Aggregate Server System
The system of aggregation servers addresses the single point of failure issue by replicating data and sessions across redundant servers, ensuring high availability and efficient session management in distributed control systems.
Patent Information
- Application Number
- JP2024522527
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2021-11-17
- Filing Date
- 2022-09-16
- Publication Date
- 2025-08-04
- Estimated Expiration
- 2042-09-16
AI Technical Summary
Existing systems with a single Aggregate OPC UA server can be a single point of failure, limiting the number of simultaneous sessions and posing a risk to the entire system, especially in distributed control systems with multiple OPC UA clients.
A system of aggregation servers that replicate structured data and sessions among redundant servers to prevent unauthorized access, manage session load balancing, and ensure seamless failover switching, using encrypted communication and load balancing strategies to maintain system availability.
Ensures high availability and scalability by preventing single points of failure, allowing for efficient handling of multiple sessions and maintaining uninterrupted communication with external clients.
Smart Images

Figure 0007717976000001 
Figure 0007717976000002 
Figure 0007717976000003
Abstract
Description
Background Art
[0001] An Aggregate Open Platform Communication Unified Architecture (OPC UA, also standardized as IEC 62541) server replicates the address spaces of individual OPC UA servers and provides an integrated coherent representation of the distributed address spaces on individual OPC UA servers. The Aggregate OPC UA server can be regarded as a proxy for remote individual OPC UA servers. In the context of integrating small servers configured for OPC UA-connected device devices, the Aggregate OPC UA server can handle more simultaneous sessions than a small device server can process, so the Aggregate OPC UA server can be regarded as a kind of extended code. Typically, such an embedded OPC UA server runs a maximum of two simultaneous sessions. In the context of a Distributed Control System (DCS), there can be more than two OPC UA clients to be connected to a device server, and the device server can be an individual small embedded OPC UA server.
Summary of the Invention
[0002] A single Aggregate OPC UA server can be, for example, a single point of failure affecting the entire system for a manufacturing site or other applications.
[0003] Therefore, the present invention is directed to a system of aggregate servers having the subject matter as described in the independent claims.
[0004] Advantageous modifications of the present invention are described in the dependent claims of this application. All combinations of at least two of the features disclosed in the specification, claims, and drawings are included within the scope of the present invention. To avoid repetition, the features disclosed according to this method are also applicable according to the system mentioned and shall be patentable.
[0005] Throughout this description of the invention, sequences of procedure steps are presented so that the process is readily understandable. However, those skilled in the art will recognize that many of the process steps can be performed in a different order and still yield the same or corresponding results. In this sense, the sequence of process steps can be varied accordingly. Some features are provided with word counts to improve readability or to make the assignment more explicit, but this does not imply the presence of a particular feature.
[0006] To achieve these and other advantages and in accordance with the purpose of the present invention, a system of aggregation servers is provided that includes a first aggregation server configured to establish a session for communicatively linking with at least one first system to be aggregated, and at least a second aggregation server configured to establish a session for communicatively linking with at least one second system to be aggregated. Thereby, the first aggregation server and the second aggregation server are configured to replicate mutually structured data provided by the first system to be aggregated and / or the second system to be aggregated to provide the first aggregation server and the second aggregation server with access to the structured data of each system to be aggregated. Additionally, the first aggregation server and the second aggregation server are configured to adjust respective sessions of the system of aggregation servers with at least the first system to be aggregated and / or at least the second system to be aggregated to prevent unauthorized access to at least the first system to be aggregated and / or at least the second system to be aggregated.
[0007] The mutually structured data provided by the first system to be aggregated and / or the second system to be aggregated can also be referred to as an "address space" or an "information model".
[0008] The system to be aggregated can be, by way of example, an embedded system and / or an embedded server that can be defined as a combination of a computer system, a computer processor, a computer memory, and input / output peripheral devices having a dedicated function within a larger mechanical or electronic system. Such an embedded server can be incorporated as part of a complete device including electrical or electronic hardware and mechanical components. An embedded server typically has real-time computing constraints since it controls the physical operation of the machine in which it is incorporated. An embedded server can control multiple devices.
[0009] The system to be aggregated can be an embedded system, particularly an OPC UA server for connecting OPC UA device devices.
[0010] An OPC UA server can be an example of a system to be aggregated and provides access to data and functions from embedded systems and / or embedded devices and / or from systems or subsystems from various devices.
[0011] A session can be, for example, a logical channel between a server as a system to be aggregated and a client as an aggregated server, particularly a device client of an aggregated server, and the structured data communicated within such a session is communicated in an encrypted form.
[0012] Information related to a session can include, for example, access rights and / or access information, such as encryption keys, and / or information models related to structured data to be exchanged within the session and / or address space, including keys used to execute a secure channel.
