Process automation system with security interface
The system addresses integration challenges by using a security interface for validating and automating machinery control, ensuring secure and efficient remote operation with enhanced safety and flexibility.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- BASF SE
- Filing Date
- 2024-05-07
- Publication Date
- 2026-06-02
AI Technical Summary
Existing industrial automation systems lack integration with advanced IT systems like IoT, mobile devices, cloud computing, VR, and AR due to security concerns and high costs, leading to inefficient and unsafe remote control, and manual intervention is required for settings, which can result in low-quality products and machine damage.
A system with a security interface that validates and stores control parameters from external requests, enabling secure, one-way data transfer to automate machinery operations, using a multilevel architecture with separate communication channels for control and feedback, and includes a security interface that performs validation checks to ensure safety and integrity.
Enables secure remote control of manufacturing processes with fine-grained control and rapid adaptation to changing conditions, reducing waiting times and enhancing security by preventing unauthorized access and ensuring machine safety and product quality.
Smart Images

Figure 2026517867000001_ABST
Abstract
Description
Technical Field
[0001] Field of the Invention The present invention relates to industrial automation systems, and more particularly to systems and methods for safely controlling automated manufacturing processes.
Background Art
[0002] Background and Prior Art So far, remote plant control has been basically prohibited due to potential risks to proper plant automation. Tasks performed "inside" and "outside" the factory were separated by essential manual operations.
[0003] For example, the automation structures described by the Purdue Reference model, especially those used in legacy automation systems, have been used for many years and have been shown to operate in a reliable manner. However, these systems lack openness and flexibility, and it is difficult or impossible to integrate new technologies (such as IoT, mobile devices, cloud computing, remote control, VR and AR applications, etc.), and the cost is high.
[0004] Integrating existing hardware-based automation technologies into a globally networked system has been found to be particularly problematic. Trained experts perform a large number of settings on the on-site machines. If the settings are made inaccurately, either intentionally or accidentally, this inaccurate setting can lead to the production of low-quality products and damage to individual machines, the entire production plant, or even employees.
[0005] To prevent plant malfunctions caused by external systems, users and / or targeted hacker attacks, security measures in these systems prohibit the execution of remote control commands or make it quite complicated. Therefore, these automation systems cannot be fully integrated into large-scale global IT systems. [Overview of the Initiative] [Problems that the invention aims to solve]
[0006] overview The object of the present invention is to provide an improved system for process automation in a manufacturing plant and a corresponding method as defined in the independent claims. Embodiments of the present invention are shown in the dependent claims. Embodiments of the present invention can be freely combined with each other if they are not mutually exclusive. [Means for solving the problem]
[0007] In one embodiment, the present invention relates to a system for process automation in a manufacturing plant. The system is - Multiple machines in the manufacturing plant, - A plant machinery database including machine control parameters, - An automation system for automatically operating machinery in a manufacturing plant according to control parameters in a plant machinery database, - Security interface and Includes.
[0008] The security interface is configured to receive requests, validate them, and, in response to determining that a request is valid, store the control parameters included in or derived from the request in the plant machinery database. The automation system is configured to perform automated operation of the machinery according to the stored control parameters included in or derived from the valid request.
[0009] For example, a request could be a request to start, stop, or modify one or more operations of a machine. The request may be received from a client via a network, such as the Internet.
[0010] Embodiments of the present invention may provide the possibility for existing and new plants to effectively integrate existing core automation systems with advanced IT systems for task monitoring, optimization, and control, thereby enabling client devices or users to send requests to a security interface over a network to operate one or more machines in the plant after successful request verification.
[0011] According to some embodiments, the security interface is one-way, meaning it allows the client to send machine-related data, such as machine-related control parameters, to the automation system via a request, but does not allow the machine-related data to be returned to the client that submitted the request. This may enhance security because the client receives no information whatsoever about the type or state of the machine whose operating state was modified in response to the request. The client also receives no information about the number of machines affected by the request, or any reason why the request could not be performed. According to some embodiments, the one-way security interface does not return any request-related feedback information to the client, except for information on whether the request was successfully performed or not.
[0012] According to the embodiment, the validation of a request includes checking whether the control parameters included in or derived from the request are valid. Only if this validation check returns that the request is valid is the request treated as a validated and valid request.
[0013] For example, validation checks may include checking whether one or more operations of a machine that follow control parameters are safe (to the machine and staff, with respect to the product being produced) and are likely to enable the production of a product having the desired characteristics. For example, validation checks may include determining whether the control parameter values specified in or derived from the requirements fall within a predetermined acceptable parameter range, and / or predicting (e.g., simulating) whether a process performed by one of the machines according to these control parameters will produce a product with acceptable or preferred parameter characteristics, such as product size, quantity, purity, shape, color, elasticity, viscosity, etc., within an acceptable or preferred parameter range. If the control parameters set the temperature of the heating element of a tank to a temperature that would damage the tank material or its components, the security interface may consider the requirement unreasonable.
[0014] Only if this check returns that the request is a valid request, the security interface stores the control parameters in the plant machinery database and thereby modifies how the machine operates.
[0015] According to one embodiment, the plant machinery database includes one or more control parameters of the machinery, where the control parameters are or include control parameters, and the automation system automatically operates the machinery by setting the control parameters in the plant machinery database to control parameter values provided with or derived from the request.
[0016] According to the embodiment, the plant machinery database includes models (e.g., structural models, e.g., simplified or realistic 3D models), location information and status information of the machinery and / or products produced by the machinery, the location information being continuously updated to reflect the actual location and status of the machinery and / or products. The models, location information and / or status information, or parts thereof, can be used to generate digital twins of the machinery and / or objects manufactured or processed by the machinery. For example, a digital twin of each individual machine can be used to graphically represent the machine through its digital twin and / or to simulate the operation of the machine and / or to control the machine through its digital twin.
[0017] In a more advantageous aspect, the security interface can function as a secure and controlled access interface that supports request-based data ingestion into the automated system from the outside without compromising integrity and plant safety.
[0018] According to one embodiment, the system is used to control the operation of one or more machines of the automation system based on control parameters generated outside the automation system, for example, by or input to a client device that generated a request. These control parameters can be set values, i.e., parameters that can be set before and / or during the operation of the machine, and which define how the machine operates.
[0019] Embodiments of the present invention enable remote process control of machinery in an automated system without compromising safety, offering the advantages of much faster and more granular process control. Generally, in process industries, a local plant operator working in the spatial vicinity of the machinery sets control parameter values for one or more machines within the automated system. For example, in conventional process automation systems, the operator may input control parameters via a local machine interface. The input control parameters may be proposed by the customer or another human or non-human user who is not part of the automated system (and therefore considered less reliable as a local operator). The local operator ensures that only verified external data is carried over into the automated system by manually inputting control parameters proposed by a remote advanced process control system. However, the number of control parameters that a human operator can understand and manually input is limited, and especially in complex manufacturing processes with multiple interdependencies, even a skilled local user may miss relevant contextual information.
[0020] Conversely, embodiments of the present invention may enable an external client of the automation system, such as a client hosting an advanced process control system, or other client software not part of the automation system, to generate and present requests containing control data, thereby ensuring that the verification of the requests does not damage the machinery, degrade product quality, and / or harm any personnel working adjacent to the respective machines. Furthermore, the request verification implemented according to embodiments of the present invention enables a higher degree of complexity in validating the control parameters, allowing for the processing and evaluation of requests at a higher frequency, thereby providing much finer control over the automation process.
[0021] According to some examples, the system includes a client configured to generate a request and present the request to a security interface via a network such as the Internet.
[0022] According to embodiments, the client that generates the request is configured to repeatedly generate and present requests at a frequency of at least once per hour, preferably at least once per minute, preferably at least once per second, and in some embodiments at least once every 0.10 seconds. Each request includes one or more control parameters for controlling one or more operations of the machine.
[0023] According to embodiments, the request is automatically generated and presented by client software, whereby the control parameters specified in the request are also dynamically calculated by the client software.
[0024] According to embodiments, the verification of the request is repeatedly performed by the security interface at a frequency of at least once per hour, preferably at least once per minute, preferably at least once per second, and in some embodiments at least once every 0.10 seconds.
[0025] The client may be configured to repeatedly predict one or more control parameter values that are optimal or suitable for controlling one or more operations of the machine so that at least one characteristic of an automated production process performed by one or more of the machines is optimized, and automatically and repeatedly present requests including one or more predicted control parameters to the security interface. In particular, the prediction of the control parameter values includes simulating the automated production process and one or more operations of one or more of the machines involved in the production process.
[0026] For example, the client software can be configured to simulate a production process or a part thereof to identify control parameters suitable for optimizing the production process or ensuring safety or good product quality. For example, possible optimization criteria can be reduction of energy or material consumption, reduction of waste, improvement of product quality or purity, presence of desirable features, or product characteristics or process parameter values within a desirable value range.
[0027] As a specific example, the manufacturing plant PA can include a plurality of machines and tanks configured to perform a continuous chemical synthesis workflow for continuously producing two products A and B, the relative proportions of which can strongly depend on process parameters such as the temperature in the reaction mixture. Product A can be used as an extract in a different synthesis workflow for synthesizing substance E in a different plant PE. Product B can be used as an extract in a further synthesis workflow for producing substance F in a further plant PF. The demand for either A or B can depend on the demand for substances E and F. Since these products are synthesized in different plants, the machines in plants PA, PE, and PF are not part of the same automation system, and thus, the automated integration of the synthesis workflows implemented in different plants has been impossible until now. Also, since the human operator had to manually set the reaction temperature of the synthesis workflow in plant PA to a temperature value suitable for producing products A and B in a proportion that meets the demand for the final products E and F, fine control has also been impossible. This has resulted in significant delays and hindered the real-time synchronization of industrial manufacturing processes between geographically dispersed plants. By using a security interface and request verification, it is possible to synchronize the manufacturing process so that the waiting time is minimized. Requests can be automatically generated at a high frequency by a client that includes or belongs to an advanced process control system that integrates the requirements, demands, and available resources of a plurality of geographically dispersed heterogeneous plants.
[0028] Therefore, the embodiments can support fully automated control of one or more plants and the integration of process control of one or more plants in an advanced process control system. Waiting times can be significantly reduced without compromising safety.
[0029] According to one embodiment, the system is configured to use a security interface as a single-point input to an automated system. The security interface can be configured to receive and verify requests presented by one or more different clients, for example, by an advanced process control system, by an edge computer system, or by a remote operator using virtual reality glasses and / or a mobile device (e.g., a smartphone) to remotely control a manufacturing process.
[0030] According to one embodiment, the system for process automation includes a multilevel system architecture. The multilevel system architecture is - A first level involving the execution of actual physical processes, particularly the sensing and manipulation of physical objects in automated production workflows, including one or more machines and optionally further objects. - A second level (L2) including components for supervising, monitoring, and / or controlling the first level of physical processes, and a process control level including a second level (L2) including devices that control the entire process in the automation system, - Includes at least a third level (L3) which includes manufacturing operation system components configured to manage the production workflow and produce the desired product by supervising, monitoring, and / or controlling the components of the second level. The L3 level is also referred to as the operation control level, which supports the management of the production workflow, such as a manufacturing operation management system.
[0031] The first submodule of the security interface is part of the third level (L3). The second submodule of the security interface is part of the second level (L2). The components of the second level are protected from components of the third level and higher by at least one security measure, in particular a firewall.
[0032] For example, a multilevel system architecture for process automation can be implemented according to a typical automation pyramid model, such as the Purdue Reference model or other similar automation pyramid models.
[0033] According to some examples, the security interface may include one or more software programs and / or software services that function as an interface between the automation system (and by extension, the automation system level "Level L2" of the automation system pyramid) and the L3 level components of the automation system pyramid structure. Embodiments of the present invention enable the implementation of a security interface on top of an existing automation system, thereby enabling request-based (and optionally remote) control of the automation system, preferably without the need to adapt the existing automation system. Requests are checked and verified, and only the control parameters of valid requests are transferred and stored in the automation system's plant machinery database. This protects the automation system and the manufacturing plant from hackers and requests that could set critical control parameters to values that could adversely or even harmfully affect the plant's machinery or the entire manufacturing plant.
[0034] For example, a request may be generated by a remote client, thereby being transmitted to a system according to an embodiment of the present invention via a network such as the Internet. The security interface may receive requests via one or more intermediate interfaces or modules, such as a service interface. In some embodiments, a request is generated, for example, by a remote user via a metaworld engine, to control one or more operations of a machine by setting one or more control parameters of the machine.
[0035] According to one embodiment, the security interface is configured to enable secure one-way transfer of at least control parameters to the automation system via a control communication channel, and is configured not to return machine-related control parameters or status information to the client that made the request.
[0036] The first and second submodules of the security interface (which may belong to the L3 and L2 layers) are functionally complementary functions and may include functions having the same or identical structure (the same or identical number and type of input and output arguments).
[0037] According to one embodiment, a request received by the security interface may be or include a call to one or more functions.
[0038] According to some examples, a second submodule of the security interface includes machine-specific functions, each configured to control the operation of one or more machines according to one or more control parameters in the plant machinery database. The number and types of input arguments and the number and types of output control commands for one or more machine-specific functions correspond at least partially to the control interface of the machine controlled by each of the machine-specific functions. For example, the structure of one or more machine-specific functions is at least partially identical to the function of each machine's control interface.
[0039] The first submodule of the security interface contains one or more general-purpose functions. Each general-purpose function is assigned to one of the machine-specific functions. Receiving a request by the first submodule of the interface triggers the execution of at least one of the general-purpose functions, and after the successful execution of at least one general-purpose function, it triggers the execution of one or more machine-specific functions assigned to the executed at least one general-purpose function. For example, the structure of one or more general-purpose functions is at least partially identical to the machine-specific functions called by each general-purpose function.
