Process automation system with security interface
The system addresses integration challenges by using a security interface for remote control with two-stage verification, ensuring secure and rapid process control across multiple plants.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- BASF SE
- Filing Date
- 2024-05-07
- Publication Date
- 2026-06-02
AI Technical Summary
Existing industrial automation systems lack integration with advanced IT systems like IoT, mobile devices, cloud computing, and VR/AR due to security concerns and lack of openness and flexibility, leading to potential production issues and safety risks.
A system with a security interface that enables remote control of manufacturing processes by validating control parameters through a two-stage verification process, ensuring safety and integrity by using a one-way communication channel and integrating with a plant machinery database.
Enables secure, granular, and rapid control of manufacturing processes across geographically dispersed plants, reducing waiting times and enhancing safety without compromising plant integrity.
Smart Images

Figure 2026517864000001_ABST
Abstract
Description
Technical Field
[0001] Field of the Invention The present invention relates to industrial automation systems, and more particularly to systems and methods for safely controlling automated manufacturing processes.
Background Art
[0002] Background and Prior Art An industrial automation system for controlling an automated manufacturing process is disclosed in European Patent No. 3318945 A2. The automation system includes, in particular, an industrial visualization system that provides virtual reality (VR) and augmented reality (AR) presentations of an industrial facility to wearable devices to facilitate remote or enhanced interaction with the automation system within the facility. The VR presentation can include a three-dimensional (3D) holographic view of a plant facility or a location within the plant facility. The system can selectively render a reduced view that renders the facility as a 3D scale model, or a first-person view that renders the facility as a full-scale representation that simulates the presence of the user on the floor of the plant. A camera icon rendered in the VR presentation can be selected to switch to a live video stream generated by a 360-degree camera within the plant. The system can also render a workflow presentation that guides the user through the process of resolving detected maintenance issues.
[0003] To address these and other issues, one or more embodiments of the present disclosure provide a system that generates and delivers to a user an augmented reality (AR) or virtual reality (VR) presentation (collectively referred to herein as “VR / AR presentation”) via a wearable computer or other client device. The VR / AR presentation generated by the system may include a three-dimensional (3D) holographic view of a plant facility or a location within a plant facility (e.g., a work area, a production line, etc.). The holographic view may be provided to a wearable visualization computer that renders the 3D view as a function of the user’s current position and / or orientation. The system may render a scaled-down view of the factory floor area, thereby allowing the user to grasp the appearance of that area. This external view may include a real-time avatar representing a human operator, superimposed production statistics and status data, and other information. In accordance with user selection input, the system may switch from this external view to an internal view that renders a realistic presentation of the factory floor area from the perspective of a person standing in the environment. This internal view may include superimposed motion data or status data placed on or near representations of relevant industrial devices or control panels.
[0004] Previously, remote plant control was essentially prohibited due to the potential risks to proper plant automation. Tasks performed "inside" and "outside" the factory were separated by essential manual work.
[0005] For example, automation structures described by the Purdue Reference model, particularly those used in legacy automation systems, have been in use for many years and have been shown to operate reliably. However, these systems lack openness and flexibility, making it difficult or impossible, and costly, to integrate new technologies (such as IoT, mobile devices, cloud computing, remote control, and VR and AR applications).
[0006] Integrating existing hardware-based automation technologies into globally networked systems has proven particularly challenging. Trained professionals perform numerous configurations on on-site machinery. If these configurations are intentionally or accidentally inaccurate, they can lead to the production of lower-quality products and damage to individual machines, the entire production plant, or even employees.
[0007] Security measures in these systems prohibit or make highly complex the execution of remote control commands in order to prevent plant malfunctions caused by external systems, users, and / or targeted hacker attacks. Therefore, these automation systems cannot be fully integrated into large-scale, global IT systems. [Overview of the project] [Problems that the invention aims to solve]
[0008] overview The object of the present invention is to provide an improved system for process automation in a manufacturing plant and a corresponding method as defined in the independent claims. Embodiments of the present invention are shown in the dependent claims. Embodiments of the present invention can be freely combined with each other if they are not mutually exclusive.
[0009] In one embodiment, the present invention relates to a system for process automation in a manufacturing plant. The system is - Multiple machines in the manufacturing plant, - A plant machinery database including machine control parameters, - An automation system for automatically operating machinery in a manufacturing plant according to control parameters in a plant machinery database, - Identity provider, ○ Multiple remote users not located within the manufacturing plant, and ○ Multiple local users located within the manufacturing plant The identity provider, including the user profile, - A visualization engine configured to create augmented reality for local users and virtual reality for remote users, including a digital twin of the plant. - Security interface (142), ○ A request to operate at least one of the machines is received from one of the remote users (108), ○ An acceptance request is a signal prompting one of the local users (146) to accept at least one requested action of the machine via augmented reality glasses worn by one of the local users, causing the visualization engine to generate an acceptance request. Only when a request is received by a single local user, the control parameters (402-408) included in or derived from the received request are stored in the plant machinery database. A security interface (142) configured as follows: Includes, The automated system is configured to perform automated operation of the machine according to stored control parameters included in or derived from the received request.
[0010] According to one embodiment, the security interface is configured to validate a request and store the control parameters in the plant machinery database only if the validation returns that the request is valid. More specifically, the security interface may be configured to receive a request, validate the request, and, in response to the determination that the request is valid, store the control parameters contained in or derived from the request in the plant machinery database. The automation system may be configured to perform automated operation of the machinery according to the stored control parameters contained in or derived from the valid request. For example, a request may be a request to start, stop, or modify one or more operations of the machinery. A request may be received from a client via a network, such as the Internet.
[0011] The present invention may provide the possibility for existing and new plants to effectively integrate existing core automation systems with advanced IT systems for task monitoring, optimization, and control, thereby enabling client devices or users to send requests to a security interface over a network to operate one or more machines in the plant after successful request verification.
[0012] The security interface can be one-way, meaning it allows a client to send machine-related data, such as machine-related control parameters, to the automation system via a request, but does not allow the machine-related data to be returned to the client that submitted the request. This can enhance security because the client receives no information whatsoever about the type or state of the machine whose operating state was modified in response to the request. The client also receives no information about the number of machines affected by the request, or any reason why the request could not be performed. According to some embodiments, the one-way security interface does not return any request-related feedback information to the client, except for information on whether the request was successfully performed. According to a further advantageous embodiment, the security interface can function as a secure and controlled access interface that supports request-based data ingestion from the outside to the automation system without compromising integrity and plant safety.
[0013] According to the embodiment, request verification includes performing a validation check, which includes determining whether the control parameters included in or derived from the request are safe for machine and human operators, and the request is considered invalid if at least one of the control parameters is determined to be unsafe. In other words, the validity of the control parameters included in or derived from the request can be checked. Only if this validation check returns that the request is valid can the request be treated as a validated and valid request. For example, a security interface may be configured to verify a request by, for example, performing a validation check to determine whether the control parameters included in and / or derived from the request are valid. The security interface may also be configured to store the control parameters included in and / or derived from the received request in a plant machinery database only if the request is successfully validated as a valid, for example, reasonable request. This can further improve the safety of remote process control. For example, if the security interface determines that the temperature of the reaction mixture is set to a value that would damage the tank walls, the security interface may treat the request as invalid. Request verification can be performed, for example, based on configurable rules and / or based on the combined actions of the first and second submodules of the security interface, as has already been described herein for various embodiments and examples.
[0014] For example, a validation check may include checking whether the operation of one or more machines that follow the control parameters is safe (for the products to be produced, for the machines and staff) and is likely to enable the production of products with desired characteristics. For example, a validation check may include determining whether the control parameter values specified in or derived from the requirements are within a predetermined acceptable parameter range, and / or predicting (e.g., simulating) whether the process performed by one of the machines according to these control parameters will produce a product with acceptable or preferred parameter characteristics, such as product size, quantity, purity, shape, color, elasticity, viscosity, etc. If the control parameters set the temperature of the heating element of a tank to a temperature that would damage the tank material or its components, the security interface may consider the requirement unvalid. Only if this check returns that the requirement is valid, the security interface may store the control parameters in the plant machinery database and thereby modify how the machines operate.
[0015] The plant machinery database may contain one or more control parameters of a machine, where the control parameters are or include control parameters, and the automation system automatically operates the machine by setting the control parameters in the plant machinery database to control parameter values provided with or derived from the request. In addition, the plant machinery database may contain models (e.g., structural models, e.g., simplified or realistic 3D models), location information and status information of the machine and / or products produced by the machine, where the location information is continuously updated to reflect the actual location and status of the machine and / or products. The models, location information and / or status information, or parts thereof, may be used to generate a digital twin of the machine and / or objects manufactured or processed by the machine. For example, a digital twin of each individual machine of a machine can be used to graphically represent the machine through its digital twin and / or to simulate the operation of the machine and / or to control the machine through its digital twin.
[0016] According to the embodiment, the security interface is configured to map control parameters included in or derived from a request to further control parameters included in a plant machinery database in order to extend the control parameters, the security interface is configured to perform validation checks of the further control parameters, the validation checks include determining whether the further control parameters are safe for machine and human operators, and the request is deemed invalid if at least one of the further control parameters is determined to be unsafe.
[0017] The disclosed system and method may, advantageously, be used to control the operation of one or more machines of an automated system based on control parameters generated outside the automated system, for example, by or entered into a client device that generated a request. These control parameters may be set values, i.e., parameters that can be set before and / or during the operation of a machine, defining how the machine operates. To that extent, the disclosed system and method may offer the advantage of enabling remote process control of machines in an automated system without compromising safety, and achieving much faster and more granular process control. Generally, in process industries, a local plant operator working in the spatial vicinity of a machine sets the control parameter values of one or more machines in an automated system. For example, in conventional process automated systems, the operator may input control parameters via a local machine interface. The input control parameters may be proposed by a customer or another human or non-human user who is not part of the automated system (and therefore considered less reliable as a local operator). The local operator ensures that only verified external data is carried over into the automated system by manually inputting the control parameters proposed by the remote advanced process control system. However, the number of control parameters that human operators can understand and manually input is limited, and especially in complex manufacturing processes with multiple interdependencies, even skilled local users may fail to consider the relevant contextual information.
[0018] On the other hand, the systems and methods disclosed herein advantageously enable external clients of the automation system, such as a client hosting an advanced process control system, or other client software not part of the automation system, to generate and present requests containing control data, thereby ensuring that the verification of the requests does not damage the machinery, degrade product quality, and / or harm any personnel working adjacent to the respective machines. Furthermore, the request verification carried out according to embodiments of the present invention enables a higher degree of complexity in validating control parameters, allows for the processing and evaluation of requests at a higher frequency, and thereby provides much finer control over the automation process.
[0019] In this case, the system disclosed herein may include a client configured to generate requests and present them to a security interface via a network, such as the Internet. The client generating the requests may be configured to repeatedly generate and present requests, in particular at a frequency of at least once per hour, preferably at least once per minute, preferably at least once per second, and in some embodiments at least once every 0.10 seconds. Each request may include one or more control parameters for controlling one or more operations of a machine. In addition, requests may be automatically generated and presented by client software, thereby dynamically calculating the control parameters specified in the requests by the client software. This allows the security interface to repeatedly perform request verification, in particular at a frequency of at least once per hour, preferably at least once per minute, preferably at least once per second, and in some embodiments at least once every 0.10 seconds.
[0020] The above client may be configured to repeatedly predict one or more control parameter values that are optimal or suitable for controlling the operation of one or more of the machines such that at least one feature of an automated production process performed by one or more of the machines is optimized, and to automatically and repeatedly present a request containing one or more predicted control parameters to a security interface. In particular, the prediction of the control parameter values may include simulating the automated production process and the operation of one or more of the machines involved in the production process.
[0021] For example, client software may be configured to simulate a production process or a part thereof to identify control parameters suitable for optimizing the production process or ensuring safety or good product quality. For example, possible optimization criteria may include reduction of energy or material consumption, reduction of waste, improvement of product quality or purity, presence of desirable features, or product characteristics or process parameter values within a desired range.
[0022] To give a more specific example, the manufacturing plant PA may include a plurality of machines and tanks configured to perform a continuous chemical synthesis workflow for continuously producing two products A and B, the relative proportions of which may strongly depend on process parameters such as the temperature in the reaction mixture. Product A may be used as an extract in a different synthesis workflow for synthesizing substance E in a different plant PE. Product B may be used as an extract in a further synthesis workflow for producing substance F in a further plant PF. The demand for either A or B may depend on the demand for substances E and F. Since these products are synthesized in different plants, the machines in plants PA, PE, and PF are not part of the same automation system, and thus, the automated integration of the synthesis workflows implemented in different plants has been impossible until now. Also, since the human operator had to manually set the reaction temperature of the synthesis workflow in plant PA to a temperature value suitable for producing products A and B at a rate that meets the demand for the final products E and F, fine control has also been impossible. This has caused significant delays and hindered the real-time synchronization of industrial manufacturing processes among geographically dispersed plants. By using a security interface and claim verification, it is possible to synchronize the manufacturing process so that the waiting time is minimized. Claims can be automatically generated at a high frequency by a client that includes or belongs to an advanced process control system that integrates the requirements, demands, and available resources of a plurality of geographically dispersed heterogeneous plants.
[0023] Therefore, the systems and methods disclosed herein may advantageously support fully automated control of one or more plants and the integration of process control of one or more plants in an advanced process control system. The waiting time can be significantly reduced without sacrificing safety.
[0024] The systems disclosed herein may also be configured to use a security interface as a single-point input to an automated system. The security interface may be configured to receive and verify requests presented by one or more different clients, for example, by an advanced process control system, by an edge computer system, or by a remote operator using virtual reality glasses and / or a mobile device (e.g., a smartphone) to remotely control a manufacturing process.
[0025] The systems disclosed herein for process automation may also include a multilevel system architecture. - A first level involving the execution of actual physical processes, particularly the sensing and manipulation of physical objects in automated production workflows, including one or more machines and optionally further objects. - A second level (L2) including components for supervising, monitoring, and / or controlling the first level of physical processes, and a process control level including a second level (L2) including devices that control the entire process in the automation system, - May include at least a third level (L3) which includes manufacturing operation system components configured to manage the production workflow and produce the desired product by supervising, monitoring, and / or controlling the components of the second level. The L3 level is also referred to as the operation control level, which supports the management of the production workflow, such as a manufacturing operation management system.
[0026] The first and second submodules of the security interface, which may belong to the L3 and L2 layers respectively, are functionally complementary functions and may include functions having similar or identical structures, for example, similar or identical numbers and types of input and output arguments. Requests disclosed herein that are received by the security interface may be or include calls to one or more such functions.
[0027] The first submodule of the security interface described above may be part of the third level (L3), and the second submodule of the security interface may be part of the second level (L2). The components of the second level may be protected from components of the third level and higher levels by at least one security measure, in particular a firewall.