[0013] The mutual replication of structured data between aggregation servers can also include status data of each system to be aggregated and session configuration data shared between aggregation servers by replication, whereby each aggregation server has access to this structured data and / or status data through communication access to each system to be aggregated, and a session between the relevant aggregation server and the relevant system to be aggregated is established.
[0014] According to an aspect, each aggregation server is configured to establish a communication link based on a session, and the communication link is established between each aggregation server and each system to be aggregated.
[0015] According to an aspect, the aggregation servers are configured to mutually replicate structured data, and the structured data is provided by each other aggregation server via a link established between each aggregation server.
[0016] According to an aspect, the aggregation servers are configured to adjust the establishment of each session with each system to be aggregated by differentiating a plurality of sessions between each aggregation server of the aggregation server system and the systems to be aggregated and the aggregation server system, for session load balancing and / or to prevent unauthorized access to at least a first system to be aggregated and / or at least a second system to be aggregated.
[0017] According to an aspect, the aggregation servers are configured to replicate data related to the session, for example as a password, and / or session adjustment data describing which aggregation servers are communicatively linked to the system to be aggregated based on the session, and / or replicate status data of the system to be aggregated, for example as the number of open sessions, and / or replicate whether the individual systems to be aggregated among the plurality of systems to be aggregated are in an idle state or in operation.
[0018] According to an aspect, the second aggregation server can operate as a redundant aggregation server until a failure of the first aggregation server is detected.
[0019] According to an aspect, it is proposed to mutually replicate structured data and replicate relevant session configuration data of the system to be aggregated.
[0020] The connection for communication can enable information exchange based on signals exchanged by the connected devices.
[0021] In other words, switching the operation of the aggregation server to a second aggregation server configured to be a redundant aggregation server, particularly a redundant aggregation OPC UA server, needs to be prepared for seamless operation, so the aggregation server system is configured to enable horizontal communication, particularly horizontal synchronization, between at least two aggregation servers, particularly OPC UA servers.
[0022] As a result, the aggregation servers are communicatively linked to replicate their information to share information among all the aggregation servers. In particular, when they are redundant and each is configured to be in standby mode, the aggregation servers - each of the aggregation servers has access to the complete set of configuration setups of the aggregation server system. In particular, for example, when at least one of the standby aggregation servers fails, the currently active aggregation server reports any deviation, - can determine the currently active aggregation server: Since complete information is shared among all the redundant aggregation servers, when the active aggregation server fails, another aggregation server in standby mode can determine, based on its known standby priority among the other standby aggregation servers, the aggregation server that should take over the operation of the previous aggregation server, All information regarding the current active sessions with the system to be aggregated is shared among all redundant aggregation servers. It is required to be configured to operate as such. The redundant aggregation server to take over applies the information regarding the current active sessions with the system to be aggregated to manage a bump-free continuation of the ongoing sessions. This includes the sessions of the device clients of the aggregation servers communicating with the system to be aggregated, as there can be sessions between the active aggregation servers and external clients. The information related to the sessions includes the keys used to execute the secure channels of the communication. Further, in order to ensure that the system to be aggregated aggregated within the node space of the aggregation server is not overwhelmed by the incoming connection methods from the aggregation server, synchronization is required in units of the number of active sessions, All status data of the system to be aggregated is shared among all redundant aggregation servers. The redundant aggregation server to take over will supply the latest status data from the system to be aggregated to the current active sessions. A database, which can be configured to be particularly redundant, can be used to share the status data of the system to be aggregated.
[0023] This mutual replication, which can be called "horizontal synchronization" among redundant aggregation servers, can be executed over encrypted communication to ensure that the "secure channel" communication between the external clients and the system to be aggregated cannot be exposed to risks.
[0024] The cycle time of the messages submitted to monitor the availability within the communication link can define the time required to detect a failure. The system can be configured such that the time required for replication as described above is shorter than the time required for the external clients to detect a communication interruption.
[0025] Using such replication operations, additional aggregation servers can be added to expand the redundant aggregation server system. An aggregation server for expanding an aggregation server system that can operate in an "offline" mode can register itself with an "active" aggregation server, and the "active" aggregation server can then transfer all information for replication, particularly including the entire aggregated address space, and / or all information regarding the current session, to the "offline" aggregation server and the URLs of those servers to be aggregated for which the expanding aggregation server in the "offline" mode will be responsible.
[0026] According to an aspect, a first aggregation server is configured to establish respective communication links with a part of a plurality of systems to be aggregated, and at least a second aggregation server is configured to establish communication links with another part of the plurality of systems to be aggregated. The aggregation servers are configured to prevent unauthorized access to the plurality of systems to be aggregated and / or to adjust respective sessions for establishing communication links with the plurality of systems to be aggregated for session load balancing.