[0040] As used herein, “generic functions” are functions that do not include, or do not depend on, knowledge of the technical characteristics of a machine, such as its manufacturer, type, current status, or orientation. For example, the generic function “Operate Centrifuge (INT revolutions per minute, FLOAT temperature)” may be a generic function that takes the control parameters “revolutions per minute” and “(centrifuge) temperature” as input parameters. A generic function may not include a reference to any particular type of centrifuge, but a call to this generic function may trigger the execution of a rule that checks whether the specified revolutions per minute and specified temperature values are valid, without depending on the specific characteristics of a particular centrifuge. For example, if the temperature exceeds the boiling point of the liquid being centrifuged, the temperature may be considered invalid without considering any details of the centrifuge used. If the validation check triggered by the execution of the generic function “Operate Centrifuge” returns that the arguments are valid, a machine-specific function having the same structure may be called. A machine-specific function may include machine-specific characteristics, such as the maximum revolutions per minute and the highest (or lowest) temperature supported by the centrifuge being operated, or may be configured to read out those machine-specific characteristics. Execution of a machine-specific function may involve validating whether the control parameters provided as arguments are supported by a particular centrifuge. A machine-specific function may have the same structure as a called general-purpose function, e.g., "operate centrifuge (INT revolutions per minute, FLOAT temperature)".
[0041] In a further example, the request may include a control parameter indicating that the reaction mixture of a chemical reaction should be set to 120°C to trigger the production of a desired substance. Receipt of this request by the first submodule of the security interface may trigger the execution of a first general-purpose function that performs a validation check if the current energy price is below a predetermined threshold. If so, the first general-purpose function returns as a result that heating the reaction mixture to 120°C is valid and should be permitted. As a result of the successful validation test performed by the first general-purpose function, the first submodule triggers the execution of a second submodule of the security interface of a first machine-specific function to which the first general-purpose function is assigned. The first machine-specific function checks whether the reaction tank containing the reaction mixture allows the chemical reaction to be carried out at this temperature. For example, this check may include checking whether the tank material is sufficiently robust and whether the heating element has sufficient strength to support a temperature of 120°C. If so, the second submodule of the security interface causes the heating element of the tank to heat the reaction mixture to 120°C. If the first general-purpose function returns that the current energy price is above a predetermined threshold, the first submodule may return via the feedback channel that it cannot fulfill the request and that the execution of the first machine-specific function is not triggered.
[0042] According to some examples, the first part of the requirements verification is performed by at least one general-purpose function, and the second part of the requirements verification is performed by one or more machine-specific functions assigned to the at least one general-purpose function that was executed.
[0043] This offers the advantage of enabling validation checks against both criteria that can be evaluated at the L3 level and criteria related to more sensitive machine-related standards that may relate to highly sensitive machine parameters and status information that should not be disclosed for security reasons. A further advantage is that CPU and memory consumption may be reduced by implementing a two-stage request verification process, as the machine-specific function is executed only if the relevant first function returns that the request is valid. Thus, the general-purpose functions and machine-specific functions assigned to each other functionally complement one another to provide functions, particularly validation functions, that cover both the L3 and L2 aspects of the automation system.
[0044] In some examples, the system includes a function synchronization module configured to automatically determine if the number or type of input arguments required by one of the machine-specific functions, or the number or type of output arguments provided by one of the machine-specific functions, has changed, and to automatically replicate the change to one of the general-purpose functions to which the modified machine-specific function is assigned, so that the input and output arguments of the general-purpose function also reflect this change.
[0045] This has the advantage of making the implementation of request verification transparent. Function calls to machine and / or system L2-level components for process automation implemented by machine-specific functions are represented as "visible" to the client or service interface through structurally identical generic functions. Therefore, the structure of the generic function exposed to the client or service interface (type and number of input and / or output arguments, and / or function name) is identical to the structure of the machine-specific function. By implementing request verification by two different submodules using the generic and machine-specific functions specified above, L2 automation-level machines and components are decoupled from L3-level components and systems outside the plant, thereby ensuring that inbound requests are forwarded only if the request is successfully verified as valid (preferably, if the requesting client is able to successfully authenticate with the ID provider module).
[0046] In a more beneficial aspect, any modifications to the structure of machine-specific functions that may be necessary to adapt the system when a machine is replaced with a different version of the machine are automatically propagated to general-purpose functions. This can ensure that the function interface is automatically kept synchronized and that errors due to incompatible function calls are avoided.
[0047] Optionally, the security interface may be configured to receive feedback data from the automation system via a feedback communication channel, which is a separate communication channel from the control channel.
[0048] For example, the security interface may completely lack any option for receiving data from the automated system and / or transferring this data to the client.
[0049] In some embodiments, there may be a separate communication channel, referred to as a feedback channel, for transmitting feedback information indicating whether the request was performed or refused.
[0050] For example, feedback information may be transmitted from the machine to a service interface that forwards feedback data to the client that submitted the request, via a database service interface (between the security interface and the plant machinery database). In addition, the security module may include an interface for receiving feedback information from the automation system and / or use a feedback channel to notify the client whether the request was validated successfully and executed.
[0051] Preferably, the feedback channel used to transfer feedback data from the automation system or security interface to the client is technically separated from the one-way control channel for transferring control parameters of a request from the client / service interface to the automation system via the security interface.
[0052] This can offer the advantage that even if the feedback channel is compromised by malware or hackers, the communication channel provided by the security interface for processing and transferring the request's control parameters remains unaffected. Therefore, using separate communication channels for feedback data and request-based control parameters (which function as control data) can ensure that feedback data, typically unimportant, can be easily distributed to one or more recipients via the feedback channel. The feedback channel may be a communication link with lower data security and data integrity than the communication channel provided by the security interface for the control parameters. This can facilitate the propagation of feedback data while still maintaining a highly secure communication channel for configuration data. For example, different channels may use different encryption techniques to ensure the integrity of the data transmitted through each channel.
[0053] According to the embodiment, the request verification is repeatedly performed by the security interface. In particular, the verification can be performed at a frequency of at least once per hour, or at least once per minute, preferably at least once per second, and in some embodiments at least once every 0.10 seconds.
[0054] This can be beneficial because it may allow the security interface to provide fine-grained control over the manufacturing process, enabling very rapid adaptation to changed requirements and / or production targets. For example, verification may include testing whether one or more control parameters provided by a request received at 12:00 are still valid, taking into account several environmental parameters at 12:05, 12:10, ..., 13:05, 13:10, etc. For example, a manufacturing plant may control a chemical reaction that produces a specific chemical substance in a reaction that may occur preferably in a temperature range of 30°C to 60°C, thereby decreasing the purity of the product with increasing temperature. The purity of the product is continuously monitored. A request received at 14:00 may indicate that this chemical reaction should be carried out at 45°C instead of 40% in order to increase the speed of the manufacturing process, while further control parameters in this request may specify that the purity of the product should be at least 80%. Upon receiving the request, the service interface may evaluate at 14:00 whether the desired purity is achievable while the reaction is proceeding at a reaction temperature of 45°C, and if so, may increase the temperature accordingly. For example, after this validation check is successfully completed, a new reaction temperature of 45°C may be stored in the plant machinery database and used by the heating element of the reaction vessel to heat the reaction mixture to the indicated temperature. For various reasons, the purity of the ongoing reaction may have deteriorated significantly by 14:35. This may be measured by a sensor device in the reaction vessel and communicated to the security interface via a feedback channel. If the security interface repeats the validation of the request (received at 14:00) at 14:35, the security interface may, considering the currently measured purity data, determine that it is highly unlikely that a product with at least 80% purity can be produced at the desired currently set temperature of 45°C. In this case, the security interface may autonomously modify the control parameters provided in the request, for example, by lowering the temperature from 45°C to 40°C and storing the new temperature in the plant machinery database instead of the old temperature.In addition or alternatively, the security interface may issue and return messages to the entity that submitted the request. The message may include a notification that the requested temperature value is no longer valid and has been replaced with a different temperature value that is better suited to achieving the optimization goal, e.g., product purity. In other embodiments, the notification may simply include an indication that the request has been rejected or that the request no longer determines the value of each control parameter in the plant machinery database.
[0055] It should be noted that if some required control parameters remain valid / acceptable with respect to process security, product quality, cost, or other optimization criteria, it is not feasible for a human operator to perform continuous checks multiple times per minute or even multiple times per second. Therefore, embodiments of the present invention can enable an automated system to respond immediately to changed production conditions and altered requirements, thereby providing a response rate that is faster and more accurate than that of an automated system that relies on additional manual quality testing of the production process.
[0056] In another embodiment, the security interface is configured to count the number of requests received at predetermined time intervals, for example, within one hour, a few minutes, or a few seconds. If the number of requests to change a given control parameter exceeds a predetermined maximum request threshold, further requests to change this control parameter may be rejected until at least a predetermined time has elapsed. This may provide protection against denial-of-service attacks and, in addition, may protect the machine from wear and tear and damage, as changes in some parameter values may trigger the movement of machine parts of the machine; therefore, it may be preferable to limit the number of machine part movements to a maximum value.
[0057] According to one embodiment, the automation system includes a programmable logic controller (PLC) configured to control one or more manufacturing processes performed by machinery in the plant.
[0058] A PLC can be an industrial computer that is more durable and adapted for controlling manufacturing processes, such as assembly lines, machinery, robotic devices, or any activity requiring high reliability, ease of programming, and process fault diagnosis.
[0059] Such PLCs can operate in a program scan cycle, where the PLC repeatedly executes a program. The simplest scan cycle consists of three steps: reading inputs, executing the program, and writing outputs. The program follows a series of instructions. Typically, it takes tens of milliseconds for the processor to evaluate all instructions and update the status of all outputs.
[0060] Most PLCs lack strict access and version control systems. This means that unauthorized changes to the program can occur and go unnoticed. Therefore, remote control of automated systems, especially those involving one or more PLCs, is typically prohibited for security reasons.
[0061] According to embodiments of the present invention, remote control of an automated system can be enabled in a secure manner, as a security interface verifies each request and transmits only the control parameters of those requests that have been verified as valid. In a preferred embodiment, the entity presenting the request must succeed in authentication within the system. If authentication fails, the request is not transmitted to the security interface either. Thus, a system according to embodiments of the present invention ensures that only requests from authenticated and trusted entities, including control parameters that have been verified as valid and secure, are propagated and stored in a plant machinery database, which is a fundamental means of controlling the actions of machinery in a manufacturing plant.
[0062] According to the embodiment, the verification of the requirement includes performing a validation check. Performing a validation check is - The value of the control parameter is achievable by one or more machines that operate according to the stored control parameter; for example, if the control parameter sets the pressure generated in a given tank to a value that is not achievable by each of the pumps used to generate the desired pressure, the request is considered invalid, and / or - The value of the control parameter is safe for one or more machines that operate according to the stored control parameter, for example, if the control parameter sets the pressure generated in a given tank to a value that is achievable by each pump but poses a security risk, the request is considered invalid, and / or - The value of the control parameter must be suitable for providing manufactured products that meet quality standards; for example, if the control parameter sets the pressure generated in a given tank to a value within a pressure range known to result in low product quality, the requirement will be considered invalid. This includes checking whether one or more criteria selected from the group including satisfy the control parameters included in or derived from the requirements.
[0063] Requirements verification may include checking whether the control parameters included in the requirements meet two or more of the above criteria, and optionally whether the parameters meet further criteria such as manufacturing process time, material cost, and energy consumption that may be associated with a given control parameter. Requirements verification may be rule-based and may include evaluating control parameters using one or more general, machine-independent and / or plant-independent rules and / or one or more machine-specific or plant-specific rules. In addition or alternatively, verification of control parameters may include performing complex computational tasks. For example, a predictive model, such as a machine learning model like a support vector machine or neural network, may be used to simulate the manufacturing process or its individual steps assuming that the control parameters specified in the requirements are used during production, and to check whether the predicted / simulated manufacturing process meets one or more criteria regarding safety, efficiency, cost, and / or product quality.
[0064] According to one embodiment, the system includes a service interface. The service interface is configured to receive requests from clients and forward them to a security interface. The security interface is configured to receive only requests from the service interface.
[0065] This can further enhance security because the security interface does not directly receive requests from clients. Rather, the security interface is protected from direct contact with clients via the service interface. This ensures that only requests processed and actively forwarded by the service interface are processed and verified by the security interface. In a further beneficial aspect, this makes it possible to implement the service interface as an interface that is easily accessible to various different clients. For example, the service interface could include multiple different web services adapted to different types of clients, such as a remote user using VR glasses to present requests to control a robot or other machine in a plant, or a remote client application run by a customer of a company operating a plant, or an edge computer system. Each service can be customized to optimize interaction with each type of client. For example, each service could include a REST API that allows the client to specify and present requests to the respective service.
[0066] According to one embodiment, the system includes an identity provider module operably coupled to a service interface. For example, the identity provider module may be an LDAP directory or another authentication system. The service interface is configured to receive requests from at least one client, authenticate at least one client, and forward the request to the security interface in response to at least one client successfully authenticating at the service interface. If at least one client fails to authenticate at the service interface, the service interface does not forward the request to the security interface.
[0067] This can improve security because automated systems typically do not include authentication measures. The security of process automation systems can be significantly improved by requiring successful authentication of the client to the service interface so that requests presented by the client are forwarded to a security interface and verified by the security interface.
[0068] According to the embodiment, the security interface is - Identify one or more further control parameters whose values depend on one or more of the values of the control parameters specified in or derived from the request, - It is configured to replace at least one control parameter included in or derived from a requirement with one or more identified further control parameters, and / or to complement a control parameter included in or derived from a requirement with one or more identified further control parameters.
[0069] One or more additional control parameters identified are stored in the plant machinery database to control the operation of one or more machines (in place of or in addition to control parameters originally included in or derived from the request).
[0070] The steps described above are sometimes referred to as the “parameter mapping” process. Identifying further parameters may involve mapping, for example, analyzing a file or database record or any other form of data structure that assigns one or more control parameters to one or more further control parameters, respectively. Mapping may involve mapping, for example, machine-independent parameters such as temperature to machine-specific parameters, such as temperatures specified on a machine-specific temperature scale ranging from 0 to 5, rather than absolute temperatures specified in Kelvin or °C. The mapping procedure may also involve more complex calculations of one or more further control parameters. For example, the originally specified control parameters may be desired product characteristics, and the calculation of further control parameters may involve predicting one or more further control parameters that will make it possible and / or are necessary to provide a product with the desired characteristics (see, for example, the descriptions of Figures 4A and 4B).