[0028] For example, a multilevel system architecture for process automation can be implemented according to a typical automation pyramid model, such as the Purdue Reference model or other similar automation pyramid models.
[0029] In such a multi-level system architecture, the security interface disclosed herein may include one or more software programs and / or software services that function as an interface between the automation system (and by extension, the automation system level "Level L2" of the automation system pyramid) and the L3 level components of the automation system pyramid structure. Embodiments of the present invention enable the implementation of a security interface on top of an existing automation system, thereby enabling request-based (and optionally remote) control of the automation system, preferably without the need to adapt the existing automation system. Requests are checked and verified, and only the control parameters of valid requests are transferred and stored in the automation system's plant machinery database. This protects the automation system and the manufacturing plant from hackers and requests that could set critical control parameters to values that could adversely or even harmfully affect the plant's machinery or the entire manufacturing plant.
[0030] For example, a request may be a request generated by a remote client, thereby being transmitted to a system according to an embodiment of the present invention via a network such as the Internet. The security interface may receive requests via one or more intermediate interfaces or modules, such as a service interface. In some embodiments, a request is a request to control one or more operations of a machine by setting one or more control parameters of the machine, generated, for example, by a remote user via a metaworld engine.
[0031] The security interfaces disclosed herein may also be configured to enable secure one-way transfer of at least control parameters to an automated system via a control communication channel, and not to return machine-related control parameters or status information to the requesting client.
[0032] According to some examples, a second submodule of the security interface includes machine-specific functions, each configured to control the operation of one or more machines according to one or more control parameters in the plant machinery database. The number and types of input arguments and the number and types of output control commands for one or more machine-specific functions correspond at least partially to the control interface of the machine controlled by each of the machine-specific functions. For example, the structure of one or more machine-specific functions is at least partially identical to the function of each machine's control interface.
[0033] The first submodule of the security interface contains one or more general-purpose functions. Each general-purpose function is assigned to one of the machine-specific functions. Receiving a request by the first submodule of the interface triggers the execution of at least one of the general-purpose functions, and after the successful execution of at least one general-purpose function, it triggers the execution of one or more machine-specific functions assigned to the executed at least one general-purpose function. For example, the structure of one or more general-purpose functions is at least partially identical to the machine-specific functions called by each general-purpose function.
[0034] As used herein, “generic functions” are functions that do not include, or do not depend on, knowledge of the technical characteristics of a machine, such as its manufacturer, type, current status, or orientation. For example, the generic function “Operate Centrifuge (INT revolutions per minute, FLOAT temperature)” may be a generic function that takes the control parameters “revolutions per minute” and “(centrifuge) temperature” as input parameters. A generic function may not include a reference to any particular type of centrifuge, but a call to this generic function may trigger the execution of a rule that checks whether the specified revolutions per minute and specified temperature values are valid, without depending on the specific characteristics of a particular centrifuge. For example, if the temperature exceeds the boiling point of the liquid being centrifuged, the temperature may be considered invalid without considering any details of the centrifuge used. If the validation check triggered by the execution of the generic function “Operate Centrifuge” returns that the arguments are valid, a machine-specific function having the same structure may be called. A machine-specific function may include machine-specific characteristics, such as the maximum revolutions per minute and the highest (or lowest) temperature supported by the centrifuge being operated, or may be configured to read out those machine-specific characteristics. Execution of a machine-specific function may involve validating whether the control parameters provided as arguments are supported by a particular centrifuge. A machine-specific function may have the same structure as a called general-purpose function, e.g., "operate centrifuge (INT revolutions per minute, FLOAT temperature)".
[0035] In a further example, the request may include a control parameter indicating that the reaction mixture of a chemical reaction should be set to 120°C to trigger the production of a desired substance. Receipt of this request by the first submodule of the security interface may trigger the execution of a first general-purpose function that performs a validation check if the current energy price is below a predetermined threshold. If so, the first general-purpose function returns as a result that heating the reaction mixture to 120°C is valid and permissible. As a result of the successful validation test performed by the first general-purpose function, the first submodule triggers the execution of a second submodule of the security interface of a first machine-specific function to which the first general-purpose function is assigned. The first machine-specific function checks whether the reaction tank containing the reaction mixture allows the chemical reaction to be carried out at this temperature. For example, this check may include checking whether the tank material is sufficiently robust and whether the heating element has sufficient strength to support a temperature of 120°C. If so, the second submodule of the security interface causes the heating element of the tank to heat the reaction mixture to 120°C. If the first general-purpose function returns that the current energy price is above a predetermined threshold, the first submodule may return via the feedback channel that it cannot fulfill the request and that the execution of the first machine-specific function is not triggered.
[0036] According to some examples, the first part of the requirements verification is performed by at least one general-purpose function, and the second part of the requirements verification is performed by one or more machine-specific functions assigned to the at least one general-purpose function that was executed.
[0037] This offers the advantage of enabling validation checks against both criteria that can be evaluated at the L3 level and criteria related to more sensitive machine-related standards that may relate to highly sensitive machine parameters and status information that should not be disclosed for security reasons. A further advantage is that CPU and memory consumption may be reduced by implementing a two-stage request verification process, as the machine-specific function is executed only if the relevant first function returns that the request is valid. Thus, the general-purpose functions and machine-specific functions assigned to each other functionally complement one another to provide functions, particularly validation functions, that cover both the L3 and L2 aspects of the automation system.
[0038] In some examples, the system includes a function synchronization module configured to automatically determine if the number or type of input arguments required by one of the machine-specific functions, or the number or type of output arguments provided by one of the machine-specific functions, has changed, and to automatically replicate the change to one of the general-purpose functions to which the modified machine-specific function is assigned, so that the input and output arguments of the general-purpose function also reflect this change.
[0039] This has the advantage of making the implementation of request verification transparent. Function calls to machine and / or system components at the L2 level for process automation implemented by machine-specific functions are represented as "visible" to the client or service interface through structurally identical generic functions. Thus, the structure of the generic function exposed to the client or service interface (type and number of input and / or output arguments, and / or function name) is identical to the structure of the machine-specific function. By implementing request verification by two different submodules using the generic and machine-specific functions specified above, L2 automation level machines and components are decoupled from L3 level components and systems outside the plant, thereby ensuring that inbound requests are forwarded only if the request is successfully verified as valid (preferably, if the requesting client is able to successfully authenticate with the ID provider module).
[0040] In a more beneficial aspect, any modifications to the structure of machine-specific functions that may be necessary to adapt the system when a machine is replaced with a different version of the machine are automatically propagated to general-purpose functions. This can ensure that the function interface is automatically kept synchronized and that errors due to incompatible function calls are avoided.
[0041] Optionally, the security interface may be configured to receive feedback data from the automation system via a feedback communication channel, which is a separate communication channel from the control channel.
[0042] For example, the security interface may completely lack any option for receiving data from the automated system and / or transferring this data to the client.
[0043] In some embodiments, there may be a separate communication channel, referred to as a feedback channel, for transmitting feedback information indicating whether the request was performed or refused.
[0044] For example, feedback information may be transmitted from the machine to a service interface that forwards feedback data to the client that submitted the request, via a database service interface (between the security interface and the plant machinery database). In addition, the security module may include an interface for receiving feedback information from the automation system and / or use a feedback channel to notify the client whether the request was validated successfully and executed.
[0045] Preferably, the feedback channel used to transfer feedback data from the automation system or security interface to the client is technically separated from the one-way control channel for transferring control parameters of a request from the client / service interface to the automation system via the security interface.
[0046] This can offer the advantage that even if the feedback channel is compromised by malware or hackers, the communication channel provided by the security interface for processing and transferring the request's control parameters remains unaffected. Therefore, using separate communication channels for feedback data and request-based control parameters (which function as control data) can ensure that feedback data, typically unimportant, can be easily distributed to one or more recipients via the feedback channel. The feedback channel may be a communication link with lower levels of data security and data integrity than the communication channel provided by the security interface for the control parameters. This can facilitate the propagation of feedback data while still maintaining a highly secure communication channel for configuration data. For example, different channels may use different encryption techniques to ensure the integrity of the data transmitted through each channel.
[0047] The verification of requests disclosed herein is performed repeatedly by the security interface. In particular, verification can be performed at a frequency of at least once per hour, or at least once per minute, preferably at least once per second, and in some embodiments at least once every 0.10 seconds.
[0048] This can be beneficial because it may allow the security interface to provide fine-grained control over the manufacturing process, enabling very rapid adaptation to changed requirements and / or production targets. For example, verification may include testing whether one or more control parameters provided by a request received at 12:00 are still valid, taking into account several environmental parameters at 12:05, 12:10, ..., 13:05, 13:10, etc. For example, a manufacturing plant may control a chemical reaction that produces a specific chemical substance in a reaction that may occur preferably in a temperature range of 30°C to 60°C, thereby decreasing the purity of the product with increasing temperature. The purity of the product is continuously monitored. A request received at 14:00 may indicate that this chemical reaction should be carried out at 45°C instead of 40% in order to increase the speed of the manufacturing process, while further control parameters in this request may specify that the purity of the product should be at least 80%. Upon receiving the request, the service interface may evaluate at 14:00 whether the desired purity is achievable while the reaction is proceeding at a reaction temperature of 45°C, and if so, may increase the temperature accordingly. For example, after this validation check is successfully completed, a new reaction temperature of 45°C may be stored in the plant machinery database and used by the heating element of the reaction vessel to heat the reaction mixture to the indicated temperature. For various reasons, the purity of the ongoing reaction may have deteriorated significantly by 14:35. This may be measured by a sensor device in the reaction vessel and communicated to the security interface via a feedback channel. If the security interface repeats the validation of the request (received at 14:00) at 14:35, the security interface may, considering the currently measured purity data, determine that it is highly unlikely that a product with at least 80% purity can be produced at the desired currently set temperature of 45°C. In this case, the security interface may autonomously modify the control parameters provided in the request, for example, by lowering the temperature from 45°C to 40°C and storing the new temperature in the plant machinery database instead of the old temperature.In addition or alternatively, the security interface may issue and return messages to the entity that submitted the request. The message may include a notification that the requested temperature value is no longer valid and has been replaced with a different temperature value that is better suited to achieving the optimization goal, e.g., product purity. In other embodiments, the notification may simply include an indication that the request has been rejected or that the request no longer determines the value of each control parameter in the plant machinery database.
[0049] It should be noted that if some required control parameters remain valid / acceptable with respect to process security, product quality, cost, or other optimization criteria, it is not feasible for a human operator to perform continuous checks multiple times per minute or even multiple times per second. Therefore, embodiments of the present invention can enable an automated system to respond immediately to changed production conditions and altered requirements, thereby providing a response rate that is faster and more accurate than that of an automated system that relies on additional manual quality testing of the production process.
[0050] The security interface disclosed herein is configured to count the number of requests received at predetermined time intervals, for example, within one hour, a few minutes, or a few seconds. If the number of requests to change a given control parameter exceeds a predetermined maximum request threshold, further requests to change this control parameter may be denied until at least a predetermined time has elapsed. This may provide protection against denial-of-service (DoS) attacks and, in addition, may protect the machine from wear and tear and damage, as changes to certain parameter values may trigger the movement of machine parts of the machine; therefore, it may be preferable to limit the number of machine part movements to a maximum value.
[0051] The automation systems disclosed herein include a programmable logic controller (PLC) configured to control one or more manufacturing processes performed by machinery in a plant. The PLC can be an industrial computer that is more robust and adapted for controlling manufacturing processes, such as assembly lines, machinery, robotic devices, or any activity requiring high reliability, ease of programming, and process fault diagnosis. Such a PLC can operate in a program scan cycle, in which the PLC repeatedly executes a program. The simplest scan cycle may consist of three steps: reading an input, executing a program, and writing an output. The program may follow a series of instructions. Typically, it may take tens of milliseconds for the processor to evaluate all instructions and update the status of all outputs.
[0052] It must be noted that most PLCs lack strict access control and version control systems. This means that unauthorized changes to the program can occur and go unnoticed. Therefore, remote control of automated systems, especially those involving one or more PLCs, is typically prohibited for security reasons.
[0053] Advantageously, the systems disclosed herein for process automation that enable remote control of automated systems can be enabled in a secure manner, since a security interface verifies each request and transmits only the control parameters of those requests that have been verified as valid. According to a preferred embodiment, the entity presenting the request must succeed in authentication with the system. If authentication fails, the request is not transmitted to the security interface either. Thus, the system according to embodiments of the present invention ensures that only requests from authenticated and trusted entities, including control parameters that have been verified as valid and secure, are propagated and stored in the plant machinery database, which is the basic means of controlling the actions of machinery in a manufacturing plant.
[0054] According to the methods disclosed herein for verifying requirements, the verification of requirements may include performing a validation check. Performing a validation check is - The value of the control parameter is achievable by one or more machines that operate according to the stored control parameter; for example, if the control parameter sets the pressure generated in a given tank to a value that is not achievable by each of the pumps used to generate the desired pressure, the request is considered invalid, and / or - The value of the control parameter is safe for one or more machines that operate according to the stored control parameter, for example, if the control parameter is set to a value that would impose a security risk because, for example, the pressure generated in a given tank exceeds the maximum pressure limit that is considered safe, although this is achievable by each pump, the request is considered invalid, and / or - The value of the control parameter must be suitable for providing manufactured products that meet quality standards; for example, if the control parameter sets the pressure generated in a given tank to a value within a pressure range known to result in low product quality, the requirement will be considered invalid. This includes checking whether control parameters included in or derived from a request satisfy one or more criteria selected from a group that includes the above.
[0055] Requirements verification may further include checking whether the control parameters included in the requirements meet two or more of the above criteria, and optionally whether the parameters meet further criteria such as manufacturing process time, material cost, and energy consumption that may be associated with a given control parameter. Requirements verification may be rule-based and may include evaluating control parameters using one or more general, machine-independent and / or plant-independent rules and / or one or more machine-specific or plant-specific rules. In addition or alternatively, verification of control parameters may include performing complex computational tasks. For example, a predictive model, such as a machine learning model like a support vector machine or neural network, may be used to simulate the manufacturing process or its individual steps assuming that the control parameters specified in the requirements are used during production, and to check whether the predicted / simulated manufacturing process meets one or more criteria regarding safety, efficiency, cost, and / or product quality.
[0056] It should be noted that a machine in which automated operation is performed according to stored control parameters included in or derived from a valid request may be a robot, in particular a robot controlled by a remote user via a visualization engine. In addition, a machine in which automated operation is performed according to stored control parameters included in or derived from a valid request may include a local control interface, which allows a local operator to access and control the machine via a separate local communication channel. For example, the local interface may be a display screen of one of the machines.