[0027] According to an aspect, unauthorized access may be caused by exceeding the permitted number of a plurality of sessions with the systems to be aggregated.
[0028] For example, such unauthorized access can be an error and / or overload regarding the construction of each session.
[0029] According to an aspect, each system to be aggregated is configured as a server for providing particularly structured data.
[0030] According to an aspect, each aggregation server is configured to be coupled for communication with a plurality of external client systems.
[0031] Based on the system of the aggregation server, the external client system can have faster access to the structured data of the system to be aggregated and / or the number of clients having access to the structured data of the system to be aggregated. Therefore, the system of the aggregation server can scale according to specific needs.
[0032] According to an aspect, each aggregation server is an information model server configured to provide an aggregated information model, which aggregates the information models of each system to be aggregated and is coupled for communication to the system of the aggregation server, and includes an information model server. Each aggregation server also includes a database configured to store the structured data of the system to be aggregated according to the aggregated information model, which is related to each system to be aggregated. Each aggregation server also includes a device connection manager configured to control a policy for establishing a session of the related systems to be aggregated with the related aggregation server, and a device client configured to enable and execute a session with the system to be aggregated.
[0033] The device client is coupled to the database via the device connection manager and is configured to be coupled to a plurality of systems to be aggregated. The device connection manager is coupled for communication with the information model server, and the information model server is configured to be coupled for communication with an external client.
[0034] According to an aspect, the database of each aggregation server is a distributed database.
[0035] According to an aspect, the system of the aggregation server is a reverse proxy server, which is coupled for communication with at least a first aggregation server and at least a second aggregation server to load balance the access of a plurality of external client systems for communication with the reverse proxy server.
[0036] Such a reverse proxy can include logic for determining how load is balanced among redundant aggregated OPC UA servers.
[0037] Load balancing means that incoming external client requests are routed to one of the aggregated servers based on a defined balancing strategy, such as round-robin.
[0038] Advantageously, the system of aggregated servers is configured to extend the "simple" failover switching between redundant components including load balancing.
[0039] Load balancing can be the logic for determining how load is balanced among aggregated servers. As an example, design strategy decisions for the configuration of a system of aggregated servers can take into account a limited number of sessions that the system to be aggregated can handle. To minimize the number of sessions between redundant aggregated servers and the system to be aggregated, for example, as a device with an embedded server, the system to be aggregated can have only one session with a single aggregated server.
[0040] This means that the applicable granularity for distributing the processing burden is bound to a single system to be aggregated.
[0041] Accordingly, the load balancing logic can measure the processing effort that an aggregated server expends on a single system to be aggregated, in terms of the relative amount of time, i.e., percentage, that the aggregated server expends on the single system to be aggregated.
[0042] When the first aggregation server of the aggregation server system is active and the second aggregation server is in standby mode for redundancy, the active first aggregation server will handle the full load of the servers to be aggregated that are linked to the aggregation server system. When the second aggregation server is operating, in order to share the burden of handling communication with the servers to be aggregated, the servers to be aggregated must be reallocated so that each aggregation server preferably processes the same number of servers to be aggregated to balance the load.
[0043] When an aggregation server system including several additional aggregation servers in addition to the first aggregation server operates together, each of the aggregation servers can normalize the measured load with respect to a common time reference, for example, as a 15% load per second.
[0044] The mutual replication of structured data between particularly redundant aggregation servers can include sharing session status information including load information for each comparison of the aggregation servers. Since all aggregation servers know their stand-in priorities and execute the same algorithm to optimize load distribution, each individual aggregation server can take over or release its task or "responsibility" for any system to be aggregated in order to aggregate based on common knowledge of status and load. Generally, the optimization method can try its various load distribution scenarios, measure the system load balance for all aggregation servers, and finally select the load distribution scenario with the best load balance, which is the minimum difference between the loads that each individual aggregation server has to manage. In a system with more than two additional, particularly redundant aggregation servers, when one of the aggregation servers fails, the rebalance calculation can be repeated. To reduce the time required to handle the malfunction of a single aggregation server, all aggregation servers can pre-calculate the distribution scenario for the scenario where one or the other aggregation server disappears. When a single aggregation server experiences a load change, according to the current threshold, this aggregation server can re-trigger the load optimization cycle and immediately share its current load status.
[0045] Particularly redundant aggregation servers are negotiating a similar list as an addition to the method of how to share the load of aggregating the systems to be aggregated, but how to share the load can be used to share the IO operations required by an external client system that communicates only with the "active" redundant aggregation servers.
[0046] In larger systems with many, particularly slower systems to be integrated, the initial aggregation of the distributed address space can be time-consuming if only a single aggregation server is configured to execute the initial aggregation cycle in which the other redundant aggregation servers are replicated.
