstream of the web server as a function of the web service and on the basis of the network request, and to convert the received network response into the web response.
[0083] According to a further embodiment of the second aspect, the local application and the centrally stored application are configured to carry out control and regulation processes depending on the industrial automation device in a communication system.
[0084] According to a further embodiment of the second aspect, the local application and the centrally stored application are configured to capture, condense and / or process sensor data from sensors in the communication system.
[0085] According to a further embodiment of the second aspect, the local application and the centrally stored application are configured to output control data at least from the industrial automation device.
[0086] According to a further embodiment of the second aspect, the industrial automation device is configured to monitor and / or control processes and / or systems of the communication system depending on the web service.
[0087] According to a further embodiment of the second aspect, the web server is further configured to monitor and / or control further processes and / or further systems of the communication system depending on the web service and depending on the at least one local application.
[0088] According to a further embodiment of the second aspect, the web server is further configured to perform management processes in the first management domain and / or in the second management domain.
[0089] Further possible implementations of the invention also include combinations of features or embodiments described above or below with regard to the exemplary embodiments not explicitly mentioned. In this case, the person skilled in the art will also add individual aspects as improvements or additions to the respective basic form of the invention. Regardless of the grammatical gender of a particular term, persons with male, female, or other gender identities are included.
[0090] Further advantageous embodiments and aspects of the invention are the subject of the dependent claims and the exemplary embodiments of the invention described below. The invention will be explained in more detail below using preferred embodiments with reference to the accompanying figures. Fig. 1 shows a schematic block diagram of a web platform according to the prior art; Fig. 2 shows a schematic block diagram of a communication system according to an embodiment; Fig. 3 shows a schematic block diagram of a web server according to an embodiment; and Fig. 4 shows a schematic block diagram of an industrial automation device according to an embodiment.
[0091] In the figures, identical or functionally equivalent elements have been given the same reference numerals unless otherwise stated.
[0092] Fig. 1 shows a schematic block diagram of a web platform 90 according to the prior art. The web platform 90 of the Fig. 1 As already described in the introduction, it has a first management domain LAR, which is designed as a local decentralized application runtime environment with a local APP store L_Store, and a second management domain IAR, which is designed as a further local decentralized application runtime environment with a central APP store I_Store.
[0093] As in Fig. 1 As shown, a proxy unit 10 is assigned to the first management domain LAR.
[0094] In the case of the first management domain LAR, the management of the local or remote APP store L_Store and its applications is carried out via a first web server unit 35. In contrast, in the case of the second management domain IAR, the management of the central APP store I_Store and its applications is carried out via a second web server unit 36.
[0095] In Fig. 1 The two web server units 35, 36 are integrated via the upstream proxy unit 10.
[0096] In the proxy unit 10, each sub-web server behind it, i.e. the first and second web server units 35, 36, is assigned a sub-URL under which this respective web server can be reached from the outside via the proxy unit 10. This is the central entry point into the web platform 90 in the Fig. 1 in the prior art, the proxy unit 10. The proxy unit 10 assumes the distribution of the incoming web requests, for example the web request W_Req, to the respective sub-web servers such as the first web server unit 35 or the second web server unit 36. In the Fig. 1 the web request W_Req is intended for the second management domain IAR, so it is forwarded to the second web server unit 36.
[0097] Fig. 2 shows a schematic block diagram of a communication system 100 according to one embodiment. The communication system 100 of Fig. 2 is designed as an automation system which is designed to process a web request W_Req from a client C to retrieve a web service W_SER in a specific network. The communication system 100 of the Fig. 2 has a web server 30 and a proxy unit 10.
[0098] The web server 30 is in Fig. 2 arranged in a first management domain LAR, wherein the first management domain LAR is designed as a local decentralized application runtime environment, which has a local or remote APP store L_Store with at least one local application. The proxy unit 10, which is separate from and arranged downstream of the web server 30, is arranged in a second management domain IAR, wherein the second management domain IAR is designed as a further local decentralized application runtime environment, which has a central APP store I_Store with at least one centrally stored application. In addition, the first management domain LAR and the second management domain IAR are logically separated from one another. In addition, the management of the central APP store I_Store and its applications takes place via a Fig. 2 not shown web server unit, such as the second web server unit 36 (cf. Fig. 1 ), which is arranged between the proxy unit 10 and the central APP store I_Store (not shown).
