Update control in industrial internet of things environments
Patent Information
- Authority / Receiving Office
- EP · EP
- Patent Type
- Applications
- Current Assignee / Owner
- GEA GROUP AG
- Filing Date
- 2024-06-03
- Publication Date
- 2026-04-15
AI Technical Summary
In industrial Internet of Things (IIoT) environments, especially safety-critical systems, software updates can inadvertently disrupt industrial processes, leading to equipment damage or operational interruptions, particularly when updates are applied during active operations.
A system comprising an interface module, an IIoT update control module, and a production monitor and control module that polls for update availability and monitors the current activity state of the industrial process, deploying updates only when the system is in a predetermined criterion state (e.g., inactive or idle), ensuring that updates are not pushed during active operations.
This approach reduces the likelihood of industrial process interruptions and equipment damage by ensuring updates are applied during safe periods, while also optimizing communication and resource usage, especially in remote installations with limited bandwidth.
Smart Images

Figure EP2024065172_12122024_PF_FP_ABST
Abstract
Description
[0001] UPDATE CONTROL IN INDUSTRIAL INTERNET OF THINGS ENVIRONMENTS
[0002] FIELD OF DISCLOSURE
[0003] The present disclosure relates to the management of software updates. Particularly, but not exclusively, the present disclosure relates to the management of software updates within an industrial environment. Particularly, but not exclusively, the present disclosure relates to the deployment of software updates within a safety critical industrial Internet- of-Things environment.
[0004] BACKGROUND
[0005] Many modern industrial systems employ an industrial Internet of Things (IIoT) ecosystem to help monitor and control an industrial process performed by the industrial system. Such IIoT systems rely on software to control and drive the hardware elements of the system. As in many modern systems, updates become available for the software to address performance or security issues, or to provide new abilities or functionality. Typically, a software update is deployed within the system as soon as the update becomes available. In some situations, such automatic updating of systems or services is not problematic since the devices being updated are either read only or are not actively engaged in a critical part of the industrial process. For other situations, where the systems or services being updated are critical to the industrial process, the incorrect management or application of an update may lead to the industrial process being unexpectedly stopped and / or equipment being damaged.
[0006] Accordingly, there is a need for improved approaches to performing software updates within IIoT environments.
[0007] SUMMARY
[0008] According to an aspect of the present disclosure, there is provided a system for update control in an Industrial Internet of Things, IIoT, environment. The system comprises an interface module communicatively coupled to one or more devices for performing an industrial process. The system further comprises an IIoT update control module configured to obtain one or more software updates from an IIoT cloud and cause the one or more software updates to be deployed within the system. The system further comprises a production monitor and control module communicatively coupled to the one or more devices for performing the industrial process via the interface module. The production monitor and control module is configured to poll the IIoT update control module to determine an update availability and in response to the update availability indicating that a software update for the system is available, monitor, via the interface module, a current activity state of the industrial process. The production monitor and control module is further configured to, when the current activity state corresponds to a predetermined criterion state, instruct the IIoT update control module to cause the software update for the system to be deployed.
[0009] According to a further aspect of the present disclosure, there is provided a computer- implemented method for update control in an industrial system, the industrial system comprising one or more devices for performing an industrial process. The computer implemented method comprises polling an industrial Internet of Things, IIoT, update control module to determine an update availability for the industrial system, in response to the update availability indicating that a software update is available for the industrial system, monitoring a current activity state of the industrial process performed by the industrial system, and when the current activity state corresponds to a predetermined criterion state, instructing the IIoT update control module to cause the software update for the industrial system to be deployed.
[0010] Advantageously, the system and method of the present disclosure help ensure that updates are not pushed to modules or devices within an industrial system whilst an industrial process is in operation. This helps to reduce the likelihood of the industrial process being adversely interrupted due to a software update being performed thereby reducing the likelihood of damage to equipment. Moreover, the configuration and architecture of the system provides efficient communication and resource usage which is particularly advantageous in more remote installations or operational sites where communication bandwidth and availability may be limited.
[0011] Additional aspects and embodiments of the present systems are disclosed, and the above aspects and embodiments should not be construed as limiting the present disclosure.
[0012] BRIEF DESCRIPTION OF DRAWINGS
[0013] Embodiments of the present disclosure will now be described, by way of example only, and with reference to the accompanying drawings, in which: Figure 1 shows a system for update control in an Industrial Internet of Things, IIoT, environment according to an aspect of the present disclosure;
[0014] Figure 2 shows a sequence diagram associated with performing a controlled update within the system shown in Figure 1 according to embodiments of the present disclosure;
[0015] Figure 3 shows a method for update control in an industrial system according to an aspect of the present disclosure;
[0016] Figure 4 shows a method for update status monitoring and management according to an embodiment of the present disclosure;
[0017] Figure 5 shows an implementation of the above-described system and methods within a liquid and powder technology (LPT) system;
[0018] Figure 6 shows an implementation of the above-described system and methods within a farm system; and
[0019] Figure 7 shows an example computing system for carrying out the methods of the present disclosure.
[0020] DETAILED DESCRIPTION
[0021] Figure 1 shows a system 100 for update control in an Industrial Internet of Things, IIoT, environment according to an aspect of the present disclosure.
[0022] The system 100 comprises an interface module 102, an IIoT update control module 104, and a production monitor and control module 106. The interface module 102, the IIoT update control module 104 and the production monitor and control module 106 form part of a production subsystem 108. Figure 1 further shows one or more devices for performing an industrial process, the one or more devices including a first device 110, a second device 112, and / or a third device 114. The system 100 is communicatively coupled to an IIoT cloud 116 which comprises a remote server 118. Figure 1 further shows a software update 120, a locally stored software update 122, and a device state 124. The IIoT cloud 116 optionally comprises a digital twin 126.
[0023] In general, the system 100 enables controlled deployment of software updates within safety critical environments (e.g., IIoT environments). The production monitor and control module 106 polls the IIoT update control module 104 to determine an update availability. In response to the update availability indicating that a software update for the system is available (e.g., the software update 120 is available), the production monitor and control module 106 monitors, via the interface module 102, a current activity state of the industrial process (e.g., determined from at least the device state 124 received from the first device 110). When the current activity state corresponds to a predetermined criterion state, the production monitor and control module 106 instructs the IIoT update control module 104 to cause the software update for the system 100 to be deployed.
[0024] Advantageously, the system 100 helps to ensure that updates are not pushed to modules or devices of the system 100 whilst the industrial process is in operation. This helps to reduce the likelihood of the industrial process being adversely interrupted due to a software update being performed. In so doing, the likelihood of damage to equipment is reduced. Furthermore, in applications where the industrial process involves livestock, such as dairy farming, adverse interruption may cause harm or distress to the livestock and such process helps avoid such issues. Moreover, the configuration and architecture of the system 100 allows for efficient handling of software updates by reducing the communication requirements between the system 100 and the IIoT cloud 116. This is particularly beneficial in more remote installations or operational sites where communication bandwidth and availability may be limited (e.g., remote installations or installations in rural areas with limited connectivity). These and other benefits of the present disclosure will be described in more detail below.