[0047] Accordingly, since the system of aggregated servers is configured to replicate structured data, any additional, particularly redundant, aggregated servers can share this initial effort in the "bootstrap" procedure. It means that each of the additional, particularly redundant, aggregated servers can have access to a complete list of the systems to be aggregated, for example, by a list of the URLs of the systems to be aggregated, and the system of aggregated servers can be configured to share the complete list. According to the stand-in priority of the additional aggregated servers, the first redundant aggregated server designated to be "active" selects one URL from the list of URL addresses of the systems to be aggregated, replaces that entry with its own URL, and finally shares the modified list with the other redundant aggregated servers. The other redundant aggregated servers immediately have access to information on which redundant aggregated server selected the system to be aggregated, and according to the stand-in priority of the redundant aggregated servers, the next redundant aggregated server will perform the same procedure step. After the setup time, all the systems to be aggregated are identified or "discovered" by one of the additional, particularly redundant, aggregated servers and aggregated.
[0048] By this concept, redundant aggregated servers can be "responsible" for a set of systems to be aggregated. At the end of the initial aggregation procedure, replication of structured data can ensure that all redundant aggregated servers have access to the structured data provided by the systems to be aggregated. The "active" redundant aggregated server can go online and is ready to perform information exchange with external client systems.
[0049] The concepts described above for the "bootstrap" procedure can also enhance the responsiveness of the system. Replication among the aggregation systems is considered to be much faster than the periodic communication of the aggregation systems with the systems to be aggregated. The redundant aggregation servers negotiated how to share the task of initially aggregating remotely the services to be aggregated, but a similar list can be taken to share the computational load required by external clients that communicate only with the "active" redundant aggregation servers. The external clients appear to communicate with the entire system, but the "active" redundant aggregation servers talk immediately to the systems to be aggregated that they first aggregated. When an inbound request refers to data aggregated by additional, particularly redundant, aggregation servers that can be in standby mode, the service forwarding layer among the redundant aggregation servers triggers the "responsibility" of the redundant aggregation server that executes the requested service in the first aggregated system to be aggregated, synchronizes the results through the service forwarding layer and replication, which relates to maintaining status update information for all redundant aggregation servers.
[0050] To avoid a single point of failure, a switch between two or more redundant aggregation servers, regardless of whether they are configured to aggregate the address spaces of other systems to be aggregated, is configured to be handled by the aggregation servers themselves for failover switching including URL endpoint sharing.
[0051] Based on the replication procedure as described above, which can be considered the first element in the solution for preparing the failover switch, the second element of the technical solution for preparing the failover switch exploits the method of how the URLs of the systems to be aggregated during failover can be processed.
[0052] Any URL of the system to be aggregated refers to a host address, a port number, and optionally a substructured path. The host address is bound to a host system, in particular a computer, on which an aggregation server that can be implemented as a computer program on that host system exists. Any system to be aggregated communicates via the communication path of the host system.
[0053] Thereby, the host system can be an electronic device or a virtual machine. Depending on whether the system of the aggregation server is configured to be executed on redundant aggregation servers on separate machines to provide hardware redundancy or on a single machine to provide software redundancy, there are slightly different concepts for managing the URL endpoints for the redundant aggregation servers.
[0054] What is common to both situations is that an external client communicating with the "active" aggregation server experiences no problems. This means that the external client can communicate with the same URL of the system of the aggregation server after the switch between the respective aggregation servers has been made. The current session remains active and is prepared by the session status shared among the redundant aggregation servers.
[0055] When implementing hardware redundancy, the failed aggregation server is modified to "hide" its MAC address and IP address. In the case of a complete hardware failure where the software cannot be executed, the technical defect "hides" the machine communicatively.
[0056] The "standby" aggregation server can be prepared to take over by using the MAC address and IP address of the previous "active" aggregation server and also using the shared session status to continue the ongoing session(s).
[0057] In the case of software redundancy, the handling of the URL used by the redundant aggregation server is such that the host address remains unchanged and only the port of the aggregation server's system or any postfix in the URL is changed. In this scenario, there is an endpoint URL that references the current "active" aggregation server. If the software of this "active" aggregation server fails, that URL will no longer respond. A "standby" aggregation server can always be synchronized with respect to session status by a replication procedure, for example, since the aggregation server can run multiple simultaneous sessions for multiple external clients, and can take over by changing its URL to the URL that the previous "active" aggregation server was using.
[0058] According to an aspect, the reverse proxy server is configured to provide a dedicated IP address for disconnecting each external client system from a first aggregation server and at least a second aggregation server.
[0059] According to an aspect, the system of the aggregation server comprises an OPC UA aggregation server.
[0060] According to an aspect, the external client system is an OPC UA client system, and / or the system to be aggregated is an OPC UA system to be aggregated, and / or the information model is an OPC UA information model, and / or the device client is an OPC UA device client.
