Manufacturing system for monitoring and / or controlling one or more chemical plants
A multi-layered system with forwarding tags facilitates secure data exchange in chemical plants, addressing the challenge of integrating cloud technologies with high security standards to enhance monitoring and control across multiple plants.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2025-10-30
- Publication Date
- 2026-03-10
AI Technical Summary
Chemical plants face challenges in leveraging cloud computing and big data analytics due to high security standards, leading to siloed computing infrastructure that limits data utilization for enhancing production efficiency.
A system with multiple processing layers, including a first layer for real-time monitoring and a second layer for contextualization and communication, allows secure data exchange with external systems while maintaining high security standards, using forwarding tags to manage data flow.
Enables seamless integration of external data sources across multiple chemical plants, enhancing monitoring and control while ensuring security, thus improving flexibility and scalability.
Smart Images

Figure 2026041709000001_ABST
Abstract
Description
[Technical Field]
[0001] Field The present invention relates to a system for monitoring and / or controlling one or more chemical plants that include at least one process layer. [Background technology]
[0002] background Chemical production is a highly sensitive production environment, especially with regard to security. A chemical plant typically contains multiple assets for producing chemical products. Multiple sensors are distributed throughout such plants for monitoring and control purposes, collecting large amounts of data. Therefore, chemical production is a data-rich environment. However, to date, the benefits from such data for increasing production efficiency in one or more chemical plants have not been fully utilized.
[0003] Therefore, applying new technologies in cloud computing and big data analytics is of great interest. However, unlike other manufacturing industries, the processing industry is subject to very high security standards. For this reason, computing infrastructure is typically siloed with very limited access to monitoring and control systems. Due to these security standards, latency and availability considerations contradict a simple migration from traditional embedded control systems to, for example, cloud computing systems. Bridging the gap between highly proprietary industrial manufacturing systems and cloud technologies is one of the main challenges.
[0004] WO2016065493 discloses a client device and a system for data acquisition and preprocessing of large amounts of process-related data from at least one CNC machine or industrial robot and transmitting the process-related data to at least one data recipient, such as a cloud-based server. The client device includes at least one first data communication interface to at least one controller of the CNC machine or industrial robot for continuously recording hard real-time process-related data via at least one real-time data channel and for recording non-real-time process-related data via at least one non-real-time data channel. The client device further includes at least one data processing unit for data mapping at least the recorded non-real-time data to the recorded hard real-time data to compile a contextualized set of process-related data. The client device further includes at least one second data interface for transmitting the contextualized set of process-related data to the data recipient and for further data communication with the data recipient.
[0005] WO2019138120 discloses a method for improving a chemical manufacturing process. A plurality of derivative chemical products are produced through a derivative chemical manufacturing process based on at least some derivative process parameters at respective chemical manufacturing facilities, the chemical manufacturing facilities each including a separate respective facility intranet. At least some of the respective derivative process parameters are measured from the derivative chemical manufacturing process by a respective production sensor computer system within each facility intranet. A process model for simulating the derivative chemical manufacturing process is recorded in a process model management computer system external to the facility intranet.
[0006] US20160320768A1 discloses an example of a network environment for monitoring a plant process using a system computer operating as a root cause analyzer. The system computer communicates with a data server to access collected data of measurable process variables from a historical database. The data server is communicatively coupled to a distributed control system (DCS) that communicates the collected data to the data server over a communication network.
[0007] The object of the present invention is to provide a highly scalable and flexible computing infrastructure for the processing industry that complies with high security standards. Summary of the Invention
[0008] overview What is proposed is a system for monitoring and / or controlling one or more chemical plants including at least one processing layer and optionally an external processing layer, the at least one processing layer being associated with, configured, located or hosted within or within a secure network and communicatively coupled to an interface for providing process or asset specific data or processing applications to the external processing layer, optionally the external processing layer being configured to provide the process or asset specific data or processing applications to the at least one processing layer, and the at least one processing layer or optionally the external processing layer being configured to add a forwarding tag to the process or asset specific data or processing application and forward or provide the process or asset specific data or processing application based on the forwarding tag.
[0009] Further, a method is proposed for monitoring and / or controlling one or more chemical plants comprising at least one processing layer and optionally an external processing layer, the at least one processing layer being associated with a secure network and communicatively coupled to an interface for providing process or asset specific data or processing applications to the external processing layer, optionally the external processing layer being configured to provide the process or asset specific data or processing applications to the at least one processing layer, the method comprising the steps of: - adding a forwarding tag to the process or asset specific data or processing application via the at least one processing layer or optionally the external processing layer; - transferring or providing processing or asset specific data or processing applications via at least one processing layer or optionally an external processing layer based on the transfer tag, optionally the processing or asset specific data or processing applications being transferred or provided from the at least one processing layer to the external processing layer based on the transfer tag, and optionally the processing or asset specific data or processing applications being transferred or provided from the external processing layer to the at least one processing layer based on the transfer tag.
[0010] The present invention further relates to a (distributed) computer program or computer program product comprising computer readable instructions that, when executed on one or more processors, cause the processors to perform the methods for monitoring and / or controlling one or more chemical plants described herein. The present invention further relates to a computer readable non-volatile or non-transitory storage medium comprising computer readable instructions that, when executed on one or more processors, cause the processors to perform the methods for monitoring and / or controlling one or more chemical plants described herein.
[0011] The proposed system, method and computer program enable highly efficient and secure data communication with external system components and even third-party systems. The proposed system, method, and computer program enable data exchange with external processing layers outside of the secure network, or even with third-party systems completely decoupled from the system infrastructure, while complying with the high security standards of the chemical industry. By introducing various processing and storage system layers and communicatively coupling them, large amounts of data transfer and processing are distributed across the various layers, improving the flexibility of contextualization, storage, and access for processing applications. In particular, the proposed system can accommodate multiple chemical plants via a second processing layer. The system is therefore highly scalable, enabling more reliable and enhanced monitoring and / or control of chemical plants.
[0012] By adding a forwarding tag at the lowest possible level—where the data or application is generated—the forwarding tag becomes an inherent part of any data point or application as soon as it is generated and follows the data on its path through the proposed system. Such forwarding tags enable seamless, secure integration of external data sources or applications and the forwarding of data or applications to external resources. For example, the deployment of a processing application that ingests external data can be streamlined across multiple assets, even across multiple chemical plants in or within different secure networks, or even across different manufacturers across a value chain or manufacturing chain. Similarly, the deployment of an external processing application that ingests internal data can be streamlined across multiple assets, even across multiple plants in or within different secure networks, or even across different manufacturers across a value chain or manufacturing chain. Thus, bridging any external network or corporate restrictions between chemical plants in different secure networks, or across different manufacturers across a value chain, can be performed without compromising security.
[0013] The following description relates to the above-listed systems, methods, computer programs, and computer-readable storage media, in particular the systems, computer programs, and computer-readable storage media configured to perform the method steps described above and further described below.
[0014] In the context of this invention, a chemical plant refers to any manufacturing facility based on chemical processing, such as converting raw materials into products using chemical processes. In contrast to discrete manufacturing, chemical manufacturing is based on continuous or batch processing. As such, monitoring and / or control of a chemical plant is time-dependent and therefore based on large time-series data sets. A chemical plant may contain more than 1,000 sensors that generate measurement data points every few seconds. Such scale results in several terabytes of data being processed by systems for controlling and / or monitoring the chemical plant. A small chemical plant may contain thousands of sensors that generate data points every 1-10 seconds. For comparison, a large chemical plant may contain tens of thousands of sensors, e.g., 10,000-30,000, that generate data points every 1-10 seconds. To contextualize this data, hundreds of gigabytes to several terabytes are processed.