[0025] The system 100 is co-located with the industrial process performed by the one or more devices (e.g., the first device 110, the second device 112, etc.). That is, the production subsystem 108 is an edge device that is located with the one or more devices (e.g., they are located on the same site, within the same complex, within the same building, etc.) and provides an entry point to external, or off-site, devices (e.g., the IIoT cloud 116). The skilled person will appreciate that the system 100 shown in Figure 1 is not limited to any particular site, industrial process, or application because the present disclosure may be applied across a range of contexts and settings where it is desirable to control the process of updating components (e.g., software, operating systems, firmware, and the like) due to the mission or safety critical nature of those components. As will be described in more detail below in relation to Figures 5 and 6, example deployments of the system 100 include factories, farms, breweries, ships, and the like.
[0026] The one or more devices (e.g., the first device 110, the second device 112, etc.) perform an industrial process. That is, the one or more devices form at least a part of an industrial process that is performed at the site or location at which the system 100 is deployed. For example, within a dairy farming setting, each of the one or more devices may be an individual milking robot, such as the DairyRobot R.9500 offered by GEA Group AG, which form a part of a milking process. As shown in Figure 1, the one or more devices are communicatively coupled to the production subsystem 108 via the interface module 102. Therefore, each of the one or more devices may send signals, data packets, and the like to the interface module 102 via a communication channel using a wired connection and protocol (e.g., ethernet, Universal Serial Bus, Universal Asynchronous / Synchronous Receiver Transmitter, Recommended Standard-232, or Recommended Standard-485) or a wireless connection and protocol (e.g., Bluetooth Low Energy, Wi-Fi, ZigBee, or Narrow Band-IoT).
[0027] Each device is configured to send a device state to the interface module 102 either periodically or on demand. As shown in Figure 1, the device state 124 is sent from the first device 110 to the interface module 102. The device state 124 includes a state value, or state values, associated with a current state of the first device 110. In general, the state value(s) provide an indication of whether the first device 110 is engaged in the industrial process. For example, if the first device 110 is a milking robot, then the state values may indicate whether there is a cow currently connected to the milking robot. The state value(s) within the device state 124 thus indicate whether the first device 110 is active, inactive, or idle. By obtaining state value(s) from the one or more devices engaged in the industrial process, the production monitor and control module 106 can monitor the current activity state of the industrial process.
[0028] For example, if the device states obtained from the first device 110, the second device 112, and the third device 114 all indicate that the devices are active, then the current activity state of the industrial process is determined to be active (or in progress). Similarly, if the device state obtained from the first device 110 indicates that the first device 110 is idle but the device states obtained from the second device 112 and the third device 114 indicate that these devices are active, then the current activity state of the industrial process is likewise determined to be active. Alternatively, if the device states obtained from the first device 110, the second device 112, and the third device 114 all indicate that the devices are inactive, then the current activity state of the industrial process is determined to be inactive.
[0029] Whilst the interface module 102 handles communications between other on-site devices, the IIoT update control module 104 handles communications with off-site devices. The IIoT update control module 104 forms a part of the production subsystem 108 of the system 100 and is communicatively coupled to the IIoT cloud 116 via one or more network connections (e.g., a wired network connection such as ethernet and / or a wireless network connection such as Wi-Fi, general packet radio service, 3G, 4G, 5G, or the like). The IIoT update control module 104 is configured to obtain one or more updates (software updates) from the IIoT cloud 116. In general, the IIoT update control module 104 is notified of an update being available (e.g., the software update 120) once the update has been deployed on the IIoT cloud 116. For example, an engineer may access a front end of the IIoT cloud 116 and deploy the software update 120 for the system 100 on the IIoT cloud 116. Here, deploying the software update 120 on the IIoT cloud 116 comprises the engineer uploading or transferring the software update 120 to the IIoT cloud 116 such that the software update 120 is added to a queue of available updates held on the IIoT cloud 116. More particularly, the software update 120 is transferred and stored on the remote server 118 within the IIoT cloud 116. The IIoT cloud 116, or a service running thereon, then notifies the IIoT update control module 104 that the software update 120 for the system 100 is available. For example, the IIoT cloud 116 may send an update available message which is received by the IIoT update control module 104 (where the update available message is associated with the software update 120).
[0030] In one embodiment, the digital twin 126 of the system 100 held within the IIoT cloud 116 is updated when an update for the system 100 becomes available. When the update becomes available (e.g., an engineer uploads or transfers the software update 120 to the IIoT cloud 116), the update is applied to the digital twin 126. After the update has announced successfully on the digital twin 126, the update control module 104 is informed of the availability of the update. In this way, the update is first applied to a replica of the system 100 prior to being deployed within the (live) system 100 thereby providing a safety mechanism should the update cause any unforeseen issues. That is, if an issue is determined to arise within the digital twin 126 as a result of the software update 120 being applied, then the IIoT update control module 104 is not informed of the software update 120 thereby helping to ensure that the issue is not replicated within the (live) system 100. Alternatively, the IIoT update control module 104 is informed that there is an issue with the update and IIoT update control module 104 does not deploy the update to the IIoT cloud 116 and / or devices 110, 112, 114.
[0031] When the software update 120 becomes available and the IIoT update control module 104 is notified of the update availability, the IIoT update control module 104 is configured to obtain the software update 120 from the IIoT cloud 116. For example, the IIoT update control module 104 downloads the software update 120 from the remote server 118 of the IIoT cloud 116 and stores the software update 120 within a local storage device. This is illustrated in Figure 1 by the locally stored software update 122 which corresponds to a local copy of the software update 120 downloaded from the remote server 118 by the IIoT update control module 104. The locally stored software update 122 is stored in a persistent storage location accessible to the IIoT update control module 104 (e.g., a non-transitory computer readable medium, a memory, a disk drive, or the like). Optionally, the IIoT update control module 104 only notifies other components within the system 100 of the availability of the update after the update has been successfully downloaded or transferred from the remote server 118 of the IIoT cloud 116. That is, the IIoT update control module 104 may download / pre-load the software update 120 (i.e., pre-load the locally stored software update 122) prior to notifying other modules within the system 100 that the locally stored software update 122 is available. Advantageously, pre-loading an update in this manner helps ensure that the update is efficiently deployed in the system 100 by reducing the time period within which the one or more devices need to be idle, inactive, or stopped for performing an update. This then reduces the time that the industrial process is "offline", or otherwise not running, due to the system 100 being updated.
[0032] To determine whether an update is available, the production monitor and control module 106 (alternatively referred to as a production management module, a control module, or a local management module) polls the IIoT update control module 104. The production monitor and control module 106 polls the IIoT update control module 104 at a predetermined frequency, or polling frequency. The predetermined polling frequency is between 0.001Hz (i.e., a request is made every 16 or so minutes) and 2Hz (i.e., two requests are made every second). In one implementation, the predetermined polling frequency is 0.01Hz such that a request is sent by the production monitor and control module 106 to the IIoT update control module 104 every 10 seconds. Because the production monitor and control module 106 and the IIoT update control module 104 are both local modules within the production subsystem 108— that is, they are modules of the same device or they are devices within the same local area network— the polling performed by the production monitor and control module 106 is more efficient, and utilises fewer resources, than if the production monitor and control module 106 were to poll an external system (e.g., the IIoT cloud 116) to determine an update availability. This is particularly beneficial for low compute resource devices, or for remote installations, where communication bandwidth and availability may be limited.