[0061] According to an aspect, the first aggregation server and at least the second aggregation server are coupled for communication, and the aggregation server is configured to mutually replicate the structured data of each system to be aggregated and the session configuration data of the system to be aggregated provided by the first system to be aggregated and / or at least the second system to be aggregated with the session configuration data of each system to be aggregated, in order to provide access to the structured data and the session configuration data of each system to be aggregated to the first aggregation server and at least the second aggregation server.
[0062] The session configuration data can be defined as the configuration data of the session and / or the policy information of the session.
[0063] According to an aspect, the connection for communication between the first aggregation server and at least the second aggregation server is provided by using encrypted communication.
[0064] According to an aspect, the first aggregation server and at least the second aggregation server are coupled for communication to coordinate the mutual distribution of their respective distributed sessions to at least the first system to be aggregated and / or at least the second system to be aggregated, and / or each aggregation server is configured to store the coordinated mutual distribution of their respective distributed sessions with at least the first system to be aggregated and / or at least the second system to be aggregated, respectively, to enable each aggregation server to take over at least the sessions of each other aggregation server in case of a failure in the system of the aggregation server.
[0065] In other words, each of the aggregation servers has access to the system configuration.
[0066] The replication using the connection link between the first aggregation server and at least the second aggregation server can include several active sessions with the system to be aggregated.
[0067] According to an aspect, the first aggregation server and the second aggregation server are installed on different hardware computing systems to provide highly available aggregation servers.
[0068] According to an aspect, at least the second aggregation server on the second hardware computing system operates in standby mode until a failure in the system of the aggregation server is detected.
[0069] Advantageously, by operating the first aggregation server and the second aggregation server on different hardware, the computing system can provide redundant aggregation servers to a high-availability system if, when a failure occurs within one computing system, the computing system operating in standby mode can provide the full operation of the aggregation server system.
[0070] In computing, an address space defines a range of individual addresses, each of which may correspond to a network host, a peripheral device, a disk sector, a memory cell, or other logical or physical entity.
[0071] Round Robin (RR) is one of the algorithms used by process and network schedulers in computing for load balancing.
[0072] The accompanying drawings, which are included to provide a further understanding of the invention and are incorporated in and constitute a part of this specification, illustrate embodiments of the invention and together with the description serve to explain the principles of the invention. The drawings show the following.
Brief Description of the Drawings
[0073]
Figure 1
Figure 2
Figure 3
Figure 4
Figure 5
Best Mode for Carrying Out the Invention
[0074] FIG. 1 schematically shows a system of aggregation servers 100, 200 having a shared session with systems 50, 60, 70, 80 to be aggregated in a proper execution mode of both aggregation servers 100, 200. An external client 10 is coupled for communication with a first aggregation server 100 and a second aggregation server 200.
[0075] The coupling for communication with the second aggregation server 200 can preferably be established by providing the address of the second aggregation server 200 to the external client 10 for communication of the external client 10 with the second aggregation server 200 when the first aggregation server 100 is not available for communication.
[0076] The first aggregation server 100 is coupled for communication with two systems 50, 60 to be aggregated, and the second aggregation server 200 is coupled to another pair of systems 70, 80 to be aggregated. The systems 50, 60, 70, 80 to be aggregated are configured to provide structured data 110, 120, 130, 140 respectively. The first aggregation server 100 and the second aggregation server 200 are coupled via a link 20, and both are configured to replicate the structured data provided by the systems 50 and 60 to be aggregated coupled to the first aggregation server 100 and / or the structured data provided by the systems 70 and 80 to be aggregated coupled to the second aggregation server 200, so as to provide the first aggregation server and the second aggregation server with access to the structured data of each of the systems 50, 60, 70, 80 to be aggregated. In this configuration, the load corresponding to the systems 50, 60, 70, 80 to be aggregated is balanced between the two aggregation servers 100 and 200.
[0077] FIG. 2 schematically shows a system of aggregation servers 100, 200 having systems 50, 60, 70, 80 to be aggregated as described with respect to FIG. 1 after failover switching is completed. For example, starting from the configuration of the systems of aggregation servers 100, 200 as described with respect to FIG. 1, the redundant second aggregation server 200 has structured data 110, 120, 130, 140 already replicated, and the connections for communication with the systems 50, 60, 70, 80 to be aggregated are provided by the second aggregation server 200 to continue access to the systems 50, 60, 70, 80 to be aggregated. Thus, the structured data 110, 120, 130, 140 of the systems 50, 60, 70, 80 to be aggregated is provided to the external client 10. In other words, FIG. 2 illustrates a scenario where the previous standby aggregation server 200 becomes the active aggregation server 200. The previous standby aggregation server 200 took over the connections for communication of the systems 50 and 60 to be aggregated.