[0015] A chemical plant may manufacture a product through one or more chemical processes that convert feedstocks into products via one or more intermediate products. Preferably, a chemical plant provides an encapsulated facility that produces a product that can be used as a feedstock for the next step in the value chain. A chemical plant can be a large-scale plant such as an oil and gas facility, a gas cleaning plant, a carbon dioxide capture facility, a liquefied natural gas (LNG) plant, an oil refinery, a petrochemical facility, or a chemical facility. For example, an upstream chemical plant in the production of petrochemical processing may include a steam cracker that begins by processing naphtha into ethylene and propylene. These upstream products may then be used to further the chemical plant. to produce downstream products such as polyethylene or polypropylene, which may again serve as feedstock for chemical plants that produce further downstream products. Chemical plants may be used to manufacture individual products. In one example, one chemical plant may be used to manufacture precursors to polyurethane foam. Such precursors may be provided to a second chemical plant to manufacture individual products, such as separator plates containing polyurethane foam.
[0016] The value chain production or manufacturing chain from various intermediate products to the final product can be distributed at different locations or integrated in a Verbund site or e-chemical park. Such a Verbund site or chemical park constitutes a network of interconnected chemical plants, where the products produced in one plant can be used as raw materials for another.
[0017] A chemical plant may include multiple assets, such as heat exchangers, reactors, pumps, pipes, distillation columns, and absorption columns, to name a few. In a chemical plant, some assets may be critical. A critical asset is an asset that, if destroyed, has a significant impact on the plant's operations. This may jeopardize the manufacturing process. Product quality may be reduced or production may be halted. In a worst-case scenario, a fire, explosion, or release of toxic gases may be the result of such a destruction. Therefore, such critical assets may require stricter monitoring and / or control than other assets, depending on the chemical process and chemicals involved. To monitor and / or control chemical processes and assets, multiple actors and sensors may be incorporated into a chemical plant. Such actors or sensors may provide process- or asset-specific data related to individual assets or processes, such as, for example, the status of individual assets, the status of individual actors, the composition of chemicals, or the status of a chemical process. In particular, process- or asset-specific data may fall into the following data categories: - Processing operation data, such as the composition of raw materials and intermediate products; - Process monitoring data such as flow, material temperature, etc. - Asset operation data such as current, voltage, and - Asset monitoring data such as asset temperature, asset pressure, vibration, etc. Contains one or more of the following:
[0018] Process or asset-specific data refers to data related to a specific asset or process and contextualized with respect to such specific asset or process. Process or asset-specific data may be contextualized only with respect to individual assets and processes. Process or asset-specific data may include measurements, data quality measurements, time, units of measurement, asset IDs for specific assets, or process IDs for specific processing sections or stages. Such process or asset-specific data is collected at the lowest or first processing layer and contextualized with respect to specific assets or processes within a single plant. Such contextualization may be related to context available at the first processing layer. Such context may be related to a single plant.
[0019] Plant-specific data refers to process- or asset-specific data that is contextualized with respect to one or more plants. Transfer tags can be added to assets to process specific data and thus become part of the plant-specific data. In this way, the transfer tags remain even when contextualized through different processing layers. Such plant-specific data can be collected in a second processing layer and contextualized with respect to multiple plants. Plant-specific data can be tagged with transfer tags directly or indirectly by tagging assets, allowing specific data to be processed in each layer configured for contextualization. Specifically, the contextualization can be related to context available in the second processing layer. Process- or asset-specific data points can be added via contextualized context such as plant identifier, plant type, reliability indicator, or plant alarm limit. In a further step, One or more plant technical asset structures, Verbund sites, other asset management structures (e.g., asset networks), or application context (e.g., model identifiers, third-party exchanges) may be added. Such comprehensive context may originate from functional locations or digital twins, such as digital piping and instrumentation diagrams, 3D models, or scans with xyz coordinates of plant assets. Additionally or alternatively, local scans, for example from a mobile device linked to piping and instrumentation diagrams, may be used for contextualization.
[0020] In one aspect, a processing layer or external processing layer is configured to initiate, prevent, or control the process of providing or forwarding process- or asset-specific data or processing applications according to the forwarding tag. Forwarding or providing in this context may include blocking, communication with any processing layer, or communication between systems in different secure networks. In the context of the present invention, the forwarding tag determines whether data or applications can be blocked or communicated to or from a processing layer or processing system within the layered architecture of the system. In the context of the present invention, the forwarding tag further determines whether data or applications can be blocked or communicated to or from systems in different secure networks. As such, the forwarding tag may set a trigger that allows or prevents data or applications from communicating to or from a processing layer, processing system, or between two systems within or within separate secure network environments. For example, the forwarding tag indicates whether process- or asset-specific data, asset-specific data in the form of contextualized process- or plant-specific data, or processing applications can be blocked or communicated between processing layers or processing systems of the proposed system. The transfer tag may indicate whether the process or asset specific data, asset specific data in the form of contextualized process or plant specific data, or processing application may be blocked or communicated to or from an external processing layer or system.The transfer tag may indicate whether the process or asset specific data, contextualized process or asset specific data in the form of plant specific data, or processing application may be blocked or communicated to or from a third party processing layer or system.
[0021] Each data set or application may be tagged with a separate transfer tag. In other words, a transfer tag may be applied to each data set of process or asset specific data, plant specific data, or each process application. A transfer tag may be applied to multiple data sets of process or asset specific data or plant specific data, or multiple process applications. A transfer tag may be applied to a data set of process or asset specific data, or a combination of data sets of plant specific data and / or process applications.
[0022] In particular, plant-specific data related to interfaces between chemical plants within a manufacturing chain may be provided between chemical plants throughout the manufacturing chain, for example, via a second or external processing layer. Thus, monitoring and / or control may be enhanced, for example, via anomaly detection, setpoint steering, and optimization of the manufacturing chain across multiple plants. Processing applications with online input / output data profiles may be used to monitor and / or control the chain across multiple plants. Such data profiles and processing applications may be transferred between plants within the manufacturing chain via a second or external processing layer. When combined with monitorable mass and energy balances, such processing applications may optimize the entire chain of chemical plants, rather than individual plants within the chain.
[0023] The process of contextualization is the linking of data points available in one or more storage units. Such units may be persistent or non-volatile storage. Data points may be associated with measurements or contextual information. Storage Unit The data may be part of the first processing tier, the second processing tier, the external processing tier, or may be distributed across two or more of these tiers. Links may be generated dynamically or statically. For example, a predefined or dynamically generated script may generate dynamic or static links between information data points within one processing tier or between processing tiers. Links may be established by generating a new data object containing the linked data itself and storing such a new data object in a new instance. Any stored data points may be actively deleted if a copy is stored elsewhere. Any data points copied from one storage unit to a new data object in the same or another storage unit in this way may be deleted to reduce storage space. Additionally or alternatively, links may be established by generating metadata objects with embedded links for addressing or accessing the respective data points in the distributed storage units. Any data points addressable or accessible via the metadata object in this way may remain in their original storage units. Linking such information to form new data objects may still be performed, for example, in an external processing tier. Data can be retrieved by directly accessing the data objects or by using metadata objects to address or access data distributed across one or more storage units. Operations on such data, such as applications, may access such data directly or may access non-persistent images of such data, for example from cache memory or a persistent copy of the data.
[0024] In one embodiment, a first processing layer is associated with one or a single chemical plant. The first processing layer may be a core processing system including one or more processing and storage devices. Such a layer may include one or more distributed processing and storage devices forming a programmable logic controller (PLC) system or a decentralized control system (DCS) with control loops distributed throughout the chemical plant. Preferably, the first processing layer is configured to control and / or monitor chemical processes and assets at the asset level. Thus, the first processing layer monitors and / or controls the chemical plant at the lowest level. Furthermore, the first processing layer may be configured to monitor and control critical assets. Additionally or alternatively, the first processing layer may be configured to provide process- or asset-specific data to a second processing layer. Such data may be provided directly or indirectly to the second processing layer.
[0025] In a further aspect, a second processing tier is associated with multiple chemical plants. The second processing tier may include a process management system with one or more processing and storage devices. A preferred second processing tier is configured to manage data transfer to and / or from the first processing tier. A further preferred second processing tier is configured to host and / or integrate processing applications. Such processing applications may monitor and / or control one or more chemical plants or one or more assets. The process management system may be associated with one or more chemical plants.