[0057] The systems disclosed herein may include a service interface. The service interface may be configured to receive requests from clients and forward them to a security interface. This allows the security interface to be configured to receive requests only from the service interface. This may further enhance security because the security interface does not directly receive requests from clients. Rather, the security interface is protected from direct contact with clients via the service interface. This ensures that only requests processed and actively forwarded by the service interface are processed and verified by the security interface. In a further beneficial aspect, this allows the service interface to be implemented as an interface that is easily accessible to various different clients. For example, the service interface may include several different web services adapted to different types of clients, such as a remote user using VR glasses to present requests for controlling a robot or other machine in a plant, or a remote client application run by a customer of a company operating a plant, or an edge computer system. Each service may be customized to optimize interaction with each type of client. For example, each service may include a REST API that allows a client to specify and present requests to the respective service.
[0058] The systems disclosed herein may also include an identity provider module operably coupled to the service interface. For example, the identity provider module may be an LDAP directory or another authentication system. The service interface is configured to receive requests from at least one client, authenticate at least one client, and forward the request to the security interface in response to at least one client successfully authenticating at the service interface. If at least one client fails to authenticate at the service interface, the service interface does not forward the request to the security interface. This can also improve security because the automated system typically does not include authentication means. The security of the process automation system can be significantly improved by requiring the client to successfully authenticate to the service interface so that requests presented by the client are forwarded to the security interface and verified by the security interface.
[0059] The security interfaces disclosed herein may also be configured to identify one or more additional control parameters whose values depend on one or more of the control parameters specified in or derived from the request, to replace at least one control parameter included in or derived from the request with the identified one or more additional control parameters, and / or to complement the control parameters included in or derived from the request with the identified one or more additional control parameters. The identified one or more additional control parameters may be stored in a plant machinery database to control the operation of one or more machines (in place of or in addition to the control parameters originally included in or derived from the request).
[0060] The steps described above are sometimes referred to as the “parameter mapping” process. Identifying further parameters may involve mapping, for example, analyzing a file or database record or any other form of data structure that assigns one or more control parameters to one or more further control parameters, respectively. Mapping may involve mapping, for example, machine-independent parameters such as temperature to machine-specific parameters, such as temperatures specified on a machine-specific temperature scale ranging from 0 to 5, rather than absolute temperatures specified in Kelvin or °C. The mapping procedure may also involve more complex calculations of one or more further control parameters. For example, the originally specified control parameters may be desired product characteristics, and the calculation of further control parameters may involve predicting one or more further control parameters that will make it possible and / or are necessary to provide a product with the desired characteristics (see, for example, the descriptions of Figures 4A and 4B).
[0061] Control parameter mapping may allow for an increase in the number of control parameters and / or the mapping of machine-independent parameters to machine-specific parameters. This may have the advantage of enabling remote clients, such as customer edge devices that strongly desire to monitor and / or control the manufacturing process of products ordered by the customer, to control and / or monitor the manufacturing process using customer-specific control parameters without having to disclose too many details of the manufacturing plant, such as the type or quantity of machines used to manufacture the products. Embodiments of the present invention may allow a manufacturing plant owner to permit a customer to monitor and / or control the manufacturing process without the risk that the customer may intentionally or unintentionally control the manufacturing process in a manner that endangers the plant and the employees working at the plant, and without the plant owner having to disclose sensitive details of the machines included in the manufacturing plant to the customer.
[0062] For example, the first control parameter specified in the request may be the desired temperature of the reaction tank (a parameter independent of the machine), and any further parameters specified may be the heating rate or cooling rate set on a particular heater or cooling device of the vessel to achieve the desired temperature (a machine-specific control parameter or setpoint).
[0063] The security interfaces disclosed herein may also be configured to verify one or more additional control parameters identified, which may also be referred to as the verification of “mapped” control parameters. The verification may include performing validation of the additional control parameters, which may include, - The values of the identified further control parameters are achievable by one or more machines operating according to the stored identified further control parameters, and / or - The values of the identified additional control parameters are safe for one or more machines that operate according to the stored identified additional control parameters, and / or - The values of the identified additional control parameters are suitable for providing manufactured products that meet quality standards. This includes checking whether further control parameters satisfy one or more criteria selected from a group that includes the specified criteria.
[0064] If one or more of the identified additional control parameters are determined to be invalid because they do not meet the criteria, neither the control parameters originally included in the request nor the identified additional control parameters will be stored in the plant machinery database. Rather, the request will be considered invalid.
[0065] The system disclosed herein further includes a feedback interface configured to return request-related feedback information to a client submitting a request, wherein the feedback information does not include control parameters or status information for one or more machines, but merely indicates whether the request was successfully executed. Providing a feedback channel separate from the communication channel used to transfer configuration data may offer the advantages of enhanced security (a compromised feedback channel will not affect the transfer of control parameters) and flexibility in controlling automated manufacturing processes (security measures for the feedback channel may not be very stringent). In addition, the accuracy of request verification performed by the security interface may be improved because the validity and appropriateness of a request may depend on the constantly changing current status of one or more machines in the manufacturing plant.
[0066] The security interfaces disclosed herein also - Generate an acceptance request (the acceptance request is configured to prompt an entity to accept one or more requested modifications to control parameters stored in the plant machinery database, the entity can be, for example, a human user working locally in the plant, or a software program), - Provide the entity with the request for acceptance (for example, the security interface may cause software, such as a visualization engine, to generate a message prompting the local user to approve the requested control action via AR glasses or via one of the machine's displays), - Upon receiving a response indicating acceptance by an entity, the control parameters included in or derived from the request are stored in the plant machinery database. It is configured in this way.
[0067] Storing control parameters only upon receiving an indication that the entity has accepted the proposed control parameters may have the advantage of improved security. A remote user may not have a complete picture of all processes in progress on the production lines within the plant, and therefore, machine reconfiguration may adversely affect products, machines, production processes, or personnel working within the plant, and these effects may only be perceptible to, or better perceived by, the local user. The risk of the aforementioned adverse effects occurring can be reduced by requiring the local user to accept control commands in the form of modified control parameters provided by the remote client. The acceptance request may be generated by a second submodule of the security interface. The entity's response may then be sent to and / or returned to the second submodule of the security interface. In response to receiving a response from the entity indicating denial of acceptance, the security interface may store the control parameters (included in or derived from the request) in the plant machinery database.
[0068] The security interfaces disclosed herein may also include at least a first submodule configured to perform a first part of request verification, wherein the first part of verification uses general-purpose, machine-specific and plant-specific rules, and a second submodule configured to perform a second part of request verification, wherein the second part of verification uses machine-specific and / or plant-specific rules. The first submodule is part of the L3 level of a multilevel automation pyramid, and the second submodule is part of the L2 level. For example, the first submodule is hosted on a computer system that hosts L3 level components, and the second submodule is part of the L2 level.
[0069] According to some examples, a first submodule includes a first rule engine and a plurality of first functions, each configured to trigger the execution of one or more non-machine-specific and non-plant-specific rules by the first rule engine. A second submodule includes a second rule engine and a plurality of second functions, each configured to trigger the execution of one or more machine-specific and / or plant-specific rules by the second rule engine.
[0070] Using a security interface that includes two different submodules hosted on different computer systems and multiple levels of automated control can have the advantage of increasing system flexibility. For example, the second submodule may be defined or customized by a plant operator who has a better understanding of the details of the machinery used within a particular plant. This can facilitate the specification of plant-specific or machine-specific rules used to validate requests. The first submodule may be defined or customized by a user who may be familiar with the overall, machine-independent and / or plant-independent aspects of the manufacturing workflow. Since the two submodules are instantiated and maintained separately, it may not be necessary to allow plant operators to modify the overall machine-independent rules, nor may it be necessary to allow operators of L3 or higher levels of automated control to modify the plant-specific or machine-specific rules of the second submodule. This can improve security. As a result, the second submodule may allow only the first submodule to provide control parameters and will not accept or process control parameters or requests, including those provided by different software programs.
[0071] It should be noted that the request presented by the requesting client may also include one or more machine-independent function calls that indicate steps in the manufacturing workflow to be performed. Therefore, the security interface may be configured to perform mapping of machine-independent function calls to calls that can be interpreted by the control interface of one of the machine's machines in the plant. If the request is deemed valid, the security interface forwards the mapped machine-independent function calls directly or, preferably indirectly, for example, via a database service interface, to one or more machines configured to interpret and execute machine-independent function calls.
[0072] The system disclosed herein may also include a first virtual machine configured to host a first submodule of the security interface (and optionally, further components of the third level (L3) of the multilevel automation system architecture), and a second virtual machine configured to host a second submodule of the security interface (and optionally, further components of the second level (L2) of the multilevel automation system architecture). The first and second virtual machines are hosted by different virtual machine hosts and / or isolated from each other via a firewall. This may enhance the isolation between tasks performed by the first submodule of the security interface / L3 level and tasks performed by the second submodule of the security interface / L2 level of the multilevel automation system, thereby ensuring that any malware or other security issues present at the L3 level are not likely to propagate to the typically more vulnerable L2 level and automation systems. For example, the only supported means of data exchange between L3-level components, L2-level components, and the machine of the automation system may be a data communication channel provided by a security interface, i.e., a one-way channel for verifying requests with control parameters and transferring them to the automation system, and a feedback channel for returning feedback information from the automation system to the client.
[0073] It must be noted that the first and second virtual machines can each be implemented as containers. By using different virtual machines that can be implemented in container form, it can be ensured that the L2 component (the only component that can control the machinery in the automation system) is strictly isolated from the outside and exchanges data only with the outside, and especially with L3 level components, through a defined, secure data exchange interface.
[0074] The security interfaces disclosed herein are also implemented as a DMZ or isolation area (sometimes referred to as a perimeter network or screen subnet). A DMZ is a physical or logical subnetwork that contains an organization's external services and exposes those services to untrusted (usually larger) networks such as the internet. This adds an additional layer of security to processes conducted within the security interface. External network nodes can only access what is exposed in the DMZ / security interface, while the remaining data and software programs running within the DMZ / security interface are protected behind a firewall. The DMZ functions as a small isolation network positioned between an external network, such as the internet, and the private internal network of IT resources. The implementation of a firewall, particularly a firewall between the security interface and the service interface, ensures that the security interface is a DMZ.
[0075] It must be noted that requests are generated by remote clients, such as human remote users, remote client devices, or client software, thereby connecting the remote clients to the system via a network, such as the Internet. Typically, the remote clients are located far from the manufacturing plant. The security interface is used as a remote control access route for remote clients to the automation system and the machines controlled by the automation system. This may have the advantage of providing a universal input point for many different remote clients, particularly users, and for integrating (existing) automation systems into new, typically more advanced control software via the security interface. The security interface provides a remote control access route to the automation system and the machines controlled by the automation system via the security interface.
[0076] Furthermore, it should be noted that one or more machines controlled by an automation system disclosing herein may include a local access interface for enabling a local user and / or local robot to directly control the machine via a second, for example, field-based communication channel. This can provide a high degree of flexibility, as both remote and local users may perform several control functions on their respective machines. In some examples, the access and control permissions for remote and local users may differ from each other. For example, only a (remote) expert user may be permitted to make changes to several control parameters that may affect many machines and processes in the automation system. On the other hand, only a local user may be permitted to initiate certain actions, such as opening and closing a door or starting a press, which may constitute a security risk if initiated only by a remote user who may not be aware of whether a moving part, such as a door or press, will hit a person or damage an object in its path.
[0077] The systems disclosed herein may further include a visualization engine configured to generate a graphic representation of a digital twin of the machinery in a plant and / or the products manufactured by the machinery. In some examples, the request is presented by a human remote user wearing virtual reality (VR) glasses operably coupled to the visualization engine. The visualization engine visualizes at least some aspects of the manufacturing process performed by the machinery via the VR glasses. For example, the visualization engine may enable the remote user wearing the VR glasses to view one or more machines that are currently being reconfigured and controlled. In addition or alternatively, the visualization engine may be configured to create an augmented reality for one or more local users working in the plant wearing augmented reality glasses, the augmented reality including avatars of the remote users and / or virtual graphic objects that assist in maintaining or controlling one or more of the machines. In addition, a robot working locally in the plant may be controlled by the remote user and function as a physical representation of the remote user. When the remote user turns in a given direction, the local robot follows this movement. A local robot may include one or more cameras, and images acquired by the robot's cameras are transmitted to a visualization engine, which then transfers them to the remote user's VR glasses. This allows the remote user to see, through the VR glasses, what the robot can see. This may improve security because it may enable the remote user to perceive objects in the spatial vicinity of one or more machines controlled by the remote user. This may enable the remote user to recognize any obstacles, other objects, or events that may indicate that certain control commands should not be presented because they pose a security risk to humans or components of the manufacturing plant, or that certain control commands should be presented to prevent a security risk. Control commands may be presented as requests to modify one or more control parameters of one or more machines in a plant machinery database.The visualization engine may also support voicemail and / or chat between a remote client, which is a human remote user, and a local user wearing AR glasses at the manufacturing plant. For example, the remote user may wear VR glasses, and the local user may wear AR glasses. Both VR glasses and AR glasses may include a microphone and an audio output interface, such as a speaker. The remote user and the local user may exchange voice messages in real time via the microphone and speaker of their respective VR glasses or AR glasses.
[0078] The aforementioned AR application may also be configured to control the volume of audio output generated by the local user's AR glasses so that the volume of the remote user's output audio is positively correlated with the local user's spatial proximity and the position of the remote user's avatar in the coordinate system used by the AR glasses to display virtual objects. In addition or alternatively, the VR application may be configured to control the volume of audio output generated by the remote user's VR glasses so that the volume of the local user's output audio is positively correlated with the remote user's spatial proximity and the position of the local user's avatar in the coordinate system used by the VR glasses to display virtual objects.
[0079] The system disclosed herein may further include a plant environment database and a database replication module. The plant machinery database includes model, location, and status information of machinery and / or products produced by the machinery. Location information may be continuously updated to reflect the actual location and status of machinery and / or products processed or produced by the machinery. The database replication module may be configured to continuously replicate only a predetermined subset of the data in the plant machinery database to the plant environment database, thereby filtering out sensitive machinery-related data. The plant machinery database may be configured to prevent access by the visualization engine. The visualization engine may be configured to use only the data contained in the plant environment database to generate a visual representation of the machinery and / or products processed by the machinery in the plant.
[0080] The use of two different databases as specified above may offer the advantage of enhanced security. The visualization engine continuously generates graphic representations of digital twins of machines and / or objects involved in automated production processes, thereby providing human users with a continuously updated overview of the process. Filtering functions ensure that sensitive machine-related data, such as precise location, sensitive status parameters, or control parameters, is not disclosed to the L3 layer or any other system outside the automated system. The database replication module simply replicates the information necessary to create a graphic representation of a machine or product, such as an identical or similar model of the machine's structure, or a highly abstract representation of the actions performed by the machine.
[0081] The graphic representation of a digital twin can be, for example, a conventional 2D representation of a machine and / or product generated for display via a computer screen or smartphone screen. In another example, the graphic representation is a 3D representation displayed via VR glasses or AR glasses, so that a 3D representation in a 3D coordinate system is provided.
[0082] In a further aspect, the present invention relates to the use of a system according to any one of the embodiments described herein for automating processes in a manufacturing plant.