[0078] FIG. 3 schematically shows a system of aggregation servers 100, 200 having systems 50, 60, 70, 80 to be aggregated that are coupled only for communication to the first aggregation server 100. By linking an additional, particularly redundant aggregation server 200 to the first aggregation server 100, coupling it to the first aggregation server 100 via link 20, and replicating the structured data provided by the first systems 50, 60, 70, 80 to be aggregated, the system of aggregation servers 100, 200 can be constructed. Therefore, a further aggregation server can be integrated into the system of aggregation servers.
[0079] FIG. 4 schematically shows a system of aggregation servers 100 and 200 having systems 50, 60, 70, 80 to be aggregated, during replication of structured data 110, 120, 130, 140 from a first aggregation server 100 coupled to systems 50, 60, 70, 80 to be aggregated via a communication link 20 to a second aggregation server 200. The second aggregation server 200 is not coupled to the systems 50, 60, 70, 80 to be aggregated during replication of the structured data, and is configured to be coupled to at least a part of the systems 50, 60, 70, 80 to be aggregated.
[0080] FIG. 5 schematically shows functional blocks of the systems of aggregation servers 100 and 200 and systems 50, 60, 70 to be aggregated, and the systems 50, 60, 70 to be aggregated are coupled to the systems of aggregation servers 100 and 200 via a link 560.
[0081] An external client 10 is coupled to the systems of aggregation servers 100 and 200 via a client link 15. The client link 15 couples the external client 10 to a reverse proxy server 510 of the systems of aggregation servers 100 and 200. The reverse proxy server 510 for load balancing is coupled for communication via input links 511, 512 to information model servers 520a, 520b of aggregation servers 100 and 200 respectively. The information model servers 520a, 520b configured to provide an aggregated information model are coupled for communication with databases 530a, 530b of aggregation servers 100 and 200 respectively.
[0082] The databases 530a, 530b of each aggregation server 100, 200 are coupled by a replication of the link 20 of the structured data provided by the systems 50, 60, 70 to be aggregated. Additionally, the databases 530a, 530b of each aggregation server 100, 200 configured to store structured data are coupled to the device connection managers 540a, 540b of each aggregation server 100, 200 configured to control policies for establishing sessions of the related systems 50, 60, 70 to be aggregated with the related aggregation servers 100, 200. And the device connection managers 540a, 540b of each aggregation server 100, 200 are coupled for communication to the device clients 550a, 550b of each aggregation server 100, 200, and the device clients 550a, 550b are configured to have and execute sessions with the systems 50, 60, 70 to be aggregated via the link 560. The invention described in the claims of the present application at the time of filing is appended below. [C1] A system of aggregation servers (100, 200), a first aggregation server (100) configured to establish a session for communicatively linking with at least one first system (50, 60, 70, 80) to be aggregated, and at least a second aggregation server (200) configured to establish a session for communicatively linking with at least one second system (50, 60, 70, 80) to be aggregated comprising, wherein the first aggregation server (100) and the second aggregation server (200) replicate mutually structured data provided by the first system (50, 60, 70, 80) to be aggregated and / or the second system (50, 60, 70, 80) to be aggregated, in order to provide the first aggregation server (100) and the second aggregation server (200) with access to the structured data (110, 120, 130, 140) of each of the systems (50, 60, 70, 80) to be aggregated; adjust each of the sessions of the aggregation server system with the at least first system (50, 60, 70, 80) to be aggregated and / or the at least second system (50, 60, 70, 80) to be aggregated, in order to prevent unauthorized access to the at least first system (50, 60, 70, 80) to be aggregated and / or the at least second system (50, 60, 70, 80) to be aggregated; A system of aggregation servers (100, 200) configured to perform the above. [C2] The first aggregation server (100) is configured to establish respective communication links with a part of a plurality of systems (50, 60, 70, 80) to be aggregated, and at least the second aggregation server (200) is configured to establish communication links with another part of the plurality of systems (50, 60, 70, 80) to be aggregated. The aggregation servers (100, 200) are configured to adjust respective sessions for establishing the communication links with the plurality of systems (50, 60, 70, 80) so as to prevent unauthorized access to the plurality of systems (50, 60, 70, 80) to be aggregated and / or for load balancing of the sessions. The system of the aggregation servers (100, 200) according to C1. [C3] The unauthorized access is caused by exceeding a permitted number of a plurality of sessions with the systems (50, 60, 70, 80) to be aggregated. The system of the aggregation servers (100, 200) according to C1 or 2. [C4] Each aggregation server (100, 200) is configured to be coupled for communication with a plurality of external client systems (10). The system of the aggregation servers (100, 200) according to any one of C1 to 3. [C5] Each of the respective aggregation servers (100, 200) is an information model server (520a, 520b) configured to provide an aggregated information model, which aggregates the information models of each of the systems (50, 60, 70, 80) to be aggregated and is coupled for communication with