[0026] The second processing tier may further include a process management system and an intermediate processing system. The second processing tier may include a process management system with one or more processing and storage devices. A preferred second processing tier or process management system is configured to manage data transfer to and / or from the first processing tier. A further preferred second processing tier or process management system is configured to host and / or organize processing applications. Such processing applications may monitor and / or control one or more chemical plants or one or more assets. The process management system may In other words, the process management system may be communicatively coupled to multiple first process layers associated with one or more chemical plants.
[0027] In a further aspect, the second processing tier may include an intermediate processing system and a processing management system. Here, the intermediate processing system may be communicatively coupled to the first processing tier, preferably the core processing system, and the processing management system may be communicatively coupled to the intermediate tier. Preferably, the first processing tier and the processing management system are coupled or communicatively coupled via the intermediate processing system. The intermediate processing system may be configured to collect process- or asset-specific data provided by the first processing tier. The processing management system may be configured to provide plant-specific data for one or more chemical plants to an interface to an external network. The intermediate processing system may be associated with one or more chemical plants. In other words, the intermediate processing system may be communicatively coupled to the first processing tier of one chemical plant or multiple first processing tiers of multiple plants. The processing management system may be communicatively coupled to one or more intermediate processing systems. Adding an intermediate processing level to the second processing tier adds another layer of security. The security layer completely removes the toxic first processing tier from any external network access. Additionally, at the intermediate level, data processing can be further enhanced by reducing data transfer rates to external processing layers through preprocessing and improving data quality through contextualization. The intermediate processing system and processing management system may include one or more processing and storage devices.
[0028] At least one processing layer may be configured to contextualize processing and asset-specific data or processing applications by adding forwarding tags. The system may include a first processing layer, a second processing layer, and optionally an external processing layer.
[0029] The first processing layer may be configured to contextualize process or asset specific data by adding a forwarding tag. The second processing layer or external processing layer may be configured to contextualize a process application by adding a forwarding tag. The external processing layer or second processing layer, particularly a process management system, may be configured to receive external data or an external application and may be configured to contextualize the external data or the external application by adding a forwarding tag.
[0030] In a further aspect, the secure network is an isolated network that includes three or more security regions separated by firewalls. Such firewalls may be network-based or host-based virtual or physical firewalls. The firewalls may be hardware-based or software-based to control incoming and outgoing network traffic, where predetermined rules in the sense of a whitelist may define allowed traffic via access control or other configuration settings. Depending on the firewall configuration, the security regions may comply with various security standards.
[0031] In a further aspect, unidirectional or bidirectional communication, e.g., data transfer or data access, can be implemented for data streams between different processing layers. One data stream can include process- or asset-specific data from a first processing layer that is passed to a second processing layer, contextualized through the second processing layer, and communicated to an external processing layer. Contextualization can be performed in the second processing layer, the external processing layer, or both. Furthermore, depending on the importance of process- or asset-specific data or plant-specific data, such data can be assigned for unidirectional or bidirectional communication. For example, a diode-type communication channel can be implemented to prohibit data communication from the second processing layer or the external processing layer to critical assets. Such communication allows only unidirectional communication from critical assets to the processing layer, but not vice versa.
[0032] In further embodiments, data streams may be assigned critical or non-critical data. Critical data refers to data essential to the operation of a chemical plant, such as short-term data from which operating points for the chemical plant are derived. Such critical data may cover short-term periods, for example, from a few hours or days to a week or more, necessary to operate the plant optimally. Non-critical data refers to data that is not critical to the operation of a chemical plant, such as medium- to long-term data for monitoring a chemical plant based on medium- to long-term behavior. Such non-critical data may cover medium- to long-term periods, for example, from multiple weeks or months to a year or more, necessary to monitor and / or control an asset or plant over a period of time. Such data may also be referred to as cold, warm, and hot data, with hot data corresponding to critical data, warm data corresponding to medium-term non-critical data, and cold data corresponding to long-term non-critical data.
[0033] The second processing layer, preferably a process management system, may be communicatively coupled to the external processing layer via an external network. The second processing layer, preferably a process management system, may be configured to manage data transfer to and / or from the external processing layer. The second processing layer, preferably a process management system, may provide plant-specific data to an interface to the external network based on an identifier added by, for example, contextualization. Such an identifier may be a confidentiality identifier based on which such data is not provided to the interface to the external network.
[0034] The external processing layer may be a computing or cloud environment that provides virtualized computing resources such as data storage and computing power. The external processing layer may provide a private, hybrid, public, community, or multiple cloud environment. Cloud environments are advantageous because they provide on-demand storage and computing power. Furthermore, when monitoring and / or controlling multiple chemical plants operated by different parties, data or processing applications that affect the chemical plants may be shared in such a cloud environment.
[0035] In a further aspect, the second processing layer, preferably a processing management system, is configured to manage data transfers to and / or from the external processing layer in real time or on demand. Real-time transfers may be buffered depending on the network and computing load of the interface to the external network. On-demand transfers may be triggered in a predefined or dynamic manner. Preferably, data transfers to the external processing layer are managed in real time, and transfers from the external processing layer are managed on demand.
[0036] In the context of this disclosure, transfer includes receiving and sending data, thus capturing the situation of pushing or pulling data.
[0037] In the context of this disclosure, internal refers to the secure network and any system components or communications associated with the secure network. A secure network may be defined by physical or virtual network boundaries. Physical network boundaries are implemented in hardware. Virtual network boundaries are implemented in software.
[0038] External or third party refers to any network or any component outside the secure network. This may be another or third party secure network, an external network, or an open network. Thus, for example: Communications that cross the outermost boundary of a chemical plant's secure network by crossing the boundary to another secure network, an external network, or an open network may be considered external transfers or communications, or transfers or communications to external components. A third-party network or component refers to an external network or component controlled by an identifiable third party. Thus, the secure network is isolated from any third-party or external network, and any connection or communication between such separate networks may be actively initiated. A secure network may include further secure areas within it.
[0039] The forwarding tag may be added on or through a processing layer where the process- or asset-specific data or processing application is generated. In other words, the processing layer may be configured to add the forwarding tag to the process- or asset-specific data or processing application at the time of generation. Alternatively, the forwarding tag may be added on or through a processing layer that serves as an entry point or first entry point into a system or processing layer. Thus, the forwarding tag may be added to a processing layer where data is forwarded or first received by the system or processing layer. In other words, the processing layer may be configured to add the forwarding tag to the process- or asset-specific data or processing application at the time of entry into the system or processing layer. In this context, entry point means that the process- or asset-specific data is not generated but is forwarded to the system or processing layer.
[0040] The forwarding tag may include at least two forwarding settings, and the at least two forwarding settings may be associated with a confidentiality setting and / or a third-party forwarding setting. The confidentiality setting may include at least two levels, such as confidential or non-confidential. The confidentiality setting may include three or four levels, such as strictly confidential, confidential, and non-confidential, or strictly confidential, confidential, internal, and non-confidential. The third-party forwarding setting may include a third-party identifier, an information category, or both. Depending on the confidentiality of the data or application, the forwarding tag may include entries for the confidentiality setting and the third-party forwarding setting.
[0041] Forwarding tags may be assigned dynamically or statically when data or applications are generated or first enter a system or processing layer. Forwarding tags may be predefined for the process or asset that generates the data. Forwarding tags may be dynamically assigned to third-party data or applications, for example, in response to compliance checks. Forwarding tags may be added on or through the processing layer where the data or application is generated, or to the closest possible processing layer in terms of time or location after generation. For example, if measurements are forwarded to a first processing layer in a plant, the tag may be added to that processing layer, or if an application is compiled in an external processing layer in the cloud, the forwarding tag may be added to that processing layer. In other embodiments, forwarding tags may be generated when data transfer to or from a system within a secure network is triggered.
[0042] The processing layer can be configured to contextualize process and asset specific data or processing applications by adding transfer tags. By specifically contextualizing process or asset specific data at the processing layer, data generated in the chemical plant can be fully controlled. Contextualization can be performed at the time of generation, or at least before the first transfer within the system, to ensure such control through all processing layers.
