Using a secondary channel to carry a distributed control node
Using out-of-band communication channels for device provisioning in process automation systems addresses manual configuration challenges, reducing errors and enhancing security and efficiency in device integration.
Patent Information
- Application Number
- JP2023555397
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2021-03-24
- Filing Date
- 2022-03-24
- Publication Date
- 2025-09-25
- Estimated Expiration
- 2042-03-24
AI Technical Summary
In process automation systems, adding devices to the network requires manual configuration by knowledgeable integrators, prone to errors, and existing methods burden the network with provisioning data, complicating the installation and replacement of devices.
Provisioning devices using an out-of-band communication channel, such as USB, NFC, or Bluetooth, to transfer configuration data separately from the process automation network, allowing automatic configuration with minimal human intervention and reducing network exposure to provisioning data.
This method reduces errors, time, and expertise required for device installation, enhances security, and ensures seamless integration of devices into the automation network.
Smart Images

Figure 0007743870000001 
Figure 0007743870000002 
Figure 0007743870000003
Abstract
Description
[Technical Field]
[0001] The present invention relates to process automation systems. [Background technology]
[0002] A process automation system may include one or more process automation networks. The process automation network may be the primary communication channel through which devices, such as compute devices and / or input / output (I / O) devices, referred to in some contexts as distributed control nodes (DCNs), communicate with other nodes in the process automation system, such as other DCNs, sensors, actuators, servers, and central control rooms. Process automation networks are typically implemented using a communication technology, such as Ethernet, that is reliable, fast, and has a significant amount of bandwidth. Summary of the Invention [Problem to be solved by the invention]
[0003] In some process automation systems, the process automation network itself may be used to provision devices with the configuration data necessary to operate as part of the process automation system. However, this presents challenges when the added device is not configured with the necessary parameters to participate in and receive and / or transmit data via the process automation network, such as a DCN. This issue is sometimes addressed by pre-configuring the added device to some known static network configuration. However, this may require a knowledgeable system integrator to set up a separate subnetwork to match the device's static network configuration before configuring the device in the process automation network's preferred network configuration. Additionally, device configuration or application deployment / upgrades may be performed by the system integrator as a manual process, which may be prone to human error / mistakes.
[0004] Accordingly, implementations are described herein for provisioning a device, such as a DCN, with configuration data using an "out-of-band" communication channel so that it can operate on a process automation network. More specifically, but without limitation, techniques are described herein for establishing such an out-of-band communication channel between a device to be provisioned and another previously provisioned device associated with the process automation network, thereby enabling the previously provisioned device to provide (e.g., replicate) configuration data to the device to be provisioned. This previously provisioned device may be, by way of example, an old DCN being replaced, a DCN being reconfigured for another purpose, a DCN simulated in software, etc.
[0005] The out-of-band communication channel can be separate from the process automation network, such as a DCN, used by devices to communicate with each other. In some implementations, the out-of-band communication channel can be established using technologies such as universal serial bus (USB), near field communication (NFC), Bluetooth, or an auxiliary Ethernet network (which in some cases can be switched to a redundant network after provisioning). By provisioning devices using such an out-of-band communication channel, more device configurations can be performed automatically with little or no human intervention. Furthermore, the process automation network itself is not burdened with or exposed to data exchanged during device provisioning. Therefore, the techniques described herein can reduce errors and the time, effort, and expertise required to install and / or replace devices, such as a DCN, and increase the security of the process automation network. [Means for solving the problem]
[0006] In various implementations, a previously configured and / or fully provisioned device, such as a DCN (sometimes referred to herein as a “provisioning device”), can provide (e.g., push) information technology (IT) configuration data and / or operational technology (OT) configuration data to an unprovisioned device, such as a DCN (sometimes referred to herein as a “provisioned device”), via an out-of-band communication channel. The IT configuration data can enable a device, such as a DCN, to engage in network communications with other nodes via a process automation network. The IT configuration data can include networking parameters, such as Internet Protocol (IP) addresses, Domain Name System (DNS) parameters and / or lookup tables, IP subnet masks, etc. The IT configuration data can also include non-OT specific data related to the device's hardware or software, such as firmware or operating system (OS) updates, redundancy policies, security policies, etc. In general, the IT configuration data can be used by devices, such as a DCN, to join and / or communicate via a process automation network.
[0007] OT configuration data, in contrast, may enable a device such as a DCN to coordinate (e.g., exchange commands and / or sensor data) with one or more actuators or sensors on a process automation network for the purpose of performing at least a partially automated process. OT configuration data for a DCN may include, among other things, process automation applications to be installed on and / or operated by the DCN, range limitations to be imposed on / by the DCN, preferred units of measurement to be used by the DCN, update frequencies to be performed by the DCN, one or more analog-to-digital conversion parameters to be used by the DCN, information about other nodes in the process automation system (e.g., their roles), one or more signal conditioning parameters to be used by the DCN, security credentials to enable operation within the process automation system, error correction parameters (e.g., error correction code techniques) to be used by the DCN, high availability configurations such as redundancy setups, etc.