the system of the aggregation servers (100, 200), the information model server (520a, 520b); is a database (530a, 530b) configured to store the structured data of the systems to be aggregated according to the aggregated information model, which is related to each of the systems to be aggregated, the database (530a, 530b); is a device connection manager (540a, 540b) configured to control a policy for establishing a session between the related aggregation server (100, 200) and the related systems (50, 60, 70, 80) to be aggregated; and is a device client (550a, 550b) configured to enable and execute a session with the systems (50, 60, 70, 80) to be aggregated. The system of the aggregation server (100, 200) according to any one of C1 to C4, comprising [C6] The system of the aggregation server (100, 200) is a reverse proxy server (510), which is coupled for communication with at least the first aggregation server (100) and at least the second aggregation server (200) to load balance the access for communication between a plurality of external client systems (10) and the reverse proxy server (510). The system of the aggregation server (100, 200) according to C4 or C5, comprising a reverse proxy server (510). [C7] The reverse proxy server (510) is configured to provide a dedicated IP address for disconnecting each external client system (10) from the first aggregation server (100) and at least the second aggregation server (200). The system of the aggregation server (100, 200) according to C6. [C8] The system of the aggregation server (100, 200) is provided with an OPC UA aggregation server. The system of the aggregation server (100, 200) according to any one of C1 to C7. [C9] The external client system (10) is an OPC UA client system, and / or the system to be aggregated (50, 60, 70, 80) is an OPC UA system to be aggregated, and / or the information model is an OPC UA information model, and / or the device clients (550a, 550b) are OPC UA device clients. The system of the aggregation server (100, 200) according to C8. [C10] The first aggregation server (100) and at least the second aggregation server (200) are coupled for communication, and the aggregation servers (100, 200) are configured to mutually replicate the structured data and the session configuration data of each of the systems (50, 60, 70, 80) to be aggregated provided by the first system (50, 60, 70, 80) to be aggregated and / or at least the second system (50, 60, 70, 80) to be aggregated, in order to provide access to the structured data and the session configuration data of each of the systems (50, 60, 70, 80) to be aggregated to the first aggregation server (100) and at least the second aggregation server (200). The system of the aggregation servers (100, 200) according to any one of C5 to C9. [C11] The coupling for communication between the first aggregation server (100) and at least the second aggregation server (200) is provided by using encrypted communication. The system of the aggregation servers (100, 200) according to C10. [C12] The first aggregation server (100) and at least the second aggregation server (200) are coupled for communication for coordinating the mutual distribution of each of the distributed sessions to at least the first system (50, 60, 70, 80) to be aggregated and / or at least the second system (50, 60, 70, 80) to be aggregated, and / or Each aggregation server (100, 200) is configured to store the adjusted mutual distribution of each of the distributed sessions with at least the first system (50, 60, 70, 80) to be aggregated and / or at least the second system (50, 60, 70, 80) to be aggregated, in order to enable each of the aggregation servers (100, 200) to take over at least the sessions of the other of the aggregation servers (100, 200) when a failure occurs within the system of the aggregation servers (100, 200). The system of the aggregation servers (100, 200) according to C10 or C11. [C13] The first aggregation server (100) and the second aggregation server (200) are systems of the aggregation servers (100, 200) according to any one of C1 to C12, which are installed on different hardware computing systems to provide highly available aggregation servers. [C14] At least the second aggregation server (200) on the second hardware computing system operates in standby mode until a failure within the system of the aggregation servers (100, 200) is detected, which is the system of the aggregation servers (100, 200) described in C13.
Claims
1. A system of aggregation servers (100, 200), comprising: A first aggregation server (100) configured to establish a session for communicatively linking with at least one first system (50, 60, 70, 80) to be aggregated; At least a second aggregation server (200) configured to establish a session for communicatively linking with at least one second system (50, 60, 70, 80) to be aggregated; The first aggregation server (100) and the second aggregation server (200) are configured to: Mutually replicate the structured data provided by the first system (50, 60, 70, 80) to be aggregated and / or the second system (50, 60, 70, 80) to be aggregated, in order to provide the first aggregation server (100) and the second aggregation server (200) with access to the structured data (110, 120, 130, 140) of each of the systems (50, 60, 70, 80) to be aggregated; Adjust each of the sessions of the aggregation server system with the at least first system (50, 60, 70, 80) to be aggregated and / or the at least second system (50, 60, 70, 80) to be aggregated, in order to prevent unauthorized access to the at least first system (50, 60, 70, 80) to be aggregated and / or the at least second system (50, 60, 70, 80) to be aggregated. A system of aggregation servers (100, 200) configured to perform the above operations.