[0043] The processing layer, preferably the second processing layer, or the processing layer, preferably the second processing layer's interface to an external network, may be configured to provide contextualized processing or asset-specific data or processing applications to the external processing layer based on the forwarding tag, wherein the processing layer or its interface is configured to provide contextualized processing or asset-specific data or processing applications to the external processing layer based on the forwarding tag's confidentiality settings or third-party In one embodiment, if the contextualized processing or asset-specific data or processing application is tagged with a predefined confidentiality setting, such as strictly confidential or sensitive, the interface may be configured to prohibit transfer to an external processing layer.
[0044] In another embodiment, if contextualized processing or asset-specific data or processing applications are tagged with a third-party setting that indicates internal use only, the interface can be configured to prohibit transfer to an external processing layer. In this way, any data transfer or communication to or from the chemical plant is highly secure, avoiding data or application leaks. When combined with a layered processing system including at least two processing layers associated with a secure network, this security is enhanced because only one of the processing layers is exposed to the external network.
[0045] A processing application may be a containerized application associated with a process or asset model for monitoring and / or controlling one or more chemical plants. In this context, a containerized application refers to an application that can be executed in an encapsulated runtime environment that is independent of the host operating system. Thus, the application may be considered to be running in a sandbox. A containerized application may be based on a container image that includes the application. The container image may include the software components, e.g., a hierarchical tree of software components, necessary to execute the respective application in the encapsulated runtime environment. Such a containerized application may be stored in or associated with a registry of one of the internal processing layers or an external processing layer.
[0046] To deploy a containerized application, an integrated application associated with a processing tier, particularly a second processing tier, or an external processing tier, may manage the execution of the containerized application. Such management may include general runtime environment configuration, such as storage and networking, for executing the containerized application. Such management may further include host allocation, which defines the distribution among a central master node or one or more computing nodes for executing the application in the first processing tier, the second processing tier, or the external management tier. In particular, such computing resource allocation depends on input data, load indicators, or system layer tags.
[0047] The input data may include real-time and non-real-time data from sensors. Such data may relate to a machine, such as a machine type and sensor data measured for a machine, a chemical, such as a chemical type and sensor data measured for a chemical component processed in a chemical plant, a process, such as a chemical process type and sensor data measured for a chemical process performed in a chemical plant, and / or a plant, such as a plant type or sensor data measured for a chemical plant, e.g., environmental measurement data.
[0048] The asset or plant model may include a data-driven model or a dynamic model that provides, for example, health status, operation prediction, event prediction, or event trigger. The asset or plant model may be based solely on a data-driven model, a hybrid model that combines a data-driven model and a dynamic model, or a solely dynamic model. The asset or plant model may be further based on a scenario matrix that maps input data, for example, sensor data, to specific events. The asset model may reflect the physical behavior of a single or multiple assets. The plant model may reflect the physical behavior of portions of one or more plants, a complete plant, or multiple plants.
[0049] The processing layer or external processing layer may be configured to provide contextualized processing and asset data or processing applications to a third party or external system based on the transfer tag. The processing layer or external processing layer may be configured to perform a third-party compliance check before transferring to the third-party system. The processing layer or external processing layer may be configured to access a third-party compliance database and determine transfer compliance based on a third-party transfer setting including a third-party identifier and at least one information category. Such information may indicate whether the third party is authorized or unauthorized.
[0050] The processing layer or external processing layer can be configured to manage containerized applications. The system can include a first processing layer associated with an individual chemical plant and a second processing layer associated with one or more chemical plants. The first processing layer can be configured to contextualize process and asset-specific data by adding forwarding tags. The second processing layer or external processing layer can be configured to contextualize processing applications by adding forwarding tags.
[0051] The processing layer or external processing layer may be configured to receive external data or external applications. In this manner, various systems, including processing layers within the secure network, can be seamlessly integrated. Thus, external data or external applications hosted on a first system, including a processing layer within the secure network and, optionally, an external processing layer, can be transmitted to a second system, including a processing layer within the secure network and, optionally, an external processing layer. In one embodiment, the external application can be transmitted from the first system to the second system and executed on internal data stored by the second system. In another embodiment, external data can be transmitted from the first system to the second system to execute an internal application stored by the second system. The latter option may generate more data traffic than the former option.
[0052] In a further embodiment, the processing layer or external processing layer is configured to contextualize external data or applications by adding a forwarding tag. The forwarding tag setting may be related, for example, to confidentiality or third-party forwarding settings. For example, depending on the confidentiality setting of data requested by an external application, such application may be contextualized according to the processing layer that stores such data and sent to the respective processing layer where the data is stored. Alternatively, third-party settings may be added, and depending on the third-party settings, external data may be communicated to the processing layer to incorporate internal data stored in such layer. In a multi-tier system setup with multiple system connections, forwarding tags provide increased flexibility in controlling data or application flow between different systems. Furthermore, such an approach provides the option to protect the integrity of data or applications depending on their confidentiality.
[0053] In a further embodiment, the processing layer or external processing layer is configured to deploy an external application in response to a third-party forwarding setting that represents the ingestion of internal data. The internal data ingestion information may include, for example, metadata that allows for the allocation of the required internal data. In such cases, forwarding tags may enable more controlled routing of external applications in a multi-tier system setup with multiple system connections. For example, if an external application enters a first system from a second system, the forwarding tags may link the internal data to be ingested or deploy the external application to the layer storing the internal data.
[0054] In a further embodiment, the processing layer or external processing layer is configured to contextualize internal applications by adding third-party forwarding settings that represent the ingestion of external data. External data ingestion information may include, for example, metadata that allows for the assignment of an internal application that ingests such external data. In such cases, forwarding tags enable more controlled routing of external data in a multi-tier system setup with multiple system connections. For example, when external data enters a first system from a second system, forwarding tags can link the external data stream to the internal application that ingests such data.
[0055] In a further embodiment, the processing layer or external processing layer is configured to deploy the internal application in response to a third-party transfer setting for external data ingestion. In the case of deployment, the internal application may be deployed to a processing layer that provides external data access. This may be a processing layer of a first system to which such external data is provided from a second system. In other situations, this may be a processing layer of the first system with a respective computing power or capability, and external data provided from the second system may be provided to such a processing layer of the first system.
[0056] The external processing layer or processing layer, preferably the second processing layer, may be configured to receive external data or an external application. The external processing layer or processing layer, preferably the second processing layer, may be configured to contextualize the external data or external application by adding a forwarding tag. The forwarding tag of the external application may specify, for example, the confidentiality setting of the internal data to be imported or the need for internal data import. The external processing layer or processing layer, preferably the second processing layer, may be configured to deploy an external application depending on the third-party forwarding setting of the internal data to be imported or for the import of internal data. In this way, external applications can be deployed to processing layers that host the respective internal data, leveraging a layered processing architecture. Alternatively, external applications may be deployed to any processing layer and provide a link to the internal data to be imported.
[0057] In a further aspect, the external processing layer or processing layer, preferably the second processing layer, is configured to contextualize the internal application by adding a third-party forwarding setting that indicates the ingestion of external data. In other words, the forwarding tag may indicate that the internal application requires external data as input data. The external processing layer or processing layer, preferably the second processing layer, may be configured to contextualize the external data by adding the forwarding tag. The external processing layer or processing layer, preferably the second processing layer, may be configured to contextualize the internal application by adding a third-party forwarding setting that indicates the ingestion of external data. The external processing layer or processing layer, preferably the second processing layer, may be configured to deploy the internal application in response to the third-party forwarding setting of the external data ingestion.