[0008] In some implementations, a provisioning device can simply replicate its IT and / or OT data to the device being provisioned via an out-of-band communication channel. This allows the provisioned device to join and operate on the process automation network relatively quickly and seamlessly. Replicating IT and / or OT information can be particularly effective and efficient when a provisioning device is being replaced by a device being provisioned because, after being provisioned, the latter can simply take over the role previously played by the former (e.g., by using the same IP address). However, there can be situations in which replicating IT / OT configuration data is problematic. For example, if IT configuration data is replicated from a provisioning device to multiple different devices, the multiple different devices may have conflicting IP addresses. If OT configuration data is replicated from a provisioning device to multiple different devices, the multiple different devices may perform conflicting actions within the process automation system. Therefore, in some implementations, after provisioning, the provisioning device can transition to a disabled state in which the provisioning device is prevented from replicating IT / OT configuration data to any additional devices (at least without subsequent human intervention).
[0009] Duplication can also be an issue if the provisioning device continues to operate as part of the process automation system. Therefore, in some implementations, measures can be taken to avoid collisions while allowing one or both of the provisioning device and the provisioned device to join and / or exchange data over the process automation network after the former provides the latter with IT / OT configuration data. In some implementations, one of the two devices cannot communicate over the process automation network until it receives some type of signal (e.g., over an out-of-band communication channel) that the other of the two devices has received a new IP address. For example, a newly provisioned device can close the out-of-band communication channel after receiving a new IP address (e.g., different from the IP address it received from the provisioning device). When the provisioning device detects that the out-of-band communication channel has been closed, it can rejoin the process automation network using the same IP address it was previously using (which may or may not require a physical reconnection).
[0010] In some implementations, a method for provisioning a first DCN to operate as part of a process automation system can be performed using one or more processors, the method including: establishing a temporary out-of-band communication channel between the first DCN and a second DCN, the temporary out-of-band communication channel being separate from a process automation network that will communicatively couple the first DCN with other process automation nodes of the process automation system; transmitting provisioning data from the second DCN to the first DCN via the temporary out-of-band communication channel, the provisioning data including information technology (IT) configuration data usable by the first DCN to join the process automation network and operational technology (OT) configuration data usable by the first DCN to coordinate with one or more other process automation nodes of the process automation system to implement at least a portion of an automated process; and, following the transmitting, closing the temporary out-of-band communication channel.
[0011] In various implementations, the IT configuration data may include one or more networking parameters previously used by the second DCN. In various implementations, the transmitting may include replicating one or both of the IT configuration data and the OT configuration data from the second DCN to the first DCN. In various implementations, the method may include, following the replicating, transitioning the second DCN to a disabled state in which the second DCN is prevented from replicating the IT configuration data or the OT configuration data to any additional DCNs. In various implementations, the method may include, following the replicating, transitioning the first DCN to a locked state in which the first DCN rejects at least some subsequent provisioning data.
[0012] In various implementations, the second DCN can be simulated by a computing device. In various implementations, the method can include, in response to the transmission, triggering a provisioning routine on the first DCN, where the provisioning routine automatically configures the first DCN based on the IT configuration data and the OT configuration data. In various implementations, the provisioning routine can resume one or more networking services performed by the first DCN after the first DCN is configured based on the IT configuration data.
[0013] In various implementations, the temporary out-of-band communication channel can be a USB channel and the process automation network can be an Ethernet network. In various implementations, the temporary out-of-band communication channel can be an NFC channel or a Bluetooth channel.
[0014] In various implementations, one of the first DCN or the second DCN can refrain from transmitting data on the process automation network until the other of the first DCN or the second DCN is assigned a new Internet Protocol (IP) address. In various implementations, the method can include exchanging, between the first DCN and the second DCN, confirmation data that the other of the first DCN or the second DCN has received the new IP address via a temporary out-of-band communication channel. In various implementations, the temporary out-of-band communication channel can be closed in response to the assignment of the new IP address.
[0015] In another aspect, the DCN can be configured to implement a method including establishing a temporary out-of-band communication channel with a provisioning DCN, the temporary out-of-band communication channel being separate from a process automation network that will communicatively couple the DCN with other process automation nodes of the process automation system; receiving IT configuration data and OT configuration data from the provisioning DCN via the temporary out-of-band communication channel; joining the process automation network based on the IT configuration data; and coordinating with one or more of the other process automation nodes of the process automation system to perform at least a portion of an automated process based on the OT configuration data.
[0016] Additionally, some implementations include one or more processors of one or more computing devices, the one or more processors operable to execute instructions stored in associated memory, and the instructions configured to cause performance of any of the aforementioned methods. Some implementations also include one or more non-transitory computer-readable storage media having stored thereon computer instructions executable by the one or more processors for performing any of the aforementioned methods.