[0071] Control parameter mapping may allow for an increase in the number of control parameters and / or the mapping of machine-independent parameters to machine-specific parameters. This may have the advantage of enabling remote clients, such as customer edge devices that strongly desire to monitor and / or control the manufacturing process of products ordered by the customer, to control and / or monitor the manufacturing process using customer-specific control parameters without having to disclose too many details of the manufacturing plant, such as the type or quantity of machines used to manufacture the products. Embodiments of the present invention may allow a manufacturing plant owner to permit a customer to monitor and / or control the manufacturing process without the risk that the customer may intentionally or unintentionally control the manufacturing process in a manner that endangers the plant and the employees working at the plant, and without the plant owner having to disclose sensitive details of the machines included in the manufacturing plant to the customer.
[0072] For example, the first control parameter specified in the request may be the desired temperature of the reaction tank (a parameter independent of the machine), and any further parameters specified may be the heating rate or cooling rate set on a particular heater or cooling device of the vessel to achieve the desired temperature (a machine-specific control parameter or setpoint).
[0073] According to the embodiment, the security interface is configured to validate one or more identified additional control parameters (also referred to as validation of “mapped” control parameters). The validation includes performing validation of the additional control parameters, the validation of - The values of the identified further control parameters are achievable by one or more machines operating according to the stored identified further control parameters, and / or - The values of the further identified control parameters are safe for one or more machines that operate according to the stored identified control parameters, and / or - The values of the identified additional control parameters are suitable for providing manufactured products that meet quality standards. This includes checking whether further control parameters satisfy one or more criteria selected from a group that includes the specified criteria.
[0074] If one or more of the identified additional control parameters are determined to be invalid because they do not meet the criteria, neither the control parameters originally included in the request nor the identified additional control parameters will be stored in the plant machinery database. Rather, the request will be considered invalid.
[0075] According to one embodiment, the system further includes a feedback interface configured to return request-related feedback information to a client that has submitted a request, wherein the feedback information does not include control parameters or status information of one or more machines, but merely indicates whether or not the request was successfully executed.
[0076] Providing a separate feedback channel from the communication channel used to transfer configuration data offers the advantages of enhanced security (a compromised feedback channel will not affect the transfer of control parameters) and flexibility in controlling automated manufacturing processes (security measures for feedback channels may not be very stringent). In addition, the accuracy of requirement verification performed by the security interface can be improved because the validity and appropriateness of the requirements may depend on the constantly changing current status of one or more machines in the manufacturing plant.
[0077] According to the embodiment, the security interface is - Generate an acceptance request configured to prompt an entity, which may be a human user or software program working locally in the plant, to accept one or more requested modifications to control parameters stored in the plant machinery database. - Provide the entity with an acceptance request (for example, the security interface may cause software, such as a visualization engine, to generate a message prompting the local user to approve the requested control action via AR glasses or via one of the machine's displays), - Upon receiving a response indicating acceptance by an entity, the control parameters included in or derived from the request are stored in the plant machinery database. It is configured in this way.
[0078] Storing control parameters only upon receiving an indication that the entity has accepted the proposed control parameters may have the advantage of improved security. A remote user may not have a complete picture of all processes in progress on the production line within the plant, and therefore, machine reconfiguration may have adverse effects on products, machines, production processes, or personnel working within the plant, effects that only the local user can perceive, or can perceive more favorably. The risk of the aforementioned adverse effects occurring can be reduced by requiring the local user to accept control commands in the form of modified control parameters provided by the remote client.
[0079] In response to receiving a response from the entity indicating that the request cannot be accepted, the security interface stores the control parameters (included in or derived from the request) in the plant machinery database.
[0080] According to the embodiment, the security interface is - A first submodule configured to perform the first part of the requirements verification, wherein the first part of the verification uses general-purpose, machine-nonspecific and plant-nonspecific rules, - A second submodule configured to perform a second part of the requirements verification, the second part of the verification using machine-specific and / or plant-specific rules, comprising at least the second submodule.
[0081] The first submodule is part of the L3 level of the multilevel automation pyramid, and the second submodule is part of the L2 level. For example, the first submodule is hosted on a computer system that hosts L3 level components, and the second submodule is part of the L2 level.
[0082] According to some examples, a first submodule includes a first rule engine and a plurality of first functions, each configured to trigger the execution of one or more non-machine-specific and non-plant-specific rules by the first rule engine. A second submodule includes a second rule engine and a plurality of second functions, each configured to trigger the execution of one or more machine-specific and / or plant-specific rules by the second rule engine.
[0083] Using a security interface that includes two different submodules hosted on different computer systems and multiple levels of automated control can have the advantage of increasing system flexibility. For example, the second submodule may be defined or customized by plant operators who have a better understanding of the details of the machinery used within a particular plant. This can facilitate the specification of plant-specific or machine-specific rules used to validate requests. The first submodule may be defined or customized by users who may be familiar with the overall, machine-independent and / or plant-independent aspects of the manufacturing workflow. Since the two submodules are instantiated and maintained separately, it may not be necessary to allow plant operators to modify the overall, machine-independent rules, nor may it be necessary to allow operators of L3 or higher levels of automated control to modify the plant-specific or machine-specific rules of the second submodule. This can improve security.
[0084] According to some embodiments, the second submodule allows only the first submodule to provide control parameters and does not accept or process control parameters or requests, including those provided by different software programs.
[0085] According to some embodiments, a request presented by a requesting client includes one or more machine-independent function calls that indicate steps in a manufacturing workflow to be performed. The security interface is configured to perform mapping of machine-independent function calls to calls that can be interpreted by the control interface of one of the machine's machines in the plant. If the request is deemed valid, the security interface forwards the mapped machine-specific function calls directly or, preferably indirectly, for example, via a database service interface, to one or more machines configured to interpret and execute machine-specific function calls.
[0086] According to one embodiment, the reception request is generated by a second submodule of the security interface. The entity's response may be sent to and / or returned to the second submodule of the security interface.
[0087] According to one embodiment, the system includes a first virtual machine configured to host a first submodule of the security interface (and optionally, further components of the third level (L3) of the multilevel automation system architecture), and a second virtual machine configured to host a second submodule of the security interface (and optionally, further components of the second level (L2) of the multilevel automation system architecture). The first and second virtual machines are hosted by different virtual machine hosts and / or isolated from each other via a firewall.
[0088] This can enhance the separation between tasks performed by the first submodule / L3 level of the security interface and tasks at the L2 level of the second submodule / multilevel automation system of the security interface, thereby ensuring that any malware or other security issues that may exist at the L3 level are unlikely to propagate to the typically more vulnerable L2 level and automation system. For example, the only supported means of data exchange between L3-level components, L2-level components, and the automation system's machinery may be a data communication channel provided by the security interface, i.e., a one-way channel for verifying requests with control parameters and forwarding them to the automation system, and a feedback channel for returning feedback information from the automation system to the client.
[0089] In some embodiments, the security interface is implemented as a DMZ or isolation area (sometimes referred to as a perimeter network or screen subnet). The DMZ is a physical or logical subnetwork that contains the organization's external services and exposes them to untrusted (usually larger) networks such as the internet. This adds an additional layer of security to processes conducted within the security interface. External network nodes can only access what is exposed in the DMZ / security interface, while the remaining data and software programs running within the DMZ / security interface are protected behind a firewall. The DMZ functions as a small isolation network positioned between an external network, such as the internet, and the private internal network of IT resources. The implementation of a firewall, particularly a firewall between the security interface and the service interface, ensures that the security interface is a DMZ.
[0090] According to this embodiment, the first virtual machine and the second virtual machine are each implemented as containers.
[0091] By using different virtual machines, which can be implemented in the form of containers, it is possible to ensure that L2 components (the only components that can control the machines in an automation system) are strictly isolated from the outside and that they only exchange data with the outside, and especially with L3 level components, through a defined, secure data exchange interface.
[0092] According to the embodiment, requests are generated by a remote client, such as a human remote user, a remote client device, or client software, thereby connecting the remote client to the system via a network, such as the Internet. Typically, the remote client is located far from the manufacturing plant. The security interface is used as a remote control access route for the remote client to the automation system and the machines controlled by the automation system.
[0093] This could have the advantage of providing a universal input point for integrating many different remote clients, particularly users, and (existing) automation systems into new, typically more advanced control software via a security interface. The security interface provides a remote control access route to the automation system and the machines controlled by the automation system via the security interface.
[0094] According to some embodiments, one or more machines controlled by an automated system include a local access interface that allows a local user and / or local robot to directly control the machine via a second, for example, field-based communication channel. This can provide a high degree of flexibility, as both remote and local users may perform several control functions on their respective machines. In some examples, the access and control permissions for remote and local users may differ from each other. For example, only a (remote) expert user may be permitted to make changes to several control parameters that may affect many machines and processes in the automated system. On the other hand, only a local user may be permitted to initiate certain actions, such as opening and closing a door or starting a press, which may constitute a security risk if initiated only by a remote user who may not be aware of whether a moving part, such as a door or press, will hit a person or damage an object in its path.
[0095] According to one embodiment, the system further includes a visualization engine configured to generate a graphic representation of a digital twin of the machinery of the plant and / or the products manufactured by the machinery.
[0096] In some examples, the request is presented by a human remote user wearing virtual reality (VR) glasses operably coupled to a visualization engine. The visualization engine visualizes at least some aspects of a manufacturing process performed by a machine via the VR glasses.
[0097] For example, a visualization engine could allow a remote user wearing VR glasses to see one or more machines that they are currently attempting to reconfigure and control.
[0098] In addition or alternatively, the visualization engine is configured to create augmented reality for one or more local users working within the plant wearing AR glasses, and the augmented reality includes avatars of remote users and / or virtual graphic objects that assist in maintaining or controlling one or more of the machines.
[0099] For example, a robot operating locally in a plant may be controlled by a remote user and function as a physical representation of the remote user. When the remote user faces a given direction, the local robot follows this movement. The local robot may include one or more cameras, and images acquired by the robot's cameras are transmitted to a visualization engine, which then transfers them to the remote user's VR glasses. This allows the remote user to see, through the VR glasses, what the robot can see. This may improve security because it may enable the remote user to perceive objects in the spatial vicinity of one or more machines controlled by the remote user. This may enable the remote user to recognize any obstacles, other objects, or events that may indicate that certain control commands should not be presented because they pose a security risk to humans or components of the manufacturing plant, or that certain control commands should be presented to prevent a security risk. Control commands may be presented as requests to modify one or more control parameters of one or more machines in a plant machinery database.
[0100] According to some embodiments, the visualization engine supports voicemail and / or chat between a remote client, which is a human remote user, and a local user wearing AR glasses in a manufacturing plant. For example, the remote user may wear VR glasses, and the local user may wear AR glasses. Both VR glasses and AR glasses may include a microphone and an audio output interface, such as a speaker. The remote user and the local user can exchange real-time voice messages through the microphone and speaker of their respective VR glasses or AR glasses.
[0101] Preferably, the AR application is configured to control the volume of audio output generated by the local user's AR glasses such that the volume of the remote user's output audio is positively correlated with the spatial proximity of the local user and the position of the remote user's avatar in the coordinate system used by the AR glasses to display virtual objects. In addition or alternatively, the VR application is configured to control the volume of audio output generated by the remote user's VR glasses such that the volume of the local user's output audio is positively correlated with the spatial proximity of the remote user and the position of the local user's avatar in the coordinate system used by the VR glasses to display virtual objects.
[0102] According to some examples, the system further includes a plant environment database and a database replication module. The plant machinery database includes model, location, and status information for machinery and / or products produced by the machinery. Location information is continuously updated to reflect the actual location and status of machinery and / or products processed or produced by the machinery. The database replication module is configured to continuously replicate only a predetermined subset of the data from the plant machinery database to the plant environment database, thereby filtering out sensitive machinery-related data. The plant machinery database is configured to be inaccessible to the visualization engine. The visualization engine is configured to use only the data contained in the plant environment database to generate a visual representation of the plant's machinery and / or products processed by the machinery.
[0103] The use of two different databases as specified above may offer the advantage of enhanced security. The visualization engine continuously generates graphic representations of digital twins of machines and / or objects involved in automated production processes, thereby providing human users with a continuously updated overview of the process. Filtering functions ensure that sensitive machine-related data, such as precise location, sensitive status parameters, or control parameters, is not disclosed to the L3 layer or any other system outside the automated system. The database replication module simply replicates the information necessary to create a graphic representation of a machine or product, such as an identical or similar model of the machine's structure, or a highly abstract representation of the actions performed by the machine.
[0104] The graphic representation of a digital twin can be, for example, a conventional 2D representation of a machine and / or product generated for display via a computer screen or smartphone screen. In another example, the graphic representation is a 3D representation displayed via VR glasses or AR glasses, so that a 3D representation in a 3D coordinate system is provided.
[0105] According to this embodiment, the entity that receives the request is one of the local users. According to the embodiment, the machine in which autonomous driving is performed according to stored control parameters included in or derived from a valid request is a robot, in particular a robot controlled by a remote user via a visualization engine.
[0106] According to the embodiment, a machine and / or another machine in a manufacturing plant in which automatic operation is performed according to stored control parameters included in or derived from a valid request includes a local control interface, which enables a local operator to access and control the machine via a separate local communication channel. For example, the local interface may be a display screen of one of the machines.
[0107] In a further aspect, the present invention relates to the use of a system according to any one of the embodiments described herein for automating processes in a manufacturing plant.
[0108] In a further embodiment, the present invention is a method for automating a process in a manufacturing plant, - A system for process automation in a manufacturing plant, • Multiple machines in the manufacturing plant, • A plant machinery database including machine control parameters, • An automation system for automatically operating machinery in a manufacturing plant according to control parameters in a plant machinery database, • Security interface and To provide a system that includes, - Receiving requests via the security interface, - Verifying requests through a security interface, - In response to determining that the request is valid, the control parameters included in or derived from the request are stored in the plant machinery database via the security interface. - To automatically operate a machine by an automated system according to stored control parameters included in or derived from a valid request. This includes methods.
[0109] As used herein, "interface" refers to a software and / or hardware-based boundary where two or more distinct components of a data processing system exchange information across those boundaries.
[0110] As used herein, a "service interface" is an interface through which two or more clients exchange information with a system in order to automate processes in a manufacturing plant. In particular, a client can be a remote client connected to the service interface via a network such as the Internet. A client can be a user, a client device, a client software program, an edge computer system, or a combination of these.