[0083] In a further embodiment, the present invention is a method for automating a process in a manufacturing plant. - A system for process automation in a manufacturing plant, 〇 Multiple machines in the manufacturing plant, 〇 A database of plant machinery, including machine control parameters, ○ An automation system for automatically operating machinery in a manufacturing plant according to control parameters in a plant machinery database, 〇 Security interface and To provide a system that includes, - Receiving requests via the security interface, - Verifying requests through a security interface, - In response to a determination that the request is valid, the control parameters included in or derived from the request are stored in the plant machinery database via the security interface. - To automatically operate a machine by an automated system according to stored control parameters included in or derived from a valid request. This includes methods.
[0084] The automation systems disclosed herein may be configured to perform automated operation of a machine in accordance with stored control parameters included in or derived from an received request.
[0085] The combined use of AR and VR visualization technologies for the safe operation of industrial manufacturing processes, as presented above, can be beneficial as it can significantly improve operational safety. Equipment and processes are increasingly being remotely controlled. However, this poses significant safety risks, particularly in situations where industrial manufacturing processes are being controlled. Intentional or accidental input of inaccurate or inappropriate control parameters can lead to reduced product quality, high levels of waste, machine malfunctions, and, in the worst case, personal injury. Remote users often have limited knowledge of the processes currently underway within or within the machine. For example, a remote user might not notice that a container is nearly full and add more material, causing it to overflow. While the use of VR glasses improves the overall view, details of the digital twin of the machine displayed to the remote user via the VR glasses may be omitted. In addition, not all aspects crucial for assessing the overall situation, such as the presence of a person near the machine for maintenance purposes or the presence of hazardous materials near the machine, are fully captured by the factory's sensor system and displayed by the VR world visualization engine. However, local users typically have this view. Damage to products, machinery, and people can be prevented by providing a security interface that automatically prompts the local user from the remote user to approve all or at least all control commands that may require the highest level of safety before they are executed. Remote control of production processes has been greatly improved and made safer, especially with the help of VR glasses.
[0086] Remote users may be located in a different location from the plant, for example, in a different city or country. The visualization engine may be configured to create a VR world that includes one or more of the plant's machines or a visible digital twin of the entire plant. The digital twin may be a 2D or 3D representation of the machines and / or physical objects processed by the machines, such as a hologram, and may represent the current state of the plant. Typically, a visible digital twin is merely a coarse visual representation of real-world objects.
[0087] According to some embodiments, requests are generated by actions of a remote user, which are recognized as control commands by VR glasses worn by the remote user. For example, a visualization engine may display a virtual object in the form of a control panel adjacent to a visible digital twin representing one of the machines. The remote user may move a control handle and press buttons on the handle to select an item within the control panel. The selection of this item, such as a virtual button or menu element, may trigger the generation of a request to operate the machine represented by the visible digital twin. The request may indicate, for example, that the machine should start or stop operating, or that a door should be opened or closed.
[0088] According to the embodiment, the security interface generates an acceptance request only if it successfully verifies the request as valid. This may reduce the CPU capacity consumed by processing the request, as well as network traffic, because the creation of virtual objects (e.g., a window prompting the user to accept the requested action) and rendering objects in the metaverse typically require a considerable amount of CPU capacity. Furthermore, prompting the local user to accept a requested action that is inherently inappropriate or high-risk may unnecessarily distract the local user from their normal work.
[0089] According to one embodiment, the system includes an identity provider computer system configured to authenticate the user who submitted the request. If authentication fails, according to a further embodiment, the request is a request to operate a robot located in a plant. To that extent, if the user fails to authenticate as a client authorized to control one robot, the security interface does not store the control parameters in the plant machinery database and the request is rejected.
[0090] The systems disclosed herein may also include a VR system that enables one remote user to use a VR system and VR glasses to present requests and, only after successful authentication, enable the remote user to control at least one of the machines, such as a robot. This may have the advantage of providing a fully immersive metaverse that enables the remote user to both monitor and control an ongoing production process by using VR glasses and / or a controller or handle interoperable with the VR glasses to present requests to the automation system to operate one or more machines.
[0091] According to the embodiment, the visualization system is configured to generate a visual representation of a remote user in the form of an avatar and display the avatar to the local user via AR glasses worn by the local user. Preferably, the visualization engine also supports the exchange of voice and text messages between the remote user and the local user. This may have the advantage that the visualization engine provides the two users with options for communication if the local user needs more information to decide whether to accept the request. Thereafter, the local user may have the impression of talking to a real person, as the avatar is displayed as an overlay of the real-world plant environment via the AR glasses. The local user wearing the AR glasses can observe the VR user's avatar moving around the factory, and thus the VR user can cooperate with, support, direct and / or instruct the AR user about processes within the factory (e.g., production processes or maintenance processes).
[0092] According to the embodiment, the system includes an update engine, a visualization database, and a replication module, the visualization database containing a subset of data from a plant machinery database. The update engine is software configured to continuously receive spatial and / or status information of machinery and / or objects processed by machinery from multiple sensors during an ongoing manufacturing process, and to continuously update the plant machinery database using the received information. The replication module is software configured to continuously select data from the plant machinery database, enabling the generation of digital visual representations of one or more physical objects, the selected data not including control parameters. The replication module is further configured to replicate only the selected data to the visualization database, and the visualization engine is configured to generate digital visual representations of one or more physical objects as a function of the data in the visualization database. The visualization software is also configured to display visual representations of one or more physical objects to one or more users via a display device, enabling users to monitor the manufacturing process, and the plant machinery database is inaccessible to the visualization engine.
[0093] According to the embodiment, the automation system and plant machinery database are implemented at the process control level (L2), and the visualization engine is implemented at the operation control level (L3), thereby the security interface being the only interface that enables the transmission of control parameters from L3-level system components to L2-level system components.
[0094] With regard to the above-mentioned request verification, which includes validating the control parameters and / or authenticating the client that submitted the request in the ID provider computer system, the control parameters included in or derived from the request can be stored in the plant machinery database only if the remote user is successfully authenticated in the ID provider computer system and the control parameters are determined to be valid. This allows the control parameters included in or derived from the request to be mapped to further control parameters in the plant machinery database in order to expand the control parameters and perform further validation of the control parameters.
[0095] In a further embodiment, the present invention relates to a computer-aided method for process automation in a manufacturing plant, - It is a system, 〇 Multiple machines in the manufacturing plant, 〇 A database of plant machinery, including machine control parameters, ○ An automation system for automatically operating machinery in a manufacturing plant according to control parameters in a plant machinery database, 〇 User registry, • Multiple remote users not located within the manufacturing plant, and • Multiple local users located within the manufacturing plant User registry, including user profiles, A visualization engine configured to create augmented reality for local users and virtual reality for remote users, including a digital twin of the plant. 〇 Security interface and Including providing a system, The method is, - A step of receiving a request from one of the remote users via a security interface to operate at least one of the machines, - A step of causing the visualization engine to generate an acceptance request via a security interface, which is an acceptance request, a signal prompting one of the local users to accept at least one requested action of the machine via augmented reality glasses worn by one of the local users, - The steps include storing control parameters included in or derived from the received request in the plant machinery database via a security interface, only when a request is accepted by a single local user. This includes methods.
[0096] A system for monitoring a manufacturing plant can be implemented as part of a system for automating the processes of the manufacturing plant, and vice versa. Modules and software architecture elements describing examples and embodiments of systems for monitoring a manufacturing plant can be freely combined with modules and software architecture elements describing examples and embodiments of systems for automating the processes of a manufacturing plant, and vice versa.
[0097] As used herein, “interface” refers to a software and / or hardware-based boundary where two or more distinct components of a data processing system exchange information across those boundaries.
[0098] As used herein, a "service interface" is an interface through which two or more clients exchange information with a system in order to automate processes in a manufacturing plant. In particular, a client can be a remote client connected to the service interface via a network such as the Internet. A client can be a user, a client device, a client software program, an edge computer system, or a combination of these.
[0099] As used herein, "security interface" refers to an interface through which requests, particularly requests to change the configuration of machinery in a manufacturing plant, are transmitted to an automated system.
[0100] As used herein, “machinery” refers to any physical entity involved in the manufacture and / or processing of products produced by a plant. For example, machine can be a single piece of equipment powered by electrical energy, mechanical energy, thermal energy, chemical energy, or other forms of energy to perform one or more operations. Machine can also be a device or device component, equipment, robotic arm, conveyor belt, robot, extruder, tumbler, oven, or any other type of physical component capable of performing one or more operations in a manufacturing workflow. The nature and location of machine within a plant may depend on the type of product being manufactured.
[0101] As used herein, “system for process automation” is a distributed network system that includes an automation system comprising multiple machines in one or more plants and one or more further system components, such as L3 and / or L4 components of a process automation pyramid, for automatically controlling the operation of the machines in each of the multiple plants so that a workflow is performed. The system is used and / or configured for process automation, in particular for process automation in one or more manufacturing plants.
[0102] As used herein, an "automation system," also referred to as a "process automation system (PAS)," is a system used to automatically control processes in plants such as chemical plants, oil refineries, and pulp and paper mills. A PAS often uses a network to interconnect sensors, controllers, operator terminals, and actuators. While a PAS as used herein may be based on open standards, a PAS may also be based on and / or include proprietary standards, in which case it is also known as a DCS (distributed control system). An automation system may be associated with a SCADA system. An automation system may use established, and possibly plant-specific, protocols or technologies. According to embodiments, an automation system includes one or more machines in the plant, a PLC (process logic control) interface and / or a PCS (process control system) interface for the machines. Optionally, an automation system may also include a plant machinery database containing control parameters for the machines.
[0103] As used herein, the terms “L3 level” or “L3 IT infrastructure system” refer to IT system components included in the manufacturing operation level. While this level is referred to as “L3” or “Level 3” in the Purdue model of multilevel automation systems, the terms “L3 level” or “L3 IT infrastructure system” are also used herein to refer to IT system components included in the manufacturing operation level, and may be referred to differently in other models of multilevel automation systems. L3 components perform a higher level of control functions than the core process control system.
[0104] As used herein, the terms “L2 level” or “L2 IT infrastructure system” refer to the IT system components included in the core process control level. This level is referred to as “L2” or “Level 2” in the Purdue model of multilevel automation systems, but the terms “L2 level” or “L2 IT infrastructure system” are also used herein to refer to the IT system components included in the core process control level, which may be referred to differently in other models of multilevel automation systems.
[0105] As used herein, “database” refers to any data structure that enables the temporary or permanent storage of data. For example, a database may be a data storage device managed by a database management system (DBMS), a file directory, a set of one or more files, or a single file such as a spreadsheet. A database may also be a data structure adapted to store data in a digital format, such as an electronic or optical storage medium.
[0106] As used herein, "plant machinery database" is a database containing data relating to one or more machines in a manufacturing plant. For example, the database may include control parameters for one or more machines, and / or data describing one or more machines, such as machine models, machine status data, machine configuration data, and / or other machine-related data that enables the generation of a digital twin of a machine and / or data that enables the simulation of machine operation or measurement data obtained by one of the machines. The plant machinery database may also include location and / or status information of objects processed or produced by the plant's machines, such as extracts or products.
[0107] As used herein, “metaverse” is a virtual representation of a portion of the world, preferably customized to be viewed through virtual reality glasses and / or augmented reality glasses. The metaverse can be implemented as a spatially fused network of 3D virtual worlds, such as a 3D world that is a digital twin of a plant and its machinery, as well as 3D worlds of one or more remote and / or local users wearing VR glasses and AR glasses.
[0108] As used herein, “digital twin” is a digital representation of a physical object or process in the real world that serves as a digital counterpart for practical purposes such as visualization, simulation, integration, testing, monitoring, or maintenance.
[0109] As used herein, the term "plant," also referred to as "factory" or "manufacturing plant," is an industrial facility, often a complex of several machine-filled buildings where workers and / or machines manufacture goods or process each item into another. A manufacturing plant may, for example, be a plant for producing vehicles or vehicle parts, a plant for producing electronic consumer goods, or a plant for synthesizing or processing chemical substances.
[0110] As used herein, "plant environment database" refers to a database containing data relating to a plant or its environment. The plant environment database may, for example, include a copy of some of the data in a plant machinery database. Preferably, highly sensitive machinery-related data (e.g., status parameters, location, configuration parameters, etc.) is not included in the plant environment database.
[0111] According to some examples, some of the data in the plant machinery database, which is included in the plant environment database, includes data used during validation checks performed by the L3 submodule of the security interface. This data may include, for example, validation criteria, thresholds, and reference parameter values that relate to the plant or its environment but not to individual machines. For example, the data may include acceptable energy price thresholds, weather data, information on ongoing manufacturing processes at other plants and their respective demands, and quality indicators required by different customers for the products being manufactured.
[0112] In addition to, or instead of, the data used for requirement verification, a portion of the data in the plant machinery database included in the plant environment database includes data that enables the visualization engine to generate digital visual representations of one or more machines included in the plant machinery database and / or to generate digital visual representations of objects processed or generated by said machines.
[0113] As used herein, “visualization database” is a database containing data that enables software, such as a visualization engine, to generate digital visual representations of one or more physical objects. For example, a visualization database may include 2D or 3D models of physical objects, such as realistic or simplified images or holograms of objects. A visualization database may also include spatial information about objects, such as their orientation or their position in a virtual coordinate system. Preferably, a visualization database does not include a representation of the precise geographical location of an object. For example, a visualization database may include digital models and / or generic status information of one or more machines whose control data is included in a plant machinery database, and / or digital models and / or generic status information of objects processed or produced by such machines.
[0114] According to some exemplary embodiments, a plant environment database is used as a visualization database, and vice versa.
[0115] As used herein, “edge computer system” refers to a computer system installed in spatial proximity to machinery in a plant and configured to process data generated by the machinery in the plant. This data may include, in particular, real-time data. Despite its spatial proximity, in some examples, an edge computer system is not part of the plant's automation system. For example, an edge computer system may not be part of the L1, L2, or L3 levels of the plant's multi-level automation architecture. An edge computer system may be configured to continuously receive, store, and evaluate data provided by machinery during the manufacturing process, such as machine status data, product status data, process parameter values, and product characteristics. Due to its spatial proximity to the data source, the edge computer system may be able to respond very quickly with very short latency to events occurring during the manufacturing process. However, for security reasons and due to the lack of suitable interfaces, integrating edge computing systems into process automation systems has historically been impossible. By enabling the edge computer system to generate and present requests to control one or more machines to a security interface, embodiments of the present invention may enable the integration of an edge computer system into a system for automated process control. For example, an edge computer system may be configured to continuously analyze status information received from one or more machines in a plant and, when it determines that an undesirable event has occurred or is expected to occur during the production workflow, present a request to the security interface, which includes control parameters adapted to prevent or mitigate the impact of the undesirable event. Undesirable events may include, for example, a shortage of consumables, congestion of products on a conveyor belt, or a machine temperature exceeding a threshold.