[0099] Furthermore, the web server 30 is configured to receive the web request W_Req from the client C and to transmit a web response W_Resp transformed on the basis of the web request W_Req back to the client C. The proxy unit 10 is arranged separately from the web server 30 and arranged downstream of the web server 30 in the communication system 100 and coupled to the web service W_SER. Thus, in Fig. 2 the web server 30 is arranged upstream of the proxy unit 10.
[0100] Furthermore, the web server 30 has a proxy adapter 20 which is configured to couple the web server 30 to the proxy unit 10 arranged separately and downstream of the web server 30.
[0101] The proxy adapter 20 is further configured to transform the web request W_Req into the web response W_Resp depending on the proxy unit 10 arranged separately and downstream of the web server 30 and the web service W_SER.
[0102] In this case, the proxy adapter 20 for transforming the web request W_Req into the web response W_Resp is configured to convert the web request W_Req into a network request N_Req, here an HTTP request, to transmit the network request N_Req to the proxy unit 10 arranged separately and downstream of the web server 30, to receive a network response N_Resp, here an HTTP response, from the proxy unit 10 arranged separately and downstream of the web server 30 as a function of the web service W_SER and on the basis of the network request N_Req, and to convert the received network response N_Resp into the web response W_Resp.
[0103] As also in Fig. 2 As shown, the web server 30 has a Uniform Resource Locator handler chain 21 with a plurality of Uniform Resource Locator handlers URL1, URL2, wherein the proxy adapter 20 in the web server 30 is arranged at the end of the Uniform Resource Locator handler chain 21.
[0104] Here, the multiple Uniform Resource Locator handlers URL1, URL2 are arranged in a series one after the other in the web server 30, wherein each Uniform Resource Locator handler URL1, URL2 is configured to forward the received web request W_Req to the next Uniform Resource Locator handler in the series. The last Uniform Resource Locator handler in the series is configured to transmit the forwarded received web request W_Req to the proxy adapter 20 and to receive the transformed web response W_Resp from the proxy adapter 20.
[0105] Furthermore, the communication system 100 of the Fig. 2 a certificate store 50 for storing digital certificates. The certificate store 50 is connected to a certification authority (not shown). These stored digital certificates include a first digital certificate CERT1 for the web server 30 and a second digital certificate CERT2 for the proxy unit 10.
[0106] The certificate store 50 is configured to store the first digital certificate CERT1 in dependence on the web server 30 and to provide it to the web server 30 and to store the second digital certificate CERT2 in dependence on the proxy unit 10 and to provide it to the proxy unit 10.
[0107] Furthermore, the web server 30 and the proxy unit 10 are configured, depending on the first digital certificate CERT1 and the second digital certificate CERT2, to establish an encrypted channel 60 between the proxy adapter 20 and the proxy unit 10 for the secure transmission of the network request N_Req and the network response N_Resp between the proxy adapter 20 and the proxy unit 10, wherein the encrypted channel 60 is secured in particular by means of HTTPS.
[0108] Fig. 3 shows a schematic block diagram of a web server 30 according to an embodiment with the proxy adapter 20. Furthermore, the web server 30 of the Fig. 3 a base web server 31, an application firewall 32, an authentication component 33 and a first URL handler URL1 and a second URL handler URL2, which form the URL handler chain 21 (cf. Fig. 2 ). The first URL handler, URL1, is responsible for static web pages, while the second URL handler, URL2, is responsible for dynamic web pages.
[0109] Fig. 3 shows the path of a web request W_Req through the web server 30 of the Fig. 3 .
[0110] The basic web server 31 is responsible for accepting the web request W_Req or web requests and sending the web responses W_Resp. The basic web server 31 is supplemented by a series of URL handlers URL1, URL2, which are registered in the web server 30 for handling specific web requests. One type of web request handler, for example the first URL handler URL1, registers itself for dedicated URLs, for example, URLs to static web pages. Incoming web requests W_Req are forwarded by the basic web server 31 to the respective responsible registered URL handler. The responsible URL handler(s) then process the web request W_Req and generate the corresponding responses. These responses (e.g. web services W_SER (cf. Fig. 2 and 4 ) such as web pages) are returned to a responder 31b of the base web server 31 and sent from the responder 31b to the client C.