[0058] Exemplary embodiments of the present disclosure are illustrated in the accompanying drawings. However, it should be noted that the accompanying drawings illustrate only particular embodiments of the present disclosure and therefore should not be considered as limiting its scope. The technical teachings may encompass other equally effective embodiments. [Brief explanation of the drawings]
[0059] [Figure 1] 1 is a first schematic diagram of a system for monitoring and / or controlling one or more chemical plants; [Figure 2] FIG. 2 is a second schematic diagram of a system for monitoring and / or controlling one or more chemical plants. [Figure 3] FIG. 10 is a third schematic diagram of a system for monitoring and / or controlling one or more chemical plants. [Figure 4] FIG. 4 is a schematic diagram of the concept of data contextualization in a system such as that shown in FIGS. 1 to 3. [Figure 5] 1 is a flow chart of a schematic diagram of a method for monitoring and / or controlling one or more chemical plants. [Figure 6] FIG. 1 is a schematic diagram of a system for monitoring and / or controlling one or more chemical plants via containerized applications. [Figure 7] 1 is a flow chart of a schematic diagram of a method for monitoring and / or controlling a chemical plant having multiple assets. [Figure 8] 1 is a schematic diagram of a system for monitoring and / or controlling multiple chemical plants in different secure networks configured for data and application transfer; DETAILED DESCRIPTION OF THE INVENTION
[0060] Detailed Description In petrochemical processing, industrial production typically begins with upstream products and is used to derive further downstream products. To date, production along the value chain from various intermediate products to final products has been very limited and based on siloed infrastructure. This hinders the adoption of new technologies such as IoT, cloud computing, and big data analytics.
[0061] Unlike other manufacturing industries, the process industry is subject to very high standards, especially regarding availability and security, which is why computing infrastructure is typically unidirectional and siloed, with very limited access to chemical plant monitoring and control systems.
[0062] Chemical manufacturing plants are typically embedded in enterprise architectures in a siloed manner at various levels to functionally separate operational technology and information technology solutions.
[0063] Level 0 relates to the physical process and specifies the actual physical processes of the plant. Level 1 relates to intelligent devices for sensing and manipulating the physical process, for example, through process sensors, analyzers, actuators, and related instrumentation. Level 2 relates to the control system for supervising, monitoring, and controlling the physical process. Typical components include real-time control and software, i.e., DCS, human-machine interface (HMI), and supervisory and data acquisition (SCADA) software. Level 3 relates to the manufacturing operations system for managing the production workflow to produce the desired product. Typical components include batch management, manufacturing execution / operations control systems (MES / MOMS), laboratories, maintenance, plant performance management systems, data historians, and related middleware. Control and monitoring time frames may be shifts, hours, minutes, or seconds. Level 4 relates to the business logistics system for managing the business-related activities of the manufacturing operation. ERP is the primary system, establishing the basic plant production schedule, material usage, shipments, and inventory levels. The time frame may be a month, a week, a day, a shift.
[0064] Furthermore, such structures adhere to strict one-way communication protocols, so there is no data flow below Level 2. Such architectures do not allow any entity outside the enterprise or its customers to access the data. The Internet is not included. However, this model remains an essential concept within the realm of cybersecurity. In this context, the challenge is to leverage the benefits of cloud computing and big data while ensuring the established advantages of existing architectures: high availability and reliability of the lower-level systems (Level 1 and Level 2) that control chemical plants and cybersecurity.
[0065] The technical teachings presented herein allow for systematic modification of this framework with enhanced monitoring and / or control, allowing new functionality to be introduced that is compatible with existing architectures. The present disclosure is particularly relevant for highly scalable, flexible, and available computing infrastructures for the processing industry, while at the same time adhering to high security standards.
[0066] FIG. 1 shows a first schematic diagram of a system 10 for monitoring and / or controlling a chemical plant 12 .
[0067] The system 10 comprises two processing layers, including a first processing layer in the form of a core processing system 14 associated with each chemical plant 12 and a second processing layer 16 in the form of, for example, a process management system associated with the two chemical plants 12. The core processing system 14 is communicatively coupled to the second processing layer 16 to enable unidirectional or bidirectional data transfer. The core processing system 14 comprises a distributed set of processing units associated with the assets of the chemical plants 12.
[0068] The core processing system 14 and the second processing tier 16 are configured within a secure network 18, 20, which generally includes two security domains. The first security domain is located at the core processing system 14 level, with a first firewall 18 controlling incoming and outgoing network traffic to and from the core processing system 14. The second security domain is located on the second processing tier 16, with a second firewall 20 controlling incoming and outgoing network traffic to and from the second processing tier 16. Such an isolated network architecture can protect vulnerable plant operations from cyber attacks.
[0069] The core processing system 14 provides process or asset specific data 22 of the chemical plant 12 to a second processing layer 16. The second processing layer 16 is configured to contextualize the process or asset specific data of the chemical plant 12. The second processing layer 16 is further configured to provide plant specific data 24 of the chemical plant 12 to an interface 26 to an external network, where the plant specific data may refer to the contextualized process or asset specific data.
[0070] Process or asset specific data may include value, quality, time, units of measure, asset identifier. Contextualization may add further context such as plant identifier, plant type, reliability indicator, or plant alarm limits. In a next step, application context (model identifier, third-party exchange, etc.) may be added in addition to the technical asset structure and other asset management (asset network, etc.) of one or more plants or sites.
[0071] The second processing layer 16 is communicatively coupled to an external processing layer 30 via an interface 26 to an external network. The external processing layer 30 may be a computing or cloud environment that provides virtualized computing resources such as data storage and computing power. The second processing layer 16 is configured to provide plant-specific data 24 from one or more chemical plants 12 to the external processing layer 30. Such data may be provided in real time or on demand. The second processing layer 16 is configured to manage data transfer to and / or from the external processing layer 30 in real time or on demand. The second processing layer 16 may provide the plant-specific data 24 to the interface to the external network 26 based on an identifier added by contextualization, for example. Such an identifier may be a confidentiality identifier based on which such data is not provided to the interface to the external network 26. The second processing layer 16 may further be configured to delete at least a portion of the data transferred to the external processing layer 30.
[0072] The external processing layer 30 is configured to aggregate plant-specific data from multiple chemical plants and / or store historical data from multiple chemical plants. In this way, data storage can be externalized, reducing the required on-premise storage capacity and making historical transfer redundant. Furthermore, such a storage concept allows historical data to be stored in the second processing layer 16 during hot windows, which are critical timeframes that allow the system 10 to monitor and / or control chemical plants in island mode without external network connectivity. In this way, the availability of the system 10 for monitoring and / or control is always guaranteed.
[0073] The second processing layer 16 and the external processing layer 30 are configured to host and / or organize processing applications. In particular, the second processing layer 16 may host and / or organize processing applications related to core plant operations, and the external processing layer 30 may be configured to host and / or organize processing applications related to non-core plant operations.
[0074] Additionally, the second processing layer 16 and the external processing layer 30 may be configured to exchange data with third-party management systems, e.g., via integration of a third-party external processing layer, to organize data visualization, to organize computing processing workflows, to organize data calculations, to organize APIs to access data, to organize data storage, transfer, and calculation metadata, to provide an interactive plant data work environment for users, e.g., operators, and to verify and improve data quality.
[0075] FIG. 2 shows a second schematic diagram of a system 10 for monitoring and / or controlling one or more chemical plants 12 .
[0076] The system 10 shown in Figure 2 is similar to the system shown in Figure 1, except that the system of Figure 2 includes a second processing tier with a processing management system 32 and an intermediate processing system 34. The intermediate processing systems 34.1, 34.2 are configured in a secure network security domain via a firewall 40.
[0077] The intermediate processing systems 34.1, 34.2 may be configured to ingest process or asset specific data 22 from individual or multiple chemical plants 12. Such data may be contextualized at the plant level in the intermediate processing systems 34.1, 34.2, and the plant specific data 38 may be provided to the process management system 32 where further contextualization may be performed across the plant level, for example, at the Verbund or site level. In this setup, data contextualization is staggered between different system 10 tiers, with each tier 14, 34, 32 mapping the contextual information available at the respective tier 14, 34, 32.
[0078] FIG. 3 shows a third schematic diagram of a system 10 for monitoring and / or controlling one or more chemical plants 12 .
[0079] The system 10 shown in Figure 3 is similar to the systems shown in Figures 1 and 2. However, the system of Figure 3 includes a monitoring device 44 communicatively coupled to the process management system 32 or external processing layer 30. The monitoring device 36 may be configured to forward monitoring data to the process management system 32 or external processing layer 30. The process management system 32 or external processing layer 30 may be configured to manage multiple monitoring devices 44. Because such IoT devices are not considered trusted, the monitoring data provided by the monitoring device 44 may be unidirectionally tagged, and any control loops associated with the chemical plant 12 may include filters for such tags. Therefore, such data is not used in any management of the chemical plant 12.