[0111] As used herein, "security interface" refers to an interface through which requests, particularly requests to change the configuration of machinery in a manufacturing plant, are transmitted to an automated system.
[0112] As used herein, “machinery” refers to any physical entity involved in the manufacture and / or processing of products produced by a plant. For example, machine can be a single piece of equipment powered by electrical energy, mechanical energy, thermal energy, chemical energy, or other forms of energy to perform one or more operations. Machine can also be a device or device component, equipment, robotic arm, conveyor belt, robot, extruder, tumbler, oven, or any other type of physical component capable of performing one or more operations in a manufacturing workflow. The nature and location of machine within a plant may depend on the type of product being manufactured.
[0113] As used herein, “system for process automation” is a distributed network system that includes an automation system comprising multiple machines in one or more plants and one or more further system components, such as L3 and / or L4 components of a process automation pyramid, for automatically controlling the operation of the machines in each of the multiple plants so that a workflow is performed. The system is used and / or configured for process automation, in particular for process automation in one or more manufacturing plants.
[0114] As used herein, an "automation system," also referred to as a "process automation system (PAS)," is a system used to automatically control processes in plants such as chemical plants, oil refineries, and pulp and paper mills. A PAS often uses a network to interconnect sensors, controllers, operator terminals, and actuators. While a PAS as used herein may be based on open standards, a PAS may also be based on and / or include proprietary standards, in which case it is also known as a DCS (distributed control system). An automation system may be associated with a SCADA system. An automation system may use established, and possibly plant-specific, protocols or technologies. According to embodiments, an automation system includes one or more machines in the plant, a PLC (process logic control) interface and / or a PCS (process control system) interface for the machines. Optionally, an automation system may also include a plant machinery database containing control parameters for the machines.
[0115] As used herein, the terms “L3 level” or “L3 IT infrastructure system” refer to IT system components included in the manufacturing operation level. While this level is referred to as “L3” or “Level 3” in the Purdue model of multilevel automation systems, the terms “L3 level” or “L3 IT infrastructure system” are also used herein to refer to IT system components included in the manufacturing operation level, and may be referred to differently in other models of multilevel automation systems. L3 components perform a higher level of control functions than the core process control system.
[0116] As used herein, the terms “L2 level” or “L2 IT infrastructure system” refer to the IT system components included in the core process control level. This level is referred to as “L2” or “Level 2” in the Purdue model of multilevel automation systems, but the terms “L2 level” or “L2 IT infrastructure system” are also used herein to refer to the IT system components included in the core process control level, which may be referred to differently in other models of multilevel automation systems.
[0117] As used herein, “database” refers to any data structure that enables the temporary or permanent storage of data. For example, a database may be a data storage device managed by a database management system (DBMS), a file directory, a set of one or more files, or a single file such as a spreadsheet. A database may also be a data structure adapted to store data in a digital format, such as an electronic or optical storage medium.
[0118] As used herein, "plant machinery database" is a database containing data relating to one or more machines in a manufacturing plant. For example, the database may include control parameters for one or more machines, and / or data describing one or more machines, such as machine models, machine status data, machine configuration data, and / or other machine-related data that enables the generation of a digital twin of a machine and / or data that enables the simulation of machine operation or measurement data obtained by one of the machines. The plant machinery database may also include location and / or status information of objects processed or produced by the plant's machines, such as extracts or products.
[0119] As used herein, “metaverse” is a virtual representation of a portion of the world, preferably customized to be viewed through virtual reality glasses and / or augmented reality glasses. The metaverse can be implemented as a spatially fused network of 3D virtual worlds, such as a 3D world that is a digital twin of a plant and its machinery, as well as 3D worlds of one or more remote and / or local users wearing VR glasses and AR glasses.
[0120] As used herein, “digital twin” is a digital representation of a physical object or process in the real world that serves as a digital counterpart for practical purposes such as visualization, simulation, integration, testing, monitoring, or maintenance.
[0121] As used herein, the term "plant," also referred to as "factory" or "manufacturing plant," is an industrial facility, often a complex of several machine-filled buildings where workers and / or machines manufacture goods or process each item into another. A manufacturing plant may, for example, be a plant for producing vehicles or vehicle parts, a plant for producing electronic consumer goods, or a plant for synthesizing or processing chemical substances.
[0122] As used herein, "plant environment database" refers to a database containing data relating to a plant or its environment. The plant environment database may, for example, include a copy of some of the data in a plant machinery database. Preferably, highly sensitive machinery-related data (e.g., status parameters, location, configuration parameters, etc.) is not included in the plant environment database.
[0123] According to some examples, some of the data in the plant machinery database, which is included in the plant environment database, includes data used during validation checks performed by the L3 submodule of the security interface. This data may include, for example, validation criteria, thresholds, and reference parameter values that relate to the plant or its environment but not to individual machines. For example, the data may include acceptable energy price thresholds, weather data, information on ongoing manufacturing processes at other plants and their respective demands, and quality indicators required by different customers for the products being manufactured.
[0124] In addition to, or instead of, the data used for requirement verification, a portion of the data in the plant machinery database included in the plant environment database includes data that enables the visualization engine to generate digital visual representations of one or more machines included in the plant machinery database and / or to generate digital visual representations of objects processed or generated by said machines.
[0125] As used herein, “visualization database” is a database containing data that enables software, such as a visualization engine, to generate digital visual representations of one or more physical objects. For example, a visualization database may include 2D or 3D models of physical objects, such as realistic or simplified images or holograms of objects. A visualization database may also include spatial information about objects, such as their orientation or their position in a virtual coordinate system. Preferably, a visualization database does not include a representation of the precise geographical location of an object. For example, a visualization database may include digital models and / or generic status information of one or more machines whose control data is included in a plant machinery database, and / or digital models and / or generic status information of objects processed or produced by such machines.
[0126] According to some exemplary embodiments, a plant environment database is used as a visualization database, and vice versa.
[0127] As used herein, “edge computer system” refers to a computer system installed in the spatial proximity of a plant machine and configured to process data generated by the plant machine. This data may include, in particular, real-time data. Despite its spatial proximity, in some examples, an edge computer system is not part of the plant's automation system. For example, an edge computer system may not be part of the L1, L2, or L3 levels of the plant's multi-level automation architecture. An edge computer system may be configured to continuously receive, store, and evaluate data provided by machines during the manufacturing process, such as machine status data, product status data, process parameter values, and product characteristics. Due to its spatial proximity to the data source, the edge computer system may be able to respond very quickly with very short latency to events occurring during the manufacturing process. However, for security reasons and due to the lack of suitable interfaces, integrating edge computing systems into process automation systems has historically been impossible. By enabling the edge computer system to generate and present requests to a security interface for controlling one or more machines, embodiments of the present invention may enable the integration of an edge computer system into a system for automated process control. For example, an edge computer system may be configured to continuously analyze status information received from one or more machines in a plant and, when it determines that an undesirable event has occurred or is expected to occur during the production workflow, present a request to the security interface, which includes control parameters adapted to prevent or mitigate the impact of the undesirable event. Undesirable events may include, for example, a shortage of consumables, congestion of products on a conveyor belt, or a machine temperature exceeding a threshold.
[0128] As used herein, “control parameters” are parameters that affect the state of a machine and / or how the machine operates. For example, control parameters may be configuration parameters, function arguments for calling the machine’s PLC interface, commands, or a combination of two or more of the above.
[0129] As used herein, a “request” is a message transmitted between objects. For example, a request may be sent from a client to a system for process automation over a network. The request may then be processed by multiple interfaces, optionally modified or supplemented, and transmitted until it reaches its destination or until the transfer of the request is rejected.
[0130] As used herein, “visualization engine” is monolithic or distributed software configured to generate visual representations of physical objects. These visual representations may be, for example, 2D representations displayed via a computer or smartphone screen, and / or 2D or 3D representations displayed via VR glasses and / or AR glasses. In the latter case, the visualization engine, sometimes referred to as a “metaverse engine,” interoperates with an AR application to cause the AR glasses controlled by the AR application to display virtual object representations to the user wearing the AR glasses. In addition or alternatively, the visualization engine is configured to interoperate with a VR application to cause the VR glasses controlled by the VR application to display streamed status information to the user wearing the VR glasses. When the visualization engine is coupled to operate on multiple users wearing AR glasses, VR glasses, or a combination of VR and AR glasses via one or more AR and / or VR applications, the visualization engine may be configured to align virtual objects (the properties, dimensions, orientation, and position of the virtual objects) with the coordinate systems used by the VR and AR glasses in order to display the virtual objects. As a result of this overall alignment of virtual objects, multiple users wearing VR and / or AR glasses may at least partially share a common virtual object world that may include digital twins of multiple machines in the plant, digital twins of one or more production lines in the plant, and / or digital twins of users working for or within the plant.
[0131] As used herein, “client” refers to a single computer hardware or software that accesses a service made available by a server over a computer network, thereby accessing the service, in particular, as part of a client-server model of the computer network. The server is often (but not always) on another computer system, in which case the client accesses the service over a network, such as the Internet. Since client software can be software that translates user actions into requests and other actions of the client software, the term client may also refer to a user who uses a single piece of hardware or software to access a service over a network. The term “client” may also apply to a computer or device running client software.
[0132] For example, a client can be a computer program that, as part of its operation, relies on sending requests to another program or computer hardware or software that accesses services made available by a server (which may or may not be located on another computer). For example, a web browser can be used as a client to connect to a web server and search for web pages for display.
[0133] As used herein, the term “computer system” refers to a machine or set of machines that can be instructed by computer programming to automatically perform a sequence of arithmetic or logical operations. Modern computers have the ability to follow a generalized set of operations called “programs,” “software programs,” or “software applications.” These programs enable computers to perform a variety of tasks. According to some embodiments, a computer system includes hardware (in particular, one or more CPUs and memory), an operating system (main software), and additional software programs and / or peripherals. A computer system can also be a group of computers connected and working together, in particular a computer network or computer cluster, such as a cloud computing system. Thus, as used herein, “computer system” can refer to a monolithic standard computer system, such as a single server computer, or a network of computers, such as a cloud computing system. In other words, one or more computerized devices, computer systems, controllers, or processors can be programmed and / or configured to operate as described herein in order to perform different embodiments of the present invention.
[0134] The embodiments and examples described herein should be understood as illustrative examples of the present invention. Further embodiments of the present invention are conceivable. While the present invention has been described as an example of specific combinations and distributions of software programs and computer systems, it should be understood that any feature described in any one embodiment may be used alone or in combination with other features described, and may be used in combination with one or more features of any other embodiment of the embodiment, or in any combination of any other embodiment of the embodiment, unless the features are mutually exclusive.
[0135] Therefore, some embodiments of this application are for computer program products. Other embodiments of this application include corresponding computer implementation methods and software programs for carrying out any of the steps and operations of the method embodiments summarized above and disclosed in detail below.
[0136] Any software program described herein may be implemented as a single software application or as a distributed multi-module software application. One or more software programs described herein may be carried by one or more carriers. Carriers may, among many other examples, be signals, communication channels, non-transient media, or computer-readable media. Computer-readable media may be tapes, disks, such as CDs or DVDs, hard disks, electronic memory, or any other suitable data storage medium. Electronic memory may be ROM, RAM, flash memory, or any other suitable electronic memory device, whether volatile or non-volatile.
[0137] Each of the various features, technologies, and configurations described herein can be implemented individually or in combination, using a single software process or a combination of processes, for example, in a client / server configuration.
[0138] It should be understood that embodiments of computer systems and / or computer implementations described herein can be implemented strictly as software programs or applications, as software and hardware, or as standalone hardware such as within a processor, an operating system, or a software application.
[0139] The operation of the flowchart will be explained with reference to the system / device shown in the block diagram. However, it should be understood that the operation of the flowchart can be performed by embodiments of systems and devices other than those described with reference to the block diagram, and that embodiments described with reference to the system / device may perform different operations than those described with reference to the flowchart.
[0140] Given the wide variety of modifications to the embodiments described herein, this detailed description is intended to be illustrative only and should not be construed as limiting the scope of the invention. Accordingly, the claims of the invention include all such modifications that may fall within the scope of the following claims and equivalents. Therefore, this specification and the drawings should be considered illustrative rather than restrictive.
[0141] Brief explanation of the drawing The following embodiments of the present invention will be described in more detail as mere examples with reference to the drawings. [Brief explanation of the drawing]
[0142] [Figure 1] This shows a high-level block diagram of a system for process automation. [Figure 2] A block diagram of the further system for process automation is shown. [Figure 2] A system block diagram is shown for reliable visualization of the components of the automation system. [Figure 4A] This shows an example of a GUI that allows local users to monitor the status of manufacturing process steps. [Figure 4B] Here is another example showing a GUI that allows local users to monitor the status of manufacturing process steps. [Figure 5] This illustrates a distributed system for controlling manufacturing processes across multiple plants. [Figure 6] This describes a system configured to display various virtual objects to the "operator" user. [Figure 7] This describes a system configured to display various virtual objects to a "maintenance worker" user. [Figure 8] This displays the avatar of the remote user. [Figure 9] This shows the coordinate system used to represent real-world machines and local user avatars in the virtual metaverse for remote control. [Figure 10] This is a flowchart illustrating a method for enabling secure remote control of automated manufacturing processes. [Modes for carrying out the invention]
[0143] Detailed explanation Figure 1 shows a block diagram of System 100 for process automation of a manufacturing plant. The plant could be, for example, a plant for synthesizing chemical compositions, or a plant for manufacturing vehicles, computers, or consumer goods, furniture, or food.
[0144] The plant comprises several machines 140 used to manufacture and / or process one or more physical objects. The type of machine is determined by the type of product to be manufactured and / or by the machine manufacturer selected by the plant owner. For example, the machines may be electronic devices, jigs, robotic arms, conveyor belts, robots, extruders, tumblers, ovens, etc.
[0145] The system further includes a plant machinery database128, which may be part of the plant's L2 level IT infrastructure. For example, the machinery database can be a directory of files, a single file, a combination of files, a database managed by a database management system (DBMS) or graph database (GDB) such as Neo4J, or a combination thereof.