[0111] This is explained in detail below: A client C sends a web request W_Req, which is received by a request receiver 31a of the base web server 31 after passing a network firewall (not shown).
[0112] The web request W_Req is then forwarded to an optional, but in Fig. 3 The request is forwarded to the existing application firewall 32. An application firewall 32, especially a web application firewall, is used to protect web applications from attacks via the HTTP protocol. If the application firewall 32 rejects the web request W_Req, an error message ERR is sent back to client C.
[0113] If the web request W_Req was not rejected by the application firewall 32, it is sent to an optional, but in the Fig. 3 existing authentication component 33, in which client C is authenticated. If client C is not accepted, an error message ERR (often in the form of an HTML page) is sent back to client C.
[0114] If this authentication of client C was successful, the web request W_Req is processed by a URL handler, e.g., for static HTML pages—in this case, the first URL handler URL1. If the web request W_Req is fulfilled by a static HTML page, a static response STA_Resp in the form of the static HTML page is returned to client C.
[0115] If the web request W_Req has not yet been processed positively in the first URL handler URL1, it is forwarded to the next URL handler and processed there. This is Fig. 3 the second URL handler URL2, which creates dynamically generated content and processes dynamic web pages.
[0116] If the web request W_Req can be fulfilled in the second URL handler URL2, a dynamic response DYN_Resp, for example in the form of a generated HTML page or a data description in JSON format, is returned to client C. If the web request W_Req cannot be fulfilled in the second URL handler URL2, a message (not shown) in the form of an HTTP error 404 ("not found") would be returned to client C in the prior art.
[0117] However, the web server 30 now has the proxy adapter 20. This means that if the web request W_Req cannot be fulfilled in the second URL handler URL2, a message in the form of an HTTP error 404 ("not found") is not returned to the client C as in the prior art, but the web request W_Req is simply forwarded to the proxy adapter 20. The proxy adapter 20, in turn, converts the web request W_Req into a network request N_Req and forwards it to the proxy unit 10 (see FIG. Fig. 2 and 4 ) of the second management domain IAR (cf. Fig. 2 and 4 ). Proxy unit 10 then uses its configuration file to check whether the network request N_Req is sent to a web service W_SER assigned to it (see Fig. 2 and 4 ), such as a web server or a web app, for processing to obtain a forwarding result. If the forwarding result is positive (positive message), the web service W_SER is present, and forwarding through the proxy unit 10 can occur. If the received forwarding result is negative, the network response N_Resp is in the form of an error message ERR, in this case an HTTP error message.
[0118] Fig. 4 shows a schematic block diagram of an industrial automation device 40 according to an embodiment. The industrial automation device 40 is in Fig. 4 as a process control device, in particular as a programmable logic controller. The industrial automation device 40 is configured to process a web request W_Req from a client C to retrieve a web service W_SER in a specific network.
[0119] The industrial automation device 40 of the Fig. 4 has a web server 30 and a proxy unit 10.
[0120] The web server 30 is in Fig. 4 arranged in a first management domain LAR, wherein the first management domain LAR is designed as a local, decentralized application runtime environment having a local or remote APP store L_Store with at least one local application. The proxy unit 10, which is separate from and arranged downstream of the web server 30, is arranged in a second management domain IAR, wherein the second management domain IAR is designed as a further local, decentralized application runtime environment having a central APP store I_Store with at least one centrally stored application. Furthermore, the first management domain LAR and the second management domain IAR are logically separated from one another.
[0121] Furthermore, the web server 30 is configured to receive the web request W_Req from the client C and to transmit a web response W_Resp transformed on the basis of the web request W_Req back to the client C. The proxy unit 10 is arranged separately from the web server 30 and arranged downstream of the web server 30 in the communication system 100 and coupled to the web service W_SER. Thus, in Fig. 4 the web server 30 is arranged upstream of the proxy unit 10.
[0122] Furthermore, the web server 30 has a proxy adapter 20 which is configured to couple the web server 30 to the proxy unit 10 arranged separately and downstream of the web server 30.
[0123] The proxy adapter 20 is further configured to transform the web request W_Req into the web response W_Resp depending on the proxy unit 10 arranged separately and downstream of the web server 30 and the web service W_SER.