[0080] FIG. 4 shows a schematic diagram of the data contextualization concept of the system 10 as shown in FIGS.
[0081] The system 10 of Figures 1-3 includes two internal processing layers 14, 16, 32, 34 and an external processing layer 30. The first processing layer 14 may be a distributed control system for supervising, monitoring, and controlling physical processes within the chemical plant 12. The first processing layer 14 may be configured to provide process or asset specific data. The second processing layer 16, 32, 34 may include an intermediate processing system 34 and a process management system 32. The intermediate processing system 34 may be configured as an edge computing layer. Such a layer may be associated with Level 3 of an individual plant. The intermediate processing system 34 may: Processing or collecting asset-specific data; Level 2 basic automation system interaction, Initial contextualization (bottom-up approach) where context is added within distributed edge devices based on what is known at Level 2 and Level 1; It may be configured for:
[0082] The process management system 32 may be configured as a centralized edge computing tier. Such a tier may be associated with Level 4 of multiple plants. The process management system 32 may: integration of data from various distributed edge devices, including intermediate processing systems 34 or monitoring devices 44; Further contextualization (bottom-up approach) where additional context is added based on the distributed pre-processed context in distributed edge devices; It may be configured for:
[0083] The external processing layer 30 may be configured as a centralized cloud computing platform. Such a platform may be associated with Level 5 of multiple plants. The external processing layer 30 may be configured as a manufacturing data workspace with complete data integration across multiple plants, including the transfer and streaming of manufacturing data history and the collection of all data from all edge components. In this way, complete contextualization of all lower-level contexts may be integrated into the external processing layer 30 of multiple plants. Thus, the external processing layer 30 may: Run cloud-native apps and Connect with external PaaS and SaaS tenants, Integrate machine learning with manufacturing data and processing, train-test-deploy, Visualize data, access apps, and organize them It may be further configured as follows.
[0084] The system architecture allows the concept of bottom-up contextualization to be realized. Such a concept is illustrated in Figure 4. In a bottom-up concept, all information available at lower levels may already be added to the data as attributes, so that the context of the lower levels is not lost. Here, the first processing layer 14, as the lowest context level, may contain measurements 11 contextualized with respect to the item 13 at which the measurement was taken. The intermediate processing system 34 may be further contextualized by adding tags 15 related to individual chemical plants 12. The process management system 32 may be further contextualized by adding tags 17 related to multiple chemical plants 12 and / or business information. The external processing layer 30 may be further contextualized by adding tags 19 related to multiple plants and / or external context information, for example from a third party.
[0085] The concept of contextualization can cover at least two basic types of context. One type may be a functional location within a production environment that includes multiple chemical plants. This can cover information about what and where this data point represents within the production environment. Examples include connections to functional locations, attributes about the physical assets from which the data is collected, etc. This context can be beneficially used in later applications to describe which data is available for which plants and assets.
[0086] Another type may be a confidentiality classification. Such a tag may be added at the lowest possible level, and this information may be propagated to further processing layers. Such tags may be added automatically or manually. For example, technical measures may be implemented, such as through filters embedded in a firewall, to automatically prohibit "strictly confidential" data from being integrated up to the external processing layer 30. Sharing data with an external party automatically notifies the party that "confidential data" is being shared. An automatic contract check may be implemented to verify whether this data can be shared with this external party.
[0087] Overall, the contextualization concept thus realized allows for highly efficient data usage in processing applications deployed at any layer of the system.
[0088] FIG. 5 shows a flow chart of a schematic diagram of a method for monitoring and / or controlling one or more chemical plants.
[0089] Preferably, the method is executed on the distributed computing system shown in Figures 1-3 associated with the chemical plant 12 and including a first processing tier 14 communicatively coupled to second processing tiers 16, 32, 34. The method may perform all steps described in the context of Figures 1-4, including steps related to contextualization, data processing, processing application management, and monitoring device management.
[0090] In a first step 61, process or asset specific data for the chemical plant 12 is provided via the first process layer 14 to the second process layer 16, 32, 34.
[0091] In a second step 63, the process or asset specific data is contextualized via a second processing layer 16, 32, 34 to generate plant specific data.
[0092] In a third step 65, plant-specific data for one or more chemical plants 12 is provided via a second processing layer 16, 32, 34 to an interface 26 to an external network.
[0093] In a fourth step 67, the one or more chemical plants are monitored and / or controlled via the second process tier 16, 32, 34 or the first process tier 14 based on the process or asset specific data or the plant specific data. Monitoring and / or control of plant 12 may be performed via second processing layer 16, 32, 34 or external processing layer 30 based on plant-specific data. Additionally, monitoring and / or control may be performed via first processing layer 14 based on process- or asset-specific data. Such monitoring and / or control may be performed via processing applications that ingest the respective data and provide output monitoring and / or control, as further shown in Figures 6-8.
[0094] FIG. 6 shows a schematic diagram of a distributed computing system for monitoring and / or controlling one or more chemical plants having multiple assets via a distributed computing system 10 with more than two deployment layers 14, 16, 30.
[0095] The schematic diagram of FIG. 6 depicts a containerized application organization at various deployment tiers 14, 16, and 30. The system 10 includes an external processing system 30, a second processing tier 16, and a first processing tier 14. Here, the second processing tier 16 may include greater storage and computing resources than the first processing tier 14, and / or the external processing tier 30 may include greater storage and computing resources than the second processing tier 16. The architecture and functionality of the system 10 may conform to the architecture and functionality described with respect to FIGS. 1-3. In particular, the first and second processing tiers 14, 16 may be configured within secure networks 20, 40, and 18. The first processing tier 14 may be communicatively coupled to the second processing tier 16, which may be communicatively coupled to the external processing tier 30 via an external network 24.
[0096] The orchestration applications 56, 58 may be hosted by the external processing layer 30 and the second processing layer 16, 32, 34, respectively. Accordingly, the containerized application or container images 48, 50 may be stored in registries of the external processing layer 30 and the second processing layer 16, 32, 34, respectively. The containerized applications 48, 50 for execution may include one or more operations for ingesting input data, providing the input data to a respective asset or plant model that generates output data, and providing the generated output data for controlling and / or monitoring the chemical plant 12. In this manner, the external processing layer 30 and the second processing layer 16, 32, 34 act as a facilitation layer that reduces the computing and storage resources required for the first processing layer 14 at the asset level.
[0097] FIG. 7 shows a flowchart of a schematic diagram of a method for monitoring and / or controlling a chemical plant 12 having multiple assets via a distributed computing system 10 as may be implemented in the system 10 shown in FIGS. 1-4.
[0098] In a first step 60, a containerized application 48, 50 is provided that includes an asset or plant template that specifies input data, output data, and an asset or plant model. The containerized application 48, 50 may be created on the external processing layer 30 or modified on the second processing layer 30. An external containerized application from a third-party environment may be provided.
[0099] In a second step 62, the containerized application 48, 50 is deployed to run in at least one of the deployment tiers 30, 32, 16, 34, 14, where the deployment tier 30, 32, 16, 34, 14 is assigned based on input data, load indicators, or system tier tags, and the containerized application 48, 50 may execute in the assigned deployment tier 30, 32, 16, 34, 14 to generate output data for controlling and / or monitoring the chemical plant 12. The deployment may be performed by deploying the containerized application 48, 50 to at least one of the deployment tiers 30, 32, 16, 34, 14 based on the input data, load indicators, or system tier tags. The deployment of containerized applications 48, 50 may be managed by an integration application 56, 50 that manages the deployment of the containerized applications 48, 50. The integration application may be hosted by the second processing tier 16, 23, 34 and / or the external processing tier 30. The integration application 56, 58 hosted by the second processing tier 16, 32, 34 may manage critical containerized applications 48, 50, while the orchestration application 56, 58 hosted by the external processing tier 30 may manage non-critical containerized applications 48, 50. The allocation of deployment tiers 30, 32, 34, 16, 14 may be based on input data that depends on data availability indicators, criticality indicators, or latency indicators. Containerized applications from third-party environments can be deployed to run on the external processing tier 30.