[0146] The plant machinery database 128 includes control parameters, such as configuration parameters of machines and / or processed digital objects, location information and / or structural or functional models, and / or data for generating digital twins of one or more machines 140 of a manufacturing plant and / or physical objects processed within the plant. For example, control parameters include the temperature of a reaction vessel for a chemical reaction, the temperature of an oven, the rotational speed of a stirrer, the speed of a pump, the pressure in a pressurized gas tank, the amount of a specific substance added to the reaction vessel, a desired pH value in the reaction vessel, and a desired CO2 level in the gas tank. 2 This could be concentration, etc. Control parameters may include target parameter values, i.e., parameter values that indicate the state of the machine to be achieved or the state of the product to be manufactured. Data for generating a digital twin may include, for example, continuously updated location information of machines and / or physical objects, digital 2D or 3D models of each of the multiple machines in the plant, and may further include data showing the dynamic behavior of the machine as a function of environmental parameters, control parameters, or other parameters.
[0147] System 100 includes an automation system 102 for automatically operating the machinery 140 of the manufacturing plant according to control parameters in a plant machinery database. For example, the automation system may include one or more programmable logic controllers (PLCs) 125 configured to control one or more manufacturing processes performed by the machinery 140 of the plant. The security interface may be configured to directly control one or more of the machinery or to control one or more of the machinery via the PLC / PCS interface 125.
[0148] A PLC can execute a program periodically. In each cycle, the program may read current measurement parameters provided by the machine and one or more control parameters stored in the plant machinery database 128 as inputs, process the inputs, and write output parameters. These output parameters are transmitted to one or more machines to control the actions performed by the machines. Thus, these output parameters, and also the control parameters on which the output parameters depend, can function as control commands to determine the behavior of the machines and, consequently, the manufacturing process. Typically, it takes tens of milliseconds for the processor of an automation system to evaluate all instructions and update the status of all outputs. For example, SIMATIC S7 can be used as a PLC in an automation system.
[0149] System 100 further includes system components at manufacturing operation level (level 3 in the Purdue model) 104, hereinafter referred to as "L3 components." The L3 components perform control functions at a higher level than those of the core process control system (level 2 in the Purdue model, hereinafter referred to as "L2 components"). For example, at least some of the control functions performed by the L3 components may be machine-independent. The L3 system components are preferably hosted on one or more monolithic or distributed computer systems 104 that operate independently of the L2 system components 102.
[0150] System 100 includes a security interface 142 which comprises a first submodule 122 that is part of the L3 level IT infrastructure and a second submodule 124 that is part of the L2 level IT infrastructure of System 100. Both submodules perform different parts of the request verification process.
[0151] The security interface 142 is configured to receive requests from one or more clients 106, 107, 108, 110, such as requests to manufacture a specific product and / or to modify the production of a product. Clients can be portable clients, such as smartphones, notebooks, or VR glasses, or stationary clients, such as desktop computer systems or edge computer systems.
[0152] For example, the edge computer system 110 may be a computer system located in close proximity to one or more of the plant's machines 140, but may not be fully integrated into the IT environment of system 110. The edge computer system may be configured to collect log data and / or status data from one or more machines 140 during an ongoing manufacturing process, analyze the data, and automatically determine control parameter values (e.g., temperature, amount of added substance, pH value, etc.) that are deemed suitable for improving the automated manufacturing process and / or the quality of the produced product. When determining these control parameters, the edge computer system creates and presents a request to transfer the control parameters to the machine 140 via a security interface.
[0153] The client computer system 106 may be any type of computer system, such as a desktop computer, laptop, tablet computer, notebook, or mobile phone.
[0154] Client 108 may be a remote user wearing VR glasses. The remote user may use the VR glasses to monitor one or more machines during the manufacturing process or maintenance period. The remote user may use the VR glasses to specify and present requests, including their respective control commands, to the security interface. Instead of implementing advanced IT equipment such as VR glasses at core process control (L2), embodiments of the present invention may enable restricting direct control of such machines to the L2 level and provide a secure option for remote clients to securely transfer control information to machines via an access-protected one-way security interface 142.
[0155] The advanced process control client 107 can be a client containing advanced process control software for integrating the requirements, demands, and available resources of one or more plants. The advanced process control client 107 can integrate multiple distributed, heterogeneous plants. The advanced process control software is used to direct process operation and includes model-based software commonly referred to as multivariable predictive control (MPC) or model predictive control. In these applications, the created process model must accurately represent the dynamic characteristics of the process.
[0156] The security interface is configured to receive client requests. Preferably, requests are received not directly from the client, but via one or more service interfaces as shown in Figure 2. Requests are validated by the security module. If the security module determines that a request is valid, it stores the control parameters included in the request or derived from the request in the plant machinery database 128 (e.g., during the mapping and / or normalization process). If the request validation returns that the request is invalid, the control parameters are not stored in the plant machinery database.
[0157] Optionally, the security interface returns a response message to the entity that presented the request indicating that the request was not performed. Preferably, the security interface prompts the local operator 146 or software application to authorize the storage of verified control parameters and / or the machine operation triggered by the control parameters, thereby storing the control parameters in the database 128 only when an acceptance message is received by the security interface.
[0158] The automation system is configured to repeatedly read control parameters stored in the plant machinery database and control the operation of the machinery as a function of the currently stored control parameters. At least some aspects of the manufacturing process can be continuously monitored by a remote operator 108 via VR glasses and a visualization engine 134.
[0159] Figure 2 shows a system 200 for process automation according to a further embodiment. System 200 includes components and subsystems already described with reference to Figure 1.
[0160] As shown in the illustrated example, each submodule 122, 124 of the security interface 142 includes task engines 144, 141. Task engine 144 is configured to process incoming requests by applying a configurable rule set 132. The rules 132 may include rules relating not to specific characteristics of machine 140, but rather to more general parameters, such as requirements or settings provided by a client (e.g., a customer), cost-related criteria parameters and thresholds, required product characteristics, extract availability, and environmental parameters such as ambient temperature. For example, a proprietary or open-source solution such as Node.js or Drools can be used to run the task engine.
[0161] Task engines 144 and 141 can run as event processing software having a low / no-code interface, such as a GUI 133 or 123, that allows users to create and maintain rules 132 and 137 without requiring programming skills. The rule set representation may enable task engines 144 and 141 to check inbound requests, particularly whether the inbound requests are valid. This allows rule 132 to perform machine-independent checks, while at least some of rule 137 may perform machine-specific checks, for example, checking whether control parameters, such as temperature or rotational speed values, are supported by and safe for the machine that should operate according to these control parameters. Executing rules by a task engine may involve comparing control parameters included in or derived from a request with reference values, a history of each control parameter previously used by each machine, a predetermined syntax, or a predetermined fixed or dynamic range.
[0162] The reference values and thresholds used by the first security interface submodule 120 to verify the request are stored in the plant environment database 130 and can be read from the plant environment database 130, and the reference values and thresholds used by the second security interface module 124 are stored in the plant machinery database 128 and can be read from the plant machinery database 128.
[0163] In addition to, or instead of, the task engines 144 and 141 trained machine learning models, such as neural networks, to check control parameters. For example, a trained machine learning model might have been trained on a training dataset containing at least some of the control parameter values previously used to operate a machine, and it might have learned to correlate these control parameter values with information about product characteristics and / or manufacturing process safety.
[0164] According to some examples, a security interface submodule 122 contains a first function (F1', F2'), and a second submodule 124 contains a second function F1, F2, thereby the structure of the first and second functions (i.e., the number and type of input and output arguments) is continuously synchronized between the first and second submodules so that any change in the structure of the second function (F1, F2) in the second submodule 124 is propagated to the first function F1', F2' in submodule 122. The names and / or structures of the second functions F1, F2 may reflect the names and structures of the respective functions of the PLC / PCS interface 125 that directly control one or more of the machine 140. A client request may be or include a call to one or more of the functions. Since the client can only trigger the execution of a function after successful authentication and request verification, and because only a subset of the functions of the PLC / PCS interface 125 are accessible by the security interface functions F1, F2 / F1', F2', automatically synchronizing the function structures may have the advantage of making calls to PLC / PCS interface functions transparent to the client without giving the client direct, unrestricted access to interface 125. By synchronizing the structure of functions F1 and F2 of the second submodule 124 with the structure of functions F1' and F2' of the first submodule 122 of the security interface 142, or with the respective functions of multiple first security interface submodules of multiple different L3 level IT infrastructure systems, it may be possible to transparently integrate an L2 level IT infrastructure into two or more different L3 level IT systems. Thus, functions F1 and F2 can similarly be used and called by two or more different security interface submodules 122 and their respective L3 level IT systems.
[0165] Any request to control and / or reconfigure the machine, presented by a remote user 108 or another client, is not presented directly to the security interface 124, but rather via a service interface 120, which may be part of the system's L3 level IT infrastructure. For example, the service interface 120 may include customized web service interfaces for each of several different client types, such as an edge computer system 110, a remote user using VR glasses and / or a VR application presenting a request, or a customer client application attempting to order a particular product and initiate its production. Each of these services may be accessible via a REST API (representational state transfer application interface). The use of a REST API can ensure the system's flexibility and scalability. The REST API can protect the security interface from untrusted clients, implement client authentication procedures, and enforce that only requests from authorized clients are forwarded to the security interface.
[0166] Upon successful request verification by the first submodule 122, the first submodule or the task engine contained within the first submodule may transfer the request or control parameters contained in or derived from the request to the second submodule 124 by calling one of the functions F1, F2 of the second submodule via the service interface 121.
[0167] As shown in the illustrated example, both service interfaces 120 and 121 may be implemented as web services using an industry-standard web server, thereby exposing the first functions F1' and F2' via the REST API of interface 120, and thereby exposing the functions F1 and F2 via the REST API of interface 121.
[0168] The system includes multiple firewalls 114, 116 that protect the automation system 103 and the security interface and other components from unauthorized access. An attacker attempting to modify the plant machinery database would have to overcome multiple firewalls. Each firewall functions as a network security system, monitoring and controlling incoming and outgoing network traffic based on predetermined security rules. This establishes a barrier between trusted networks or subsystems and untrusted networks or subsystems.
[0169] Some embodiments may include a log database, and the security interface 142 may be configured to record the results of all requests and request validations in the log database. This can facilitate error analysis and fraud detection. In some examples, the plant environment database 130 is used as the log database.
[0170] According to some examples, the system, for example, the system's L3 level IT infrastructure, may include a visualization engine 134 configured to allow a remote user 108 to present requests to a security interface via VR glasses. The visualization engine may support collaboration between the remote user 108 and one or more local operators 146 working within the plant via shared virtual reality (remote user) or augmented reality (local user, not shown). For example, the visualization engine 134 may be operably coupled to a database 130 containing data objects that are digital twins of plant objects, particularly machine 140. The database may also include objects that are digital representations of the remote user 108, particularly avatars, so that the coordinate systems of these objects in the database 130 are continuously updated with the current positions of each object and user, and the positions of these objects and users in a shared metaverse coordinate system are continuously mapped to the plant's real-world coordinate system.
[0171] The system may further include an identity provider 135, such as an enterprise identity provider like Active Directory, Azure AD, or any LDAP service. Any client can be authenticated by identity provider 135. Depending on the requesting system, authentication can use a personal ID or a functional ID / machine ID. The service interface 120 may support different authentication workflows for different types of clients. Similarly, company authentication standards can be applied to systems and authentication processes, such as single-factor or multi-factor authentication, authentication information, certificates, etc. Identity provider 135 may be configured to check the authorization of the requesting client based on the client's group and group membership.
[0172] In some embodiments, the security interface 142 does not directly store the control parameters provided in the validated request in the plant machinery database. Rather, the security interface calls the database service interface, which stores the control parameters in the plant machinery database. The plant machinery database may be configured to allow write access only to the database service interface and optionally to some further trusted entities. This further enhances security and can protect the automated system from unauthorized operation.
[0173] As can be inferred from Figure 2, system 100 implements a one-way and highly secure communication channel for transferring control parameters contained in requests from clients 108, 106, and 110 to the machinery in the plant. The requests and / or control parameters must successfully pass multiple firewalls, request verification steps, and additional security checks such as authentication at the service interface 120 via the ID provider 135 before the parameters are finally stored in the database 128 so that the parameters are accessible to the machinery.
[0174] The system, particularly the L3 level IT infrastructure of the system, may include a communication module, which may include a key manager module. The communication module may establish an encrypted one-way communication channel between the service interface 120 and the security interface 142. The communication module may also establish encrypted communication channels between the service interface and a first submodule of the security interface, and between the first submodule of the security interface and a second submodule. For example, as used herein, an encrypted communication channel may mean that only the first submodule of the security interface is permitted to receive data from and access the service interface 120. In some embodiments, the communication module may further include a user registry, user-specific keys, and other user-related data. The user registry may include registered local users, registered remote users, and other clients.
[0175] According to some embodiments, the system 100 includes a feedback channel 143 separate from the communication channel used to transfer control parameters to the plant machinery database. For example, the first and second submodules of the security interface may each include a function to report whether a processed request was accepted or rejected. Preferably, the reason for rejection (e.g., authentication failure, invalid control parameters, etc.) and / or machine status information are not communicated to the client.
[0176] According to some embodiments, a first submodule of the security interface, and optionally further components of the system's L3 IT infrastructure, and a second submodule of the security interface, and optionally further components of the IT infrastructure system at the L2 level, are instantiated within different virtual machines running on different virtual machine hosts. The virtual machines may be containers, for example, Docker containers running on different container management systems. This can improve the security and robustness of the system because the sensitive L2 layer is isolated and protected from the L3 level and from untrusted entities that have successfully infiltrated the L3 level.
[0177] According to a preferred embodiment, the system is configured to process requests using a predetermined set of processing steps, and the system accepts requests from untrusted sources such as remote clients 106, 107, 108, and 110.
[0178] First, the client submitting the request must successfully authenticate at the service interface 120 by providing the identity provider 135 with one or more certificates, such as a signed certificate, a secret shared with the security interface, biometric data, a password, whitelist presence, or a combination thereof. Only if the client has authenticated itself as a trusted entity with the identity provider does the service interface forward the request to the security interface, in this case to the first submodule 122 of the security interface 142. According to the embodiment, authentication of the entity at the service interface includes checking the integrity of the request, such as signature verification or checksum verification.