[0124] The proxy adapter 20 is configured to transform the web request W_Req into the web response W_Resp to convert the web request W_Req into a network request N_Req, here an HTTP request, to transmit the network request N_Req to the proxy unit 10 arranged separately and downstream of the web server 30, to receive a network response N_Resp, here an HTTP response, from the proxy unit 10 arranged separately and downstream of the web server 30 as a function of the web service W_SER and on the basis of the network request N_Req, and to convert the received network response N_Resp into the web response W_Resp.
[0125] Furthermore, Fig. 4 the local decentralized application runtime environment is configured to drag the local application onto the industrial automation device 40 depending on the received web request W_Req.
[0126] The additional local decentralized application runtime environment in Fig. 4 is configured to load the web service W_SER depending on a network request N_Req received via the proxy unit 10 and to make it available to the proxy unit 10 for provision to the client C.
[0127] Furthermore, the local application and the centrally stored application are configured to carry out control and regulation processes depending on the industrial automation device 40 in a communication system 100 (cf. Fig. 2 ), to collect, condense and / or process sensor data from sensors in the communication system 100 and to output control data at least from the industrial automation device 40.
[0128] Furthermore, the industrial automation device 40 is configured to monitor and / or control processes and / or systems of the communication system 100 depending on the web service W_SER.
[0129] In addition, the web server 30 is further configured to monitor and / or control further processes and / or further systems of the communication system 100 depending on the web service W_SER and depending on the at least one local application, and to carry out management processes in the first management domain LAR and / or in the second management domain IAR.
[0130] Although the present invention has been described using exemplary embodiments, it can be modified in many ways.
[0131] Regardless of the grammatical gender of a particular term, persons with male, female or other gender identities are included.
Claims
1. Communication system (100) for processing a web request (W_Req) from a client (C) to retrieve a web service (W_SER) in a specific network, comprising: a web server (30) for receiving the web request (W_Req) from the client (C) and for transmitting a web response (W_Resp), which has been transformed on the basis of the web request (W_Req), back to the client (C), a proxy unit (10) which is arranged separately from the web server (30) and downstream of the web server (30) in the communication system (100), and is coupled to the web service (W_SER), wherein the web server (30) has a proxy adapter (20) which is configured to couple the web server (30) to the proxy unit (10) which is arranged separately from and downstream of the web server (30), wherein the proxy adapter (20) is further configured to transform the web request (W_Req) into the web response (W_Resp) in a manner dependent on the proxy unit (10) which is arranged separately from and downstream of the web server (30) and dependent on the web service (W_SER), wherein the web server is arranged in a first management domain (LAR) and the proxy unit, which is arranged separately from and downstream of the web server, is arranged in a second management domain (IAR), wherein the first management domain (LAR) and the second management domain (IAR) are logically separate from each other, characterised in that the first management domain (LAR) is designed as a local decentralised application runtime environment having a local or remote APP store (L_Store) with at least one local application, and the second management domain (IAR) is designed as a further local decentralised application runtime environment having a central APP store (I_Store) with at least one centrally stored application.
2. Communication system according to claim 1, characterised in that the web server (30) has a uniform resource locator handler chain (21) comprising a plurality of uniform resource locator handlers (URL1, URL2), wherein the proxy adapter (20) in the web server (30) is arranged at the end of the uniform resource locator handler chain (21).
3. Communication system according to claim 2, characterised in that the plurality of uniform resource locator handlers (URL1, URL2) of the uniform resource locator handler chain (21) are arranged in series one behind the other in the web server (30), wherein each uniform resource locator handler (URL1, URL2) of the uniform resource locator handler chain (21) is configured to forward the received web request (W_Req) to the next uniform resource locator handler in the series, wherein the last uniform resource locator handler in the series is configured to transmit the forwarded received web request (W_Req) to the proxy adapter (20) and to receive the transformed web response (W_Resp) from the proxy adapter (20).
4. Communication system according to one of claims 1 - 3, characterised in that, for the purpose of transforming the web request (W_Req) into the web response (W_Resp), the proxy adapter (20) is configured to convert the web request (W_Req) into a network request (N_Req), to transmit the network request (N_Req) to the proxy unit (10) that is arranged separately from and downstream of the web server (30), to receive a network response (N_Resp), from the proxy unit (10) that is arranged separately from and downstream of the web server (30), said network response being dependent on the web service (W_SER) and based on the network request (N_Req), and to convert the received network response (N_Resp) into the web response (W_Resp).