[0017] It should be understood that all combinations of the foregoing concepts, and additional concepts described in more detail herein, are contemplated as being part of the present subject matter disclosed herein, for example, all combinations of claimed subject matter in the claims appearing at the end of this disclosure are contemplated as being part of the present subject matter disclosed herein. [Brief explanation of the drawings]
[0018] [Figure 1] 1A-1C are diagrams that illustrate generally how selected aspects of the present disclosure may be implemented in particular scenarios, according to various embodiments. [Figure 2] 1A-1C are diagrams that illustrate generally how selected aspects of the present disclosure may be implemented in particular scenarios, according to various embodiments. [Figure 3] FIG. 10 illustrates a schematic diagram of another example of how the techniques described herein may be implemented, according to various embodiments. [Figure 4] 1A-1C illustrate exemplary methods for implementing selected aspects of the present disclosure. [Figure 5] FIG. 1 illustrates another exemplary method for implementing selected aspects of the present disclosure. [Figure 6] FIG. 1 illustrates a schematic diagram of an exemplary computer architecture upon which selected aspects of the present disclosure may be implemented. DETAILED DESCRIPTION OF THE INVENTION
[0019] As used herein, an "at least partially automated process" includes any process performed cooperatively by multiple devices within a process automation system with little or no human intervention. One common example of an at least partially automated process is a process loop in which one or more actuators operate automatically (without human intervention) based on the output of one or more sensors. Some at least partially automated processes can be subprocesses of an overall process automation system workflow, such as the single process loop mentioned above. Other at least partially automated processes can include all or a significant portion of the overall process automation system workflow. In some cases, the degree to which a process is automated can exist along a gradient, range, or scale of automation. Processes that are partially automated but still require human intervention may be at or near one end of the scale. Processes that require less human intervention may be closer to the other end of the scale, representing fully autonomous processes. Process automation can generally be used to automate processes in a variety of fields, such as the manufacturing, development, and / or improvement of chemicals (e.g., chemical processing), catalysts, machinery, etc.
[0020] 1, an exemplary environment 100 in which various aspects of the present disclosure may be implemented is generally illustrated. Within a process automation facility 108, a process automation management system 102 is operably coupled to a process automation network 106. The process automation facility 108 (also referred to herein as a "process automation system 108") can take many forms and can be designed to perform any number of processes, at least some of which are automated. For example, the process automation facility 108 can form all or part of a chemical processing plant, an oil or natural gas refinery, a catalyst plant, a manufacturing facility, etc.
[0021] The process automation network 106 can be implemented using various wired and / or wireless communication technologies, including, but not limited to, the Institute of Electrical and Electronics Engineers (IEEE) 802.3 standard (Ethernet), IEEE 802.11 (Wi-Fi), cellular networks such as 3GPP Long Term Evolution ("LTE") and other wireless protocols referred to as 3G, 4G, 5G, and beyond, and / or other types of communication networks with various types of topologies (e.g., mesh). Process automation is often used in scenarios where the cost of failure tends to be high, both in terms of personnel safety and financial costs to stakeholders. Therefore, in various implementations, the process automation network 106 can be configured with redundancy and / or backups to enable high availability (HA) and / or high quality of service (QoS).
[0022] The process automation management system 102 may include an authorization module 104 and a database 105 that stores information used by the authorization module 104 to authorize new devices to the process automation facility 108. Various aspects of the process automation management system 102, such as the authorization module 104, may be implemented using any combination of hardware and software. In some implementations, the process automation management system 102 may be implemented across multiple computer systems as part of what is often referred to as a "cloud infrastructure" or simply "cloud." However, this is not required, and in FIG. 1 , by way of example, the process automation management system 102 is implemented within the process automation facility 108, e.g., within a single building or across a single campus of multiple buildings or other industrial infrastructure. In such implementations, the process automation management system 102 may be implemented on one or more local computing systems, such as on one or more server computers.
[0023] In addition to the process automation management system 102, various other nodes / devices are operatively coupled to the process automation network 106. In FIG. 1 , by way of example, N (a positive integer) DCNs 110-1 through 110-N are operatively coupled to the process automation network 106. Each DCN may include circuitry or logic 112, which may take various forms, such as a processor that executes instructions in a memory, a field programmable gate array (FPGA), an application specific integrated circuit (ASIC), etc. Each DCN 110 may have a specific role to play within the process automation facility 108. By way of example, a “compute” DCN may control a process loop (e.g., a chemical process loop) in which various “field” devices (e.g., devices having sensors and / or actuators) interface with each other to implement a number of functional control blocks (FBs).
[0024] Each DCN 110 may have various input / output (I / O) and other hardware components that define at least a portion of its OT capabilities, and more generally, its role in the process automation facility 108. OT capabilities may vary significantly between industries. In some cases, OT capabilities may include, but are not limited to, the number of I / O channels, one or more types of one or more I / O channels, range limitations, nominal units of measure, nominal update frequency, one or more analog-to-digital conversion parameters, one or more signal conditioning parameters, supported open standard protocols such as Open Platform Communications (OPC) Unified Architecture (OPC UA) and / or Modbus, or any combination thereof.