[0179] The security interface, in this case the security interface submodule 122, verifies the request by performing various validity and / or safety checks of the control parameters included in the request, thereby, preferably, based on global rules rather than machine-specific (machine-independent) rules. For example, some rules may analyze whether the control parameters are acceptable considering current weather conditions such as ambient temperature or humidity. Request verification may include checking whether the parameter values of a given control parameter are specified with the correct data type (e.g., integer, string, boolean, etc.). Verification may include checking whether requests to modify a particular control parameter have been received at a maximum permissible frequency or less, for example, to protect the system from a denial-of-service attack. Only if the verification returns that the request is valid (the control parameter is valid and safe), submodule 122 forwards the control parameter to the automated system-side submodule 124 of the security interface 142. In addition or alternatively, the security interface may check whether this request, in combination with a predetermined number of previously received requests, modifies a particular control parameter and, as a result, exceeds a maximum permissible variation threshold. If the variation is too large, this may indicate that the entity submitting the request is not familiar with each machine, or that multiple users are trying to move the manufacturing process in different directions.
[0180] According to some embodiments, request verification by the security interface also includes checking whether the client submitting the request has the necessary permissions to modify a particular control parameter. For example, if remote user 148 is not authorized to modify the temperature of a particular tank, the user's request to modify the temperature of this tank is deemed invalid. In addition or alternatively, the verification request may include a simulation of the future state of one or more machines affected by the change in the control parameter. If the simulated future state is associated with a violation of constraints, such as a low-quality product or a production process considered unsafe, the request is deemed invalid.
[0181] Submodule 124 verifies the transferred control parameters, for example, by performing various further validity and / or safety checks, thereby including, preferably, machine-specific and / or plant-specific rules. Only if the verification returns that the request is valid (the control parameters are valid and safe), submodule 124 transfers the control parameters to a database service interface configured to store the control parameters included in the request in the plant machinery database 128.
[0182] According to the embodiment, the requirement verification performed by the security interface may be used to determine whether the control parameters specified in the requirement are reasonable, achievable, acceptable, and safe for the plant and its machinery. The verification is accompanied by the security interface having at least rough knowledge of the processes performed by the machinery during the manufacturing process. For example, if the requirement specifies a requirement to lower the temperature of a reaction tank by 10°K, the security interface must check how this change will affect the specific machinery and control signals, and whether the safety parameter range will be exceeded as a result of the temperature reduction.
[0183] According to some embodiments, the security interface is further configured to perform mapping of control parameters specified in the request. In particular, if the security interface is a distributed security interface, the control system unit of the security interface can perform the mapping process. During mapping, the security interface determines how changes in specified parameters affect other control signal thresholds and machine settings, which can also be represented and controlled by their respective control parameters in the plant machinery database. For example, to achieve a 10°K temperature drop in a tank, it may be necessary to decrease the activity of heating elements and / or increase the activity of cooling elements. It may also be necessary to increase the stirring speed to compensate for an increase in the viscosity of the fluid contained in the tank. During mapping, one or more further control parameters are determined, the values of which depend on the value of one of the control parameters specified in the request. Also, parameter values of further control parameters (e.g., desired stirring speed, cooling speed, and / or heating intensity) are determined after the value of one control parameter has been changed.
[0184] Preferably, any additional control parameters identified during the mapping step are also validated, i.e., checked to see if they are achievable, reasonable, and / or safe. If the mapped parameters fail validation, the entire request may be rejected, and the control parameters in the request are not stored in the database 128.
[0185] After the control parameters are successfully validated and mapped, and the mapped parameters are successfully validated, the mapped parameters are transferred along with the control parameters originally included in the request to the database service interface 126, and are finally stored in the plant machinery database 128.
[0186] After the mapping step is completed, the control parameters in the request and any additional control parameters identified during the mapping are stored in the plant machinery database.
[0187] In a preferred embodiment, the security interface is configured to generate an acceptance request after the acceptance request has been successfully validated. The acceptance request is a request configured to prompt a user 146 working locally at the plant or software included in the security interface (not shown) to accept a requested change to one or more control parameters stored in the plant machinery database. For example, the acceptance request may be displayed to the local user 146 via a local operation user interface, such as a display included in or coupled to one of the plant's machines 140, or may be output in other ways. An acceptance check may be the final step in request validation performed by the security interface. For example, if the security interface is a distributed interface, the acceptance check may be performed by a security interface submodule 124. The local user / software sends an acceptance message to the security module only if the local user 146 or software included in the security interface accepts the proposed control parameter setting. The request is considered successfully validated (valid) only if the local user or software accepts the proposed change. Otherwise, the request is considered invalid, and the control parameters included in the request are not stored. For example, a request from a remote user 108 to lower the temperature inside a reaction tank may trigger the creation of an acceptance request displayed to the local operator 146 via the reaction tank's display. The local operator may have a better understanding of the overall manufacturing process and / or critical status parameters of the tank than the remote user. For added safety, the local operator 146 must confirm the new control parameters, for example, by clicking the "OK" button displayed on screen 125. If the operator does not accept the proposed parameter change, the safety interface does not transfer the control parameters to the machinery database 126.For example, the security interface may determine that a request is invalid if it does not receive an acknowledgment message from the local operator 146 within a predetermined timeout interval.
[0188] If a valid request is confirmed by local user 146, the security interface submodule stores the respective control parameters in the plant machinery database.
[0189] In other embodiments, the security interface may not be implemented as a multi-module distributed system, but may be entirely part of the L2 or L3 level IT infrastructure (and their respective virtual machines).
[0190] Figure 3 shows a block diagram of a system 300 for monitoring a manufacturing plant. The system includes an automation system 103 which includes several machines 140 in the manufacturing plant and a plant machinery database 128. The plant machinery database includes machine control parameters and spatial and / or status information of physical objects (machines and / or objects processed by machines).
[0191] The automation system is configured to automatically operate machinery according to control parameters in a plant machinery database. For example, the automation system may include a PLC and / or PCS interface 125 to allow local operators and / or safety interfaces 142 to operate machinery through these interfaces 142.
[0192] The system further includes an update engine 160, which is software configured to continuously receive spatial and / or status information of physical objects from a plurality of sensors 162 during the ongoing manufacturing process (e.g., at least once per hour, or at least once per minute, or at least once per second) and to update the machinery database 128 using the received information. For example, the sensors may include temperature sensors, humidity sensors, pH meters, and internal machine sensors configured to determine the operating state or mode of a machine (e.g., the rotational speed of a centrifuge or agitator, the speed of a conveyor belt, the open / closed state of doors and other openings).
[0193] The system further includes a visualization database 130 containing a subset of data from the plant machinery database.
[0194] System 300 further includes a replication module 150. The replication module is software configured to continuously select data from the plant machinery database data (for example, at least once per hour, or at least once per minute, or at least once per second) that enables the generation of digital visual representations of one or more physical objects, thereby replicating only the selected data, without control parameters, into the visualization database. Thus, the replication module can be considered to filter the data contents of the plant machinery database so that only a selected subset of the data is replicated into the visualization database 130. For example, the visualization database may include 2D or 3D models of machines and / or objects processed by the machines. The models may be static models or dynamic models that can be used to visualize the state of the machines or the state of the manufacturing workflow. In addition, the visualization database may include spatial information of objects, such as the current orientation of robots and other machines or machine parts, and the location of extracts or products in a production line. Preferably, the spatial information does not include information that enables the identification of the precise geographical location of each physical object. The 2D or 3D models of at least some of the machines are not scaled to actual size and / or represent a coarse-grained abstraction of the machines. This may allow for the protection of the structural design of the machines and other sensitive information, such as know-how regarding the total / maximum production capacity of the plant, machines, or production lines.
[0195] The system further compresses the visualization engine 134. The visualization engine is a software program, for example, a monolithic software application or a set of interoperable software programs configured to generate digital visual representations of one or more physical objects as a function of data in a visualization database. Preferably, the visualization engine does not have access to the plant machinery database, but rather uses a subset of data replicated in the visualization database by a replication module as the basis for generating visual representations of one or more physical objects involved in the plant's manufacturing process, particularly machines involved in the process and / or objects processed by the machines.
[0196] In some examples, the replication module 150 may use a streaming protocol to continuously stream database updates from the plant machinery database 128 to the visualization database 130. For example, Apache Kafka may be used to create a stream of measurements continuously stored in the plant machinery database and transfer them to the visualization database. The measured parameter values may indicate the orientation or state of one or more machines and / or the result of previously executed control commands providing new configuration data via requests. By streaming the measured parameter values to the visualization database, the visualization engine gains access to the measured parameter values.
[0197] The visualization engine is interoperable with one or more client software programs running on each client device, including display devices 154 and 108. The client software receives visual representations of physical objects from the visualization engine and displays one or more visual representations of physical objects to the user on each display device. This allows the user to monitor the manufacturing process without disclosing sensitive control parameters or other sensitive data and know-how.
[0198] For example, client software that interoperates with a visualization engine may be software configured to display visual representations on a 2D screen, such as the screen of a smartphone, notebook, or desktop computer. This could allow remote users to monitor production processes using standard devices without requiring the user to use specialized equipment such as VR glasses.
[0199] In another example, client software interoperating with the visualization engine could be VR software (virtual reality software) configured to display visual representations through the user's VR glasses, thereby giving the user a sense of immersion, that they are spatially near the physical objects represented by the visual representations, even though they may be far away from the plant.
[0200] In another example, client software interoperating with the visualization engine may be augmented reality (AR) software configured to display visual representations via AR glasses worn by a local user 146 working in the plant, thereby providing the user with additional information that may be useful in operating or maintaining the plant's machinery. For example, system 300 may further include a security interface 142 configured to receive and verify requests from remote clients 106, 107, 108 to operate one or more machines. The security interface may be configured to prompt the local user 146 to accept the requested action via a visual object generated by the visualization engine and displayed via the local user's AR glasses. For example, the visual object may be a menu describing the requested action and / or the identity or role of the requesting user, and the menu may include one or more selectable items, such as buttons, that allow the local user to accept or reject the requested action. In addition or alternatively, the visualization engine in interoperation with the AR software may cause menus, text, videos, or other types of data related to the machinery or manufacturing process to be displayed on the AR glasses. For example, the data may include text or video instructions on how to operate or maintain the machine, a GUI that allows a local user to input configuration data locally, or alarms or error messages.
[0201] A remote user wearing VR glasses to remotely monitor the manufacturing process may be the user who submitted the request. However, the request may also be submitted by another remote user or remote client software, and the user wearing the VR glasses 108 may simply be monitoring the process.
[0202] According to one embodiment, the visualization database 130 includes, for at least one of the machines, two or more different user role-specific models of the machine. The visualization engine is configured to identify the role of a remote user wearing VR glasses, identify one of the models assigned to this role, and use the identified model to generate a visual representation of the machine. The different models may differ from one another in terms of the degree of structural detail or status information disclosed in the model. This allows for flexible and granular control over the level of detail that the remote user can see.
[0203] The security interface 142, and its interoperability with the client, PLC / PCS interface 125, and machine 140, may be implemented and carried out as previously described herein for other embodiments and examples. However, the security interface is optional, and the plant machinery database 128, visualization database 130, visualization engine 134, update engine 160, and replication module 150 may also be used in computer systems for monitoring and / or operating the manufacturing process without including these optional components. Using the database replication mechanism described herein in combination with the security interface may have the advantage of providing a highly secure system for remotely monitoring and controlling an automated manufacturing process. Only a one-way communication channel exists for transferring control parameters from a remote client to the machine, and there is only a further one-way path for providing visual feedback to the remote user, ensuring that the remote user cannot access or view sensitive control parameters or know-how, as they are merely viewing predetermined typically simplified visual representations of real-world objects in the form of a digital twin.
[0204] Figure 4A shows an example GUI 400 that allows a user 146, for example a local user, to monitor and / or control the status of the manufacturing process. Because the status information may reveal sensitive data of the manufacturing process, the GUI 400 may be accessible only from within the automated system / plant and not by remote users.
[0205] In the illustrated example, a remote user or edge computer system may be requesting that the “target bulk density” control parameter 402 be set to a value of 115,000 g / l. During the mapping operation performed by the security interface, the security interface may calculate additional control parameter values for the temperature 408 and pressure 406 parameters. For example, the manufacturing process may be a chemical synthesis, and the security interface may include a predictive model configured to predict temperature and pressure values that are likely to provide the substance at (at least approximately) the desired bulk density. The predicted bulk density 404, as well as the predicted temperature and pressure for each reaction vessel, may be calculated during the parameter mapping step, passed by the security interface to the database service interface, and stored in the plant machinery database. One or more of the plant machinery 140, for example, a local computer, may be configured to read the parameters from the plant machinery database and generate a GUI that displays the parameter values (the target bulk density specified by the requesting entity and the bulk density, temperature, and pressure predicted by the service interface).
[0206] The local user can choose whether to manually or automatically set the mechanical parameters, pressure, and temperature to achieve a given target bulk density of the material produced by the manufacturing plant. When the mechanical control values are set to "automatic mode," as shown in Figure 4A, the control parameters predicted by the safety interface are automatically set and used as a basis for controlling the synthesis process and process conditions. The prediction is preferably performed at the L2 level of the safety interface. As a result, the automatically calculated parameter values, e.g., 8.48 bar and 37°C, are automatically set and can be continuously updated during the ongoing manufacturing process.
[0207] According to some embodiments, the local operator 146 must select either "automatic mode" or "manual" at least once to start the synthesis process. By selecting "automatic mode," the local operator sends an acceptance message to the security interface indicating that the local operator considers the specified control parameters, particularly temperature and pressure, to be safe and appropriate.
[0208] Figure 4B shows another example 410 of GUI 144, which allows a local user to monitor and / or control the manufacturing process. Corresponding to GUI 400 shown in Figure 4A, the illustrated GUI 410 has the machine control values set to "manual" by the local user. As a result, the local user has the ability to edit the values calculated by the safety interface, thereby overriding control parameters that are considered unsafe, unattainable, or otherwise problematic.
[0209] Figure 5 shows a distributed system 500 for controlling manufacturing processes within multiple plants.