[0116] As used herein, “control parameters” are parameters that affect the state of a machine and / or how the machine operates. For example, control parameters may be configuration parameters, function arguments for calling the machine’s PLC interface, commands, or a combination of two or more of the above.
[0117] As used herein, a “request” is a message transmitted between objects. For example, a request may be sent from a client to a system for process automation over a network. The request may then be processed by multiple interfaces, optionally modified or supplemented, and transmitted until it reaches its destination or until the transfer of the request is rejected.
[0118] As used herein, “visualization engine” is monolithic or distributed software configured to generate visual representations of physical objects. These visual representations may be, for example, 2D representations displayed via a computer or smartphone screen, and / or 2D or 3D representations displayed via VR glasses and / or AR glasses. In the latter case, the visualization engine, sometimes referred to as a “metaverse engine,” interoperates with an AR application to cause the AR glasses controlled by the AR application to display virtual object representations to the user wearing the AR glasses. In addition or alternatively, the visualization engine is configured to interoperate with a VR application to cause the VR glasses controlled by the VR application to display streamed status information to the user wearing the VR glasses. When the visualization engine is coupled to operate on multiple users wearing AR glasses, VR glasses, or a combination of VR and AR glasses via one or more AR and / or VR applications, the visualization engine may be configured to align virtual objects (the properties, dimensions, orientation, and position of the virtual objects) with the coordinate systems used by the VR and AR glasses in order to display the virtual objects. As a result of this overall alignment of virtual objects, multiple users wearing VR and / or AR glasses may at least partially share a common virtual object world that may include digital twins of multiple machines in the plant, digital twins of one or more production lines in the plant, and / or digital twins of users working for or within the plant.
[0119] As used herein, “client” refers to a single computer hardware or software that accesses a service made available by a server over a computer network, thereby accessing the service, in particular, as part of a client-server model of the computer network. The server is often (but not always) on another computer system, in which case the client accesses the service over a network, such as the Internet. Since client software can be software that translates user actions into requests and other actions of the client software, the term client may also refer to a user who uses a single piece of hardware or software to access a service over a network. The term “client” may also apply to a computer or device running client software.
[0120] For example, a client can be a computer program that, as part of its operation, relies on sending requests to another program or computer hardware or software that accesses services made available by a server (which may or may not be located on another computer). For example, a web browser can be used as a client to connect to a web server and search for web pages for display.
[0121] As used herein, the term “computer system” refers to a machine or set of machines that can be instructed by computer programming to automatically perform a sequence of arithmetic or logical operations. Modern computers have the ability to follow a generalized set of operations called “programs,” “software programs,” or “software applications.” These programs enable computers to perform a variety of tasks. According to some embodiments, a computer system includes hardware (in particular, one or more CPUs and memory), an operating system (main software), and additional software programs and / or peripherals. A computer system can also be a group of computers connected and working together, in particular a computer network or computer cluster, such as a cloud computing system. Thus, as used herein, “computer system” can refer to a monolithic standard computer system, such as a single server computer, or a network of computers, such as a cloud computing system. In other words, one or more computerized devices, computer systems, controllers, or processors can be programmed and / or configured to operate as described herein in order to perform different embodiments of the present invention.
[0122] The embodiments and examples described herein should be understood as illustrative examples of the present invention. Further embodiments of the present invention are conceivable. While the present invention has been described as an example of specific combinations and distributions of software programs and computer systems, it should be understood that any feature described in any one embodiment may be used alone or in combination with other features described, and may be used in combination with one or more features of any other embodiment of the embodiment, or in any combination of any other embodiment of the embodiment, unless the features are mutually exclusive.
[0123] Therefore, some embodiments of this application are for computer program products. Other embodiments of this application include corresponding computer implementation methods and software programs for carrying out any of the steps and operations of the method embodiments summarized above and disclosed in detail below.
[0124] Any software program described herein may be implemented as a single software application or as a distributed multi-module software application. One or more software programs described herein may be carried by one or more carriers. Carriers may, among many other examples, be signals, communication channels, non-transient media, or computer-readable media. Computer-readable media may be tapes, disks, such as CDs or DVDs, hard disks, electronic memory, or any other suitable data storage medium. Electronic memory may be ROM, RAM, flash memory, or any other suitable electronic memory device, whether volatile or non-volatile.
[0125] Each of the various features, technologies, and configurations described herein can be implemented individually or in combination, using a single software process or a combination of processes, for example, in a client / server configuration.
[0126] It should be understood that embodiments of computer systems and / or computer implementations described herein can be implemented strictly as software programs or applications, as software and hardware, or as standalone hardware such as within a processor, an operating system, or a software application.
[0127] The operation of the flowchart will be explained with reference to the system / device shown in the block diagram. However, it should be understood that the operation of the flowchart can be performed by embodiments of systems and devices other than those described with reference to the block diagram, and that embodiments described with reference to the system / device may perform different operations than those described with reference to the flowchart.
[0128] Brief explanation of the drawing The following embodiments of the present invention will be described in more detail as mere examples with reference to the drawings. [Brief explanation of the drawing]
[0129] [Figure 1] This shows a high-level block diagram of a system for process automation. [Figure 2] A block diagram of the further system for process automation is shown. [Figure 3] A system block diagram is shown for reliable visualization of the components of the automation system. [Figure 4A] This shows an example of a GUI that allows local users to monitor the status of manufacturing process steps. [Figure 4B] Here is another example showing a GUI that allows local users to monitor the status of manufacturing process steps. [Figure 5] This illustrates a distributed system for controlling manufacturing processes across multiple plants. [Figure 6] This describes a system configured to display various virtual objects to the "operator" user. [Figure 7] This describes a system configured to display various virtual objects to a "maintenance worker" user. [Figure 8] This displays the avatar of the remote user. [Figure 9] This shows the coordinate system used to represent real-world machines and local user avatars in the virtual metaverse for remote control. [Figure 10]This is a flowchart illustrating a method for enabling secure remote control of automated manufacturing processes. [Modes for carrying out the invention]
[0130] Detailed explanation Figure 1 shows a block diagram of System 100 for process automation of a manufacturing plant. The plant could be, for example, a plant for synthesizing chemical compositions, or a plant for manufacturing vehicles, computers, or consumer goods, furniture, or food.
[0131] The plant comprises several machines 140 used to manufacture and / or process one or more physical objects. The type of machine is determined by the type of product to be manufactured and / or by the machine manufacturer selected by the plant owner. For example, the machines may be electronic devices, jigs, robotic arms, conveyor belts, robots, extruders, tumblers, ovens, etc.
[0132] The system further includes a plant machinery database128, which may be part of the plant's L2 level IT infrastructure. For example, the machinery database can be a directory of files, a single file, a combination of files, a database managed by a database management system (DBMS) or graph database (GDB) such as Neo4J, or a combination thereof.
[0133] The plant machinery database 128 includes control parameters, such as configuration parameters of machines and / or processed digital objects, location information and / or structural or functional models, and / or data for generating digital twins of one or more machines 140 of a manufacturing plant and / or physical objects processed within the plant. For example, control parameters include the temperature of a reaction vessel for a chemical reaction, the temperature of an oven, the rotational speed of a stirrer, the speed of a pump, the pressure in a pressurized gas tank, the amount of a specific substance added to the reaction vessel, a desired pH value in the reaction vessel, and a desired CO2 level in the gas tank. 2 This could be concentration, etc. Control parameters may include target parameter values, i.e., parameter values that indicate the state of the machine to be achieved or the state of the product to be manufactured. Data for generating a digital twin may include, for example, continuously updated location information of machines and / or physical objects, digital 2D or 3D models of each of the multiple machines in the plant, and may further include data showing the dynamic behavior of the machine as a function of environmental parameters, control parameters, or other parameters.
[0134] System 100 includes an automation system 102 for automatically operating the machinery 140 of the manufacturing plant according to control parameters in a plant machinery database. For example, the automation system may include one or more programmable logic controllers (PLCs) 125 configured to control one or more manufacturing processes performed by the machinery 140 of the plant. The security interface may be configured to directly control one or more of the machinery or to control one or more of the machinery via the PLC / PCS interface 125.
[0135] A PLC can execute a program periodically. In each cycle, the program may read current measurement parameters provided by the machine and one or more control parameters stored in the plant machinery database 128 as inputs, process the inputs, and write output parameters. These output parameters are transmitted to one or more machines to control the actions performed by the machines. Thus, these output parameters, and also the control parameters on which the output parameters depend, can function as control commands to determine the behavior of the machines and, consequently, the manufacturing process. Typically, it takes tens of milliseconds for the processor of an automation system to evaluate all instructions and update the status of all outputs. For example, SIMATIC S7 can be used as a PLC in an automation system.
[0136] System 100 further includes system components at manufacturing operation level (level 3 in the Purdue model) 104, hereinafter referred to as "L3 components." The L3 components perform control functions at a higher level than those of the core process control system (level 2 in the Purdue model, hereinafter referred to as "L2 components"). For example, at least some of the control functions performed by the L3 components may be machine-independent. The L3 system components are preferably hosted on one or more monolithic or distributed computer systems 104 that operate independently of the L2 system components 102.
[0137] System 100 includes a security interface 142 which comprises a first submodule 122 that is part of the L3 level IT infrastructure and a second submodule 124 that is part of the L2 level IT infrastructure of System 100. Both submodules perform different parts of the request verification process.
[0138] The security interface 142 is configured to receive requests from one or more clients 106, 107, 108, 110, such as requests to manufacture a specific product and / or to modify the production of a product. Clients can be portable clients, such as smartphones, notebooks, or VR glasses, or stationary clients, such as desktop computer systems or edge computer systems.
[0139] For example, the edge computer system 110 may be a computer system located in close proximity to one or more of the plant's machines 140, but may not be fully integrated into the IT environment of system 110. The edge computer system may be configured to collect log data and / or status data from one or more machines 140 during an ongoing manufacturing process, analyze the data, and automatically determine control parameter values (e.g., temperature, amount of added substance, pH value, etc.) that are deemed suitable for improving the automated manufacturing process and / or the quality of the produced product. When determining these control parameters, the edge computer system creates and presents a request to transfer the control parameters to the machine 140 via a security interface.
[0140] The client computer system 106 may be any type of computer system, such as a desktop computer, laptop, tablet computer, notebook, or mobile phone.
[0141] Client 108 may be a remote user wearing VR glasses. The remote user may use the VR glasses to monitor one or more machines during the manufacturing process or maintenance period. The remote user may use the VR glasses to specify and present requests, including their respective control commands, to the security interface. Instead of implementing advanced IT equipment such as VR glasses at core process control (L2), embodiments of the present invention may enable restricting direct control of such machines to the L2 level and provide a secure option for remote clients to securely transfer control information to machines via an access-protected one-way security interface 142.
[0142] The advanced process control client 107 can be a client containing advanced process control software for integrating the requirements, demands, and available resources of one or more plants. The advanced process control client 107 can integrate multiple distributed, heterogeneous plants. The advanced process control software is used to direct process operation and includes model-based software commonly referred to as multivariable predictive control (MPC) or model predictive control. In these applications, the created process model must accurately represent the dynamic characteristics of the process.
[0143] The security interface is configured to receive client requests. Preferably, requests are received not directly from the client, but via one or more service interfaces as shown in Figure 2. Requests are validated by the security module. If the security module determines that a request is valid, it stores the control parameters included in the request or derived from the request in the plant machinery database 128 (e.g., during the mapping and / or normalization process). If the request validation returns that the request is invalid, the control parameters are not stored in the plant machinery database.
[0144] Optionally, the security interface returns a response message to the entity that presented the request indicating that the request was not performed. Preferably, the security interface prompts the local operator 146 or software application to authorize the storage of verified control parameters and / or the machine operation triggered by the control parameters, thereby storing the control parameters in the database 128 only when an acceptance message is received by the security interface.
[0145] The automation system is configured to repeatedly read control parameters stored in the plant machinery database and control the operation of the machinery as a function of the currently stored control parameters. At least some aspects of the manufacturing process can be continuously monitored by a remote operator 108 via VR glasses and a visualization engine 134.
[0146] Figure 2 shows a system 200 for process automation according to a further embodiment. System 200 includes components and subsystems already described with reference to Figure 1.
[0147] As shown in the illustrated example, each submodule 122, 124 of the security interface 142 includes task engines 144, 141. Task engine 144 is configured to process incoming requests by applying a configurable rule set 132. The rules 132 may include rules relating not to specific characteristics of machine 140, but rather to more general parameters, such as requirements or settings provided by a client (e.g., a customer), cost-related criteria parameters and thresholds, required product characteristics, extract availability, and environmental parameters such as ambient temperature. For example, a proprietary or open-source solution such as Node.js or Drools can be used to run the task engine.
[0148] Task engines 144 and 141 can run as event processing software having a low / no-code interface, such as a GUI 133 or 123, that allows users to create and maintain rules 132 and 137 without requiring programming skills. The rule set representation may enable task engines 144 and 141 to check inbound requests, particularly whether the inbound requests are valid. This allows rule 132 to perform machine-independent checks, while at least some of rule 137 may perform machine-specific checks, for example, checking whether control parameters, such as temperature or rotational speed values, are supported by and safe for the machine that should operate according to these control parameters. Executing rules by a task engine may involve comparing control parameters included in or derived from a request with reference values, a history of each control parameter previously used by each machine, a predetermined syntax, or a predetermined fixed or dynamic range.
[0149] The reference values and thresholds used by the first security interface submodule 120 to verify the request are stored in the plant environment database 130 and can be read from the plant environment database 130, and the reference values and thresholds used by the second security interface module 124 are stored in the plant machinery database 128 and can be read from the plant machinery database 128.
[0150] In addition to, or instead of, the task engines 144 and 141 trained machine learning models, such as neural networks, to check control parameters. For example, a trained machine learning model might have been trained on a training dataset containing at least some of the control parameter values previously used to operate a machine, and it might have learned to correlate these control parameter values with information about product characteristics and / or manufacturing process safety.
[0151] According to some examples, a security interface submodule 122 contains a first function (F1', F2'), and a second submodule 124 contains a second function F1, F2, thereby the structure of the first and second functions (i.e., the number and type of input and output arguments) is continuously synchronized between the first and second submodules so that any change in the structure of the second function (F1, F2) in the second submodule 124 is propagated to the first function F1', F2' in submodule 122. The names and / or structures of the second functions F1, F2 may reflect the names and structures of the respective functions of the PLC / PCS interface 125 that directly control one or more of the machine 140. A client request may be or include a call to one or more of the functions. Since the client can only trigger the execution of a function after successful authentication and request verification, and because only a subset of the functions of the PLC / PCS interface 125 are accessible by the security interface functions F1, F2 / F1', F2', automatically synchronizing the function structures may have the advantage of making calls to PLC / PCS interface functions transparent to the client without giving the client direct, unrestricted access to interface 125. By synchronizing the structure of functions F1 and F2 of the second submodule 124 with the structure of functions F1' and F2' of the first submodule 122 of the security interface 142, or with the respective functions of multiple first security interface submodules of multiple different L3 level IT infrastructure systems, it may be possible to transparently integrate an L2 level IT infrastructure into two or more different L3 level IT systems. Thus, functions F1 and F2 can similarly be used and called by two or more different security interface submodules 122 and their respective L3 level IT systems.