[0033] The poll response from the IIoT update control module 104 received by the production monitor and control module 106 is indicative of an update availability. If the poll response (i.e., the update availability) indicates than no update is available, then the production monitor and control module 106 continues to poll the IIoT update control module 104 at the predetermined frequency. If the poll response (i.e., the update availability) indicates that an update is available, then the production monitor and control module 106 is configured to monitor a current activity state of the industrial process to determine whether it is safe for the update to be deployed.
[0034] The current activity state of the industrial process is obtained by the production monitor and control module 106 via the interface module 102. As stated in more detail above, each device (e.g., the first device 110, the second device 112, etc.) provides a device state to the production monitor and control module 106, via the interface module 102, which provide an indication of whether the device is engaged in the industrial process. The production monitor and control module 106 then determines the current activity state of the industrial process based on the collected device states. The current activity state of the industrial process is either active, inactive, idle, or stopped. The production monitor and control module 106 uses the current activity state to determine whether to instruct the IIoT update control module 104 to cause the update to be deployed. If the current activity state corresponds to a predetermined criterion state, then the production monitor and control module 106 instructs the IIoT update control module 104 to cause the update to be deployed. If the current activity state does not correspond to a predetermined criterion state, then the production monitor and control module 106 continues to monitor the activity state of the industrial process. The predetermined criterion state corresponds to a target state which the industrial process is to transition to for the update to be deployed within the system 100. As such, the predetermined criterion state comprises an indication corresponding to, or is indicative of, the industrial process being inactive, idle, or stopped.
[0035] When the industrial process is in a predetermined criterion state (e.g., the industrial process is inactive, idle, or stopped), the production monitor and control module 106 is configured to instruct the IIoT update control module 104 to cause the update to be deployed. Beneficially, such activity-based deployment of updates provides a mechanism for controlling updates within the system 100 such that the likelihood of any disruptions to the system 100, and the industrial process to which the system 100 relates, is substantially reduced. This is particularly advantageous in safety critical systems where it is particularly desirable to reduce the occurrences of issues arising due to the update process.
[0036] Optionally, the production monitor and control module 106 instructs the IIoT update control module 104 to deploy the update during an update timeframe. The update timeframe corresponds to a time window, or time period, within which the update is to be deployed. The update timeframe also corresponds to the period of time within which the production monitor and control module 106 monitors the current activity state of the industrial process. That is, the production monitor and control module 106 may be configured to monitor the current activity state of the industrial process only when a current time (e.g., the current system time) is determined to be within the update timeframe. For example, if the update timeframe corresponds to a time window of from 23:00 to 04:00, then the production monitor and control module 106 would begin monitoring the current activity state of the industrial process at or near 23:00 and would end monitoring at or near 04:00 (and would not instruct the IIoT update control module 104 to cause the update to be deployed before 23:00 or after 04:00). The update timeframe is obtained from a user of the system 100 or from a predetermined schedule associated with the industrial process. When the update is available, the production monitor and control module 106 is configured to notify the user that an update is available and request an update timeframe from the user. For example, a notification may be sent to a device of the user such as a terminal or smartphone, or the notification may be provided as an alert presented on a web portal associated with the system 100 accessible to the user. The user is then provided with an interface for inputting an update timeframe. Advantageously, by restricting the monitoring of the activity state of the industrial process, and the installation of an update, to a timeframe provided by a user, the likelihood of the update being deployed during a period of time in which the industrial process is active is reduced.
[0037] When the update timeframe is obtained from a predetermined schedule associated with the industrial process, the production monitor and control module 106 is configured to obtain the predetermined schedule and determine the update timeframe from the predetermined schedule. The predetermined schedule comprises information or data indicative of the time period(s) within which the industrial process is expected to be in operation. For example, the predetermined schedule may be a daily log listing the times at which the industrial process is expected to be running. The update timeframe is then determined by identifying time periods within the predetermined schedule during which the industrial process is not expected to be running. Alternatively, the update timeframe is expressly contained within the predetermined schedule. Beneficially, by restricting the monitoring of the activity state of the industrial process, and the installation of an update, to a timeframe associated with the predetermined schedule, the likelihood of the update being deployed during a period of time in which the industrial process is active is reduced. Moreover, the automation of such a determination using a predetermined schedule provides a further efficiency and allows update timeframes to be managed centrally and deployed efficiently across multiple sites (i.e., by the modification, update, and distribution of the predetermined schedule).
[0038] In one embodiment, the production monitor and control module 106 receives an override command while the current activity state of the industrial process is being monitored (i.e., before the production monitor and control module 106 instructs the IIoT update control module 104 to cause the update to be deployed). In response to the override command being received, the production monitor and control module 106 is configured to instruct the IIoT update control module 104 to cause the update to be deployed regardless of whether the current activity state is in a predetermined activity state. The override command is received from a user of the system 100 (e.g., via an input provided on a user interface of dashboard associated with control of the system 100), a service or module running on or connected to the IIoT cloud 116, or a user of the IIoT cloud 116 (e.g., an engineer or technician). Following the production monitor and control module 106 instructing the IIoT update control module 104 to cause the update to be deployed, the IIoT update control module 104 sends an instruction (e.g., a message or data packet) to the IIoT cloud 116 to indicate that the update can now be deployed within the system 100. The IIoT cloud 116 then orchestrates the update process by deploying, or installing, the locally stored software update 122 on the system 100.
[0039] The update (e.g., the locally stored software update 122) is a software update comprising a firmware update and / or a software service update. A firmware update is used to update the software used for low-level device control. A firmware update is thus used to update one or more of the interface module 102, the IIoT update control module 104, the production monitor and control module 106, the production subsystem 108, and / or the one or more devices (e.g., the first device 110, the second device 112, the third device 114, etc.). A software service update is used to update a service, or software component, of the system such as an operating system (OS) or a software application installed on a device or component within the system 100. The software component is installed on one or more of the interface module 102, the IIoT update control module 104, the production monitor and control module 106, the production subsystem 108, and / or the one or more devices (e.g., the first device 110, the second device 112, the third device 114, etc.). By orchestrating the update process remotely, the IIoT cloud 116 is able to monitor and manage the deployment of the update thereby providing a mechanism for efficient recovery in the event of an issue arising during the update process. For example, the IIoT cloud 116 may rollback the update and restore the system 100, or any specific module therein, to its previous state if the update was not successfully deployed or installed.