2. The first aggregation server (100) is configured to establish respective communication links with a part of a plurality of systems (50, 60, 70, 80) to be aggregated, and at least the second aggregation server (200) is configured to establish a communication link with another part of the plurality of systems (50, 60, 70, 80) to be aggregated. The aggregation servers (100, 200) are configured to adjust respective sessions for establishing the communication links with the plurality of systems (50, 60, 70, 80) so as to prevent unauthorized access to the plurality of systems (50, 60, 70, 80) and / or for load balancing of the sessions. The system of the aggregation servers (100, 200) according to claim 1.
3. The unauthorized access is caused by exceeding a permitted number of a plurality of sessions with the systems (50, 60, 70, 80) to be aggregated. The system of the aggregation servers (100, 200) according to claim 1 or 2.
4. Each aggregation server (100, 200) is configured to be coupled to the plurality of external client systems (10) for communication with the plurality of external client systems (10). The system of the aggregation servers (100, 200) according to claim 1 or 2.
5. Each of the aggregation servers (100, 200) is an information model server (520a, 520b) configured to provide an aggregated information model, which aggregates the information models of each system (50, 60, 70, 80) to be aggregated and is coupled for communication with the system of the aggregation servers (100, 200); an information model server (520a, 520b), is a database (530a, 530b) configured to store the structured data of the systems to be aggregated according to the aggregated information model, which is related to each of the systems to be aggregated; a database (530a, 530b), is a device connection manager (540a, 540b) configured to control a policy for establishing a session between the related aggregation server (100, 200) and the related systems (50, 60, 70, 80) to be aggregated. A device client (550a, 550b) configured to have and execute a session with the system (50, 60, 70, 80) to be aggregated The system of the aggregation server (100, 200) according to claim 1 or 2, comprising the device client (550a, 550b).
6. The system of the aggregation server (100, 200) is a reverse proxy server (510), which is coupled for communication with at least the first aggregation server (100) and at least the second aggregation server (200) to load balance access for communication of a plurality of external client systems (10) with the reverse proxy server (510). The system of the aggregation server (100, 200) according to claim 4, comprising a reverse proxy server (510).
7. The reverse proxy server (510) is configured to provide a dedicated IP address for disconnecting each external client system (10) from the first aggregation server (100) and at least the second aggregation server (200). The system of the aggregation server (100, 200) according to claim 6.
8. The system of the aggregation server (100, 200) comprises an OPC UA aggregation server. The system of the aggregation server (100, 200) according to claim 1 or 2.
9. The external client system (10) is an OPC UA client system. The system of the aggregation server (100, 200) according to claim 4.
10. The system (50, 60, 70, 80) to be aggregated is an OPC UA system to be aggregated, and / or the information model is an OPC UA information model, and / or the device client (550a, 550b) is an OPC UA device client. The system of the aggregation server (100, 200) according to claim 5.
11. The first aggregation server (100) and at least the second aggregation server (200) are coupled for communication, and the aggregation servers (100, 200) are configured to mutually replicate the structured data and the session configuration data of each of the systems (50, 60, 70, 80) to be aggregated provided by the first system (50, 60, 70, 80) to be aggregated and / or at least the second system (50, 60, 70, 80) to be aggregated, to provide access to the structured data and the session configuration data of each of the systems (50, 60, 70, 80) to the first aggregation server (100) and at least the second aggregation server (200). The system of the aggregation servers (100, 200) according to claim 5.
12. The coupling for communication between the first aggregation server (100) and at least the second aggregation server (200) is provided by using encrypted communication. The system of the aggregation servers (100, 200) according to claim 11.
13. The first aggregation server (100) and at least the second aggregation server (200) are coupled for communication to coordinate the mutual distribution of at least the first system (50, 60, 70, 80) to be aggregated and / or at least the second system (50, 60, 70, 80) to be aggregated of each distributed session, and / or Each aggregation server (100, 200) is configured to store the adjusted mutual distribution of each distributed session with at least the first system (50, 60, 70, 80) to be aggregated and / or at least the second system (50, 60, 70, 80) to be aggregated, in order to enable each of the aggregation servers (100, 200) to take over the session of at least the other of the aggregation servers (100, 200) when a failure occurs within the system of the aggregation servers (100, 200). The system of the aggregation servers (100, 200) according to claim 11.
14. The system of the aggregation servers (100, 200) according to claim 1 or 2, wherein the first aggregation server (100) and the second aggregation server (200) are installed on different hardware computing systems to provide highly available aggregation servers.
15. The system of the aggregation servers (100, 200) according to claim 14, wherein at least the second aggregation server (200) on the second hardware computing system operates in standby mode until a failure within the system of the aggregation servers (100, 200) is detected.
Citation Information
Patent Citations
Multi-tenant provider network database connection management and governance
US20210133183A1
System and method for aggregating data in a remote address space
WO2021198178A1