[0025] 1, the first DCN 110-1 includes a flow transmitter (FT) component 114-1 and an actuator (e.g., a valve) 116-1. The second DCN 110-2 includes an FT component 114-2 but no actuator. The third DCN 110-3 includes a sensor 118-3 but no actuator.
[0026] The actuators 116 can be any electrical, hydraulic, mechanical, and / or pneumatic components that can be controlled to affect some aspect of the process automation workflow occurring in the process automation facility 108. Often, the actuators 116 can perform their functions in response to various signals, such as sensor signals or commands from the compute DCN (which itself can monitor for sensor signals). Some non-limiting examples of actuators 116 include, but are not limited to, valves, pistons, rotors, switches, heaters, coolers, agitators, injectors, vacuum generators, belts, tracks, gears, grippers, motors, relays, servo mechanisms, etc. The sensors 118 can take various forms, including, but not limited to, pressure sensors, temperature sensors, flow sensors (e.g., FT component 114), various types of proximity sensors, optical sensors (e.g., photodiodes), pressure wave sensors (e.g., microphones), humidity sensors (e.g., humistors), radiation dosimeters, laser absorption spectroscopy (e.g., multi-pass optical cells), etc.
[0027] Unlike DCNs 110-1 through 110-3, DCN 110-N does not include any inputs / outputs (actuators or sensors). Instead, DCN 110-N may be a “compute-only” DCN whose role is to facilitate coordination between itself and one or more other DCNs 110 on process automation network 106 to implement at least a partially automated process. For example, DCN 110-N may control a single process loop (e.g., a chemical process control loop) involving one or more other DCNs 110. In some cases, such a compute DCN 110 may perform a role similar to that of an autopilot on an aircraft, i.e., it may receive various signals and control various actuators based on those signals and various criteria and / or thresholds. For example, Compute DCN 110 may monitor various sensors 118 and / or FT components 114 to ascertain data about chemical levels, flow rates (e.g., through valves), tank temperatures, control rates, etc., and may control one or more actuators 116 based on this data and / or comparisons of this data to various criteria and / or thresholds. As an example, Compute DCN 110-N may control actuator 116-1 by sending corresponding commands to DCN 116-1 that may optionally conform to a protocol specific to DCN 116-1.
[0028] As previously mentioned, adding a DCN to a process automation network 106, whether as a new addition, replacement, or upgrade, can be complex and cumbersome because, for example, the authorization process is performed at least in part by exchanging data over the process automation network 106. Accordingly, improved techniques are described herein for provisioning devices such as the DCN 110 with IT and / or OT configuration data using “out-of-band” communication channels so that they can operate on the process automation network 106. The DCN 110 may be provisioned using the techniques described herein in a variety of situations, such as to extend the capabilities of the process automation facility 108, replace underperforming, malfunctioning, disabled, or obsolete nodes, repurpose nodes, or bring the process automation facility 108 into compliance with various standards.
[0029] 1 and 2 illustrate a scenario in which a DCN is replaced with another DCN. In FIG. 1, the first DCN 110-1 is shaded to indicate that it is being replaced, for example, due to a failure of actuator 116-1. The first DCN 110-1 is in the process of being replaced with a fourth DCN 110-4, which also includes both FT component 114-4 and actuator 116-4. In FIGS. 1 and 2, each DCN 110 includes a corresponding interface 113 that can be used to establish an out-of-band communication channel (not yet established in FIG. 1 and shown as 109 in FIG. 2) between the DCN 110 and another device, such as another DCN or a computing device simulating another DCN. Interfaces 113-1 through 113-N may all support the same communication technology, or they may support different communication technologies. For example, interface 113-1 may enable USB communication, and interface 113-2 may enable NFC or Bluetooth communication.
[0030] The out-of-band communication channel 109 established between the interfaces 113 of the two DCNs 110 is separate from the process automation network 106. The out-of-band communication channel 109 may or may not be transient. In scenarios where the process automation network 106 is implemented using Ethernet, the connection 107 between the DCNs 110 and the process automation network 106 may be a registered jack (RJ) 45 connection in some implementations. In many such cases, the out-of-band communication channel 109 may be implemented using a different communication technology, such as USB, NFC, Bluetooth, etc. However, in other implementations, the out-of-band communication channel 109 may be implemented as a separate network / subnet sandboxed from the process automation network 106 but using the same type of communication technology (e.g., Ethernet) as the process automation network 106.
[0031] 2, an out-of-band communication channel 109 is established between a first interface 113-1 of a first DCN 110-1 and a fourth interface 113-4 of its replacement, a fourth DCN 110-4. For example, the first DCN 110-1 may be small enough to be carried by a person and thus may be easily physically coupled to other nearby devices, such as the fourth DCN 110-4, via the interface 113-1. Although FIG. 2 shows the first DCN 110-1 disconnected from the process automation network 106 and the fourth DCN 110-4 connected to the process automation network 106, this is not required. In some implementations, the techniques described herein may be performed between two DCNs (or between other devices) without either being connected to the process automation network 106.