[0152] Any request to control and / or reconfigure the machine, submitted by a remote user 108 or another client, is not submitted directly to the security interface 124, but rather via a service interface 120, which may be part of the system's L3 level IT infrastructure. For example, the service interface 120 may include customized web service interfaces for each of several different client types, such as an edge computer system 110, a remote user submitting a request using VR glasses and / or a VR application, or a customer client application attempting to order a particular product and initiate its production. Each of these services may be accessible via a REST API (representational state transfer application interface). The use of a REST API can ensure the system's flexibility and scalability. The REST API can protect the security interface from untrusted clients, implement client authentication procedures, and enforce that only requests from authorized clients are forwarded to the security interface.
[0153] Upon successful request verification by the first submodule 122, the first submodule or the task engine contained within the first submodule may transfer the request or control parameters contained in or derived from the request to the second submodule 124 by calling one of the functions F1, F2 of the second submodule via the service interface 121.
[0154] As shown in the illustrated example, both service interfaces 120 and 121 may be implemented as web services using an industry-standard web server, thereby exposing the first functions F1' and F2' via the REST API of interface 120, and thereby exposing the functions F1 and F2 via the REST API of interface 121.
[0155] The system includes multiple firewalls 114, 116 that protect the automation system 103 and the security interface and other components from unauthorized access. An attacker attempting to modify the plant machinery database would have to overcome multiple firewalls. Each firewall functions as a network security system, monitoring and controlling incoming and outgoing network traffic based on predetermined security rules. This establishes a barrier between trusted networks or subsystems and untrusted networks or subsystems.
[0156] Some embodiments may include a log database, and the security interface 142 may be configured to record the results of all requests and request validations in the log database. This can facilitate error analysis and fraud detection. In some examples, the plant environment database 130 is used as the log database.
[0157] According to some examples, the system, for example, the system's L3 level IT infrastructure, may include a visualization engine 134 configured to allow a remote user 108 to present requests to a security interface via VR glasses. The visualization engine may support collaboration between the remote user 108 and one or more local operators 146 working within the plant via shared virtual reality (remote user) or augmented reality (local user, not shown). For example, the visualization engine 134 may be operably coupled to a database 130 containing data objects that are digital twins of plant objects, particularly machine 140. The database may also include objects that are digital representations of the remote user 108, particularly avatars, so that the coordinate systems of these objects in the database 130 are continuously updated with the current positions of each object and user, and the positions of these objects and users in a shared metaverse coordinate system are continuously mapped to the plant's real-world coordinate system.
[0158] The system may further include an identity provider 135, such as an enterprise identity provider like Active Directory, Azure AD, or any LDAP service. Any client can be authenticated by identity provider 135. Depending on the requesting system, authentication can use a personal ID or a functional ID / machine ID. The service interface 120 may support different authentication workflows for different types of clients. Similarly, company authentication standards can be applied to systems and authentication processes, such as single-factor or multi-factor authentication, authentication information, certificates, etc. Identity provider 135 may be configured to check the authorization of the requesting client based on the client's group and group membership.
[0159] In some embodiments, the security interface 142 does not directly store the control parameters provided in the validated request in the plant machinery database. Rather, the security interface calls the database service interface, which stores the control parameters in the plant machinery database. The plant machinery database may be configured to allow write access only to the database service interface and optionally to some further trusted entities. This further enhances security and can protect the automated system from unauthorized operation.
[0160] As can be inferred from Figure 2, system 100 implements a one-way and highly secure communication channel for transferring control parameters contained in requests from clients 108, 106, and 110 to the machinery in the plant. The requests and / or control parameters must successfully pass multiple firewalls, request verification steps, and additional security checks such as authentication at the service interface 120 via the ID provider 135 before the parameters are finally stored in the database 128 so that the parameters are accessible to the machinery.
[0161] The system, particularly the L3 level IT infrastructure of the system, may include a communication module, which may include a key manager module. The communication module may establish an encrypted one-way communication channel between the service interface 120 and the security interface 142. The communication module may also establish encrypted communication channels between the service interface and a first submodule of the security interface, and between the first submodule of the security interface and a second submodule. For example, as used herein, an encrypted communication channel may mean that only the first submodule of the security interface is permitted to receive data from and access the service interface 120. In some embodiments, the communication module may further include a user registry, user-specific keys, and other user-related data. The user registry may include registered local users, registered remote users, and other clients.
[0162] According to some embodiments, the system 100 includes a feedback channel 143 separate from the communication channel used to transfer control parameters to the plant machinery database. For example, the first and second submodules of the security interface may each include a function to report whether a processed request was accepted or rejected. Preferably, the reason for rejection (e.g., authentication failure, invalid control parameters, etc.) and / or machine status information are not communicated to the client.
[0163] According to some embodiments, a first submodule of the security interface, and optionally further components of the system's L3 IT infrastructure, and a second submodule of the security interface, and optionally further components of the IT infrastructure system at the L2 level, are instantiated within different virtual machines running on different virtual machine hosts. The virtual machines may be containers, for example, Docker containers running on different container management systems. This can improve the security and robustness of the system because the sensitive L2 layer is isolated and protected from the L3 level and from untrusted entities that have successfully infiltrated the L3 level.
[0164] According to a preferred embodiment, the system is configured to process requests using a predetermined set of processing steps, and the system accepts requests from untrusted sources such as remote clients 106, 107, 108, and 110.
[0165] First, the client submitting the request must successfully authenticate at the service interface 120 by providing the identity provider 135 with one or more certificates, such as a signed certificate, a secret shared with the security interface, biometric data, a password, whitelist presence, or a combination thereof. Only if the client has authenticated itself as a trusted entity with the identity provider does the service interface forward the request to the security interface, in this case to the first submodule 122 of the security interface 142. According to the embodiment, authentication of the entity at the service interface includes checking the integrity of the request, such as signature verification or checksum verification.
[0166] The security interface, in this case the security interface submodule 122, verifies the request by performing various validity and / or safety checks of the control parameters included in the request, thereby, preferably, based on global rules rather than machine-specific (machine-independent) rules. For example, some rules may analyze whether the control parameters are acceptable considering current weather conditions such as ambient temperature or humidity. Request verification may include checking whether the parameter values of a given control parameter are specified with the correct data type (e.g., integer, string, boolean, etc.). Verification may include checking whether requests to modify a particular control parameter have been received at a maximum permissible frequency or less, for example, to protect the system from a denial-of-service attack. Only if the verification returns that the request is valid (the control parameter is valid and safe), submodule 122 forwards the control parameter to the automated system-side submodule 124 of the security interface 142. In addition or alternatively, the security interface may check whether this request, in combination with a predetermined number of previously received requests, modifies a particular control parameter and, as a result, exceeds a maximum permissible variation threshold. If the variation is too large, this may indicate that the entity submitting the request is not familiar with each machine, or that multiple users are trying to move the manufacturing process in different directions.
[0167] According to some embodiments, request verification by the security interface also includes checking whether the client submitting the request has the necessary permissions to modify a particular control parameter. For example, if remote user 148 is not authorized to modify the temperature of a particular tank, the user's request to modify the temperature of this tank is deemed invalid. In addition or alternatively, the verification request may include a simulation of the future state of one or more machines affected by the change in the control parameter. If the simulated future state is associated with a violation of constraints, such as a low-quality product or a production process considered unsafe, the request is deemed invalid.
[0168] Submodule 124 verifies the transferred control parameters, for example, by performing various further validity and / or safety checks, thereby including, preferably, machine-specific and / or plant-specific rules. Only if the verification returns that the request is valid (the control parameters are valid and safe), submodule 124 transfers the control parameters to a database service interface configured to store the control parameters included in the request in the plant machinery database 128.
[0169] According to the embodiment, the requirement verification performed by the security interface may be used to determine whether the control parameters specified in the requirement are reasonable, achievable, acceptable, and safe for the plant and its machinery. The verification is accompanied by the security interface having at least rough knowledge of the processes performed by the machinery during the manufacturing process. For example, if the requirement specifies a requirement to lower the temperature of a reaction tank by 10°K, the security interface must check how this change will affect the specific machinery and control signals, and whether the safety parameter range will be exceeded as a result of the temperature reduction.
[0170] According to some embodiments, the security interface is further configured to perform mapping of control parameters specified in the request. In particular, if the security interface is a distributed security interface, the control system unit of the security interface can perform the mapping process. During mapping, the security interface determines how changes in specified parameters affect other control signal thresholds and machine settings, which can also be represented and controlled by their respective control parameters in the plant machinery database. For example, to achieve a 10°K temperature drop in a tank, it may be necessary to decrease the activity of heating elements and / or increase the activity of cooling elements. It may also be necessary to increase the stirring speed to compensate for an increase in the viscosity of the fluid contained in the tank. During mapping, one or more further control parameters are determined, the values of which depend on the value of one of the control parameters specified in the request. Also, parameter values of further control parameters (e.g., desired stirring speed, cooling speed, and / or heating intensity) are determined after the value of one control parameter has been changed.
[0171] Preferably, any additional control parameters identified during the mapping step are also validated, i.e., checked to see if they are achievable, reasonable, and / or safe. If the mapped parameters fail validation, the entire request may be rejected, and the control parameters in the request are not stored in the database 128.
[0172] After the control parameters are successfully validated and mapped, and the mapped parameters are successfully validated, the mapped parameters are transferred along with the control parameters originally included in the request to the database service interface 126, and are finally stored in the plant machinery database 128.
[0173] After the mapping step is completed, the control parameters in the request and any additional control parameters identified during the mapping are stored in the plant machinery database.
[0174] In a preferred embodiment, the security interface is configured to generate an acceptance request after the acceptance request has been successfully validated. The acceptance request is a request configured to prompt a user 146 working locally at the plant or software included in the security interface (not shown) to accept a requested change to one or more control parameters stored in the plant machinery database. For example, the acceptance request may be displayed to the local user 146 via a local operation user interface, such as a display included in or coupled to one of the plant's machines 140, or may be output in other ways. An acceptance check may be the final step in request validation performed by the security interface. For example, if the security interface is a distributed interface, the acceptance check may be performed by a security interface submodule 124. The local user / software sends an acceptance message to the security module only if the local user 146 or software included in the security interface accepts the proposed control parameter setting. The request is considered successfully validated (valid) only if the local user or software accepts the proposed change. Otherwise, the request is considered invalid, and the control parameters included in the request are not stored. For example, a request from a remote user 108 to lower the temperature inside a reaction tank may trigger the creation of an acceptance request displayed to the local operator 146 via the reaction tank's display. The local operator may have a better understanding of the overall manufacturing process and / or critical status parameters of the tank than the remote user. For added safety, the local operator 146 must confirm the new control parameters, for example, by clicking the "OK" button displayed on screen 125. If the operator does not accept the proposed parameter change, the safety interface does not transfer the control parameters to the machinery database 126.For example, the security interface may determine that a request is invalid if it does not receive an acknowledgment message from the local operator 146 within a predetermined timeout interval.
[0175] If a valid request is confirmed by local user 146, the security interface submodule stores the respective control parameters in the plant machinery database.
[0176] In other embodiments, the security interface may not be implemented as a multi-module distributed system, but may be entirely part of the L2 or L3 level IT infrastructure (and their respective virtual machines).
[0177] Figure 3 shows a block diagram of a system 300 for monitoring a manufacturing plant. The system includes an automation system 103 which includes several machines 140 in the manufacturing plant and a plant machinery database 128. The plant machinery database includes machine control parameters and spatial and / or status information of physical objects (machines and / or objects processed by machines).
[0178] The automation system is configured to automatically operate machinery according to control parameters in a plant machinery database. For example, the automation system may include a PLC and / or PCS interface 125 to allow local operators and / or safety interfaces 142 to operate machinery through these interfaces 142.
[0179] The system further includes an update engine 160, which is software configured to continuously receive spatial and / or status information of physical objects from a plurality of sensors 162 during the ongoing manufacturing process (e.g., at least once per hour, or at least once per minute, or at least once per second) and to update the machinery database 128 using the received information. For example, the sensors may include temperature sensors, humidity sensors, pH meters, and internal machine sensors configured to determine the operating state or mode of a machine (e.g., the rotational speed of a centrifuge or agitator, the speed of a conveyor belt, the open / closed state of doors and other openings).
[0180] The system further includes a visualization database 130 containing a subset of data from the plant machinery database.
[0181] System 300 further includes a replication module 150. The replication module is software configured to continuously select data from the plant machinery database data (for example, at least once per hour, or at least once per minute, or at least once per second) that enables the generation of digital visual representations of one or more physical objects, thereby replicating only the selected data, without control parameters, into the visualization database. Thus, the replication module can be considered to filter the data contents of the plant machinery database so that only a selected subset of the data is replicated into the visualization database 130. For example, the visualization database may include 2D or 3D models of machines and / or objects processed by the machines. The models may be static models or dynamic models that can be used to visualize the state of the machines or the state of the manufacturing workflow. In addition, the visualization database may include spatial information of objects, such as the current orientation of robots and other machines or machine parts, and the location of extracts or products in a production line. Preferably, the spatial information does not include information that enables the identification of the precise geographical location of each physical object. The 2D or 3D models of at least some of the machines are not scaled to actual size and / or represent a coarse-grained abstraction of the machines. This may allow for the protection of the structural design of the machines and other sensitive information, such as know-how regarding the total / maximum production capacity of the plant, machines, or production lines.
[0182] The system further compresses the visualization engine 134. The visualization engine is a software program, for example, a monolithic software application or a set of interoperable software programs configured to generate digital visual representations of one or more physical objects as a function of data in a visualization database. Preferably, the visualization engine does not have access to the plant machinery database, but rather uses a subset of data replicated in the visualization database by a replication module as the basis for generating visual representations of one or more physical objects involved in the plant's manufacturing process, particularly machines involved in the process and / or objects processed by the machines.
[0183] In some examples, the replication module 150 may use a streaming protocol to continuously stream database updates from the plant machinery database 128 to the visualization database 130. For example, Apache Kafka may be used to create a stream of measurements continuously stored in the plant machinery database and transfer them to the visualization database. The measured parameter values may indicate the orientation or state of one or more machines and / or the result of previously executed control commands providing new configuration data via requests. By streaming the measured parameter values to the visualization database, the visualization engine gains access to the measured parameter values.
[0184] The visualization engine is interoperable with one or more client software programs running on each client device, including display devices 154 and 108. The client software receives visual representations of physical objects from the visualization engine and displays one or more visual representations of physical objects to the user on each display device. This allows the user to monitor the manufacturing process without disclosing sensitive control parameters or other sensitive data and know-how.