[0210] A user 108 who can work in Plant A and is therefore far away from Plant B may wear VR glasses. Through the VR glasses, user 108 can view video and / or images acquired by cameras placed in Plant B. For example, the camera may be mounted on a movable robot 510 whose movement and / or position can be controlled by a remote operator 108. Thus, the remote operator views, through the VR glasses, what the robot 510 sees as it moves around Plant B. Image and / or video data may be transmitted from the robot 510 to the remote user via a database replication module and a visualization engine, as shown in Figure 3. At least some of the machines or physical objects processed by the machines are represented to the remote user via the VR glasses in the form of a visual digital twin as part of "virtual reality". When a user wants to monitor the operation of one of the machines 140 in the plant, for example, to rotate the robot 510 to the left, user 108 simply needs to rotate their own body to the left. Sensors in the VR glasses recognize changes in position and / or orientation and transmit a turn-left command in the form of a request to control the robot so that it turns left, in the new position and orientation. Requests to move the robot are transmitted to the robot via the security interface 142, as described herein with respect to embodiments and examples. For example, the transfer of a request from L3 to L2 may include authenticating the remote user 108, validating the request, mapping control parameters, validating the mapped control parameters, and storing the new position or movement details in the database 128. The robot 510 and other machines 140 are configured to repeatedly read control parameters from the database 128 and adjust their position and / or the actions performed accordingly.
[0211] The current position and / or orientation of one or more of the machines 140, including robots, may be continuously sensed and stored in the plant machinery database 128, and the acquired position data may be used to continuously update the database 128. At least some of the data indicating the position and / or location of robots is replicated to the plant environment database 130, which is used as a data base for a visualization engine to generate and display a continuously updated visual representation of the plant's robots and / or other machines 140 to a remote user.
[0212] In some embodiments as illustrated, the visualization engine 134 can be configured to create an avatar 505 which is a virtual representation (or "twin") of the remote user 108. The avatar can be displayed to one or more local operators 146 working at Plant B and wearing AR glasses. Thus, the local operators 504 view the digital twin of the remote user through their AR glasses.
[0213] User 146 may wear AR glasses, which means that User 146 can still see the actual machinery 140 at Plant B. However, several virtual objects, including the avatar 505, are displayed in the AR glasses as an overlay on the “real world” which is still visible through the AR glasses. Thus, User 146 perceives a sense of reality as if the remote user 108 were actually present on the premises of Plant B, as they see the avatar moving and / or hear the avatar speaking through the AR glasses. The impression of the avatar and other virtual objects through User 146's AR glasses may be generated by an augmented reality application 504 installed locally in the IT infrastructure of Plant B. In addition, the IT infrastructure of Plant B may include a virtual reality application 506 configured to interoperate via a visualization engine 134 with a virtual reality application 524 installed locally in the IT infrastructure of another plant, e.g., Plant A. This allows operators of different plants to share a common virtual reality, which could be useful for users working in different countries who wish to discuss manufacturing-related issues without needing to meet physically.
[0214] The visualization engine can be configured to align virtual objects, such as avatars, virtual user menus, instruction manuals, or videos, with the coordinate systems of virtual reality and the "real world." Because the visualization engine has access to the global object representation layer, any virtual object, such as a machine instruction manual, can be viewed by all users wearing VR or AR glasses and registered with the visualization engine.
[0215] Remote user 108 can not only remotely control some manufacturing tasks in plant B, but also control some manufacturing tasks in plant A. For example, user 108 may normally be a local operator in plant A, but may want to remotely control tasks from home. In this case, user 108 is also a remote user of the system for controlling manufacturing in plant A.
[0216] Remote control of one or more machines 526, 528, 530, 532, and / or 534 by user 108 via security interface submodules 542, 544 may be carried out as already described with respect to other figures, e.g., Figures 1, 2, and / or 3. Service interfaces 540, 120 may be based on a REST API, may include streaming applications such as Apache Kafka, and may use MQTT or WebSocket protocols to forward requests.
[0217] At the L3 level, security interface submodules 542 and 122 typically contain or access rules and / or object representations relating to manufacturing site, cluster, or plant-level objects that are not machine-dependent. These rules and object representations can be used to validate requests at the L3 level.
[0218] At the L2 level (automation system level), security interface submodules 544 and 124 contain or access rules and / or object representations relating to plant, line, or machine-level objects. These rules and object representations can be used to validate requests at the automation system / L2 layer.
[0219] Embodiments of the present invention enable a remote user 108 to control machinery in multiple plants without imposing security risks on the plants.
[0220] Figure 6 shows a system 600 configured to display various virtual objects in a position-dependent manner through AR glasses for a user wearing AR glasses and taking on the role of an "operator". For example, the operator can wear the AR glasses and see actual physical objects, such as plant machinery or objects processed by machinery. Task instructions A1 to A6 are shown by the AR glasses at predetermined x / y / z coordinates in an augmented reality coordinate system aligned with the real-world coordinate system. For example, the AR glasses may use the xy coordinates of machinery such as a loading unit, a conveying and heating unit, or a packaging unit to display their respective instruction manuals or images at a predetermined distance from the real-world position of the real-world object.
[0221] For example, a user wearing glasses may have a registered user account in the user database of the visualization engine and / or ID provider 135, and the user ID may be associated with one or more user roles, in this case the "operator" role. In addition or alternatively, each user role may optionally include one or more user privileges.
[0222] Therefore, the visualization engine is configured to select the content of incoming data to display based on one or more user roles and / or one or more user privileges associated with the user ID (e.g., "filtering" the content of incoming task instructions). For example, one or more user roles include, in a non-exclusive and exemplary embodiment, operator roles, maintenance roles, engineering roles, managerial roles, and guest roles. One or more user privileges and / or roles restrict and determine which virtual objects / information are displayed through the AR glasses. For example, a user privilege for the engineering role may define which machines in the plant a user associated with a user ID that has the engineering role can access, in the sense that they can view data corresponding to machines through the display of each task instruction. A user associated with a user ID may have two or more roles and two or more user privileges.
[0223] In the example shown in Figure 6, the user wearing AR glasses is assigned the role of "operator." As a result, the executable program logic causes the AR glasses to display view 600, and when the user approaches the input unit, they can view instruction manual A1 regarding the filter cleaning method in view 600, and further view additional task commands and their respective command images A2 and A3. When the user approaches the conveying and heating unit, they view task command A7 through the AR glasses. Similarly, when the user approaches the packaging machine, they view task commands A4-A6. Tasks A1-A7 relate to standard tasks that must be performed in the normal operating mode of the industrial plant.
[0224] Figure 7 shows a system 700 configured to display various virtual objects in a position-dependent manner via AR glasses to a user assigned the role of "maintenance worker." When the maintenance worker wears the AR glasses and looks at the actual machine, they see task commands related to maintenance rather than operational tasks. For example, when the user approaches the loading unit, they see task command B1 to replace a defective pressure sensor 1234, and / or when they approach the conveying and heating unit, they see command B2 regarding how to inspect the heater.
[0225] Figure 8 shows a manufacturing plant system 800 that displays the avatar of a remote user 108 in the controlled plant using spatial anchors.
[0226] A human remote operator 108 may be an expert in maintaining one or more machines in a plant, for example, a complex machine 808. Both the machine and the local operator 146 are located at Industrial Plant B in Country B. The remote user 108 is located in a different location, for example, within Plant A in Country A. The remote user 108 wears VR glasses operably coupled to a virtual reality application 524 ("VR application"). The VR application is interoperable with an AR application 504 operably coupled to AR glasses worn by the local operator 146. The VR application 524 and the AR application 504 can be connected to each other via a visualization engine configured to spatially align virtual reality and augmented reality virtual objects with respect to each other. The AR application enables the remote user to support local colleague 146 in various operations and / or maintenance tasks performed locally using or on machine 808. The AR application is configured to create an avatar 505 for the remote user and position the avatar at a predetermined location, for example, close to machine 808 where user 108's support is needed.
[0227] According to a preferred embodiment, the VR application 524 is configured to generate a virtual reality for a remote user 108, which enables the remote user to view local user 146 and / or other real-world objects of the industrial plant, such as machine 808, as they are perceived from the viewpoint of avatar 505. For example, the remote user can view the raw values of the production line and machinery through a robot equipped with a camera and / or further sensors positioned in the same position and orientation as avatar 505. For example, the robot may be robot 510 as described with reference to Figure 5. In some examples, plants A and B and their respective IT infrastructures may be made to operate as described with reference to Figure 5.
[0228] In some embodiments, the robot is remotely controlled by a remote user 108, enabling the remote user to perform actions defined by the robot. The avatar has a defined position within a 3D environment generated by the AR application 504 and displayed to the local user 146 via AR glasses. The local user 146 (AR user), who is human, and the machine 808 also have defined positions within a 3D environment used as the coordinate system for augmented reality ("mixed reality").
[0229] An AR application 504 interoperating with the visualization engine is configured to ensure that the VR coordinate system viewed by the remote user and the AR coordinate system viewed by the local user 146 via AR glasses have the same coordinate system as the reference for positioning virtual objects (avatars, holograms, GUIs, etc.). Both the AR application 504 and the VR application 524 receive positional information of virtual objects displayed in augmented / virtual reality from the same global object representation layer 503. According to some embodiments, a VR application program 524 for a remote user 108 generates a virtual reality ("manufactured metaverse") in which an avatar of a human local operator 146 is shown with a defined optical representation (e.g., name only, or even 3D avatar shape) so that the remote user can view the local user within the VR application (not shown). Conversely, the local user (AR user) 146 can perceive the remote user 108's avatar 505 as a hologram (for example, as a name only or as a 3D avatar shape) within the "manufactured metaverse" presented to the local user 146 as augmented reality via AR glasses 804.
[0230] According to one embodiment, the AR glasses 804 include a microphone 810 and an acoustic output interface 812, such as a speaker that provides a user interface to the local user. Similarly, the VR application 524 may include a user interface that includes a microphone and an acoustic output interface to enable a remote user 108 to interact with the VR application. The AR application program 504, operably coupled to the local user's AR glasses, interoperates with the VR application so that the remote user 108 and the local user 146 can converse with each other. Preferably, the AR application uses the positional information of the local user and the remote user's avatars in a shared coordinate system to control the volume of the acoustic output interface of the AR glasses. That is, the closer the local user 146 is to the avatar 505, the louder the volume. Similarly, the sensitivity of the microphone may be fitted as a function of the distance between the two users in a shared coordinate system. That is, the greater the distance, the lower the sensitivity of the microphone.
[0231] Therefore, the AR system according to the illustrated embodiment, which includes AR and VR applications, enables two users to collaborate using a shared coordinate system also referred to as the “manufacturing metaverse.” The manufacturing metaverse consists of a virtual coordinate system shared by all users and AR objects within the metaverse, thereby mapping this virtual coordinate system onto real-world objects 808 of an industrial plant and presenting them as an overlay. This allows an experienced remote user to experience the same or similar visual context as a guided local user.
[0232] According to the first scenario, thermoplastic polyurethane (TPU) is produced at Plant B. The production line has been modified to adapt to a new product that was not previously produced on this line. The remote operator is an expert in this type of production and lives at location A (Plant A, Country A). The remote user instructs the local operator on when and which valves should be inspected. The remote user also notifies the local user of important matters that the local user should pay attention to in order to ensure proper and smooth production. Furthermore, the remote user can instruct the local user on the appropriate action steps at the appropriate time and in the appropriate circumstances.
[0233] According to the second scenario, TPU production is already underway at location B. During the night shift, the work coordinator for that shift falls ill. An experienced human operator located remotely at location A (plant A, country A, other time zone) can provide support for production at location B during the day shift. This operator uses their avatar for direct collaboration with one or more human local operators. The remote user can coordinate the work of local workers by creating processes / tasks that local users (AR users) can perform.
[0234] According to the third scenario, autonomous TPU production is taking place at Plant B. Under normal / standard conditions, the line can operate completely autonomously. Manual intervention is only required in the event of an unexpected situation. This supervision is performed remotely via the manufacturing metaverse using a VR application. One or more robots are coordinated and triggered by a human remote operator by creating / using appropriate processes / tasks for the robots. If the human remote operator needs to view actual photos and / or video streams of the local situation, the remote user can move to the target machine using VR and AR applications associated with the robot's control program. The robot is equipped with a camera and controlled to take the same position and orientation as the remote user's avatar. When the robot reaches this position, the robot's camera is made to capture images and / or videos of the machine in front of the avatar / robot and transfer those images or videos to the VR application. The remote user will view the images and / or videos through the virtual reality created by the VR application. The robot is controlled to capture images and / or videos from the same position and orientation as the remote user's avatar in the mixed reality coordinate system of the industrial plant, so that the photographs and images show the machine in question from the same viewpoint as the human local operator would have at that position and orientation.
[0235] Embodiments of the present invention can be used in many other scenarios and industries. For example, embodiments of the present invention could be used in the automotive manufacturing industry, enabling experienced engineers to support colleagues working in other locations within an automotive manufacturing company.
[0236] Similarly, systems for representing ongoing manufacturing processes graphically via VR glasses, AR glasses, or other display types based on automated production control and / or visualization engines may be used in the chemical industry or any other type of industry where physical objects are processed to manufacture one or more products.
[0237] In some use case scenarios, robots can be used not only to acquire images or videos, but also to solve problems under the control of a remote user. For example, robots may be used to perform maintenance tasks in locations hazardous to human operators, such as in relation to chemical synthesis pathways involving hazardous chemicals, or in relation to tasks performed in environments contaminated or at risk of being contaminated with radioactive or hazardous chemicals.
[0238] According to some embodiments, spatial anchors are used to position virtual objects at a predetermined position and orientation relative to real-world objects such as machine 808. For example, it may be desirable to display a GUI hologram that allows a user to monitor and control machine 808 at a distance of approximately 40 cm in front of it.
[0239] To ensure that local user 146 always views the GUI hologram at this defined location in augmented reality, regardless of user 108's current location, the AR application generates and displays the GUI hologram at or at a defined distance from the spatial anchor. According to some embodiments, spatial anchors (i.e., at least the anchor ID and anchor coordinates) are stored in a database system so that they are accessible to the VR application 524. The VR application is configured to read the stored spatial anchors and generate and display a GUI hologram for the same virtual object, e.g., machine 708, at or at the spatial anchor.