[0032] The first DCN 110-1 can transmit (e.g., push) IT and / or OT configuration data to the fourth DCN 110-4 using the out-of-band communication channel 109. In the replacement scenario demonstrated in Figures 1-2, the first DCN 110-1 can replicate its IT and / or OT configuration data to the fourth DCN 110-4, e.g., thereby enabling the fourth DCN 110-4 to take over the role previously played by the first DCN 110-1 within the process automation facility 108. For example, the fourth DCN 110-4 can take over the IP address previously used by the first DCN 110-1. Similarly, to the extent that the OT capabilities of DCN 110-4 correspond to and / or are compatible with the OT capabilities of the first DCN 110-1, the first DCN 110-1 can replicate its OT configuration data to the fourth DCN 110-4, thereby enabling the latter to take over the former's role with little to no disruption. In various implementations, the out-of-band communication channel 109 can then be closed, for example, logically using software and / or physically by severing the cable connection between the two.
[0033] In a non-replacement scenario, by contrast, the first DCN 110-1 may continue to operate as part of the process automation facility 108. In such a scenario, the first DCN 110-1 and / or the fourth DCN 110-4 may take various measures to avoid future IT and / or OT conflicts, including, but not limited to, conflicts between network parameters such as IP addresses. By way of example, neither DCN 110-1 / 110-4 may be able to transmit data over the process automation network 106 until they are assigned different IP addresses, e.g., the first DCN 110-1 retains its original IP address and the fourth DCN 110-4 is assigned a new, available IP address. In some implementations, the authorization module 104 may determine and assign the new IP address based on, for example, a table of assigned and unassigned IP addresses stored in the database 105. In various implementations, the authorization module 104 may determine / assign a new IP address in response to various events, such as a request from one or both of the DCNs 110-1 / 110-4.
[0034] In some implementations, the DCNs 110-1 / 110-4 can exchange signals to confirm the assignment of the new IP address. For example, upon receiving the new available IP address, the first DCN 110-1 can close the out-of-band communication channel 109. This closure can signal the fourth DCN 110-4 that it can now rejoin the process automation network 106 and / or begin exchanging data over the process automation network 106 again. As another example, the DCN that received the new IP address can send a signal to the other DCN, for example, over the out-of-band communication channel 109 or even over the process automation network 106, thereby enabling the other DCN to rejoin the process automation network 106 and / or begin exchanging data over the process automation network 106 again.
[0035] Referring now to FIG. 3 , an exemplary process flow between a provisioned DCN 310-1, a provisioning DCN 310-2, and the process automation network 106 is illustrated schematically. In FIG. 3 , time progresses down the page. In some cases, the process may begin with a first DCN 310-1 (including actuator 316-1) being physically connected to the process automation network 106, for example, using an RJ-45 connection 107, although this is not required. If such a physical connection is made, the first DCN 310-1 may initially be unable to join or exchange data over the process automation network 106 because the first DCN 310-1 lacks the appropriate network parameters. Meanwhile, in FIG. 3 , a second DCN 310-2, including actuator 316-2, is physically connected to the first DCN 310-1 to establish an out-of-band communication channel 109. As previously mentioned, out-of-band communication channel 109 may be implemented using wired or wireless technologies. Thus, in a wireless context, the physical connection shown between DCNs 310-1 to 310-2 in FIG. 3 may be omitted.
[0036] The second DCN 310-2 then sends / push the IT configuration data to the first DCN 310-1 via the out-of-band communication channel 109. This IT configuration data may be usable by the first DCN 310-1 to join the process automation network 106. In various implementations, the IT configuration data may include networking parameters such as IP addresses (e.g., those previously used by the second DCN 310-2) and / or subnet masks, as well as other networking parameters and / or tools such as public encryption keys, certificates, time-sensitive networking parameters, Domain Name System (DNS) lookup tables, etc.
[0037] In various implementations, this pushing of the IT configuration data can trigger a provisioning routine on the first DCN 310-1. In various implementations, the provisioning routine can be performed, for example, by the first DCN 310-1 to automatically configure the first DCN 310-1 based on the IT configuration data. For example, the first DCN 310-1 can configure its network interfaces with IP addresses and / or subnet masks. In some implementations, as shown in FIG. 3 , the provisioning routine can restart one or more networking services (e.g., TCP, UDP, IP, etc.) run by the first DCN after the first DCN 310-1 is configured based on the IT configuration data.
[0038] After the first DCN 310-1 is configured with the IT configuration data (and any applicable networking services are restarted), the first DCN 310-1 may be able to join the process automation network 106. Meanwhile, the second DCN 310-2 may push OT configuration data to the first DCN 310-1. The provisioning routine described above may also include the first DCN 310-1 making various adjustments (installation, parameter adjustments, etc.) based on the OT configuration data received from the second DCN 310-2 via the out-of-band communication channel 109.