[0040] During the update process, the production monitor and control module 106 is configured to obtain an update status from the IIoT update control module 104 and output the update status to a user of the system 100. For example, the update status may be displayed on a graphical user interface or dashboard viewable by the user. The update status indicates a status of the update which can include an indication of whether the update is complete, an indication of the outcome of the update (e.g., success, failure, interrupted, etc.), an indication of the current progress made through the update (e.g., a percentage completion), an indication of elapsed time since the update began, and / or an estimation of the time remaining for the update to be complete. Optionally, the production monitor and control module 106 is configured to obtain and output the update status provided the update does not directly affect the operation or functionality of the production monitor and control module 106 (i.e., the update does not prevent the production monitor and control module 106 from obtaining and outputting the update status). Similarly, if the update does not relate to an update for the production monitor and control module 106, then the production monitor and control module 106 can cause the IIoT update control module 104 to instruct the IIoT cloud 116 to roll back the update when the update status indicates that the update has failed. As stated above, the IIoT cloud 116 will then revert the component(s) being updated to the state held prior to the update. For example, the state of the digital twin 126 can be reverted to the prior state and then the state of the digital twin 126 used to update the state of the component(s) being updated within the system 100. Additionally or alternatively, the IIoT cloud 116 is configured to perform the above described update status monitoring and update rollback.
[0041] Figure 2 shows a sequence diagram 200 associated with performing a controlled update within the system 100 shown in Figure 1 according to embodiments of the present disclosure.
[0042] The sequence diagram 200 comprises a sequence of operations 202-222 (instructions or steps) performed by the IIoT update control module 104, the production monitor and control module 106, the one or more devices (e.g., the first device 110, the second device 112, the third device 114, etc.), and the IIoT cloud 116 of the system 100 shown in Figure 1. Therefore, references will be made to the numbered features of Figure 1 throughout the description of Figure 2 for ease of reference.
[0043] At operation 202, the production monitor and control module 106 polls the IIoT update control module 104 to determine an update availability. At operation 204, the IIoT update control module 104 provides a response, or update availability, to the request received at operation 202. If the response indicates that no update is currently available, then the production monitor and control module 106 continues to poll the IIoT update control module 104 at a predetermined polling frequency (e.g., 0.001Hz, 0.01Hz, 0.1Hz, 1Hz, etc.). Consequently, a loop is formed between operation 202 and operation 204 while the response provided at operation 204 indicates that no update is currently available.
[0044] At operation 206, the IIoT cloud 116 sends an update available message to the IIoT update control module 104 to indicate that an update (e.g., the software update 120) is available. As stated above, the IIoT update control module 104 may then download or preinstall the update.
[0045] At operation 208, the IIoT update control module 104 provides a response to the request received at operation 202 (i.e., during the polling loop) which indicates to the production monitor and control module 106 that the update is available. In consequence, the production monitor and control module 106 stops polling the IIoT update control module 104. At operation 210, the production monitor and control module 106 obtains an update timeframe within which the update is to be performed. As stated above in relation to Figure 1, the update timeframe is obtained from a user of the system 100 or from a predetermined schedule associated with the industrial process. When the update timeframe is obtained at operation 210, the production monitor and control module 106 at operation 212 waits for the update timeframe to be reached. For example, if the update timeframe starts at 20:00, then at operation 210, the production monitor and control module 106 will wait until the system clock reaches 20:00 before proceeding to operation 214. Alternatively, no update timeframe is obtained, and the sequence of operations proceeds directly from operation 208 to operation 214.
[0046] At operation 214 and operation 216, the production monitor and control module 106 monitors the activity state of the industrial process by monitoring the device state(s) of the one or more devices. For example, at operation 214 the production monitor and control module 106 may send a request to each device requesting the first device(s) to send a current device state indication. In reply, at operation 216, the device(s) may send their current device state(s) to the production monitor and control module 106 such that the activity state of the industrial process can be determined from the collected device state(s). Alternatively, the production monitor and control module 106 is passive (i.e., does not send the response at operation 214) and periodically receives device state(s) from the device(s) at operation 216. For example, the one or more devices may be configured to report their state periodically (e.g., every Is, 10s, 30s, 60s, etc.). If the activity state of the industrial process does not meet a predetermined criterion state (e.g., the activity state of the industrial process is idle, inactive, or stopped), then the production monitor and control module 106 continues to monitor the activity state of the industrial process by returning to operation 214 thereby forming a loop, or by waiting for the next device state(s) to be periodically reported. If the activity state of the industrial process does meet a predetermined criterion state, then the production monitor and control module 106 proceeds to operation 218.
[0047] At operation 218, the production monitor and control module 106 instructs the IIoT update control module 104 to cause the update to be deployed. In response, at operation 220 the IIoT update control module 104 sends an instruction (e.g., a message or data packet) to the IIoT cloud 116 to indicate that the update can now be deployed within the system. At operation 222, the IIoT cloud 116 orchestrates the deployment of the update within the system in response to the instruction received from the IIoT update control module 104.
[0048] The skilled person will appreciate that the set of operations shown in the sequence diagram 200 are not intended to be an exhaustive or limiting set of operations performed by the system 100. Indeed, as described in more detail in the foregoing, the system 100 and the modules included therein are configured to perform a number of other steps not shown in the sequence diagram 200 as part of the update control process. Rather, the sequence diagram 200 shown in Figure 2 is intended to illustrate the general flow of operations performed by the system 100 during the update control process.
[0049] Figure 3 shows a method 300 for update control in an industrial system according to an aspect of the present disclosure.
[0050] The method 300 comprises the steps of polling 302 an IIoT update control module, determining 304 an update availability, monitoring 306 a current activity state, determining 308 if a predetermined criterion state is reached, and instructing 310 the IIoT update control module to cause a software update to be deployed. Figure 3 further shows the optional steps of obtaining 312 an update timeframe and determining 314 if the update timeframe has been reached. In one embodiment, the method 300 is performed by one or more modules or components of the system 100 shown in Figure 1 (e.g., the production monitor and control module 106).
[0051] In general, the method 300 helps to reduce the likelihood of an industrial process being adversely interrupted due to a software update being performed by helping to ensure that updates are not pushed to modules or devices of a system involved in the industrial process whilst the industrial process is in operation.
[0052] At the step of polling 302, an IIoT update control module is polled to determine an update availability for the industrial system (e.g., the production monitor and control module 106 polls the IIoT update control module 104 to determine an update availability for the system 100).
[0053] At the step of determining 304, the update availability is analysed to determine if an update is available. That is, the production monitor and control module analyses the poll response received from the IIoT update control module to determine whether an update for the industrial system is available.
[0054] In response to the update availability indicating that no software update is available for the industrial system, the method 300 returns to the step of polling 302. If the production monitor and control module is configured to poll the IIoT update control module at a predetermined polling frequency, then the production monitor and control module waits for the requisite length of time before sending the next poll message (e.g., Is, 2s, 5s, 10s, etc.).
[0055] In response to the update availability indicating that a software update is available for the industrial system, the method 300 proceeds to the step of monitoring 306, where a current activity state of the industrial process performed by the industrial system is monitored. As stated in more detail above in relation to Figures 1 and 2, monitoring the current activity state of the industrial process comprises obtaining one or more device states from the one or more devices operable to perform the industrial process.