[0240] According to some embodiments, spatial anchors are defined and created by placing machine-readable codes, such as QR codes® 811, 813, and 814, at various locations within an industrial plant. AR glasses may include a camera that acquires a digital image of the machine-readable code, extracts the encoded anchor ID therein, creates anchors with the coordinates of the machine-readable code in a real-world coordinate system, and stores these anchors in a database system. Alternatively, a user 146 may create a spatial anchor by performing an anchor creation gesture at a desired location in the real world. This gesture is captured by the camera of the AR glasses, and the spatial anchor is similarly created and stored by the visualization engine. The anchor ID may be automatically generated when the spatial anchor is created.
[0241] Figure 9 shows a coordinate system 900 that can be used by the visualization engine and VR application 524 to represent real-world objects and local user avatars in a virtual metaverse for a remote operator 108. The VR application 524 generates a virtual representation 908 of a real-world machine 808 in an industrial plant and displays the virtual representation to the remote user 108 using virtual reality display technology. This virtual reality coordinate system 900 may further include a virtual representation 904, e.g., an avatar, of the local user 146 working in the spatial vicinity of the real-world object 808. The distance between the virtual representations 908, 904 of the machine 808 and the local user 146 in coordinate system 900 corresponds to and reflects the actual distance of the real-world object. Coordinate system 900 may include a spatial mesh aligned with “real-world” objects such as the machine 808 and the local user 146 in the industrial plant. The mesh may also be aligned with the respective virtual representations 908, 904 (digital twins) of the real-world objects. In addition, the remote user 108 may be represented in this coordinate system 900 as a virtual entity, for example, an avatar 505 that can be viewed by the local user 146 via AR glasses 804. Figure 9 shows a coordinate system shared by the virtual reality generated by the VR application and the AR reality generated by the AR application, but preferably, the remote user 108 views real-world objects and virtual objects representing other users in the coordinate system 900 from the viewpoint (position and orientation) of the avatar 505.
[0242] Figure 10 shows a flowchart of a method for automating processes in a manufacturing plant. The method includes providing systems 100, 200, 300, 500 for automating processes in a manufacturing plant, 602, as will be described herein in various exemplary embodiments. The system may include several machines 140, 536 in the manufacturing plant, plant machinery databases 128, 548 containing control parameters for the machines, an automation system 103 for automatically operating the machines in the manufacturing plant according to the control parameters in the plant machinery database, and a security interface 142. The method further includes receiving requests from clients over a network (604) and verifying the requests by the security interface (604). If the security interface determines that the request is valid, the security interface stores the control parameters 402-408 contained in or derived from the request in the plant machinery database 608. The automation system automatically operates the machines according to the stored control parameters contained in or derived from the valid request 610. If the security interface determines that the request is invalid, the security interface returns a message to the client via the feedback channel indicating that the request was not executed (612). [Explanation of symbols]
[0243] List of reference symbols 100 Systems for Process Automation 102 Automation Systems (L2) 103 Automation Systems 104 Automation System (L3) 106 Client: Computer System 107 Client: Advanced Process Control Software 108 Client: Remote user using VR glasses 110 Client: Edge computing system 114 Firewall 116 Firewall 120 Service Interfaces 121 Service Interface 122 Security Interface Submodules 123 Configuration GUI for Rule 137 124 Security Interface Submodules 125 PLC / PCS interface for machines 128 Plant Machinery Database 130 Plant Environment Database 132 Rules 133 Configuration GUI for Rule 132 134 Visualization Engines 137 Rules 135 ID providers 140. Physical manufacturing assets (e.g., plants, production lines or units, machinery, devices) 141 Task Engine 142 Security Interface 143 Feedback Channels 144 Task Engines 146 local users 150 Replicated Modules 154 2D / 3D representations of physical objects / machines 200 Systems for Process Automation 202 Administrator 214 Local Operator 400 GUI 402 Control parameter "Target bulk density" 404 Further calculated control parameters 406 Further calculated control parameters 408 Further calculated control parameters 410 GUI 500 Systems 501 L3 IT Infrastructure System 502 Global Object Representation Layer 503 L2 IT Infrastructure System 504 Plant B's local AR application 505 Avatar 506 Plant B's local VR application 508 Plant B's local web application 510 Robot controlled by a remote user 512-518 Machinery / Devices 520 Plant A's local web application 522 Plant A's local AR application 524 Plant A's local VR application 540 Service Interfaces 542 Security Interface Submodule 544 Security Interface Submodule 546 Database Service Interface 548 Configuration Databases 526 Robots 528-534 Machinery / Devices 552 L2 IT Infrastructure Systems 554 L3 IT Infrastructure System 600 System Steps 602-612 700 System 800 System 804 AR glasses 808 Machines / Devices 810 Microphone 811 QR code 812 Audio Output Interface 813 QR code 814 QR code 900 coordinate system 908 Machine 808 Digital Twin 904 users 146 digital twin
Claims
1. A system for automating manufacturing plant processes (100, 200, 300, 500), Multiple machines (140, 536) of the aforementioned manufacturing plant, A plant machinery database (128, 548) including the control parameters of the aforementioned machine, An automation system (103) for automatically operating the machinery of the manufacturing plant according to the control parameters in the plant machinery database, We will receive your request. The requirements are partially verified using comparative values from the plant environment database or the plant machinery database. In response to the determination that the request is valid, the control parameters (402-408) included in or derived from the request are stored in the plant machinery database or directly in the PLC / PCS interface to the machine. A security interface (142) configured as follows: Includes, The automation system (100, 200, 300, 500) is configured to perform the automated operation of the machine according to the stored control parameters included in or derived from the valid request.
2. The system according to claim 1, wherein the security interface is configured to allow one-way transfer of at least the control parameters to the automation system via a control communication channel, and is configured not to return any machine-related control parameters or status information to the client (106, 107, 108, 110, 504, 506, 508) that made the request.
3. The system according to any one of the preceding claims, comprising clients (106, 107, 108, 110, 504, 506, 508) configured to generate the request and present the request to the security interface.
4. The client includes client software, The client software is configured to repeatedly generate and present requests to the security interface at a frequency of at least once per hour, preferably at least once per minute, preferably at least once per second, and in some embodiments at least once every 0.10 seconds, wherein the requests include one or more control parameters for controlling one or more of the operations of the machines, and / or The client software is configured to repeatedly predict one or more control parameter values that are optimal or suitable for controlling the operation of one or more of the machines, such that at least one feature of an automated production process performed by one or more of the machines is optimized, and to automatically and repeatedly present to the security interface a request including the one or more predicted control parameters, wherein the prediction of the control parameter values includes simulating the automated production process and the operation of one or more of the machines involved in the production process, according to claim 3.
5. The verification of the request is performed repeatedly by the security interface, in particular at a frequency of at least once per hour, preferably at least once per minute, preferably at least once per second, and in some embodiments at least once every 0.10 seconds, according to the system of any one of the preceding claims.
6. The verification of the aforementioned requirements includes conducting a validation check, and the validation check is: The value of the control parameter is achievable by one or more of the machines that operate according to the stored control parameter, and / or The value of the control parameter is safe for one or more of the machines that operate according to the stored control parameter, and / or The value of the control parameter is suitable for providing manufactured products that meet quality standards. The system according to any one of the preceding claims, comprising checking whether the control parameters included in or derived from the request satisfy one or more criteria selected from the group including the above.
7. The system according to any one of the preceding claims, comprising a service interface (120, 540), the service interface configured to receive the request from a client (106, 107, 108, 110, 504, 506, 508) and forward the request to the security interface, and the security interface configured to accept and process requests only when received from the service interface.
8. The system includes an ID provider module (135) operably coupled to the service interface, and the service interface is Having received the request from at least one client (106, 107, 108, 110, 504, 506, 508), Authenticate at least one of the aforementioned clients, In response to the success of authentication by at least one client on the service interface, the request is forwarded to the security interface. The system according to claim 7, wherein at least one client is configured not to forward the request to the security interface in response to authentication failure at the service interface.
9. The aforementioned security interface is Identify one or more further control parameters whose values depend on one or more of the control parameters specified in or derived from the above request, The system is configured to replace the at least one control parameter included in or derived from the requirement with one or more identified further control parameters, and / or to complement the control parameter included in or derived from the requirement with one or more identified further control parameters. The system according to any one of the preceding claims, wherein one or more identified further control parameters are stored in the plant machinery database to control the operation of one or more of the machines.
10. The aforementioned security interface is A first submodule (122, 542) configured to perform the first part of the verification of the requirement, wherein the first part of the verification uses general-purpose, machine-non-machine-specific and plant-non-plant-specific rules, A second submodule (124, 544) configured to perform the second part of the verification of the requirement, wherein the second part of the verification uses machine-specific and / or plant-specific rules, and The system according to any one of the prior claims, comprising at least the following:
11. The aforementioned system, A first virtual machine configured to host the first submodule of the security interface, A second virtual machine configured to host the second submodule of the security interface and Includes, The system according to claim 10, wherein the first virtual machine and the second virtual machine are hosted by different virtual machine hosts and / or isolated from each other via a firewall.
12. The system for process automation includes a multilevel system architecture, and the multilevel system architecture is A first level including one or more machines and optionally further objects involved in the execution of actual physical processes, particularly the sensing and manipulation of physical objects, A second level (L2) includes components for supervising, monitoring, and / or controlling the physical processes at the first level, A third level (L3) includes a manufacturing operation system component configured to manage the production workflow and produce the desired product by supervising, monitoring, and / or controlling the components at the second level, and It includes at least, The system according to claim 10 or 11, wherein the first submodule of the security interface is part of the third level, the second submodule of the security interface is part of the second level, and the components of the second level are protected from the components of the third level and higher levels by at least one security means, in particular a firewall.
13. The second submodule of the security interface includes machine-specific functions, each configured to control the operation of one or more of the machines according to the control parameters in the plant machinery database, wherein the number and type of input arguments and the number and type of output control commands of the one or more machine-specific functions correspond at least partially to the control interface of the machine controlled by each of the machine-specific functions. The first submodule of the security interface includes one or more general-purpose functions, each general-purpose function being assigned to one of the machine-specific functions. The system according to any one of claims 10 to 12, wherein the reception of the request by the first submodule of the interface triggers the execution of at least one of the general-purpose functions, and after the successful execution of the at least one general-purpose function, triggers the execution of one or more of the machine-specific functions assigned to the executed at least one general-purpose function.
14. The first part of the request verification is performed by the at least one general-purpose function, The system according to claim 13, wherein the second part of the requirement verification is performed by one or more of the machine-specific functions assigned to the at least one general-purpose function that has been executed.
15. The aforementioned system, The system automatically determines if the number or type of input arguments required by one of the aforementioned machine eigenfunctions, or the number or type of output arguments provided by one of the aforementioned machine eigenfunctions, The input and output arguments of the aforementioned general-purpose function are also automatically duplicated to one of the general-purpose functions to which the modified machine-specific function is assigned, so that the changes are reflected in the input and output arguments of the aforementioned general-purpose function. The system according to any one of claims 10 to 14, comprising a function synchronization module configured as follows.
16. The request is generated by a remote client (106, 108, 110) connected via a network to the system described in any one of the preceding claims, the security interface is used as a remote control access path for the remote client to the automation system and the machine controlled by the automation system, the remote client is selected from the group including a human remote user, an edge computer system, a remote client device, in particular a mobile device, or remote client software, the system described in any one of the preceding claims.
17. The system according to any one of the preceding claims, further comprising a visualization engine (134) configured to generate a graphic representation of a digital twin of the machine (140) of the plant and / or products manufactured by the machine.
18. The request is presented by a human remote user (108) wearing virtual reality (VR) glasses operably coupled to the visualization engine, and the visualization engine visualizes at least some aspects of a manufacturing process performed by the machine via the VR glasses, and / or The visualization engine (134) is configured to create augmented reality for one or more local users (146) working in the plant wearing AR glasses, the augmented reality including avatars of remote users (108) and / or virtual graphic objects that assist in maintaining or controlling one or more of the machines. Preferably, the visualization engine supports voicemail and / or chat between the human remote user and the local user (146) in the system according to claim 17.
19. It further includes a plant environment database (130), a visualization engine (134), and a database replication module (150), The plant machinery database (128) includes model, location information, and status information of the machinery and / or products produced by the machinery, wherein the location information is continuously updated to reflect the actual location and status of the machinery and / or products. The aforementioned plant machinery database is configured to prohibit access by the visualization engine. The database replication module is configured to continuously replicate only a predetermined subset of the data from the plant machinery database to the plant environment database, thereby filtering out at least some machine-related data, particularly highly sensitive machine-related data. The system according to any one of the preceding claims, wherein the visualization engine is configured to use only data contained in the plant environment database to generate a visual representation of the machine (140) of the plant and / or the products processed by the machine.
20. The aforementioned security interface is The system generates an acceptance request configured to prompt an entity (146), which is a human user or software program working locally in the plant, to accept one or more requested modifications of the control parameters stored in the plant machinery database, The aforementioned request for acceptance is provided to the aforementioned entity, Upon receiving a response indicating acceptance by the aforementioned entity, the control parameters included in or derived from the request are stored in the plant machinery database. The system according to any one of the preceding claims, configured as described above.
21. The system according to any one of the preceding claims, wherein the machine, which is driven automatically according to the stored control parameters included in or derived from the valid request, is a robot (510), in particular a robot controlled by a remote user (108) via a visualization engine.
22. The machine and / or another machine in the manufacturing plant, which are operated automatically according to the stored control parameters included in or derived from the valid request, include a local control interface, the local control interface enabling a local operator (146) to access and control the machine via a separate local communication channel, according to any one of the preceding claims.
23. A method for automating processes in a manufacturing plant, A system for process automation of the aforementioned manufacturing plant (100, 200, 300, 500), Multiple machines (140, 536) of the aforementioned manufacturing plant, A plant machinery database (128, 548) including the control parameters of the aforementioned machine, An automation system (103) for automatically operating the machinery of the manufacturing plant according to the control parameters in the plant machinery database, Security interface (142) and (602) To provide a system (100, 200, 300, 500) including, Receiving a request through the security interface (604), The security interface verifies the request (606), In response to the determination that the request is valid, the security interface stores the control parameters (402-408) included in or derived from the request in the plant machinery database (608), (610) The automated system operates the machine automatically in accordance with the stored control parameters included in or derived from the valid request. Methods that include...