[0185] For example, client software that interoperates with a visualization engine may be software configured to display visual representations on a 2D screen, such as the screen of a smartphone, notebook, or desktop computer. This could allow remote users to monitor production processes using standard devices without requiring the user to use specialized equipment such as VR glasses.
[0186] In another example, client software interoperating with the visualization engine could be VR software (virtual reality software) configured to display visual representations through the user's VR glasses, thereby giving the user a sense of immersion, that they are spatially near the physical objects represented by the visual representations, even though they may be far away from the plant.
[0187] In another example, client software interoperating with the visualization engine may be augmented reality (AR) software configured to display visual representations via AR glasses worn by a local user 146 working in the plant, thereby providing the user with additional information that may be useful in operating or maintaining the plant's machinery. For example, system 300 may further include a security interface 142 configured to receive and verify requests from remote clients 106, 107, 108 to operate one or more machines. The security interface may be configured to prompt the local user 146 to accept the requested action via a visual object generated by the visualization engine and displayed via the local user's AR glasses. For example, the visual object may be a menu describing the requested action and / or the identity or role of the requesting user, and the menu may include one or more selectable items, such as buttons, that allow the local user to accept or reject the requested action. In addition or alternatively, the visualization engine in interoperation with the AR software may cause menus, text, videos, or other types of data related to the machinery or manufacturing process to be displayed on the AR glasses. For example, the data may include text or video instructions on how to operate or maintain the machine, a GUI that allows a local user to input configuration data locally, or alarms or error messages.
[0188] A remote user wearing VR glasses to remotely monitor the manufacturing process may be the user who submitted the request. However, the request may also be submitted by another remote user or remote client software, and the user wearing the VR glasses 108 may simply be monitoring the process.
[0189] According to one embodiment, the visualization database 130 includes, for at least one of the machines, two or more different user role-specific models of the machine. The visualization engine is configured to identify the role of a remote user wearing VR glasses, identify one of the models assigned to this role, and use the identified model to generate a visual representation of the machine. The different models may differ from one another in terms of the degree of structural detail or status information disclosed in the model. This allows for flexible and granular control over the level of detail that the remote user can see.
[0190] The security interface 142, and its interoperability with the client, PLC / PCS interface 125, and machine 140, may be implemented and carried out as previously described herein for other embodiments and examples. However, the security interface is optional, and the plant machinery database 128, visualization database 130, visualization engine 134, update engine 160, and replication module 150 may also be used in computer systems for monitoring and / or operating the manufacturing process without including these optional components. Using the database replication mechanism described herein in combination with the security interface may have the advantage of providing a highly secure system for remotely monitoring and controlling an automated manufacturing process. Only a one-way communication channel exists for transferring control parameters from a remote client to the machine, and there is only a further one-way path for providing visual feedback to the remote user, ensuring that the remote user cannot access or view sensitive control parameters or know-how, as they are merely viewing predetermined typically simplified visual representations of real-world objects in the form of a digital twin.
[0191] Figure 4A shows an example GUI 400 that allows a user 146, for example a local user, to monitor and / or control the status of the manufacturing process. Because the status information may reveal sensitive data of the manufacturing process, the GUI 400 may be accessible only from within the automated system / plant and not by remote users.
[0192] In the illustrated example, a remote user or edge computer system may be requesting that the “target bulk density” control parameter 402 be set to a value of 115,000 g / l. During the mapping operation performed by the security interface, the security interface may calculate additional control parameter values for the temperature 408 and pressure 406 parameters. For example, the manufacturing process may be a chemical synthesis, and the security interface may include a predictive model configured to predict temperature and pressure values that are likely to provide the substance at (at least approximately) the desired bulk density. The predicted bulk density 404, as well as the predicted temperature and pressure for each reaction vessel, may be calculated during the parameter mapping step, passed by the security interface to the database service interface, and stored in the plant machinery database. One or more of the plant machinery 140, for example, a local computer, may be configured to read the parameters from the plant machinery database and generate a GUI that displays the parameter values (the target bulk density specified by the requesting entity and the bulk density, temperature, and pressure predicted by the service interface).
[0193] The local user can choose whether to manually or automatically set the mechanical parameters, pressure, and temperature to achieve a given target bulk density of the material produced by the manufacturing plant. When the mechanical control values are set to "automatic mode," as shown in Figure 4A, the control parameters predicted by the safety interface are automatically set and used as the basis for controlling the synthesis process and process conditions. The prediction is preferably performed at the L2 level of the safety interface. As a result, the automatically calculated parameter values, e.g., 8.48 bar and 37°C, are automatically set and can be continuously updated during the ongoing manufacturing process.
[0194] According to some embodiments, the local operator 146 must select either "automatic mode" or "manual" at least once to start the synthesis process. By selecting "automatic mode," the local operator sends an acceptance message to the security interface indicating that the local operator considers the specified control parameters, particularly temperature and pressure, to be safe and appropriate.
[0195] Figure 4B shows another example 410 of GUI 144, which allows a local user to monitor and / or control the manufacturing process. Corresponding to GUI 400 shown in Figure 4A, the illustrated GUI 410 has the machine control values set to "manual" by the local user. As a result, the local user has the ability to edit the values calculated by the safety interface, thereby overriding control parameters that are considered unsafe, unattainable, or otherwise problematic.
[0196] Figure 5 shows a distributed system 500 for controlling manufacturing processes within multiple plants.
[0197] A user 108 who can work in Plant A and is therefore far away from Plant B may wear VR glasses. Through the VR glasses, user 108 can view video and / or images acquired by cameras placed in Plant B. For example, the camera may be mounted on a movable robot 510 whose movement and / or position can be controlled by a remote operator 108. Thus, the remote operator views, through the VR glasses, what the robot 510 sees as it moves around Plant B. Image and / or video data may be transmitted from the robot 510 to the remote user via a database replication module and a visualization engine, as shown in Figure 3. At least some of the machines or physical objects processed by the machines are represented to the remote user via the VR glasses in the form of a visual digital twin as part of "virtual reality". When a user wants to monitor the operation of one of the machines 140 in the plant, for example, to rotate the robot 510 to the left, user 108 simply needs to rotate their own body to the left. Sensors in the VR glasses recognize changes in position and / or orientation and transmit a turn-left command in the form of a request to control the robot so that it turns left, in the new position and orientation. Requests to move the robot are transmitted to the robot via the security interface 142, as described herein with respect to embodiments and examples. For example, the transfer of a request from L3 to L2 may include authenticating the remote user 108, validating the request, mapping control parameters, validating the mapped control parameters, and storing the new position or movement details in the database 128. The robot 510 and other machines 140 are configured to repeatedly read control parameters from the database 128 and adjust their position and / or the actions performed accordingly.
[0198] The current position and / or orientation of one or more of the machines 140, including robots, may be continuously sensed and stored in the plant machinery database 128, and the acquired position data may be used to continuously update the database 128. At least some of the data indicating the position and / or location of robots is replicated to the plant environment database 130, which is used as a data base for a visualization engine to generate and display a continuously updated visual representation of the plant's robots and / or other machines 140 to a remote user.
[0199] In some embodiments as illustrated, the visualization engine 134 can be configured to create an avatar 505 which is a virtual representation (or "twin") of the remote user 108. The avatar can be displayed to one or more local operators 146 working at Plant B and wearing AR glasses. Thus, the local operators 504 view the digital twin of the remote user through their AR glasses.
[0200] User 146 may wear AR glasses, which means that User 146 can still see the actual machinery 140 at Plant B. However, several virtual objects, including the avatar 505, are displayed in the AR glasses as an overlay on the “real world” which is still visible through the AR glasses. Thus, User 146 perceives a sense of reality as if the remote user 108 were actually present on the premises of Plant B, as they see the avatar moving and / or hear the avatar speaking through the AR glasses. The impression of the avatar and other virtual objects through User 146's AR glasses may be generated by an augmented reality application 504 installed locally in the IT infrastructure of Plant B. In addition, the IT infrastructure of Plant B may include a virtual reality application 506 configured to interoperate via a visualization engine 134 with a virtual reality application 524 installed locally in the IT infrastructure of another plant, e.g., Plant A. This allows operators of different plants to share a common virtual reality, which could be useful for users working in different countries who wish to discuss manufacturing-related issues without needing to meet physically.
[0201] The visualization engine can be configured to align virtual objects, such as avatars, virtual user menus, instruction manuals, or videos, with the coordinate systems of virtual reality and the "real world." Because the visualization engine has access to the global object representation layer, any virtual object, such as a machine instruction manual, can be viewed by all users wearing VR or AR glasses and registered with the visualization engine.
[0202] Remote user 108 can not only remotely control some manufacturing tasks in plant B, but also control some manufacturing tasks in plant A. For example, user 108 may normally be a local operator in plant A, but may want to remotely control tasks from home. In this case, user 108 is also a remote user of the system for controlling manufacturing in plant A.
[0203] Remote control of one or more machines 526, 528, 530, 532, and / or 534 by user 108 via security interface submodules 542, 544 may be carried out as already described with respect to other figures, e.g., Figures 1, 2, and / or 3. Service interfaces 540, 120 may be based on a REST API, may include streaming applications such as Apache Kafka, and may use MQTT or WebSocket protocols to forward requests.
[0204] At the L3 level, security interface submodules 542 and 122 typically contain or access rules and / or object representations relating to manufacturing site, cluster, or plant-level objects that are not machine-dependent. These rules and object representations can be used to validate requests at the L3 level.
[0205] At the L2 level (automation system level), security interface submodules 544 and 124 contain or access rules and / or object representations relating to plant, line, or machine-level objects. These rules and object representations can be used to validate requests at the automation system / L2 layer.
[0206] Embodiments of the present invention enable a remote user 108 to control machinery in multiple plants without imposing security risks on the plants.
[0207] Figure 6 shows a system 600 configured to display various virtual objects in a position-dependent manner through AR glasses for a user wearing AR glasses and taking on the role of an "operator". For example, the operator can wear the AR glasses and see actual physical objects, such as plant machinery or objects processed by machinery. Task instructions A1 to A6 are shown by the AR glasses at predetermined x / y / z coordinates in an augmented reality coordinate system aligned with the real-world coordinate system. For example, the AR glasses may use the xy coordinates of machinery such as a loading unit, a conveying and heating unit, or a packaging unit to display their respective instruction manuals or images at a predetermined distance from the real-world position of the real-world object.
[0208] For example, a user wearing glasses may have a registered user account in the user database of the visualization engine and / or ID provider 135, and the user ID may be associated with one or more user roles, in this case the "operator" role. In addition or alternatively, each user role may optionally include one or more user privileges.
[0209] Therefore, the visualization engine is configured to select the content of incoming data to display based on one or more user roles and / or one or more user privileges associated with the user ID (e.g., "filtering" the content of incoming task instructions). For example, one or more user roles include, in a non-exclusive and exemplary embodiment, operator roles, maintenance roles, engineering roles, managerial roles, and guest roles. One or more user privileges and / or roles restrict and determine which virtual objects / information are displayed through the AR glasses. For example, a user privilege for the engineering role may define which machines in the plant a user associated with a user ID that has the engineering role can access, in the sense that they can view data corresponding to machines through the display of each task instruction. A user associated with a user ID may have two or more roles and two or more user privileges.
[0210] In the example shown in Figure 6, the user wearing AR glasses is assigned the role of "operator." As a result, the executable program logic causes the AR glasses to display view 600, and when the user approaches the input unit, they can view instruction manual A1 regarding the filter cleaning method in view 600, and further view additional task commands and their respective command images A2 and A3. When the user approaches the conveying and heating unit, they view task command A7 through the AR glasses. Similarly, when the user approaches the packaging machine, they view task commands A4-A6. Tasks A1-A7 relate to standard tasks that must be performed in the normal operating mode of the industrial plant.
[0211] Figure 7 shows a system 700 configured to display various virtual objects in a position-dependent manner via AR glasses to a user assigned the role of "maintenance worker." When the maintenance worker wears the AR glasses and looks at the actual machine, they see task commands related to maintenance rather than operational tasks. For example, when the user approaches the loading unit, they see task command B1 to replace a defective pressure sensor 1234, and / or when they approach the conveying and heating unit, they see command B2 regarding how to inspect the heater.
[0212] Figure 8 shows a manufacturing plant system 800 that displays the avatar of a remote user 108 in the controlled plant using spatial anchors.
[0213] A human remote operator 108 may be an expert in maintaining one or more machines in a plant, for example, a complex machine 808. Both the machine and the local operator 146 are located at Industrial Plant B in Country B. The remote user 108 is located in a different location, for example, within Plant A in Country A. The remote user 108 wears VR glasses operably coupled to a virtual reality application 524 ("VR application"). The VR application is interoperable with an AR application 504 operably coupled to AR glasses worn by the local operator 146. The VR application 524 and the AR application 504 can be connected to each other via a visualization engine configured to spatially align virtual reality and augmented reality virtual objects with respect to each other. The AR application enables the remote user to support local colleague 146 in various operations and / or maintenance tasks performed locally using or on machine 808. The AR application is configured to create an avatar 505 for the remote user and position the avatar at a predetermined location, for example, close to machine 808 where user 108's support is needed.
[0214] According to a preferred embodiment, the VR application 524 is configured to generate a virtual reality for a remote user 108, which enables the remote user to view local user 146 and / or other real-world objects of the industrial plant, such as machine 808, as they are perceived from the viewpoint of avatar 505. For example, the remote user can view the raw values of the production line and machinery through a robot equipped with a camera and / or further sensors positioned in the same position and orientation as avatar 505. For example, the robot may be robot 510 as described with reference to Figure 5. In some examples, plants A and B and their respective IT infrastructures may be made to operate as described with reference to Figure 5.
[0215] In some embodiments, the robot is remotely controlled by a remote user 108, enabling the remote user to perform actions defined by the robot. The avatar has a defined position within a 3D environment generated by the AR application 504 and displayed to the local user 146 via AR glasses. The local user 146 (AR user), who is human, and the machine 808 also have defined positions within a 3D environment used as the coordinate system for augmented reality ("mixed reality").
[0216] An AR application 504 interoperating with the visualization engine is configured to ensure that the VR coordinate system viewed by the remote user and the AR coordinate system viewed by the local user 146 via AR glasses have the same coordinate system as the basis for positioning virtual objects (avatars, holograms, GUIs, etc.). Both the AR application 504 and the VR application 524 receive positional information of virtual objects displayed in augmented / virtual reality from the same global object representation layer 503. According to some embodiments, a VR application program 524 for a remote user 108 generates a virtual reality ("manufactured metaverse") in which an avatar of a human local operator 146 is shown with a defined optical representation (e.g., name only, or even 3D avatar shape) so that the remote user can view the local user within the VR application (not shown). Conversely, the local user (AR user) 146 can perceive the remote user 108's avatar 505 as a hologram (for example, as a name only or as a 3D avatar shape) within the "manufactured metaverse" presented to the local user 146 as augmented reality via AR glasses 804.