[0056] At the step of determining 308, the current activity state is analysed to determine if the current activity state of the industrial process corresponds to a predetermined criterion state. For example, the current activity state is analysed to determine if the industrial process is idle, inactive, or stopped. When the current activity state does not correspond to a predetermined criterion state, the method 300 returns to the step of monitoring 306 to continue the monitoring of the current activity state of the industrial process.
[0057] When the current activity state corresponds to a predetermined criterion state, the method proceeds to the step of instructing 310, where the IIoT update control module is instructed to cause the software update to be deployed. For example, the IIoT update control module (e.g., the IIoT update control module 104) is instructed to send an instruction (e.g., a message or data packet) to the IIoT cloud (e.g., the IIoT cloud 116) to indicate that the update (e.g., the locally stored software update 122) can now be deployed within the system.
[0058] In one embodiment, the method 300 further comprises the steps of receiving (not shown) an override command while the current activity state of the industrial process is being monitored (i.e., at the step of monitoring 306), and in response to the override command being received, proceeding directly to the step of instructing 310 the IIoT update control module to cause the software update for the industrial system to be deployed.
[0059] As stated above, the method 300 further comprises the optional steps of obtaining 312 and determining 314 which are optionally performed after the step of polling 302 and before the step of monitoring 306. That is, the method 300 either proceeds directly from polling 302 and determining 304 an update availability to the step of monitoring 306, or proceeds from polling 302 and determining 304 to the steps of obtaining 312 and determining 314 before proceeding to the step of monitoring 306.
[0060] At the optional step of obtaining 312, an update timeframe is obtained. The update timeframe corresponds to a time window, or time period, within which the update is to be deployed. The update timeframe also corresponds to the period of time within which the production monitor and control module monitors the current activity state of the industrial process. The update timeframe is obtained from a user of the system or from a predetermined schedule associated with the industrial process.
[0061] At the optional step of determining 314, the current time is compared to the update timeframe to determine if the update timeframe has been reached. If the update timeframe has not been reached, then the method 300 continues to wait until the update timeframe has been reached. If the update timeframe has been reached, then the method 300 proceeds to the step of monitoring 306.
[0062] Figure 4 shows a method 400 for update status monitoring and management according to an embodiment of the present disclosure.
[0063] The method 400 comprises the steps of obtaining 402 an update status, outputting 404 the update status, determining 406 whether the update has failed, and causing 408 the update to be rolled back. In an embodiment, the method 400 is performed in conjunction with the method 300 shown in Figure 3. More particularly, the step of obtaining 402 the update status may be performed after the step of instructing 310 in the method 300. The method 400 is performed by a remote computing device such as the IIoT cloud 116 shown in Figure 1. Alternatively, the method 400 is performed by a local device (e.g., the production monitor and control module 106) when the update being monitored does not directly affect the ability of the local device to monitor the update, for example due to the update relating to the firmware or operating system of the local device.
[0064] At the step of obtaining 402, an update status is obtained from an IIoT update control module after the IIoT update control module has been instructed to cause the software update to be deployed. For example, after the IIoT update control module 104 shown in Figure 1 has been instructed to cause the locally stored software update 122 to be deployed, the update status is obtained in the manner previously described (e.g., by the production monitor and control module 106 or the IIoT cloud 116).
[0065] At the step of outputting 404, the update status is output to a user of the system. For example, the update status may be displayed on a graphical user interface or dashboard viewable by the user. The update status indicates a status of the update, which can include an indication of whether the update is complete, an indication of the outcome of the update (e.g., success, failure, interrupted, etc.), an indication of the current progress made through the update (e.g., a percentage completion), an indication of elapsed time since the update began, and / or an estimation of the time remaining for the update to be complete.
[0066] At the step of determining 406, a determination is made as to the success of the update. That is, a determination is made as to whether the update has failed. If the determination indicates that the update has not failed (i.e., the update has been successfully deployed), then the method 400 terminates. Optionally, a notification is provided to a user of the system to notify them that the update has been successful. If the determination indicates that the update has failed, the method 400 proceeds to the step of causing 408. At the step of causing 408, the IIoT update control module causes the software update to be rolled back when the update status indicates that the software update has failed. For example, the IIoT update control module 104 instructs the IIoT cloud 116 to roll back the software update thereby restoring the system 100, or the module / device being updated, to its previous state. The roll back is performed in a manner known in the art.
[0067] Figure 5 shows an implementation of the above-described system and methods within a Liquid and Powder Technology (LPT) system 500 according to an embodiment of the present disclosure.
[0068] The LPT system 500 comprises an on-premise computing device 502 communicatively coupled to an external cloud 504. The on-premise computing device 502 is also communicatively coupled to one or more spray dryers 506, one or more freeze dryers 508, brewing devices 510, and evaporators 512. The on-premise computing device 502 comprises an open platform communications (OPC) connector 514, an IIoT update control module 516, a production monitor and control module 518, and a web interface 520. The web interface 520 is accessible to a user 522 of the LPT system 500 (e.g., via one or more output devices such as a monitor, screen, or the like, and one or more input devices such as a keyboard, mouse, touchscreen, etc.). The external cloud 504 comprises an IIoT manager 524 and a storage 526.
[0069] In one embodiment, the on premise computing device 502, the OPC connector 514, the IIoT update control module 516, the production monitor and control module 518, and the external cloud 504 correspond to the production subsystem 108, the interface module 102, the IIoT update control module 104, the production module and control module 106, and the IIoT cloud 116 of the system 100 in Figure 1. Similarly, the one or more spray dryers 506, one or more freeze dryers 508, brewing devices 510, and evaporators 512 correspond to the one or more devices 110, 112, 114 of the system 100 in Figure 1. As such, the operations, functionality, and benefits of the system 100 described in detail above are likewise applicable to the LPT system 500 shown in Figure 5.
[0070] Liquid and Powder Technologies relate to the processing of liquids and powders using equipment such as dryers, evaporators, filtration systems, and the like. The LPT system 500 corresponds to a liquid or powder technology system associated with an industrial process such as the manufacture of dairy powder or coffee, a brewing process, etc. The industrial process is performed at least in part by the one or more spray dryers 506, one or more freeze dryers 508, brewing devices 510, and evaporators 512.
[0071] The on-premise computing device 502 is an on-premise server or industrial personal computer (PC) which is hosted on premise at the factory which undertakes the abovedescribed industrial process. The on-premise computing device 502 is accessible by users (e.g., the user 522) through a dedicated application or directly through the web interface 520. For example, the on-premise computingt device 502 executes a local web server which allows users within the local network, or users with direct access to the onpremise computing device 502, to access the web interface 520.