5. Communication system according to one of claims 1 - 4, characterised in that the communication system (100) also has a certificate store (50) for storing digital certificates, wherein the stored digital certificates comprise a first digital certificate (CERT1) for the web server (30) and a second digital certificate (CERT2) for the proxy unit (10), wherein the certificate store (50) is configured to store the first digital certificate (CERT1) in a manner dependent on the web server (30) and to make it available for the web server (30), and to store the second digital certificate (CERT2) in a manner dependent on the proxy unit (10) and to make it available for the proxy unit (10).
6. Communication system according to claim 5, characterised in that the web server (30) and the proxy unit (10) are configured in a manner dependent on the first digital certificate (CERT1) and the second digital certificate (CERT2) to establish an encrypted channel (60) between the proxy adapter (20) and the proxy unit (10) for secure transmission of the network request (N_Req) and the network response (N_Resp) between the proxy adapter (20) and the proxy unit (10), wherein the encrypted channel (60) is secured.
7. Industrial automation device (40) for processing a web request (W_Req) from a client (C) to retrieve a web service (W_SER) in a specific network, comprising: a web server (30) for receiving the web request (W_Req) from the client (C) and for transmitting a web response (W_Resp), which has been transformed on the basis of the web request (W_Req), back to the client (C), a proxy unit (10) which is arranged separately from the web server (30) and downstream of the web server (30) on the industrial automation device (40), and is coupled to the web service (W_SER), wherein the web server (30) has a proxy adapter (20) which is configured to couple the web server (30) to the proxy unit (10) which is arranged separately from and downstream of the web server (30), wherein the proxy adapter (20) is further configured to transform the web request (W_Req) into the web response (W_Resp) in a manner dependent on the proxy unit (10) which is arranged separately from and downstream of the web server (30) and dependent on the web service (30), wherein the web server is arranged in a first management domain (LAR) and the proxy unit, which is arranged separately from and downstream of the web server, is arranged in a second management domain (IAR), wherein the first management domain (LAR) and the second management domain (IAR) are logically separate from each other, characterised in that the first management domain (LAR) is designed as a local decentralised application runtime environment having a local or remote APP store (L_Store) with at least one local application, and the second management domain (IAR) is designed as a further local decentralised application runtime environment having a central APP store (I_Store) with at least one centrally stored application.
8. Automation device according to claim 7, characterised in that the local decentralised application runtime environment is configured to perform a pulling of the local application onto the industrial automation device (40) in a manner dependent on the received web request (W_Req), wherein the further local decentralised application runtime environment is configured to load the web service (W_SER) in a manner dependent on a network request (N_Req) received via the proxy unit (10) and make it available to the proxy unit (10) for provision to the client (C).
9. Automation device according to one of claims 7 or 8, characterised in that, for the purpose of transforming the web request (W_Req) into the web response (W_Resp), the proxy adapter (20) is configured to convert the web request (W_Req) into a network request (N_Req), to transmit the network request (N_Req) to the proxy unit (10) that is arranged separately from and downstream of the web server (30), to receive a network response (N_Resp) from the proxy unit (10) that is arranged separately from and downstream of the web server (30), said network response being dependent on the web service (W_SER) and based on the network request (N_Req), and to convert the received network response (N_Resp) into the web response (W_Resp).
10. Automation device according to one of claims 7 - 9, characterised in that the local application and the centrally stored application are configured to carry out open-loop and closed-loop control operations in a manner dependent on the industrial automation device (40) in a communication system (100).
11. Automation device according to one of claims 7 - 10, characterised in that the local application and the centrally stored application are configured to capture, collate and / or process sensor data of sensors in the communication system (100).
12. Automation device according to one of claims 7 - 11, characterised in that the local application and the centrally stored application are configured to output control data at least of the industrial automation device (40).
13. Automation device according to one of claims 7 - 12, characterised in that the industrial automation device (40) is configured to monitor and / or control processes and / or facilities of the communication system (100) in a manner dependent on the web service (W_SER).
14. Automation device according to one of claims 7 - 13, characterised in that the web server (30) is additionally configured to monitor and / or control further processes and / or further facilities of the communication system (100) in a manner dependent on the web service (W_SER) and in a manner dependent on the at least one local application.
15. Automation device according to one of claims 7 - 14, characterised in that the web server (30) is additionally configured to perform management processes in the first management domain (LAR) and / or in the second management domain (IAR) .