[0039] The first DCN 310-1 can then coordinate with various other process automation nodes communicatively coupled to the process automation network 106, for example, by exchanging commands and / or sensor data therewith via the process automation network 106 for purposes of performing at least a portion of an automated process. Once the first DCN 310-1 is able to exchange data via the process automation network 106, the first DCN 310-1 or the second DCN 310-2 can close the out-of-band communication channel 109 and / or the DCNs 310-1 and 310-2 can be physically disconnected from each other, as shown in FIG.
[0040] 4 is a flowchart illustrating an example method 400 for provisioning a first DCN to operate as part of a process automation system, according to implementations disclosed herein. For convenience, the operations of the flowchart are described with reference to a system that performs those operations. The system may include various components of various computer systems, such as one or more components of the process automation management system 102, and / or other devices, such as the DCN 110 / 310. Additionally, while the operations of method 400 are shown in a particular order, this is not intended to be limiting. One or more operations may be rearranged, omitted, or added.
[0041] In block 402, the system may establish a temporary out-of-band communication channel (e.g., 109) between the first DCN and the second DCN. In various implementations, the temporary out-of-band communication channel may be separate from the process automation network (e.g., 106) that will communicatively couple the first DCN with other process automation nodes of the process automation system (e.g., 108).
[0042] In block 404, the system may transmit provisioning data, for example, by the second DCN from the second DCN to the first DCN via a temporary out-of-band communication channel. In some implementations, this transmission may be one-way, but is not required. In various implementations, this provisioning data may include IT configuration data usable by the first DCN to participate in a process automation network and OT configuration data usable by the first DCN to coordinate with one or more other process automation nodes of the process automation system to implement at least a portion of an automated process.
[0043] In block 406, in response to the transmission of block 404, the system may trigger a provisioning routine on the first DCN. This provisioning routine may perform a variety of different actions to prepare the first DCN to join a process automation network and cooperate with other process automation nodes as part of a process automation system. For example, the file system and / or OS used by the first DCN may be detected and used to determine where certain IT and / or OT data should be stored. As another example, various networking and / or other services may be restarted so that parameters contained within the IT / OT configuration data become active. In some implementations, particularly when the second DCN is simulated by a computer system, the display and / or other output of the computer system may be used to present a user interface operable to manually configure the data and / or the data, if necessary or beneficial.
[0044] Following the transmitting, the out-of-band communication channel may be closed, for example, by the first DCN or the second DCN, or even manually by a technician, in block 408. However, in other implementations and / or in certain scenarios, the out-of-band communication channel may be maintained for other purposes, such as redundancy, load balancing, etc., in which case block 408 may be omitted.
[0045] As mentioned above, if both DCNs are to continue to be used, measures can be taken to avoid collisions between networking parameters, particularly IP addresses. For example, in block 410, the first DCN can be transitioned to a locked state in which the first DCN rejects at least some subsequent provisioning data. This locked state may or may not be permanent. In some implementations, the locked state can prevent the first DCN from being accidentally or maliciously overwritten, at least until an administrator manually unlocks it. As another example, in block 412, the second DCN can be transitioned to a disabled state in which the second DCN is prevented from exchanging data over the process automation network and / or the second DCN is prevented from replicating IT and / or OT configuration data to any additional DCNs. This can avoid potential collisions and ensure that different people do not accidentally (or maliciously) use the same DCN to overwrite multiple other DCNs.
[0046] 5 is a flowchart illustrating an example method 500 for a provisioned DCN 110 / 310 to practice selected aspects of the present disclosure, according to implementations disclosed herein. While the operations of method 500 are shown in a particular order, this is not intended to be limiting. One or more operations may be rearranged, omitted, or added.
[0047] In block 502, a DCN (e.g., 110-4 in FIGS. 1-2, 310-1 in FIG. 3) may establish a temporary out-of-band communication channel (e.g., 109) with a provisioning DCN (e.g., 110-1 in FIGS. 1-2, 310-2 in FIG. 3). As previously mentioned, the temporary out-of-band communication channel may be separate from the process automation network (e.g., 106) that will communicatively couple the DCN with other process automation nodes of the process automation system (e.g., 108).
[0048] In block 504, the DCN 110 / 310 may receive IT configuration data and OT configuration data from the provisioning DCN via a temporary out-of-band communication channel. Based on the IT configuration data, the DCN may join the process automation network in block 506. Based on the OT configuration data, the DCN may then coordinate with one or more of the other process automation nodes of the process automation system to implement at least a portion of the automated process.
[0049] 6 is a block diagram of an exemplary computing device 610 that can optionally be utilized to implement one or more aspects of the techniques disclosed herein. The computing device 610 typically includes at least one processor 614 that communicates with several peripheral devices via a bus subsystem 612. These peripheral devices can include, for example, a storage subsystem 624 including a memory subsystem 625 and a file storage subsystem 626, a user interface output device 620, a user interface input device 622, and a network interface subsystem 616. The input and output devices enable user interaction with the computing device 610. The network interface subsystem 616 provides an interface to external networks and is coupled to corresponding interface devices in other computing devices.