[0072] The skilled person will appreciate that the LPT system 500 may comprise further devices and components not shown within Figure 5. For example, the LPT system 500 may include one or more storage devices for persistently storing data such as logs, recipe data, and the like. As a further example, the LPT system 500 may include one or more control devices for optimising the industrial process. Such devices continuously read from the devices involved in the industrial process (e.g., the one or more spray dryers 506, one or more freeze dryers 508, etc.) and then write back to these devices with updated control parameters and the like. Updating software (e.g., firmware, operating systems, software services, etc.) within the LPT system 500 could interrupt this continuous read / write process potentially damaging the equipment and disrupting the industrial process. To help address issues arising when updating software components within the LPT system 500, the software update process is managed by the production monitor and control module 518 which is located on the (local) on premise computing device 502 and interfaces to the devices involved in the industrial process via the OPC connector 514.
[0073] As described in detail above in relation to Figures 1 to 4, the production monitor and control module 518 polls the IIoT update control module 516 to determine an update availability. When an update is available, the production monitor and control module 518 monitors the activity state of the industrial process (e.g., by monitoring the states of the devices involved in the industrial process, such as the one or more spray dryers 506, one or more freeze dryers 508, etc.). When the activity state of the industrial process corresponds to a predetermined criterion state (e.g., inactive, idle, or stopped), the production monitor and control module 518 instructs the IIoT update control module 516 to cause the update to be deployed. Consequently, the IIoT update control module 516 informs the external cloud 504 that the update can be deployed and the external cloud 504 orchestrates the deployment of the update within the LPT system 500.
[0074] Advantageously, updates are not pushed to modules or devices of the LPT system 500 whilst the industrial process is in operation. As previously stated, this helps to reduce the likelihood of the industrial process being adversely interrupted due to a software update being performed. Moreover, the above-described update process allows for efficient handling of software updates by reducing the communication requirements between the LPT system 500 and the external cloud 504. This is particularly beneficial in more remote installations or operational sites where communication bandwidth and availability may be limited. Figure 6 shows an implementation of the system and methods of Figures 1-4 within a farm management system 600 according to an embodiment of the present disclosure.
[0075] The farm management system 600 comprises an on-premise computing device 602 which is communicatively coupled to an external cloud 604. The on-premise computing device 602 is also communicatively coupled to a milking system 606, one or more feeding robots 608, and one or more milking robots 610. The on-premise computing device 602 comprises a system interface 612, an IIoT update control module 614, a production monitor and control module 616, and a local application 618. The local application 618 is accessible to a user 620 via a personal computing device 622. The external cloud 604 is a service comprising an IIoT manager 624 and a mobile proxy 626. The user 620 accesses the mobile proxy 626 by means of a device such as a mobile computing device 628.
[0076] In one embodiment, the on premise computing device 602, the system interface 612, the IIoT update control module 614, the production monitor and control module 616, and the external cloud 604 correspond to the production subsystem 108, the interface module 102, the IIoT update control module 104, the production module and control module 106, and the IIoT cloud 116 of the system 100 in Figure 1. Similarly, the milking system 606, one or more feeding robots 608, and one or more milking robots 610 correspond to the one or more devices 110, 112, 114 of the system 100 in Figure 1. As such, the operations, functionality, and benefits of the system 100 described in detail above are likewise applicable to the farm management system 600 shown in Figure 6.
[0077] The farm management system 600 corresponds to a farm or herd management system associated with an industrial process involving the automation of the milking process. The industrial process— i.e., the automated milking of a herd of cows— is performed at least in part by the milking system 606, one or more feeding robots 608, and one or more milking robots 610.
[0078] The on premise computing device 602 is an on premise server or industrial PC which is hosted on premise at the farm which undertakes the above mentioned milking process. The on premise computing device 602 is accessible by a farmer (e.g., the user 620) through the local application 618. For example, the on premise computing device 602 executes a local web server which allows users within the local network, or users with direct access to the on premise computing device 602, to access the local application 618.
[0079] Updating software (e.g., firmware, operating systems, software services, etc.) within the farm management system 600 could interrupt the milking process potentially damaging the equipment, disrupting the milking process, and / or cause harm, or distress, to livestock. To help address issues arising when updating software components within the farm management system 600, the software update process is managed by the production monitor and control module 616 which is located on the (local) on premise computing device 602 and interfaces to the devices involved in the milking process via the system interface 612.
[0080] As described in detail above in relation to Figures 1 to 4, the production monitor and control module 616 polls the IIoT update control module 614 to determine an update availability. When an update is available, the production monitor and control module 616 requests an update timeframe. The update timeframe may be obtained from the user 620 or from a predetermined schedule associated with the milking process. When obtained from the user 620, the user 620 is notified that an update is available (e.g., an alert is provided on the personal computing device 622 and / or the mobile computing device 628) and the user 620 is provided with an interface (e.g., on the personal computing device 622 and / or the mobile computing device 628) to enter the update timeframe onto the farm management system 600. When the update timeframe has been reached, the production monitor and control module 616 monitors the activity state of the milking process (e.g., by monitoring the states of the devices involved in the milking process, such as the milking system 606, one or more feeding robots 608, etc.). When the activity state of the milking process corresponds to a predetermined criterion state (e.g., inactive, idle, or stopped), the production monitor and control module 616 instructs the IIoT update control module 614 to cause the update to be deployed. Consequently, the IIoT update control module 614 informs the external cloud 604 that the update can be deployed and the external cloud 604 orchestrates the deployment of the update within the farm management system 600.
[0081] The user 620 can be provided with an alert or notification to indicate that an update is available, or that an update is currently in process. For example, an alert may be sent to the mobile computing device 628 to notify the user that the farm management system 600, or a component thereof, is being updated.
[0082] Advantageously, updates are not pushed to modules or devices of the farm management system 600 whilst the milking process is in operation (e.g., whilst livestock are actively being milked or entering / exiting the milking system, etc.). As previously stated, this helps to reduce the likelihood of the milking process being adversely interrupted due to a software update being performed thereby reducing the likelihood of damage to equipment and / or livestock. In addition, by ensuring that the update is only performed during the update timeframe, the safety of the overall farm management system 600 is improved by ensuring that the update is only performed during a "safe" timeframe (e.g., a time period when it is known or expected that no cows are being milked). Moreover, the abovedescribed update process allows for efficient handling of software updates by reducing the communication requirements between the farm management system 600 and the external cloud 604. This is particularly beneficial in more remote installations or operational sites where communication bandwidth and availability may be limited (as may be the case for many farm-based installations).
[0083] Figure 7 shows an example computing system for carrying out the methods of the present disclosure. Specifically, Figure 7 shows a block diagram of an embodiment of a computing system according to example embodiments of the present disclosure. The computing system shown in Figure 7 may correspond to a part, or the whole, of any of the functional units described above.
[0084] Computing system 700 can be configured to perform any of the operations disclosed herein such as, for example, any of the operations discussed with reference to the functional units described in relation to Figure 1. Computing system includes one or more computing device(s) 702. The one or more computing device(s) 702 of computing system 700 comprise one or more processors 704 and memory 706. One or more processors 704 can be any general purpose processor(s) configured to execute a set of instructions. For example, one or more processors 704 can be one or more general- purpose processors, one or more field programmable gate array (FPGA), and / or one or more application specific integrated circuits (ASIC). In one embodiment, one or more processors 704 include one processor. Alternatively, one or more processors 704 include a plurality of processors that are operatively connected. One or more processors 704 are communicatively coupled to memory 706 via address bus 708, control bus 710, and data bus 712. Memory 706 can be a random access memory (RAM), a read only memory (ROM), a persistent storage device such as a hard drive, an erasable programmable read only memory (EPROM), and / or the like. The one or more computing device(s) 702 further comprise I / O interface 714 communicatively coupled to address bus 708, control bus 710, and data bus 712.
[0085] Memory 706 can store information that can be accessed by one or more processors 704. For instance, memory 706 (e.g., one or more non-transitory computer-readable storage mediums, memory devices) can include computer-readable instructions (not shown) that can be executed by one or more processors 704. The computer-readable instructions can be software written in any suitable programming language or can be implemented in hardware. Additionally, or alternatively, the computer-readable instructions can be executed in logically and / or virtually separate threads on one or more processors 704. For example, memory 706 can store instructions (not shown) that when executed by one or more processors 704 cause one or more processors 704 to perform operations such as any of the operations and functions for which computing system 700 is configured, as described herein. In addition, or alternatively, memory 706 can store data (not shown) that can be obtained, received, accessed, written, manipulated, created, and / or stored. In some implementations, the one or more computing device(s) 702 can obtain from and / or store data in one or more memory device(s) that are remote from the computing system 700.
[0086] Computing system 700 further comprises storage unit 716, network interface 718, input controller 720, and output controller 722. Storage unit 716, network interface 718, input controller 720, and output controller 722 are communicatively coupled to the central control unit (i.e., the memory 706, the address bus 708, the control bus 710, and the data bus 712) via I / O interface 714.
[0087] Storage unit 716 is a computer readable medium, preferably a non-transitory computer readable medium, comprising one or more programs, the one or more programs comprising instructions which when executed by the one or more processors 704 cause computing system 700 to perform the method steps of the present disclosure. Alternatively, storage unit 716 is a transitory computer readable medium. Storage unit 716 can be a persistent storage device such as a hard drive, a cloud storage device, or any other appropriate storage device.
[0088] Network interface 718 can be a Wi-Fi module, a network interface card, a Bluetooth module, and / or any other suitable wired or wireless communication device. In an embodiment, network interface 718 is configured to connect to a network such as a local area network (LAN), or a wide area network (WAN), the Internet, or an intranet.
[0089] The skilled person will appreciate that the systems and methods of the present disclosure are not limited to a single programming language or paradigm. Indeed, the systems and methods of the present disclosure are applicable to any suitable programming language or environment, including but not limited to Java, C, C++, any suitable assembly language, Python, C#, a script language code e.g., JavaScript, Ruby, PHP, and the like.
[0090] Some embodiments described herein may relate to a computer storage product with a transitory, or non-transitory, computer-readable medium (also can be referred to as a transitory, or non-transitory, processor-readable medium) having instructions or computer code thereon for performing various computer implemented operations. The computer- readable medium (or processor readable medium) is non transitory in the sense that it does not include transitory propagating signals per se (e.g., a propagating electromagnetic wave carrying information on a transmission medium such as space or a cable). The media and computer code (also can be referred to as code) is those designed and constructed for the specific purpose or purposes. Examples of non-transitory computer-readable media include, but are not limited to, magnetic storage media such as hard disks, floppy disks, and magnetic tape; optical storage media such as Compact Disc / Digital Video Discs (CD / DVDs), Compact Disc-Read Only Memories (CD ROMs), and holographic devices; magneto-optical storage media such as optical disks; carrier wave signal processing modules; and hardware devices that are specially configured to store and execute program code, such as Application-Specific Integrated Circuits (ASICs), Programmable Logic Devices (PLDs), Read-Only Memory (ROM) and Random-Access Memory (RAM) devices. Other embodiments described herein relate to a transitory computer program product, which can include, for example, the instructions and / or computer code discussed herein.
[0091] Some embodiments and / or methods described herein can be performed by software (executed on hardware), hardware, or a combination thereof. Hardware modules include, for example, a general-purpose processor, a field programmable gate array (FPGA), and / or an application specific integrated circuit (ASIC). Software modules (executed on hardware) can be expressed in a variety of software languages (e.g., computer code), including C, C++, Java, Ruby, Visual Basic, Python, and / or other object-oriented, procedural, or other programming language and development tools. Examples of computer code include, but are not limited to, micro-code or micro-instructions, machine instructions, such as produced by a compiler, code used to produce a web service, and files containing higher- level instructions that are executed by a computer using an interpreter. For example, embodiments can be implemented using imperative programming languages (e.g., C, Fortran, etc.), functional programming languages (Haskell, Erlang, etc.), logical programming languages (e.g., Prolog), object-oriented programming languages (e.g., Java, C++, etc.) or other suitable programming languages and / or development tools. Additional examples of computer code include, but are not limited to, control signals, encrypted code, and compressed code.
[0092] In the present disclosure, references to items in the singular should be understood to include items in the plural, and vice versa, unless explicitly stated otherwise or clear from the context. Grammatical conjunctions are intended to express any and all disjunctive and conjunctive combinations of conjoined clauses, sentences, words, and the like, unless otherwise stated or clear from the context. Thus, the term "or" should generally be understood to mean "and / or" and so forth. The use of all examples, or exemplary language ("e.g.," "such as," "including," or the like) provided herein, is intended merely to better illuminate the embodiments, and does not pose a limitation on the scope of the embodiments or the claims. NUMBERED STATEMENTS A system for update control in an Industrial Internet of Things, IIoT, environment, the system comprising: an interface module communicatively coupled to one or more devices for performing an industrial process; an IIoT update control module configured to: obtain one or more software updates from an IIoT cloud; and cause the one or more software updates to be deployed within the system; and a production monitor and control module communicatively coupled to the one or more devices for performing the industrial process via the interface module, wherein the production monitor and control module is configured to: poll the IIoT update control module to determine an update availability; in response to the update availability indicating that a software update for the system is available, monitor, via the interface module, a current activity state of the industrial process; and when the current activity state corresponds to a predetermined criterion state, instruct the IIoT update control module to cause the software update for the system to be deployed. The system of statement 1 wherein the production monitor and control module is configured to instruct the IIoT update control module to cause the software update for the system to be deployed during an update timeframe. The system of statement 2 wherein the production monitor and control module is further configured to: prior to the current activity state of the industrial process being monitored, obtain the update timeframe. 4. The system of statement 3 wherein the production monitor and control module is configured to monitor the current activity state of the industrial process when a current time is determined to be within the update timeframe.
[0093] 5. The system of either of statements 3 or 4 wherein the update timeframe is obtained from a user of the system.
[0094] 6. The system of either of statements 3 or 4 wherein the update timeframe is a predetermined schedule associated with the industrial process.
[0095] 7. The system of any preceding statement wherein the predetermined criterion state is indicative of the industrial process being idle, inactive, and / or stopped.
[0096] 10. The system of any preceding statement wherein the IIoT update control module is further configured to pre-load the software update for the system.
[0097] 11. The system of statement 10 wherein the IIoT update control module is further configured to: obtain, from the IIoT cloud, the software update for the system; pre-load the software update for the system; and in response to the software update being pre-loaded, indicate that the software update for the system is available.
[0098] 12. The system of any preceding statement wherein the production monitor and control module is configured to monitor the current activity state of the industrial process by obtaining state values from the one or more devices.
[0099] 13. The system of statement 12 wherein a first state value associated with a first device is indicative of whether the first device is active, inactive, or idle.
[0100] 14. The system of any preceding statement wherein the production monitor and control module is further configured to: obtain an update status from the IIoT update control module after the IIoT update control module has been caused to deploy the software update; and output the update status to a user of the system. 15. The system of statement 14 wherein the production monitor and control module is further configured to: cause the IIoT update control module to instruct the IIoT cloud to roll back the software update when the update status indicates that the software update has failed.
[0101] 16. The system of either of statements 14 or 15 wherein the production monitor and control module is configured to obtain the update status from the IIoT update control module after a predetermined period of time has elapsed from the IIoT update control module having been caused to deploy the software update.
[0102] 17. The system of any preceding statement wherein the software update comprises a firmware update for updating one or more of the interface module, the IIoT update control module, the production monitor and control module, and the one or more devices.
[0103] 18. The system of any of statements 1 to 16 wherein the software update is for updating a service of the system.
[0104] 19. The system of statement 18 wherein the service is a software component of the interface module, the IIoT update control module, and / or the production monitor and control module.
[0105] 20. The system of any preceding statement wherein the production monitor and control module is configured to poll the IIoT update control module periodically.
[0106] 21. The system of statement 20 wherein the production monitor and control module is configured to poll the IIoT update control module periodically at a predetermined polling frequency between 0.001Hz and 2Hz.
[0107] 22. The system of any preceding statement wherein the IIoT update control module is further configured to: receive an update available message from the IIoT cloud, wherein the update available message is associated with the software update; and in response to the update available message being received, obtain the software update from the IIoT cloud. The system of any preceding statement wherein the production monitor and control module is further configured to: while the current activity state of the industrial process is being monitored, receive an override command; and in response to the override command being received, instruct the IIoT update control module to cause the software update to be deployed. A computer-implemented method for update control in an industrial system, the industrial system comprising one or more devices for performing an industrial process, the computer implemented method comprising: polling an industrial Internet of Things, IIoT, update control module to determine an update availability for the industrial system; in response to the update availability indicating that a software update is available for the industrial system, monitoring a current activity state of the industrial process performed by the industrial system; and when the current activity state corresponds to a predetermined criterion state, instructing the IIoT update control module to cause the software update for the industrial system to be deployed. The computer-implemented method of statement 24 further comprising: prior to the current activity state of the industrial process being monitored, obtaining an update timeframe; wherein the current activity state of the industrial process is monitored when a current time is determined to be within the update timeframe. The computer-implemented method of either of statements 24 or 25 further comprising: obtaining an update status from the IIoT update control module after the IIoT update control module has been instructed to cause the software update to be deployed; and outputting the update status to a user of the system. The computer-implemented method of statement 26 further comprising: causing the IIoT update control module to roll back the software update when the update status indicates that the software update has failed. The computer-implemented method of any of statements 24 to 27 further comprising: while the current activity state of the industrial process is being monitored, receiving an override command; and in response to the override command being received, instructing the IIoT update control module to cause the software update for the system to be deployed. A computer-readable medium comprising instructions which, when executed by one or more processors of a device, cause the device to carry out the steps of any of statements 24 to 28.
Claims
CLAIMSWhat is claimed is:
1. A system for update control in an Industrial Internet of Things, IIoT, environment, the system comprising: an interface module communicatively coupled to one or more devices for performing an industrial process; an IIoT update control module configured to: obtain one or more software updates from an IIoT cloud; and cause the one or more software updates to be deployed within the system; and a production monitor and control module communicatively coupled to the one or more devices for performing the industrial process via the interface module, wherein the production monitor and control module is configured to: poll the IIoT update control module to determine an update availability; in response to the update availability indicating that a software update for the system is available, monitor, via the interface module, a current activity state of the industrial process; and when the current activity state corresponds to a predetermined criterion state, instruct the IIoT update control module to cause the software update for the system to be deployed.
2. The system of claim 1 wherein the production monitor and control module is further configured to: prior to the current activity state of the industrial process being monitored, obtain an update timeframe, wherein the production monitor and control module is configured to instruct the IIoT update control module to cause the software update for the system to be deployed during an update timeframe.
3. The system of claim 2 wherein the production monitor and control module is configured to monitor the current activity state of the industrial process when a current time is determined to be within the update timeframe.
4. The system of either of claims 2 or 3 wherein the update timeframe is obtained from a user of the system or a predetermined schedule associated with the industrial process.
5. The system of any preceding claim wherein the predetermined criterion state is indicative of the industrial process being idle, inactive, and / or stopped.
6. The system of claim any preceding claim wherein the IIoT update control module is further configured to: obtain, from the IIoT cloud, the software update for the system; pre-load the software update for the system; and in response to the software update being pre-loaded, indicate that the software update for the system is available.
7. The system of any preceding claim wherein the production monitor and control module is configured to monitor the current activity state of the industrial process by obtaining state values from the one or more devices.
8. The system of claim 7 wherein a first state value associated with a first device is indicative of whether the first device is active, inactive, or idle.
9. The system of any preceding claim wherein the production monitor and control module is further configured to: obtain an update status from the IIoT update control module after the IIoT update control module has been caused to deploy the software update; and output the update status to a user of the system.
10. The system of claim 9 wherein the production monitor and control module is further configured to:cause the IIoT update control module to instruct the IIoT cloud to roll back the software update when the update status indicates that the software update has failed.
11. The system of any preceding claim wherein the software update comprises a firmware update for updating one or more of the interface module, the IIoT update control module, the production monitor and control module, and the one or more devices.
12. The system of any of claims 1 to 10 wherein the software update is for updating a software component of the interface module, the IIoT update control module, and / or the production monitor and control module.
13. The system of any preceding claim wherein the production monitor and control module is configured to poll the IIoT update control module periodically at a predetermined polling frequency between 0.001Hz and 2Hz.
14. A computer-implemented method for update control in an industrial system, the industrial system comprising one or more devices for performing an industrial process, the computer implemented method comprising: polling an industrial Internet of Things, IIoT, update control module to determine an update availability for the industrial system; in response to the update availability indicating that a software update is available for the industrial system, monitoring a current activity state of the industrial process performed by the industrial system; and when the current activity state corresponds to a predetermined criterion state, instructing the IIoT update control module to cause the software update for the industrial system to be deployed.
15. A computer-readable medium comprising instructions which, when executed by one or more processors of a device, cause the device to carry out the steps of claim 14.