[0217] According to one embodiment, the AR glasses 804 include a microphone 810 and an acoustic output interface 812, such as a speaker that provides a user interface to the local user. Similarly, the VR application 524 may include a user interface that includes a microphone and an acoustic output interface to enable a remote user 108 to interact with the VR application. The AR application program 504, operably coupled to the local user's AR glasses, interoperates with the VR application so that the remote user 108 and the local user 146 can converse with each other. Preferably, the AR application uses the positional information of the local user and the remote user's avatars in a shared coordinate system to control the volume of the acoustic output interface of the AR glasses. That is, the closer the local user 146 is to the avatar 505, the louder the volume. Similarly, the sensitivity of the microphone may be fitted as a function of the distance between the two users in a shared coordinate system. That is, the greater the distance, the lower the sensitivity of the microphone.
[0218] Therefore, the AR system according to the illustrated embodiment, which includes AR and VR applications, enables two users to collaborate using a shared coordinate system also referred to as the “manufacturing metaverse.” The manufacturing metaverse consists of a virtual coordinate system shared by all users and AR objects within the metaverse, thereby mapping this virtual coordinate system onto real-world objects 808 of an industrial plant and presenting them as an overlay. This allows an experienced remote user to experience the same or similar visual context as a guided local user.
[0219] According to the first scenario, thermoplastic polyurethane (TPU) is produced at Plant B. The production line has been modified to adapt to a new product that was not previously produced on this line. The remote operator is an expert in this type of production and lives at location A (Plant A, Country A). The remote user instructs the local operator on when and which valves should be inspected. The remote user also notifies the local user of important matters that the local user should pay attention to in order to ensure proper and smooth production. Furthermore, the remote user can instruct the local user on the appropriate action steps at the appropriate time and in the appropriate circumstances.
[0220] According to the second scenario, TPU production is already underway at location B. During the night shift, the work coordinator for that shift falls ill. An experienced human operator located remotely at location A (plant A, country A, other time zone) can provide support for production at location B during the day shift. This operator uses their avatar for direct collaboration with one or more human local operators. The remote user can coordinate the work of local workers by creating processes / tasks that local users (AR users) can perform.
[0221] According to the third scenario, autonomous TPU production is taking place at Plant B. Under normal / standard conditions, the line can operate completely autonomously. Manual intervention is only required in the event of an unexpected situation. This supervision is performed remotely via the manufacturing metaverse using a VR application. One or more robots are coordinated and triggered by a human remote operator by creating / using appropriate processes / tasks for the robots. If the human remote operator needs to view actual photos and / or video streams of the local situation, the remote user can move to the target machine using VR and AR applications associated with the robot's control program. The robot is equipped with a camera and controlled to take the same position and orientation as the remote user's avatar. When the robot reaches this position, the robot's camera is made to capture images and / or videos of the machine in front of the avatar / robot and transfer those images or videos to the VR application. The remote user will view the images and / or videos through the virtual reality created by the VR application. The robot is controlled to capture images and / or videos from the same position and orientation as the remote user's avatar in the mixed reality coordinate system of the industrial plant, so that the photographs and images show the machine in question from the same viewpoint as the human local operator would have at that position and orientation.
[0222] Embodiments of the present invention can be used in many other scenarios and industries. For example, embodiments of the present invention could be used in the automotive manufacturing industry, enabling experienced engineers to support colleagues working in other locations within an automotive manufacturing company.
[0223] Similarly, systems for representing ongoing manufacturing processes graphically via VR glasses, AR glasses, or other display types based on automated production control and / or visualization engines may be used in the chemical industry or any other type of industry where physical objects are processed to manufacture one or more products.
[0224] In some use case scenarios, robots can be used not only to acquire images or videos, but also to solve problems under the control of a remote user. For example, robots may be used to perform maintenance tasks in locations hazardous to human operators, such as in relation to chemical synthesis pathways involving hazardous chemicals, or in relation to tasks performed in environments contaminated or at risk of being contaminated with radioactive or hazardous chemicals.
[0225] According to some embodiments, spatial anchors are used to position virtual objects at a predetermined position and orientation relative to real-world objects such as machine 808. For example, it may be desirable to display a GUI hologram that allows a user to monitor and control machine 808 at a distance of approximately 40 cm in front of it.
[0226] To ensure that local user 146 always views the GUI hologram at this defined location in augmented reality, regardless of user 108's current location, the AR application generates and displays the GUI hologram at or at a defined distance from the spatial anchor. According to some embodiments, spatial anchors (i.e., at least the anchor ID and anchor coordinates) are stored in a database system so that they are accessible to the VR application 524. The VR application is configured to read the stored spatial anchors and generate and display a GUI hologram for the same virtual object, e.g., machine 708, at or at the spatial anchor.
[0227] According to some embodiments, spatial anchors are defined and created by placing machine-readable codes, such as QR codes® 811, 813, and 814, at various locations within an industrial plant. AR glasses may include a camera that acquires a digital image of the machine-readable code, extracts the encoded anchor ID therein, creates anchors with the coordinates of the machine-readable code in a real-world coordinate system, and stores these anchors in a database system. Alternatively, a user 146 may create a spatial anchor by performing an anchor creation gesture at a desired location in the real world. This gesture is captured by the camera of the AR glasses, and the spatial anchor is similarly created and stored by the visualization engine. The anchor ID may be automatically generated when the spatial anchor is created.
[0228] Figure 9 shows a coordinate system 900 that can be used by the visualization engine and VR application 524 to represent real-world objects and local user avatars in a virtual metaverse for a remote operator 108. The VR application 524 generates a virtual representation 908 of a real-world machine 808 in an industrial plant and displays the virtual representation to the remote user 108 using virtual reality display technology. This virtual reality coordinate system 900 may further include a virtual representation 904, e.g., an avatar, of the local user 146 working in the spatial vicinity of the real-world object 808. The distance between the virtual representations 908, 904 of the machine 808 and the local user 146 in coordinate system 900 corresponds to and reflects the actual distance of the real-world object. Coordinate system 900 may include a spatial mesh aligned with “real-world” objects such as the machine 808 and the local user 146 in the industrial plant. The mesh may also be aligned with the respective virtual representations 908, 904 (digital twins) of the real-world objects. In addition, the remote user 108 may be represented in this coordinate system 900 as a virtual entity, for example, an avatar 505 that can be viewed by the local user 146 via AR glasses 804. Figure 9 shows a coordinate system shared by the virtual reality generated by the VR application and the AR reality generated by the AR application, but preferably, the remote user 108 views real-world objects and virtual objects representing other users in the coordinate system 900 from the viewpoint (position and orientation) of the avatar 505.
[0229] Figure 10 shows a flowchart of a method for automating processes in a manufacturing plant. The method includes providing systems 100, 200, 300, 500 for automating processes in a manufacturing plant, 602 as various exemplary embodiments are described herein. The systems may include several machines 140, 536 in the manufacturing plant, plant machinery databases 128, 548 containing control parameters for the machines, an automation system 103 for automatically operating the machines in the manufacturing plant according to the control parameters in the plant machinery database, and a security interface 142. The method further includes receiving requests from clients over a network, 604 and verifying the requests by the security interface, 604. If the security interface determines that the request is valid, the security interface stores the control parameters 402-408 contained in or derived from the request in the plant machinery database, 608. The automation system automatically operates the machines according to the stored control parameters contained in or derived from the valid request, 610. If the security interface determines that the request is invalid, the security interface returns a message to the client via the feedback channel indicating that the request was not performed (612). [Explanation of symbols]
[0230] List of reference symbols 100 Systems for Process Automation 102 Automation Systems (L2) 103 Automation Systems 104 Control System (L3) 106 Client: Computer System 107 Client: Advanced Process Control Software 108 Client: Remote user using VR glasses 110 Client: Edge computing system 114 Firewall 116 Firewall 120 Service Interfaces 121 Service Interface 122 Security Interface Submodules 123 Configuration GUI for Rule 137 124 Security Interface Submodules 125 PLC / PCS interface for machines 128 Plant Machinery Database 130 Plant Environment Database 132 Rules 133 Configuration GUI for Rule 132 134 Visualization Engines 137 Rules 135 ID Providers 140. Physical manufacturing assets (e.g., plants, production lines or units, machinery, devices) 141 Task Engine 142 Security Interface 143 Feedback Channels 144 Task Engines 146 local users 150 Replicated Modules 154 2D / 3D representations of physical objects / machines 200 Systems for Process Automation 202 Administrator 214 Local Operator 400 GUI 402 Control parameter "Target bulk density" 404 Further calculated control parameters 406 Further calculated control parameters 408 Further calculated control parameters 410 GUI 500 Systems 501 L3 IT Infrastructure System 502 Global Object Representation Layer 503 L2 IT Infrastructure System 504 Plant B's local AR application 505 Avatar 506 Plant B's local VR application 508 Plant B's local web application 510 Robot controlled by a remote user 512-518 Machinery / Devices 520 Plant A's local web application 522 Plant A's local AR application 524 Plant A's local VR application 540 Service Interfaces 542 Security Interface Submodule 544 Security Interface Submodule 546 Database Service Interface 548 Configuration Databases 526 Robots 528-534 Machinery / Devices 552 L2 IT Infrastructure Systems 554 L3 IT Infrastructure System 600 System Steps 602-612 700 System 800 System 804 AR glasses 808 Machines / Devices 810 Microphone 811 QR code 812 Audio Output Interface 813 QR code 814 QR code 900 coordinate system 908 Machine 808 Digital Twin 904 users 146 digital twin
Claims
1. A system for automating manufacturing plant processes (100, 200, 300, 500), - Multiple machines (140, 536) in the aforementioned manufacturing plant, - A plant machinery database (128,548) including the control parameters of the aforementioned machine, - An automation system (103) for automatically operating the machinery of the manufacturing plant according to the control parameters in the plant machinery database, - Identity provider, ○ Multiple remote users not located within the aforementioned manufacturing plant, and ○ Multiple local users located within the aforementioned manufacturing plant The identity provider, including the user profile, A visualization engine configured to create augmented reality for the local user and virtual reality for the remote user, including a digital twin of the plant, - A security interface (142), 〇 A request to operate at least one of the machines is received from one of the remote users (108), ○ A reception request, which is a signal prompting one of the local users (146) to accept the requested operation of at least one of the machines via augmented reality glasses worn by one of the local users, causes the visualization engine to generate the reception request. ○ Only when the aforementioned local user accepts the request, the control parameters (402-408) included in or derived from the received request are stored in the plant machinery database. A security interface (142) and Includes, The automation system (100, 200, 300, 500) is configured to perform automatic operation of the machine according to the stored control parameters included in or derived from the received request.
2. The system according to claim 1, wherein the security interface is configured to verify the request and store the control parameters in the plant machinery database only if the verification returns that the request is valid.
3. The system according to claim 2, wherein the verification of the request includes performing a validation check, the validation check includes determining whether the control parameters included in or derived from the request are safe for the machine and human operators, and the request is deemed invalid if at least one of the control parameters is determined to be unsafe.
4. The system according to any one of the preceding claims, wherein the security interface is configured to map the control parameters included in or derived from the request to further control parameters included in the plant machinery database in order to extend the control parameters, the security interface is configured to perform validation checks of the further control parameters, the validation checks include determining whether the further control parameters are safe for the machine and the human operator, and the request is deemed invalid if at least one of the further control parameters is determined to be unsafe.
5. The system according to any one of the preceding claims, wherein the request is created by an action of the remote user, and the action is recognized as a control command by the VR glasses worn by the remote user.
6. The system according to any one of the preceding claims, wherein the security interface generates the acceptance request and generates the acceptance request only if the authentication of the request is successful as valid.
7. The system according to any one of the preceding claims, further comprising an ID provider computer system configured to authenticate the user who made the request, wherein the security interface is configured not to store the control parameters in the plant machinery database if the authentication fails.
8. The system according to any one of the preceding claims, wherein the requirement is to operate a robot located in the plant.
9. The visualization system according to any one of the preceding claims, configured to generate a visual representation of the remote user in the form of an avatar and to display the avatar to the local user via the AR glasses worn by the local user.
10. The system according to claim 9, wherein the visualization engine is configured to support the exchange of voice and text messages between the remote user and the local user.
11. It further includes an update engine (160), a visualization database (130), and a replication module (150), - The visualization database (130) includes a subset of the data from the plant machinery database, - The update engine is software configured to continuously receive spatial information and / or status information of the machine and / or objects processed by the machine from a plurality of sensors (162) during the ongoing manufacturing process, and to continuously update the plant machinery database using the received information. - The replication module is software configured to sequentially select data from the plant machinery database that enables the generation of digital visual representations of one or more physical objects, wherein the selected data does not include the control parameters, and the replication module is further configured to replicate only the selected data to the visualization database. - The system according to any one of the preceding claims, wherein the visualization engine is configured to generate the digital visual representations of one or more physical objects as a function of the data in the visualization database, and to display the visual representations of the one or more physical objects to one or more users via display devices (154, 108) to enable the users to monitor the manufacturing process, and the plant machinery database is inaccessible to the visualization engine.
12. The system according to any one of the preceding claims, wherein the automation system and the plant machinery database are implemented at the process control level (L2), and the visualization engine is implemented at the operation control level (L3), so that the security interface is the sole interface enabling the transmission of control parameters from the L3-level system components to the L2-level system components.
13. Use of the system described in any one of the embodiments described herein for automating processes in a manufacturing plant.
14. A computer-aided method for automating processes in a manufacturing plant, - The system (100, 200, 300, 500) 〇 Multiple machines (140, 536) in the aforementioned manufacturing plant, 〇 A plant machinery database (128,548) including the control parameters of the aforementioned machine, ○ An automation system (103) for automatically operating the machinery of the manufacturing plant according to the control parameters in the plant machinery database, 〇 Security interface and This includes providing a system (100, 200, 300, 500) that includes, The aforementioned method, - The step of receiving a request through the security interface, - A step of verifying the request using the security interface, - In response to the determination that the request is valid, the security interface stores the control parameters included in or derived from the request in the plant machinery database. - The steps of automatically operating the machine by the automation system in accordance with the stored control parameters included in or derived from the valid request. Methods that include...
15. 〇 User registry, - Multiple remote users not located within the aforementioned manufacturing plant, and - Multiple local users located within the aforementioned manufacturing plant User registry, including user profiles, A visualization engine configured to create augmented reality for the local user and virtual reality for the remote user, including a digital twin of the plant, 〇 Security interface (142) and It further includes, The aforementioned method, - The step of receiving a request to operate at least one of the machines from one of the remote users (108) via the security interface, - A step of causing the visualization engine to generate an acceptance request via the security interface, which is an acceptance request, a signal prompting one of the local users (146) to accept the at least one of the requested operations of the machine via augmented reality glasses worn by one of the local users (146), - The steps of storing the control parameters (402-408) included in or derived from the received request in the plant machinery database via the security interface, only if the one local user has accepted the request. The method according to claim 14, including the method described in claim 14.