[0050] The user interface input devices 622 may include a keyboard, a pointing device (such as a mouse, trackball, touchpad, or graphics tablet), a scanner, a touchscreen integrated into a display, an audio input device (such as a voice recognition system, a microphone), and / or other types of input devices. In general, use of the term "input device" is intended to include all possible types of devices and ways to input information into the computing device 610 or over a communications network.
[0051] The user interface output devices 620 may include a display subsystem, a printer, a fax machine, or a non-visual display such as an audio output device. The display subsystem may include a cathode ray tube (CRT), a flat panel device such as a liquid crystal display (LCD), a projection device, or some other mechanism for producing a visible image. The display subsystem may also provide a non-visual display, such as via an audio output device. In general, use of the term "output device" is intended to include all possible types of devices and ways to output information from the computing device 610 to a user or to another machine or computing device.
[0052] Storage subsystem 624 stores programming and data structures that provide the functionality of some or all of the modules described herein. For example, storage subsystem 624 may include logic for performing selected aspects of the methods of Figures 4-5 and for implementing various components shown in Figures 1-3.
[0053] These software modules are typically executed by the processor 614 alone or in combination with other processors. The memory 625 used within the storage subsystem 624 may include several memories, including a main random access memory (RAM) 630 for storing instructions and data during program execution, and a read-only memory (ROM) 632 in which fixed instructions are stored. The file storage subsystem 626 may provide persistent storage for program files and data files and may include hard disk drives, floppy disk drives and associated removable media, CD-ROM drives, optical drives, or removable media cartridges. Modules that implement functionality of some implementations may be stored by the file storage subsystem 626 within the storage subsystem 624 or within other machines accessible to the processor 614.
[0054] The bus subsystem 612 provides a mechanism for allowing the various components and subsystems of the computing device 610 to communicate with each other as intended. Although the bus subsystem 612 is shown schematically as a single bus, alternative implementations of the bus subsystem may use multiple buses.
[0055] Computing device 610 can be of various types, including a workstation, a server, a computing cluster, a blade server, a server farm, or any other data processing system or computing device. Due to the ever-changing nature of computers and networks, the description of computing device 610 shown in Figure 6 is intended only as one particular example intended to illustrate some implementations. Many other configurations of computing device 610 are possible, having more or fewer components than the computing device shown in Figure 6.
[0056] Although several implementations have been described and illustrated herein, various other means and / or structures can be utilized to perform the functions described herein and / or obtain one or more of the results and / or advantages described herein, and each such variation and / or modification is considered to be within the scope of the implementations described herein. More generally, all parameters, dimensions, materials, and configurations described herein are intended to be exemplary, and the actual parameters, dimensions, materials, and / or configurations will depend on the specific application or applications in which the present teachings are used. Those skilled in the art will recognize, or be able to ascertain using no more than routine experimentation, many equivalents to the specific implementations described herein. Accordingly, it should be understood that the foregoing implementations are presented by way of example only, and that, within the scope of the appended claims and their equivalents, implementations may be practiced otherwise than as specifically described and claimed. Implementations of the present disclosure are directed to each individual feature, system, article, material, kit, and / or method described herein. Additionally, any combination of two or more such features, systems, articles, materials, kits, and / or methods is included within the scope of the present disclosure, if such features, systems, articles, materials, kits, and / or methods are not mutually inconsistent. [Explanation of symbols]
[0057] 100 Environment 102 Process Automation Management System 104 Authorization Module 105 databases 106 Process Automation Network 107 RJ-45 connection 108 Process automation facilities, process automation systems 109 Out-of-Band Communication Channels 110 DCN, Compute DCN 110-1 First DCN 110-2 Second DCN 110-3 Third DCN 110-N Compute DCN 112 Circuit or Logic 113 Communication Interface 113-1 First Interface 113-2 Interface 113-4 The Fourth Interface 113-N interface 114FT Components 114-1 Flow Transmitter (FT) Components 114-2 FT Component 116 Actuator 116-1 DCN, Actuator 116-4 Actuator 118 Sensors 118-3 Sensor 310 DCN 310-1 First DCN 316-1 Actuator 316-2 Actuator 400 ways 500 ways 610 Computing Devices 612 Bus Subsystem 614 processor 616 Network Interface Subsystem 620 User Interface Output Device 622 User Interface Input Devices 624 Storage Subsystem 625 Memory Subsystem, Memory 626 File Storage Subsystem 630 Main Random Access Memory (RAM) 632 Read-Only Memory (ROM)
Claims
1. 1. A method for provisioning a first distributed control node (DCN) to operate as part of a process automation system, the method being implemented using one or more processors, comprising: establishing a temporary out-of-band communication channel between the first DCN and a second DCN, the temporary out-of-band communication channel being separate from a process automation network that communicatively couples the first DCN with other process automation nodes of the process automation system; transmitting provisioning data from the second DCN to the first DCN via the temporary out-of-band communication channel, the provisioning data comprising: Information technology (IT) configuration data usable by the first DCN to participate in the process automation network; and operational technology (OT) configuration data usable by the first DCN to coordinate with one or more of the other process automation nodes of the process automation system to implement at least a portion of an automated process; and following the transmitting step, closing the temporary out-of-band communication channel; Including, 10. The method of claim 1, wherein one of the first DCN or the second DCN refrains from transmitting data on the process automation network until the other of the first DCN or the second DCN is assigned a new Internet Protocol (IP) address.
2. The method of claim 1 , wherein the IT configuration data includes one or more networking parameters previously used by the second DCN.
3. The method of claim 2 , wherein the transmitting step includes replicating one or both of the IT configuration data and the OT configuration data from the second DCN to the first DCN.
4. 4. The method of claim 3, further comprising, following the replicating step, transitioning the second DCN to a disabled state in which the second DCN is prevented from replicating IT configuration data or OT configuration data to any additional DCNs.
5. The method of claim 4 , further comprising, following the replicating step, transitioning the first DCN to a locked state in which the first DCN rejects at least some subsequent provisioning data.
6. The method of claim 1 , wherein the second DCN is simulated by a computing device.
7. 7. The method of claim 1, further comprising: in response to the transmission, triggering a provisioning routine on the first DCN, the provisioning routine automatically configuring the first DCN based on the IT configuration data and the OT configuration data.
8. The method of claim 7 , wherein the provisioning routine restarts one or more networking services performed by the first DCN after the first DCN is configured based on the IT configuration data.
9. 9. The method of claim 1, wherein the temporary out-of-band communication channel comprises a Universal Serial Bus (USB) channel and the process automation network comprises an Ethernet network.
10. 10. The method of claim 1, wherein the temporary out-of-band communication channel comprises a Near Field Communication (NFC) channel or a Bluetooth channel.
11. 2. The method of claim 1, further comprising exchanging, between the first DCN and the second DCN, confirmation data that the other of the first DCN or the second DCN has received the new IP address via the temporary out-of-band communication channel.
12. 12. The method of claim 1 or 11, wherein in response to the assignment of the new IP address, the temporary out-of-band communication channel is closed.
13. A distributed control node (DCN), comprising: establishing a temporary out-of-band communication channel with a provisioning DCN, the temporary out-of-band communication channel being separate from a process automation network that will communicatively couple the DCN with other process automation nodes of a process automation system; receiving information technology (IT) configuration data and operational technology (OT) configuration data from the provisioning DCN via the temporary out-of-band communication channel; joining the process automation network based on the IT configuration data; coordinating with one or more of the other process automation nodes of the process automation system to perform an at least partially automated process based on the OT configuration data; a circuit for performing A distributed control node (DCN), wherein the DCN refrains from transmitting data on the process automation network until the provisioning DCN is assigned a new Internet Protocol (IP) address.
14. The DCN of claim 13 , wherein the IT configuration data includes one or more networking parameters previously used by the provisioning DCN.
15. The DCN of claim 14 , wherein one or both of the IT configuration data and the OT configuration data are replicated from the provisioning DCN to the DCN.
16. 16. The DCN of claim 15, further comprising instructions for transitioning the DCN to a locked state in which the DCN rejects at least some subsequent provisioning data.
17. 17. The DCN of claim 13, further comprising instructions for triggering a provisioning routine on the DCN in response to receiving the IT configuration data and the OT configuration data, the provisioning routine automatically configuring the DCN based on the IT configuration data and the OT configuration data.
18. 20. The DCN of claim 17, wherein the provisioning routine restarts one or more networking services performed by the DCN after the DCN is configured based on the IT configuration data.
19. 1. At least one non-transitory computer-readable medium for provisioning a first distributed control node (DCN) to operate as part of a process automation system, the medium comprising instructions that, when executed by one or more processors, cause the one or more processors to: establishing a temporary out-of-band communication channel between the first DCN and a second DCN, the temporary out-of-band communication channel being separate from a process automation network that communicatively couples the first DCN with other process automation nodes of the process automation system; transmitting provisioning data from the second DCN to the first DCN via the temporary out-of-band communication channel, wherein the provisioning data comprises: Information technology (IT) configuration data usable by the first DCN to participate in the process automation network; and operational technology (OT) configuration data usable by the first DCN to coordinate with one or more of the other process automation nodes of the process automation system to implement at least a portion of an automated process; transmitting, closing the temporary out-of-band communication channel following said transmission of said provisioning data; Let them do this, At least one non-transitory computer-readable medium, wherein one of the first DCN or the second DCN refrains from transmitting data on the process automation network until the other of the first DCN or the second DCN is assigned a new Internet Protocol (IP) address.
Citation Information
Patent Citations
Device setting device, and device setting method
JP2010002967A
Safety control device and method for controlling safety control device
JP2011170581A
Controller
JP2017097526A
Modular monitoring, control and device management for use with process control systems
US20040260405A1
Setting in wireless communication device for encrypted communication
US20050154874A1