[0100] The orchestration applications 56, 58 may be hosted by the external processing tier 30 and the second processing tier 16, respectively. The orchestration applications 56, 58 may deploy the containerized applications 48, 50 to any deployment tier 30, 16, 14. The containerized applications 48, 50 may then be executed in the respective deployment tier 30, 16, 14 by running the processing applications 46, 52, 54 in a sandbox-type environment. The deployment tiers 30, 16, 14 may be assigned based on input data, load indicators, or system tier tags. For example, management of a critical containerized application 50 may optionally be assigned to the second processing tier 16 based on historical criteria reflecting the time frame of historical data available on the first or second processing tier 16. Advantageously, the containerized applications 48, 50 may be deployed to multiple assets or plants of the same type. Additionally, the containerized applications 50, 48 may be modified based on input and output data provided by containerized applications 46, 52, 54 executed on multiple assets or plants of the same type.
[0101] In a third step 64, the containerized applications 48, 50 may be monitored during or after each execution based on a confidence level of the input data, asset model, or plant model. Based on the resulting confidence level, an event signal or a change to the asset or plant model may be triggered. Such a trigger may be set if the confidence level exceeds a threshold. Such a threshold may be predefined or dynamic. If a trigger is set, the asset or plant model change may be executed, for example, in the second processing layer 16, 32, 34 or the external processing layer 30.
[0102] In a fourth step 66, the generated output data is provided for controlling and / or monitoring the chemical plant 12. Such output data may be passed to a persistence instance after execution of the containerized application 48, 50. In particular, such output data may be passed to a control instance on, for example, the first processing tier 14 of the chemical plant 12. Additionally or alternatively, such output data may be passed to a monitoring instance on the first processing tier 14, the second processing tier 16, 32, 34, or the external processing tier 30. The output data may be passed to, for example, a client application for display to an operator or to a further containerized application 48, 50 for execution.
[0103] FIG. 8 shows a schematic diagram of a system 10.2, 10.2 for monitoring and / or controlling multiple chemical plants 12.1, 12.2 within separate secure networks 20.1, 20.2 configured for data and processing application transfer. FIG. 8 shows the system 10 of FIGS. 1-3, including, by way of example, first and second processing layers 14, 16, 32, 34 and an external processing layer 30. Other system architectures may be suitable for processing applications and data transfer as well. Both systems are associated with separate secure networks 20.1, 20.2 and communicate with each other via interfaces 26.1, 26.2. and communicatively coupled to external networks 24.1, 24.2.
[0104] Systems 10.1 and 10.2 are configured to exchange process or asset-specific data or processing applications based on transfer tags. By adding transfer tags at the earliest possible level, i.e., where the data or application is generated or where it first enters the system, the transfer tag becomes an inherent part of any data point or application as soon as the tag is added and follows the data or application on its path through systems 10.1 and 10.2. Such transfer tags enable seamless and secure integration of external data sources or external applications and the transfer of data or applications to external resources.
[0105] In one case shown in FIG. 8, an application 48 is exchanged between systems 10.1 and 10.2. In this example, the containerized application 48 is transferred via external processing layers 30.1 and 30.2, which are communicatively coupled to the two systems 10.1 and 10.2. Here, the external processing layer 30.1 is communicatively coupled to system 10.1, and the external processing layer 30.2 is communicatively coupled to system 10.2. The exchange of the containerized application 48 is performed indirectly via the external processing layers 30.1 and 30.2. The containerized application is tagged with a transfer tag that includes two transfer settings related to confidentiality settings and / or third-party transfer settings. In this manner, transfers can be permitted or prohibited based on a compliance check by the external processing layer 30.2, for example, if the transfer using the respective third-party identifier is associated or not associated with a third-party identifier stored in a database of permitted third-party transfers for the processing application 48. Similarly, process- or asset-specific data can be communicated 72 between systems 10.1 and 10.2. Any transfer between systems 10.1, 10.2 may then be followed by a further transfer from the external processing layer 30.1, 30.2 to the respective system 10.1, 10.2.
[0106] Additionally, such forwarding based on forwarding tags can occur directly between systems 10.1, 10.2 between processing layers 32, 16 associated with secure networks 20.1, 20.1. Such forwarding based on forwarding tags can be achieved via a secure connection 74 between such layers 16, 23, such as a VPN connection. Any forwarding between systems 10.1, 10.2 can then be followed by further forwarding between system components within secure networks 20.1, 20.2 or to processing layers 30.1, 30.2 external to the respective systems 10.1, 10.2. By attaching forwarding tags to data points and processing applications, whether containerized or not, third-party forwarding between systems 10.1, 10.2 within separate secure networks 20.1, 20.1 can be handled securely.
[0107] To enable controlled communication between systems 10.1, 10.2, processing layers 32, 16, or external processing layers 30.1, 30.2, processing and asset-specific data, as well as processing applications, may be contextualized with transfer tags. Specifically, external data or applications may be added with transfer tags to control communication between systems 10.1, 10.2 and 10.1, prohibiting or allowing such communication. Processing layers 32, 16 or external processing layers 30.1, 30.2 may be configured to deploy external applications in response to third-party transfer settings intended for internal data ingestion. In such cases, external applications, whether containerized or not, may be securely transmitted between systems 10.1, 10.2, and internal data of one system 10.1, 10.2 may be provided to such transmitted applications. In this manner, external applications may be executed within systems 10.1, 10.2, where data for ingestion by the external application is stored. The execution of external applications is controlled by processing layers 32, 30.1, 30.2. The processing layer 32, 16 or the external processing layer 30.1, 30.2 may be configured to contextualize the internal application by adding a third-party forwarding setting for external data ingestion. External data may be securely transmitted between the systems 10.2, 10.2 based on the forwarding tag, and an internal application of one system 10.1, 10.2 may be provided with such external data. The processing layer 32, 16 or the external processing layer 30.1, 30.2 may be configured to deploy the internal application according to the third-party forwarding setting for external data ingestion. In this way, the internal application may be executed within the system 10.1, 10.2 to which data for ingestion by the internal application is sent. Execution may occur in the processing layer 32, 16 or the external processing layer 30.1, 30.2.
[0108] Any of the components described herein used to implement the methods described herein may be in the form of a distributed computer system having one or more processing devices capable of executing computer instructions. The components of the computer system may be communicatively coupled (e.g., networked) to other machines in a local area network, a secure network, an intranet, an extranet, or the Internet. The components of the computer system may operate as peer machines in a peer-to-peer (or distributed) network environment. Part of the computer system may be a virtualized cloud computing environment, an edge gateway, a web appliance, a server, a network router, a switch, or a bridge, or any machine capable of executing a set of instructions (sequential or otherwise) that specify operations to be performed by that machine. Furthermore, it should be understood that terms such as "computer system," "machine," "electronic circuit," and the like are not necessarily limited to a single component, but are intended to include a collection of machines that individually or jointly execute a set (or sets) of instructions to perform any one or more of the methodologies described herein.
[0109] Some or all of the components of such a computer system may be utilized by or exemplify any of the components of system 10. In some embodiments, one or more of these components may be distributed across multiple devices or integrated into fewer devices than shown. Furthermore, some components may refer to physical components implemented in hardware, while other components may refer to virtual components implemented in software on remote hardware.
[0110] Any processing layer may include a general-purpose processing device such as a microprocessor, microcontroller, central processing unit, etc. More specifically, a processing layer may include a Complex Instruction Set Computing (CISC) microprocessor, a Reduced Instruction Set Computing (RISC) microprocessor, a Very Long Instruction Word (VLIW) microprocessor, or a processor implementing other instruction sets or a processor implementing a combination of instruction sets. A processing layer may also include one or more special-purpose processing devices, such as an Application-Specific Integrated Circuit (ASIC), a Field Programmable Gate Array (FPGA), a Complex Programmable Logic Device (CPLD), a Digital Signal Processor (DSP), a network processor, etc. The methods, systems, and devices described herein may be implemented as software on a DSP, microcontroller, or any other side processor, or as part of an ASIC, CISC, FPGA, FPGA, CPLD, or other special-purpose processing device. It may be implemented as hardware circuitry within a PLD, a FPGA, or the like. It should be understood that the term "processing tier" may also refer to one or more processing devices, such as a distributed system of processing devices located across multiple computer systems (e.g., cloud computing), and is not limited to a single device unless otherwise specified.
[0111] Any processing layer may include a suitable data storage device, such as a computer-readable storage medium, on which is stored one or more sets of instructions (e.g., software) embodying any one or more of the methodologies or functions described herein. The instructions may also reside, completely or at least partially, within a main memory and / or within a processor during its execution by a processing device, which may constitute a computer system, the main memory, and the computer-readable storage medium. The instructions may further be transmitted or received over a network via a network interface device.
[0112] A computer program for implementing one or more of the embodiments described herein may be stored and / or distributed on a suitable medium, such as an optical storage medium or a solid-state medium supplied together with or as part of other hardware, but may also be distributed in other forms, such as over the Internet or other wired or wireless communication systems, although the computer program may also be presented over a network such as the World Wide Web and may be downloaded into the working memory of a data processor from such a network.
[0113] The terms "computer-readable storage medium," "machine-readable storage medium," and the like should be interpreted to include a single medium or multiple media (e.g., centralized or distributed databases, and / or associated caches and servers) that store one or more sets of instructions. The terms "computer-readable storage medium," "machine-readable storage medium," and the like should also be interpreted to include any transitory or non-transitory medium that can store, encode, or carry a set of instructions for execution by a machine, whereby the machine performs any one or more of the methodologies of the present disclosure. Thus, the term "computer-readable storage medium" should be interpreted to include, but is not limited to, solid-state memory, optical media, and magnetic media.
[0114] Some of the detailed descriptions may be presented in terms of algorithms and symbolic representations of operations on data bits within a computer memory. These algorithmic descriptions and representations are the means used by those skilled in the data processing arts to most effectively convey the substance of their work to others skilled in the art. An algorithm is here, and generally, conceived to be a self-consistent sequence of steps leading to a desired result. The steps are those requiring physical manipulations of physical quantities. Usually, though not necessarily, these quantities take the form of electrical or magnetic signals capable of being stored, transferred, combined, compared, and otherwise manipulated. It is sometimes convenient, principally for reasons of common usage, to refer to these signals as bits, values, elements, symbols, characters, terms, numbers, or the like.
[0115] It should be noted, however, that all of these and similar terms are associated with the appropriate physical quantities and are merely convenient labels applied to those quantities. Unless otherwise indicated, as is clear from the preceding discussion, throughout the description, terms such as "receive," "retrieve," "send," "calculate," "generate," "add," "subtract," "multiply," "divide," "select," "optimize," "calibrate," "detect," "store," "execute," "analyze," "determine," "enable," "identify," "modify," "convert," "apply," "extract," and the like refer to manipulating and transforming data represented as physical (e.g., electronic) quantities in the registers and memory of a computer system, and other data similarly represented as physical quantities in the memory or registers of a computer system, or other such information storage, transmission, or It is understood to refer to the operations and processing of a computer system or similar electronic computing device that translates to a display device.
[0116] It should be noted that embodiments of the present invention are described with reference to different subject matter: in particular, some embodiments are described with reference to method-type claims, and other embodiments are described with reference to system-type claims.
[0117] However, those skilled in the art will gather from the above and following descriptions that, unless otherwise noted, any combination of features belonging to one type of subject matter, as well as any combination between features relating to different subjects, is considered to be disclosed in the present application, although all features may be combined to provide synergistic effects that are greater than the simple sum of the features.
[0118] While the invention has been illustrated and described in detail in the drawings and the foregoing description, such illustration and description are to be considered exemplary or exemplary, and not restrictive. That is, the invention is not limited to the disclosed embodiments. Other variations to the disclosed embodiments can be understood and practiced by those skilled in the art from a study of the drawings, the disclosure, and the appended claims. In some instances, well-known structures and devices are shown in block diagram form, rather than in detail, in order to avoid obscuring the disclosure.
[0119] In the claims, the word "comprising" does not exclude other elements or steps, and the indefinite articles "a" or "an" do not exclude a plurality. A single processor or controller or other unit may fulfill the functions of several items recited in the claims. The mere fact that certain measures are recited in mutually different dependent claims does not indicate that a combination of these measures cannot be used to advantage. Reference signs in the claims are not to be construed as limiting the scope.
Claims
1. 1. A system (10) for monitoring and / or controlling one or more chemical plants (12), comprising at least one processing layer (14, 16, 32, 34), the at least one processing layer (14, 16, 32, 34) associated with a secure network (20) and communicatively coupled to an interface (26) for providing process or asset specific data or processing applications to an external processing layer (30), the at least one processing layer (14, 16, 32, 34) configured to add a transfer tag to the process or asset specific data or the processing application and to provide the process or asset specific data or the processing application based on the transfer tag.
2. 2. The system of claim 1, comprising a first processing layer (14.1, 14.2) and a second processing layer (16, 32, 34) associated with the secure network (20), and optionally an external processing layer (30), the external processing layer (30) configured to add a forwarding tag to the process or asset specific data or the processing application, and to provide the process or asset specific data or the processing application based on the forwarding tag.
3. 3. The system of claim 2, wherein the first processing layer (14.1, 14.2) is configured to contextualize the process or asset specific data by adding the transfer tag, and the second processing layer or the external processing layer is configured to contextualize a processing application by adding the transfer tag.
4. 10. The system of claim 1, wherein the processing layer (14, 16, 32, 34) is configured to add a transfer tag to the processing or asset specific data or processing application at the time of creation or at the entry point to the system (10) or the processing layer (14, 16, 32, 34).
5. 10. The system of any of the preceding claims, wherein the forwarding tag comprises at least two forwarding settings, the at least two forwarding settings relating to confidentiality settings and / or third party forwarding settings.
6. 10. The system of claim 9, wherein the processing layer (14, 16, 32, 34) or the external processing layer (30) is configured to provide contextualized processing and asset data or processing applications to a third-party system based on the forwarding tag.
7. The system of claim 6 , wherein the processing layer (14, 16, 32, 34) or the external processing layer (30) is configured to perform a third-party compliance check before forwarding to a third-party system.
8. 8. The system of claim 6 or 7, wherein the processing layer (14, 16, 32, 34) or the external processing layer (30) is configured to access a third-party compliance database and determine transfer compliance based on the third-party transfer settings, which include a third-party identifier and at least one information category.
9. 10. The system of any of the preceding claims, wherein the processing layer (14, 16, 32, 34) or the external processing layer (30) is configured to receive external data or an external application.
10. 10. The system of claim 1, wherein the processing layer (14, 16, 32, 34) or the external processing layer (30) is configured to contextualize external data or an external application by adding the forwarding tag.
11. 10. The system of claim 1, wherein the processing layer (14, 16, 32, 34) or the external processing layer (30) is configured to deploy external applications according to a third-party transfer setting representing an internal data ingestion.
12. 10. The system of claim 9, wherein the processing layer (14, 16, 32, 34) or the external processing layer (30) is configured to contextualize internal applications by adding the third-party transfer setting representing external data ingestion.
13. 10. The system of claim 1, wherein the processing layer (14, 16, 32, 34) or the external processing layer (30) is configured to deploy internal applications depending on the third-party transfer settings of the external data ingestion.
14. 10. The system of claim 9, wherein the processing layer (14, 16, 32, 34) or the external processing layer (30) is configured to initiate, prevent or control a process that provides processing or asset specific data or a processing application according to the transfer tag.
15. 1. A method for monitoring and / or controlling one or more chemical plants including at least one process layer, the at least one process layer being associated with a secure network and communicatively coupled to an interface for providing process or asset specific data or process applications to an external process layer, the method comprising: adding a transfer tag to the process or asset specific data or the process application via the at least one process layer; providing the process or asset specific data or the processing application via the at least one processing layer based on the transfer tag; A method comprising: