Methods, computer programs, and industrial plant systems for integrating asset data from industrial assets located within an industrial plant.

A two-layered processing system in industrial plants integrates and analyzes data efficiently, addressing security and latency issues by generating technical context data in a secure layer, ensuring uninterrupted and safe data access and transfer.

JP7860002B2Active Publication Date: 2026-05-15BASF SE
View PDF 3 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
BASF SE
Filing Date
2021-06-22
Publication Date
2026-05-15

AI Technical Summary

Technical Problem

Industrial plants face challenges in efficiently integrating and analyzing data from geographically dispersed sensors due to security constraints and latency issues, leading to inefficient production and safety risks.

Method used

A method involving a two-layered processing system where technical context data is generated in a secure second processing layer, allowing data integration and analysis while adhering to security standards, and includes accessibility criteria to manage resource allocation and data transfer.

Benefits of technology

Enables scalable, flexible, and reliable data handling across multiple plants, ensuring uninterrupted access and improved monitoring without compromising plant safety or efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007860002000001
    Figure 0007860002000001
  • Figure 0007860002000002
    Figure 0007860002000002
Patent Text Reader

Abstract

The present invention provides a medical device fixation system (10) for releasably fastening a medical device (C), such as a catheter hub, to a patient's skin. The system (10) comprises a main body having a first section (14) and a second section (16) displaceable relative to one another to translate the system between an undeployed state and a deployed state, skin-adherable elements in the form of a microneedle array projecting from a tissue-contacting surface of the first section (14) and a second array of microneedles projecting from a tissue-contacting surface of the second section (16), and a retention device (24) provided on the main body for receiving and engaging the medical device (C), wherein the first section (14) includes a first base defining a tissue-contacting surface and a closure member (20) articulated to the first base by a hinge.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] Technical Field The present disclosure generally relates to computer-based monitoring and / or optimization of industrial plants.

Background Art

[0002] Background Art Industrial plants, such as process plants, comprise equipment that is operated to produce one or more industrial products. The equipment can be, for example, machinery and / or heat exchangers that require monitoring and maintenance. The maintenance requirements can depend on several factors including the operating time and / or the load on the equipment, the environmental conditions to which the equipment is exposed, etc. Excessive or unplanned downtime of the equipment is generally undesirable. This is because it often causes production stoppages, which can reduce the efficiency of the plant and result in waste. Since the period between two maintenance operations can vary, it can be difficult to plan the downtime of the equipment when maintenance is actually required. In addition, safety is of high importance in industrial plants. Different equipment or parts of the plant can be monitored to prevent dangerous situations from occurring.

[0003] For example, an industrial plant such as a chemical plant can comprise equipment such as reactors, storage tanks, heat exchangers, compressors, valves, etc., which are monitored using sensors. At least some of the equipment can be monitored and / or controlled to produce one or more industrial products. The monitoring and / or control can even be performed to optimize the production of one or more products.

[0004] Industrial plants typically comprise a plurality of sensors distributed within the plant for monitoring and / or control purposes. Such sensors can generate large amounts of data. Therefore, production, such as chemical production, can be an environment with a large amount of data. However, at present, the benefits of such data from multiple data sources for increasing production efficiency in one or more plants have not been fully utilized.

[0005] Furthermore, data sources such as sensors are sometimes geographically dispersed or located across multiple sites. In some cases, a site may be located in a different city from one or more other sites, or even in a different country. As can be understood, utilizing data from one or more geographically dispersed data sources can be challenging.

[0006] The application of new technologies in cloud computing and big data analytics is of great interest in industrial plants. Unlike some other manufacturing sectors, process industries may be subject to higher security standards. For this reason, computing infrastructure is typically siloed, and access to monitoring and control systems is very limited. Due to such security standards, considerations of latency and availability may conflict with the simple migration of embedded control systems to, for example, cloud computing systems. Therefore, bridging the gap between highly proprietary industrial manufacturing systems and cloud technology has become one of the challenges in process industries.

[0007] Therefore, there is a need for methods to monitor and / or analyze data from industrial plants that can enable scalable and flexible integration of data from distributed data sources. [Overview of the project] [Means for solving the problem]

[0008] overview It is shown that at least some of the problems inherent in the prior art are solved by the subject matter of the attached independent claims.

[0009] From a first perspective, a method for integrating asset data from industrial assets located within an industrial plant, wherein the assets are communicatively coupled to a first processing layer, asset data is provided to a second processing layer via the first processing layer, the first processing layer is communicatively coupled to the second processing layer, and the first and second processing layers are configured within a secure network, and this method is - In the second processing layer, technical context data related to the asset is generated, - Providing technical context data to the interface to the external network via the second processing layer, Includes, A method may be provided in which the technical context data includes one or more accessibility criteria for asset data, and the accessibility criteria include one or more rules and / or parameters that can be conformed to by an external processing layer in order to receive the asset data.

[0010] The method for integrating asset data as described above may also be understood as a method for data integration of asset data, or further, a method for monitoring and / or analyzing at least a portion of asset data, wherein the asset data is generated through industrial assets in an industrial plant, the assets are communicatively coupled to a first processing layer, at least a portion of the asset data is provided to a second processing layer via the first processing layer, the first processing layer is communicatively coupled to the second processing layer, and the first and second processing layers are configured within a secure network.

[0011] The teachings of this proposal enable more efficient data handling via a second processing layer. Furthermore, uninterrupted data access across different processing layers and cloud connectivity can be provided. These teachings can bridge the gap between operational and information technologies in highly advanced process industrial environments. By aggregating contextualized data within a separate layer, the availability and performance of the first layer remain unaffected. Moreover, data exchange with external processing layers outside a secure network can be enabled while adhering to high security standards in the chemical industry. By introducing different process and storage system layers and connecting them communicatively, large-scale data transfer and handling can be distributed across different layers, enabling greater flexibility in contextualization, storage, and access for process applications. In some cases, even multiple industrial plants can be supported via the second processing layer. Thus, highly scalable, more reliable, and enhanced monitoring and / or control of industrial plants can be achieved. In this way, even new technologies such as serverless IaaS / PaaS / SaaS can be integrated into the production environment, enabling continuous application delivery and deployment. It will be understood that there may even be one or more additional processing layers besides the first and second processing layers. These could even be one or more additional processing layers between the first and second processing layers.

[0012] This teaching can also enable more flexible handling of process applications. For example, the deployment of process applications that ingest plant or asset data can be streamlined for multiple assets, even across multiple plants. In addition, the appropriate processing layer can be selected depending on the specific data required by the process application and computing resources needed to run such applications, thus adhering to high availability standards in specific industrial plants such as chemical plants. For example, computationally intensive process applications that require the ingestion of plant-specific data can be run on a second processing layer, while process applications that require the ingestion of asset data and demand low latency can be run on a first processing layer.

[0013] Within an industrial plant, such as a chemical production plant, multiple distributed data sources may exist. Some of these data sources or assets may also be distributed globally. Typically, the aforementioned assets provide data that can be stored in a system or database, such as a Plant Information Management System (PIMS). It is also common for a plant to have a Supervisory Control and Data Acquisition (SCADA) system. The PIMS may be part of the SCADA system or a separate system. In this disclosure, when the term PIMS is used, it should be assumed that alternatives in which the PIMS and SCADA are the same system are also included within the scope of the term PIMS. Similarly, if these are two different systems, data may be transferred to one or both, and therefore their alternatives should also be understood to be within the scope of the term. In some cases, a data source or asset may contain or generate more data than the data provided to the SCADA or PIMS. Therefore, the internal data of a data source may be greater than the data transmitted to and / or stored in the PIMS. For data analysis, such internal asset data, or asset data, can be useful. For example, a change in internal data may be normal for the asset itself, but it may cause or indicate a significant impact on another part of the plant that would not be apparent by simply observing the internal data alone and / or only the output data provided to the PIMS. Furthermore, if similar assets are operating in another plant, data from similar assets can also be used for the optimization of one or more such assets in the other plant. Optimization in this sense can mean any one or more of the following: training machine learning models, monitoring output signals, deriving one or more control or monitoring setpoints, and such functions.Therefore, data from one asset can be used to optimize other similar assets. For process analysis, it can therefore be useful to integrate asset data from different processing layers and / or assets.

[0014] To perform data analysis on data, including asset data, a user operablely connected to an external processing layer may need to define the data analysis. The user may be a person responsible for performing the data analysis via the external processing layer, or another computer processor from which data from the external layer may be supplied, or the user may be the other computer processor itself used to automatically perform the data analysis using the data analysis. The user may even be the external processing layer itself, which has the capability to perform the data analysis. Hereafter, the term “user” will be used to refer to any of the above definitions, or any combination thereof.

[0015] Users may not be aware of the technical status of assets within an industrial plant. The plant, or industrial assets within the plant (or more generally, hereafter referred to as assets), and the plant's network infrastructure are typically secure environments with little to no access to plant data outside the plant. Users with appropriate access rights may be provided with access to asset data generated by one or more assets within the plant, but users may still lack information about other operating parameters within the plant network. Such operating parameters may include resource usage such as network load, central processing unit (CPU) and / or controller load, memory usage, and power consumption within the plant's internal infrastructure. In certain cases, user requests may overload at least part of the plant infrastructure. For example, when a user requests access to or transfer of asset data while critical plant operations require some of the same resources within the plant. In particular, if the request uses a lot of resources, the performance of critical plant operations may be affected due to the processing of the request. In a worse scenario, the plant infrastructure may fail due to the nature of the resource requests in user requests. Therefore, the safety and / or efficiency of the plant may be compromised. To prevent this, this teaching proposes generating technical context data related to the asset in a second processing layer. The technical context data can then be provided to an external network via an interface, and from the external network, it can be provided, for example, to an external processing layer where asset data may be requested. By forwarding requests through the second processing layer, it is possible to prevent the first processing layer from being overloaded.

[0016] In one embodiment, technical context data is at least partially generated using at least one of a priori determined parameters, which include at least a portion of the asset network address, asset CPU load, asset memory such as Random Access Memory ("RAM"), and the network path between the asset and the user. More generally, the a priori determined parameters can be one or more arbitrary properties of one or more computational and / or network resources between the asset and the user. Such parameters preferably indicate one or more physical constraints of computational and / or network resources between the asset and the user, such as available memory, network capacity, processing power, etc. The a priori parameters can be determined from the current operating status of one or more resources, or they can be determined from one or more past accesses and / or transfers of data from or around the asset.

[0017] In one embodiment, a priori determined parameters represent temporal network load values, for example, between assets and users, or between any part of the network, which are critical to the network capacity for transferring asset data from assets to external processing layers or users and / or accessing it. For example, network load can increase almost every morning on a workday because employees access the on-site or plant network essentially simultaneously. During such high-resource-demand periods, the network can be heavily loaded, for example, because many computers start up in a short period of time and applications requiring network access are launched. Due to excessive load, the network may fail. During such periods, the transfer and / or access of asset data may suffer from low throughput, intermittently, or even completely fail. Therefore, data analysis that relied on asset data may also be affected. Further load resulting from the transfer and / or access of asset data may contribute to, or even cause, a failure of network and / or computing resources. Therefore, a temporal network load value, which indicates the estimated or calculated network capacity at a given time, can be at least one of a priori determined parameters based at least partially on the generation of technical context data. This can be used, for example, to prevent or appropriately prioritize the transfer and / or access of asset data from assets to users. Thus, the reliability of remote data analysis requiring asset data can be improved, and in some cases, the efficiency of such analysis can even be increased by minimizing the time within which asset data is transferred. By this aspect of the teaching, and further by other aspects, analysis can therefore be prioritized and optimized according to one or more of the resource capacities.

[0018] In addition, or alternatively, technical context data may be generated at least partially using at least one iterative parameter. The iterative parameter may be determined via a second processing layer by analyzing the response to a partial request, the response indicating the impact of the partial request on plant performance. The iterative parameter may be determined, for example, by analyzing or measuring the response. The response may indicate the impact of the partial request on one or more resources that are critical to the operation, and / or efficiency, and / or safety of any of the plant's assets and / or asset groups. For example, the impact may be estimated by analyzing the response in terms of latency values ​​in response to the partial request.

[0019] In addition, or alternatively, the response may even be calculated using changes in processing load, and / or memory and / or network load. Processing load and / or memory may be measured on any one or more of the assets in the plant, in particular on one or more critical assets. Partial requests may be generated by a second processing layer to access data from an asset. A partial request may include a request for a partial set of asset data from an asset. The partial set of asset data may be a portion of the data requested by an external layer or user, or it may simply be test data for the purpose of evaluating resource capacity. In any case, partial requests are fail-safe requests generated by a second processing layer so as not to cause any harm to plant performance that would result in a real decrease in plant safety, and preferably, efficiency. In other words, partial requests may result in only short-term changes in plant behavior that are not sufficient to cause a significant, practical, or substantial decrease in plant safety. Thus, a partial set of asset data or test data is a small dataset that requests just enough resources, or just enough resources, to allow the response to be analyzed. Therefore, at least one iterative parameter can be used to generate technical context data. As previously disclosed, therefore, at least one iterative parameter can be used to define one or more accessibility criteria. Thus, at least one iterative parameter indicates resource allocation for the outer layer when receiving asset data. It will be understood that the resource allocation can be for any one or more computation and / or network resources between the asset and the user.

[0020] Or, more specifically, this method also, - Through the second processing layer, generate partial requests to access data from assets or asset data, - Measuring the response to a partial request, wherein the response indicates the impact of the partial request on one or more computations and / or network resources. - Determine at least one iteration parameter depending on the response, Includes, Technical context data is generated at least partially using at least one iteration parameter.

[0021] In a further embodiment, a second processing unit may even generate a second partial request in response to a partial request. The second partial request may have a larger resource request for one or more resources than the partial request. Thus, the iteration parameter may be determined via the second processing layer by measuring a second response to the second partial request. A second partial request may be generated if the response to the partial request does not have a sufficiently large or substantial adverse effect on one or more resources than the partial request, and the second partial request has a larger resource request than the partial request.

[0022] Next, at least one iteration parameter can be generated by measuring the response to the second partial request. In some cases, any one or more iteration parameters determined from the partial request and any one or more iteration parameters determined from the second partial request may be included in at least one iteration parameter, thereby using the iteration parameters from each partial request to define one or more accessibility criteria. By doing this, for example, when transfers from multiple assets in a plant are required, the user or external processing layer can adapt the transfer and / or access of asset data. Thus, by managing requests from multiple assets, the data transfer and / or access of asset data can be made more intelligent. In this case, the second processing layer can obtain a more precise determination of one or more resource bottlenecks for providing the data transfer and / or access of asset data to the external layer. For example, in order to respond to requests for asset data from multiple assets, the resource capacity of one or more resources required to satisfy the requests can be distributed in a manner that can provide the best transfer and / or access parameters for the overall data transfer.

[0023] The distribution of resource capacity can be performed based on any one or more of the iterative parameters determined from the partial request and any one or more of the iterative parameters determined from the second partial request. Each response from the partial request and the second partial request can provide a guideline for resource allocation required for various requests. This can be used to allocate capacity for each request when data from multiple assets needs to be accessed simultaneously or almost simultaneously. In any case, the process of determining at least one iterative parameter can be repeated by incrementally adapting the partial request so that the second processing layer can iteratively determine at least one iterative parameter. Therefore, there can be one or more additional partial requests, i.e., more than two partial requests, for determining the resource capacity associated with different resource requirements. This can be used not only to maximize resource allocation for responding to requests from the external processing layer while ensuring that sufficient resource capacity remains for plant operation, but also, as described above, in some cases, the second processing layer and / or the external processing layer can also help pre-actively adapt requests for asset data from multiple assets.

[0024] Or, more specifically, the method also - generating, depending on the response, a second partial request for accessing asset data via the second processing layer, wherein the second partial request requires more resources than the partial request; - measuring a second response to the second partial request, wherein the second response indicates the impact of the second partial request on one or more computing and / or network resources; - determining at least one iterative parameter depending on the response and / or the second response; comprising Technical context data is generated at least in part using at least one iterative parameter.

[0025] Therefore, by combining both aspects, the method - Generating a partial request to access data from an asset or asset data via a second processing layer; - Measuring the response to the partial request, where the response indicates the impact of the partial request on one or more computational and / or network resources; - Depending on the response, generating a second partial request to access data from an asset or asset data via the second processing layer, where the second partial request requires more resources than the partial request; - Measuring the second response to the second partial request, where the second response indicates the impact of the second partial request on one or more computational and / or network resources; - Determining at least one iterative parameter depending on the response and / or the second response; and Technical context data is generated at least in part using at least one iterative parameter.

[0026] As described, the data from an asset can be a subset of the asset data or it can be test data.

[0027] As described above, the technical context data includes one or more accessibility criteria for accessing asset data. The accessibility criteria may include one or more rules that must be followed by the external processing layer in order to access or receive the asset data. Alternatively, or in addition, the accessibility criteria may also include one or more parameters that the transfer and / or access to the asset data must have or be compliant with.

[0028] It will be understood that one or more rules and / or parameters included in the accessibility criteria are selected so that access to and / or transfer of asset data to the external transfer layer, performed either automatically or in accordance with the aforementioned one or more rules and / or parameters, does not affect any critical operation of the plant and / or any of its assets. In other words, by specifying one or more compliant rules and / or parameters, it is possible to prevent any critical plant or asset operation from being adversely affected as a result of access to and / or transfer of asset data to the external processing layer. Critical operation can be any operation or mode of operation of an asset, a group of assets, or the entire plant that, when affected, could lead to a decrease in the safety, and / or efficiency, and / or reliability of the plant and / or any of its associated assets. It can be said that no critical operation of the plant is affected as a result of access to and / or transfer of asset data being performed using one or more rules and / or parameters.

[0029] Therefore, the technical context data includes one or more accessibility criteria for asset data, which include one or more rules and / or parameters that can be followed by an external processing layer to receive the asset data so that no critical plant operation is affected.

[0030] Furthermore, it can be achieved that the user does not need to know at least the operational or resource status within the plant in order for asset data to be accessed or transferred. Therefore, the second processing layer can automatically adapt the accessibility conditions for accessing and / or transferring asset data according to the plant status. Thus, plant security can be improved. Moreover, it can be prevented that sensitive information regarding operational and / or resource status needs to leave the plant's secure network. For example, the external layer does not need to know the plant operational parameters. Rather, the second processing layer can specify one or more rules and / or parameters and provide them to the external processing layer, so that the external processing layer only needs to know one or more accessibility criteria to follow in order for asset data to be accessed and / or transmitted to the external processing layer.

[0031] In certain cases, data transfer and / or access using a given characteristic, such as a data transfer rate, may not be possible over a given network path. For example, a user may require a data transfer rate higher than a given value to perform an analysis, and this rate may not be achievable due to infrastructure constraints. Such constraints may be latency, for example, which can limit total data throughput by affecting the bandwidth-delay product of the data link between the asset and the user. Therefore, in some cases, accessibility criteria or sets of criteria provided to the external processing layer by the second processing layer may be used by the user to request data transfer and / or access according to any reasonable criteria or sets of criteria from the provided accessibility criteria or sets of criteria. In some cases, accessibility criteria or sets of criteria may be provided to the external processing layer after the second processing layer has received a request for access and / or transfer. The request may be initiated by the user. In some cases, the request may include one or more data transfer and / or access characteristics required by the user. If the aforementioned characteristics can be addressed by the plant infrastructure and / or operating conditions, the accessibility criteria or set of criteria provided to the external processing layer by the second processing layer may include one or more data transfer and / or access characteristics required by the user. If one or more access characteristics are available that are superior to one or more of those requested by the user, those superior characteristics may be included in the accessibility criteria or set of criteria provided to the external processing layer. In this case, the external processing layer may decide whether to select the superior data transfer and / or access characteristics from the set of accessibility criteria. Otherwise, the accessibility criteria or set of criteria provided to the external processing layer by the second processing layer may simply include one or more data transfer and / or access characteristics requested by the user.This may be true, for example, when a user request can be addressed without affecting critical plant operations or functions.

[0032] In some cases, technical context data may even include one or more performance parameters, such as latency values ​​or estimates thereof, between the asset and the user. Latency values ​​may be provided for the entire network path between the asset and the user, or for a portion of the network path. For example, in certain cases, the overall latency value may be dominated by a portion of the network or a bottleneck within the network path. In some cases, it may be sufficient to include and provide latency values ​​only for that portion of the network or bottleneck in the technical context data.

[0033] In some cases, the second layer may also apply additional contextualization to the asset data. This additional contextualization may relate to the context available on the second processing layer. Through contextualization, context such as plant identifiers, plant types, reliability indicators, or alarm limits for industrial plants may be added to the asset data. In addition, or alternatively, the technical asset structure, Verbund locations, other asset management structures (e.g., asset networks), or even application context (e.g., model identifiers, third-party exchanges) of one or more plants may also be added to the asset data. Such comprehensive context may be generated from functional locations or digital twins, such as digital piping and instrumentation diagrams, 3D models or scans using the three-dimensional coordinates of plant assets. In addition, or alternatively, for example, local scans from mobile devices linked to piping and instrumentation diagrams may be used for contextualization.

[0034] The contextualization process refers to linking data points available in one or more storage units. Such units may be persistent or non-volatile storage. Data points may be associated with measurements or contextual information. At least one of the storage units may be part of a first processing layer. In addition, or alternatively, at least one of the storage units may be part of a second processing layer. In addition, or alternatively, at least one of the storage units may be part of an external processing layer. Storage units may even be distributed across more than two processing layers. Linking may be generated dynamically or statically. For example, a default or dynamically generated script may generate dynamic or static links between informational data points within one processing layer or across multiple processing layers. Links may be established by generating a new data object containing the linked data itself and storing such a new data object in a new instance. Any stored data point may be actively deleted if a copy is stored elsewhere. Therefore, any data point copied from one storage unit to a new data object in the same or another storage unit may be deleted to reduce storage space. In addition, or alternatively, links can be established by creating metadata objects that have built-in links to address or access each data point within a distributed storage unit. Any data point thus addressable or accessible through the metadata object may remain within its original storage unit. Linking such information and forming new data objects can still be performed, for example, on an external processing layer. For data retrieval, the data objects are accessed directly, or the metadata objects are used to address or access data distributed across one or more storage units.Any actions performed by applications or other entities using such data may either directly access this data, or access a non-persistent image of it, or a persistent copy of it, for example, from cache memory.

[0035] In one embodiment, the first processing layer is associated with only a single plant, i.e., only an industrial plant. Therefore, the first processing layer may be a core process system including one or more processing and storage devices. Such a layer may include one or more distributed processing and storage devices that form a programmable logic controller ("PLC") system and / or a distributed control system ("DCS") having a control loop distributed throughout the plant. Preferably, the first processing layer is configured to control and / or monitor chemical processes and assets at the asset level. Therefore, the first processing is communicatively coupled to the assets. The first processing layer may also monitor and / or control the chemical plant at the lowest level. Furthermore, the first processing layer may be configured to monitor and control critical assets. In addition, or alternatively, the first processing layer may be configured to provide asset data to the second processing layer. The first processing layer may even be configured to provide process data to the second processing layer. Asset data and / or process data may be provided directly or indirectly to the second processing layer.

[0036] The second processing layer may be associated solely with an industrial plant, or it may be associated with more than one plant, e.g., a group of plants or a Verbund. The second processing layer may include a process management system having one or more processing and storage devices. In one embodiment, the second processing layer is configured to manage data transfer to and / or from the first processing layer. The second processing layer may even host and / or organize a process application. Such a process application may monitor and / or control one or more chemical plants or one or more assets. The process management system may be associated with one or more industrial plants.

[0037] In further embodiments, the second processing layer may include an intermediate processing layer, or intermediate processing system, and optionally, a process management system. The intermediate processing layer may be communicatively coupled to the first processing layer. In this case, the first processing layer and the process management system may be coupled via the intermediate processing system. The intermediate processing system may be configured to collect process or asset data provided by the first processing layer. The process management system may be configured to provide plant-specific data for one or more plants to an interface to an external network. The intermediate processing system may be associated with one or more industrial plants. An additional layer of security is added by including an intermediate processing level to the second processing layer. This allows the confidential first processing layer to be isolated from any external network access. In addition, the intermediate level can enable improved data handling by reducing the rate of data transfer to the external processing layer via preprocessing and by improving data quality through contextualization. The load on the first processing layer due to the external processing layer may therefore be reduced in order to provide access to and / or transfer of asset data. In some cases, the intermediate processing layer may even be used to perform data analysis specified by the external processing layer. In particular, when large amounts of data access and / or transfer to the external processing layer are difficult or impossible, asset data can still be utilized by performing analysis on the intermediate processing layer. The data analysis results from the analysis of asset data can then be transmitted to the user via an interface. The option to perform data analysis locally on the intermediate layer can be specified in the technical context data. In some cases, the intermediate layer may be used to cache data from assets with high data throughput, at least. Therefore, an intermediate layer isolated from the first processing layer may be used to better handle and respond to resource-intensive requests from users without affecting the behavior of the first processing layer as a result of requests from the external processing layer.Therefore, plant safety and / or reliability can be further improved while enabling better access to asset data. Thus, asset data can be better utilized in a scalable and flexible manner, regardless of plant size and the user's remote location from the assets. Intermediate processing systems and process management systems may include one or more processing and storage devices.

[0038] Therefore, as described in this disclosure, the second processing layer may be configured to contextualize process and / or asset-specific data. Performing contextualization through the second processing layer does not affect the performance of the first processing layer. This can also be advantageous for legacy plants, as such plants can be retrofitted using the second processing layer while leaving the first processing layer essentially immutable. Typical core process systems in legacy plants are built using older generation computer systems to implement the plant infrastructure. Such legacy process systems often lack the computing power required to perform data-intensive tasks. Core processing systems in most industrial plants are rarely upgraded because such systems are highly integrated with several other components of the plant, and any changes may require thorough testing to ensure the performance and safety of the new system. Therefore, many plants may continue to use systems that would be outdated or legacy systems compared to the latest technologies on the market. Contextualization can be made possible even for such plants by adding a separate second processing layer as a further system with higher performance. Therefore, this teaching can provide a scalable and flexible way to implement contextualization even in older plants. In addition, in some cases, a second processing layer and, if an intermediate processing system is implemented, can also enable data contextualization at the plant level rather than the asset level. In the context of this disclosure, data contextualization relates to adding contextual information to process or asset data, or reducing data size by preprocessing process or asset-specific data. Adding context may include adding further informational tags to process or asset data. Preprocessing may include filtering, aggregating, normalizing, averaging, or inferring from process or asset data.

[0039] In further embodiments, one-way or two-way communication, such as data transfer or data access, may be implemented for data streams between different processing layers. One data stream may include process or asset data from a first processing layer, which is passed to a second processing layer, contextualized through it, and communicated to an external processing layer. Contextualization may be performed on the second processing layer. In some cases, contextualization may even be performed on the external processing layer, or on both the second and external processing layers. Furthermore, depending on the importance of the process or asset data, or plant-specific data, such data may be allocated for one-way or two-way communication. For example, data communication from a second or external processing layer to a critical asset may be prohibited by implementing a one-way communication channel. Such communication may only allow one-way communication from the critical asset to the processing layer, and not the other way around. Therefore, access to at least some critical assets may be read-only, for example, allowing only the reading of asset data and not the transmission of data to the asset.

[0040] The second processing layer, as disclosed in this disclosure, may be implemented as a process control system. As stated above, the second processing layer may be communicably coupled to an external processing layer via an external network. The second processing layer may even be configured to manage data transfer to and / or from the external processing layer.

[0041] In one embodiment, the external processing layer may be at least partially implemented as a computing or cloud environment that provides virtualized computing resources, such as data storage and computing power. In addition, in cases where multiple industrial plants operated by different parties are to be monitored and / or controlled, data or process applications affecting the industrial plants may be shared within such a cloud environment.

[0042] In a further embodiment, the second processing layer is configured to manage data transfer to and / or from the external processing layer either in real time or on demand. It will be understood that data transfer is performed via any one of one or more accessibility criteria. Depending on the network and computing load to the interface to the external network, or further to the user, real-time transfers may be buffered. On-demand transfers may be triggered by one or more accessibility criteria in a predetermined, default, or dynamic manner.

[0043] In a further embodiment, the second processing layer and / or external processing layer are configured to exchange data via a third-party management system. This can be achieved through a secure connection such as a VPN, or through the integration of a third-party or shared processing layer.

[0044] An asset can be an Internet of Things ("IoT") device or system, or even a system comprising one or more IoT devices. More specifically, an asset can be an industrial Internet of Things ("IIoT") device or system, or even a system comprising one or more IIoT devices. For example, an asset could be an IoT sensor or even a Cyber-Physical System ("CPS"). In this context, CPS encompasses any industrial system comprising a network of interacting elements. Therefore, the term includes industrial systems such as modern robotic systems and industrial control systems that leverage intelligent mechanisms to establish closer links between the computational and physical elements of such systems.

[0045] Therefore, based on the above, this method may also have the following embodiments. Or, more specifically, according to one embodiment, this method also, - This includes transmitting technical context data to an external processing layer via an interface.

[0046] In a further embodiment, this method also, - In the second processing layer, receive one or more selected accessibility criteria. Includes, One or more selected accessibility criteria are chosen from technical context data, and the selection is performed by an external processing layer.

[0047] In a further embodiment, this method also, - Receiving asset data in the external processing layer. Includes, Asset data is transmitted via a second processing layer according to one or more selected accessibility criteria.

[0048] In one embodiment, technical context data is stored as historical technical context data in user-side memory or a database, for example, via an external processing layer. The user or the external processing layer may then use the historical context data from one or more past accesses and / or transfers of asset data to access and / or transfer further asset data. The historical technical context data may even be stored in the external processing layer, and / or the memory or database may be accessible via the external processing layer.

[0049] In a further embodiment, this method also, - To store at least a portion of the technical context data as historical context data via an external processing layer, - In the second processing layer, one or more pre-selected accessibility criteria are received, Includes, One or more pre-selected accessibility criteria are chosen from the technical context data of the history, and the selection is performed by an external processing layer.

[0050] This can further increase the speed of the access and / or transfer process for asset data. Historical context data may even include data related to the availability of assets and / or other resources within the plant based on date and / or time (e.g., processing load, network bandwidth, latency). Therefore, the external processing layer can automatically adapt access and / or transfer for asset data according to the historical availability of plant resources and / or assets. Thus, even though isolated from the plant, users may be able to leverage and adapt to the data availability from assets.

[0051] An industrial asset can be any part of the equipment associated with an industrial plant, or more simply, a plant. Therefore, it will be understood that an asset can be any device or any single part of equipment that has the ability to generate data that can be used to evaluate the performance of the asset and / or that of the plant. The data preferably includes measurement data indicating the values ​​of one or more process parameters of the asset and / or plant, but it may even indicate one or more binary parameters, such as the state of a valve or the "on" or "off" state of one or more devices. The terms “industrial asset” and “asset” are used interchangeably in this disclosure to refer to any single part or group of plant equipment. As stated above, an asset can be any equipment that has the ability to generate data, preferably in digital format, that can be used for plant monitoring and / or analysis. As stated above, the term “asset” may even refer to a group of equipment, for example, a robot station including multiple motors, actuators, and sensors. Other non-limiting examples of an asset include any one or more of heat exchangers, reactors, pumps, tubes, distillation or absorption cylinders, or any combination thereof. Asset data can be data generated by the asset or data generated within the asset. For example, using the same example of a robot station, asset data could be data from any one or more of the robot station's sensors. Asset data could be data from a combination of multiple sensors and / or process parameters, or from the robot station's memory, or even from the controller. Some non-limiting examples of process parameters include controller setpoints, output signals, settings, history or log data, and any kind of configuration data.

[0052] In newer plant operation technology (OT) systems, it may be desirable to run one or more computer applications on a cloud computing platform. Such applications may require data from one or more assets in the plant. Therefore, in some cases, it may be necessary to transfer asset data to the cloud platform in order to make the data accessible for the application. It will be understood that the external processing layer in such cases can also be implemented within the cloud platform. The problem with older OT systems, particularly PIMS or SCADA, is that they may have a much longer lifecycle, and in such plants, the system as a whole remains outdated / legacy technology. Typically, older OT systems are not designed to provide data in real time or near real time. Furthermore, such systems often lack a streaming interface for sending or reading data. Therefore, the only solution for the user or external processing layer may be to periodically poll for data requests to receive new asset data. The applicant recognized that such a polling interface can be very inefficient.

[0053] Therefore, the applicant recognized a more efficient way of transferring asset data. If not all asset data can be provided from the system in real time or near real time, the second processing layer may be configured to provide or transmit at least low-resolution asset data. At least this embodiment will be understood to be patentable on its own for the technical advantages which will be outlined below. Combined with the rest of the features of this teaching, this can result in further synergies which include the ability to pre-plan the transfer of asset data from the plant with computational bottlenecks by configuring and planning the data transfer to an external processing layer or user using technical context data. This can result in better ordering of data analysis tasks according to the availability of asset data.

[0054] The term "all asset data" may mean asset data requested by the external processing layer, or it may be asset data required by the external processing layer. Situations where all asset data cannot be provided in real-time or near real-time may include, for example, when all requested or required asset data cannot be retrieved from the assets in real-time or near real-time by the second processing layer. In addition, or alternatively, situations where all asset data cannot be provided in real-time or near real-time may even occur when the transmission of all requested or required asset data is not possible in real-time or near real-time. Therefore, any computational and / or network bottlenecks may prevent data transfer in real-time or near real-time.

[0055] Therefore, from another perspective, a method for preprocessing asset data from industrial assets located within an industrial plant, wherein the assets are communicatively coupled to a first processing layer, the asset data is provided to a second processing layer via the first processing layer, the first processing layer is communicatively coupled to the second processing layer, and the first and second processing layers are configured within a secure network, and this method, - A method may also be provided which involves providing low-resolution asset data via a second processing layer, wherein the low-resolution asset data is a subset of asset data requested by an external processing layer, and the low-resolution data is available to the external processing layer to initiate at least one or more data analyses.

[0056] The preprocessing method may be carried out independently or in conjunction with the rest of the embodiments. Accordingly, industrial systems for preprocessing asset data and software products for carrying out the preprocessing steps may also be provided as independent embodiments or in conjunction with the rest of the embodiments of this teaching.

[0057] In some cases, low-resolution asset data may be the lowest-resolution portion of asset data available to the external processing layer, while the remainder of one or more portions of the asset data may be provided later. It will be understood that this has the advantage that the external processing layer does not have to wait until the entire asset data is available and data processing, such as data analysis, can finally begin. Therefore, the external processing layer can begin processing the lowest-resolution portion of the asset data, or coarse asset data, while the remainder of the asset data is received in the background or provided later. Similarly, low-resolution or coarse asset data may even be data with a higher resolution than the lowest-resolution portion of asset data available to the external processing layer. Therefore, if it is possible to provide the external processing layer with data with a higher resolution than the minimum available resolution, it may be provided, while the remainder of the required asset data is provided in the background or provided later. The term "provided in the background" may mean, for example, caching or storing the remainder of one or more portions of the asset data in a second processing layer, and / or caching or storing the remainder of one or more portions of the asset data in the external processing layer. The remaining asset data may be provided in a single transfer or over multiple transfer cycles. Preferably, the provision of the remaining asset data is prioritized in the form of one or more data chunks, each available to the external processing layer without having any pending asset data to be subsequently transferred to the external processing layer. In other words, the asset data is preferably subdivided into data chucks, which are available to the external processing layer without using the remaining asset data. It will be understood that by doing so, the data resolution of the asset data received at the external processing layer can be gradually and seamlessly improved without waiting for the rest of the data to be processed as the received data progresses. Therefore, despite the constraints of data transfer speed, data processing can be made more efficient.The resolution is preferably the temporal resolution of the asset data.

[0058] Most signals from sensors are time-based signals, and therefore, at least the majority of asset data is time-series data. One or more techniques may be used to generate low-resolution asset data, for example, to downsample one or more signals contained within the asset data. The specific techniques for generating low-resolution asset data are not limiting to the scope or generality of this teaching. Therefore, any technique that enables the generation of low-resolution asset data usable by an external processing layer can be used for that purpose.

[0059] In one embodiment, the transfer and / or access of asset data is initiated in response to a variable bulk read history query. This can be done, for example, by changing the target period for history calls from an external processing layer to a network interface. By requesting asset data from a longer period, the computational resources and / or storage units required to deliver asset data from the asset can be used more efficiently (query time / data point). This may result in data transfers that include older data points, but this can lead to a more strongly directed overall transfer to deliver better resolution for specific parts of the asset data, while still reducing the computational load by delivering all other data points or measurements that are not required with higher time frequency or resolution.

[0060] In one embodiment, the resolution of each portion of the asset data is adapted according to a calculated relevance value for the data analysis that requires the asset data. In a further embodiment, a machine learning ("ML") model trained with asset data with a target period of approximately two years and a one-hour average of the data points of the asset data is used to determine the data points of the asset data that need to be delivered with high resolution, while the remaining data points only need to be delivered with lower resolution. Similarly, for some assets, a machine learning ("ML") model may be trained with asset data with a target period of approximately one year and a one-hour, half-hour, or 15-minute average of the data points of the asset data. More generally, a machine learning ("ML") model may be trained with asset data with a target period of more than six months and a data point average of up to one day for the asset data.

[0061] The advantage of doing so may be that, even though the asset data portion for the most recent time period is not available in the external processing layer, lower-resolution data from the long-term history of the asset data can be used for scaling purposes in analysis.

[0062] In a further embodiment, asset data usage is monitored to categorize the relevance of specific data points according to a particular usage scenario. Monitoring may be performed via a second or third processing layer. In doing so, it may be determined that the resolution of a particular data portion is suitable for a particular usage scenario. By adapting the resolution of data points in asset data, data transfer can be made more efficient. This may be achieved, for example, by monitoring the technical context of the request as at least one boundary condition and calculating a cost function for how the requested asset data should be delivered, for example, to an external processing layer. Furthermore, optimization algorithms may be applied to parameterize data polling in the second processing layer. In one embodiment, data usage is monitored essentially continuously or periodically, and the weights of the cost function are adapted. Optimization may be rerun for different assets and / or different external processing layers.

[0063] In this context, the term, in particular the term "near real-time," may refer to signals or data that comprise a time delay of 15 seconds or less between the generation of the signal / data and its transmission, more specifically, 10 seconds or less, and more specifically, 5 seconds or less. Therefore, as an example, an asset dataset provided at a network interface for transmission to an external processing layer within 15 seconds of its generation in a plant asset can be considered a near real-time transmission, or provided in a near real-time manner. Similarly, transmissions with smaller time delays may be called real-time transmissions.

[0064] With respect to technical context data, the rules may include, for example, the time or period before or after when access to and / or transmission of asset data may be permitted, any of the network paths through which access to and / or transmission of data may be permitted, or a combination thereof.

[0065] The parameters may be any one or more of the following: data transfer rate, number of data packets, size of the dataset of asset data for which access and / or transfer is requested, size of one or more data packets to be combined with the asset data for which access and / or transfer is requested, and resolution of one or more data packets.

[0066] It will be understood that a secure network is a network or part of a network used for communication between at least some of the plant assets used in plant operation. Therefore, a secure network can be an intranet belonging to a plant. Typically, a secure network is located within an industrial plant, but it can sometimes even extend beyond the plant's physical location. For example, this may occur if any one or more plant-related databases, processing systems, or other computing services are implemented as one or more cloud-based services. The first and second processing layers are parts of the secure network. A secure network can even be an isolated network containing two or more security zones separated by firewalls. Such firewalls can be network or host-based virtual or physical firewalls. Firewalls can be hardware or software-based for controlling inbound and outbound network traffic. Here, predetermined rules in the sense of whitelisting can define permitted traffic through access management or other configuration settings. Depending on the firewall configuration, security zones may adhere to different security standards.

[0067] The external network may, at least in part, be a public network such as the Internet. Alternatively, or in addition, the external network may, at least in part, be another secure network isolated from the internal secure network, with a second processing layer provided. In certain cases, for example, when two plants are interconnected via a dedicated private or non-public network, it will be understood that the secure network of one plant may be isolated from the internal network of the other plant. Thus, a user located within the other plant may still face at least some of the same problems in accessing asset data from the plant, such as the problem that the user is unaware of the plant's operating parameters. Therefore, this teaching may also be applied to solve similar problems in a group of plants interconnected by any kind of external network, public or private.

[0068] In a further embodiment, the first processing layer is configured within a first security zone via a first firewall, and the second processing layer is configured within a second security zone via a second firewall. To securely protect the first processing layer, the first security level may adhere to a higher security standard than the second security level. The security levels may adhere to common industry standards, such as those outlined in the Namur document IEC62443. The second processing layer may provide further isolation via security zones. For example, the intermediate processing system may be configured within a third security zone via a third firewall, and the process control system may be configured within a second security zone via a second firewall. The third and second security zones may also have different security standards. For example, the third security zone may adhere to a higher security standard than the second security zone. This allows for a higher security standard for the lower security zones of the first processing layer, and a lower security standard for the higher security zones of the second processing layer.

[0069] In one embodiment, technical context data is generated using a machine learning ("ML") model, such as a trainable neural network, trained with historical access and / or transfer data associated with the asset. For example, the training data may include historical latency and performance data associated with the asset. The training data may include specific latency and performance data that depend on multiple possible network paths for transmitting the asset data from the asset to an external database or destination memory into which the asset data will be integrated. Alternatively, or in addition, the training data may even include technical context data of history from one or more past accesses and / or transfers of the asset data. Alternatively, or in addition, the training data may even include data from one or more historical partial requests used to determine at least one iteration parameter. The ML model may run at least partially on a second processing layer and / or on an intermediate processing layer. The ML model may even run partially on an external processing layer. The ML model may even be used to determine at least one bottleneck and / or to learn the characteristics of at least one internal bottleneck of the network paths between the asset and the external processing layer or user. Therefore, ML models can also be used to determine at least one characteristic of at least one bottleneck. The term “bottleneck” can refer to any kind of constraint in the computing resources required to provide access to and / or transfer of asset data to a user. Thus, a bottleneck could be a constraint in the network path, e.g., data bandwidth and / or latency. Alternatively, a bottleneck could even be a constraint on the processing load of any processing layer or any processor that asset data must pass through for processing. Further alternatively, a bottleneck could even refer to a memory constraint or limited data storage capacity, e.g., limited random access memory ("RAM") or cache.

[0070] As explicitly stated above, it will be understood that using a trained ML model can further enable the determination of bottlenecks in accessing and / or transferring asset data. Therefore, ML models can be used to elucidate data integration parameters between the user or external processing layer and the assets by using the ML model as a medium.

[0071] In another embodiment, the training data is divided into internal training data, which includes latency and performance data related to one or more possible internal network paths for transmitting asset data to an interface to an external network, and external training data, which includes latency and performance data related to one or more possible external network paths for transmitting asset data from the interface to an external processing layer. Preferably, the external training data includes latency and performance data to an external database or destination memory into which the asset data will be integrated. In some cases, the external training data may even be related to one or more subpaths between the interface and the external database or destination memory. This may be the case, for example, when sufficient external training data is not available or can not be used. The advantage of dividing the training data into internal and external training data is that it increases the flexibility of training for changed paths. For example, if one or more external paths change, training can be performed only for the external paths. This can also save training time and allow for faster data integration. Similarly, a machine learning ("ML") model can even be divided into an internal ML model and an external ML model. Internal ML models can be trained using internal training data, while external ML models can be trained using external training data.

[0072] Another synergistic effect of splitting the training data into internal and external training data is that the second processing layer can more flexibly determine combinations of internal and external paths that provide convenient accessibility criteria for the external processing layer. Thus, one or more of these combinations can be provided to the external processing layer as part of the technical context data. The external processing layer can then request access to the asset data using the most suitable accessibility criteria.

[0073] The applicant further recognizes that this teaching may be particularly suitable for applications in value chains, or even further, in continuous production where assets or products produced by a first plant are used by a second plant. Those skilled in the art will understand that the number of plants in a value chain can be more than two. Or, more generally, a user may be a supplier for another user downstream in the value chain.

[0074] An industrial plant, or simply a plant, comprises infrastructure used for industrial purposes. The industrial purpose may be the manufacture of one or more products, i.e., process manufacturing carried out by a process plant. Products can be any products, such as chemicals, bio-based products, pharmaceuticals, food, beverages, textiles, metals, plastics, semiconductors, etc. Thus, a plant can be any or more of the following: a chemical plant, a pharmaceutical plant, an oil and / or natural gas well, a refinery, a petrochemical plant, a cracking plant, a fracking facility, and other fossil fuel facilities. Those skilled in the art will understand that a plant also includes assets in the form of instrumentation, which may include several different types of sensors for monitoring plant parameters and equipment. Therefore, some of the asset data may be generated via instrumentation such as sensors.

[0075] From yet another perspective, a system for managing asset data of industrial assets may also be provided, wherein the system comprises at least one processor, and any of the at least one processor is configured to perform any of the method steps disclosed herein.

[0076] More specifically, an industrial plant system comprising a first processing layer and a second processing layer, wherein the first processing layer is communicatively coupled to the second processing layer, the first and second processing layers are configured within a secure network, at least one industrial asset is configured to be communicatively coupled to the first processing layer, the asset is configured to provide asset data to the second processing layer via the first processing layer, and the system further comprises an interface to an external network. The second processing layer is - To generate technical context data related to the asset, - Providing technical context data to the interface, It is configured to do the following: An industrial plant system may be provided in which technical context data includes one or more accessibility criteria for asset data, and the accessibility criteria include one or more rules and / or parameters that can be conformed to by an external processing layer to receive the asset data.

[0077] Therefore, the system is suitable for integrating asset data from industrial assets.

[0078] From another perspective, a computer program including instructions can also be provided, wherein the instructions cause a processor to perform method steps disclosed herein when the program is executed by a suitable computer processor. A non-temporary computer-readable medium can also be provided for storing a program that causes a suitable computer processor to perform any method steps disclosed herein.

[0079] Computer-readable data media or carriers include any suitable data storage device storing one or more instruction sets (e.g., software) that embody any one or more of the methodologies or functions described herein. Instructions may also reside fully or at least partially in main memory and / or the processor during their execution by a computer system, and may constitute computer-readable storage media, main memory and processing device. Instructions may be further transmitted or received over a network via a network interface device.

[0080] The networks described herein may be any type of data transmission medium, whether wired, wireless, or a combination thereof. No particular type of network is limited to the scope or generality of this instruction.

[0081] Computer programs for implementing one or more of the embodiments described herein may be stored and / or distributed on a suitable medium, such as an optical storage medium or a solid-state medium, provided together with other hardware as part thereof, or they may be distributed in other forms, such as via the Internet or other wired or wireless telecommunications systems. However, computer programs may also be presented through a network such as the World Wide Web and can be downloaded from such a network into the working memory of a data processor.

[0082] From another perspective, a data carrier or data storage medium may also be provided for making a computer program element configured to perform the method according to one of the embodiments described above available for download.

[0083] The word “comprising” does not exclude other elements or steps, and the indefinite articles “a” or “an” do not exclude plurals. A single processor, controller, or other unit may perform the functions of several items described in the claims. The mere fact that a particular strategy is described in different dependent claims does not indicate that a combination of these strategies cannot be used to their advantage. No reference numeral in a claim should be construed as limiting in scope.

[0084] Exemplary embodiments are described below with reference to the attached drawings. [Brief explanation of the drawing]

[0085] [Figure 1] This is a block diagram of a system with a processing layer. [Figure 2] This is a flowchart illustrating one aspect of the process. [Modes for carrying out the invention]

[0086] Detailed explanation In industrial plants such as chemical plants, process industrial production typically begins with upstream products, which are then used to obtain further downstream products. In typical plants or their mechanisms, value chain production to the final product via one or more intermediate products is highly limited and based on siloed infrastructure. This can hinder the adoption of new technologies such as IoT, cloud computing, and big data analytics.

[0087] Unlike other manufacturing industries, process industries can be subject to very high standards, particularly regarding availability and security. For this reason, computing infrastructure is typically highly secure, unidirectional, siloed, and access to monitoring and control systems in such plants is extremely limited.

[0088] Generally, such industrial plants are incorporated into enterprise architectures in a siloed manner, with different levels of functional separation between operational technology and information technology solutions.

[0089] Level 0 relates to physical processes and defines the actual physical processes within a plant. Level 1 concerns intelligent devices for sensing and manipulating physical processes, such as process sensors, analyzers, actuators, and associated instrumentation. Level 2 concerns control systems for supervising, monitoring, and controlling physical processes. Real-time control and software; DCS, human-machine interface ("HMI"); and supervisory and data acquisition ("SCADA") software are some of the typical components. Level 3 concerns manufacturing work systems for managing production workflows to produce desired products. Batch management; manufacturing execution / operations management systems (MES / MOMS); laboratory, maintenance, and plant performance management systems, data historians, and associated middleware are typical components. The time frame for control and monitoring can be shifts, hours, minutes, or seconds. Level 4 concerns business logistics systems for managing business-related activities of manufacturing operations. Enterprise resource planning (ERP) is typically the primary system, establishing basic plant production schedules, material usage, shipments, and inventory levels. The time frame can be monthly, weekly, daily, or shift-based.

[0090] In addition, such a structure can adhere to a strict one-way communication protocol that ensures no data flow to internal systems below Level 2. What is not covered in such an architecture is the external internet outside the company or enterprise. However, this model remains an essential concept within the realm of cybersecurity. In this context, the challenge may be to leverage the benefits of cloud computing and big data while still ensuring the established advantages of existing architectures: namely, the high availability and reliability of lower-level systems (Level 1 and Level 2) controlling chemical plants, as well as cybersecurity.

[0091] This teaching can enable improved monitoring and / or control by systematically modifying this framework and introducing new capabilities that fit into existing architectures. This disclosure can provide a scalable, flexible, and available computing infrastructure for process industries that simultaneously adheres to high security standards. Furthermore, it can enable the utilization of data and analytics between separate plants while ensuring that plant performance is not unduely affected as a result of externally requested access and / or transfer of data from assets located within the plant.

[0092] Figure 1 shows a system 100 or mechanism comprising a processing layer. For example, a first industrial plant 101 is shown, which may be a chemical plant. A chemical plant can be any manufacturing facility based on chemical processes, for example, that uses chemical processes to transform raw materials into products. System 100 is shown to comprise two processing layers, including a first processing layer in the form of a core process system 114 associated with plant 101, and a second processing layer 116 associated with plant 101, which may be in the form of a process control system, for example. The first processing layer 114, or core process system, is communicatively coupled to the second processing layer 116, enabling one-way or bidirectional data transfer. The core process system 114 includes a decentralized set of processing units associated with the assets of the chemical plant 101.

[0093] The first processing layer 114 and the second processing layer 116 are configured within a secure network, shown in this example as two security zones separated by firewalls 118 and 120 in the schematic diagram. The first security zone is located at the level of the core process system 114, with the first firewall 118 controlling inbound and outbound network traffic to and from the core process system 114. The second security zone is located around the second processing layer 116, with the second firewall 120 controlling inbound and outbound network traffic to and from the second processing layer 116. Such an isolated network architecture can enable the protection of vulnerable plant operations from unauthorized access or cyberattacks.

[0094] The first processing layer 114 provides asset data 122 of plant 101 to the second processing layer 116. The first processing layer 114 may also provide process or asset-specific data of plant 101 to the second processing layer 116. Process or asset-specific data may include values, quality, time, units of measurement, and asset identifiers. Further context may be added for the plant, such as a plant identifier, plant type, reliability indicator, or alarm limits, through contextualization. The second processing layer 116 is further configured to provide technical context data to an interface 126 to an external network 124.

[0095] The technical context data includes one or more accessibility criteria for asset data. The accessibility criteria include one or more rules and / or parameters that must be followed by the external processing layer 150 in order to receive the asset data. The external processing layer 150 may be located within a second plant 102. Although the processing layers or security zones associated with the second plant 102 are not shown in the diagram, the second plant 102 may have a similar layer configuration to that associated with the first plant 101. Alternatively, the second plant 102 may have a different processing mechanism compared to the first plant 101. Since a user located within the second plant 102 may not have a complete overview of critical operating parameters within the first plant 101, a request for data from an asset, e.g., asset 12, may affect performance or security within the first plant 101. In some cases, the user may be an application running on the external processing layer 150. The external processing layer 150 may even be part of a cloud computing platform or service. Therefore, it is not mandatory for the external processing layer 150 to be located within the second plant 102. In some cases, unlike in Figure 1 where the external processing layer 150 is associated with the second plant 102, the external processing layer 150 may even be unrelated to any plant. The external processing layer 150 may even be a separate remote computing service aimed at analyzing asset data from one or more plants.

[0096] The second processing layer 116 is communicably coupled to the external processing layer 150 via an interface 126 to an external network. In some cases, the external processing layer 150 may be a computing or even cloud environment that provides virtualized computing resources such as data storage and computing power.

[0097] One or more rules and / or parameters included in the accessibility criteria may be automatically specified, or they may be selected so that access to and / or transfer of asset data to the external processing layer 150, performed in accordance with the aforementioned one or more rules and / or parameters, does not affect any critical operation of plant 101 and / or any of the assets 10-12.

[0098] For example, to analyze vibrations on pump 11, the user may request measurement data from pump 11 via an external processing layer 150. The measurement data may have a frequency, for example, 10 kHz. Therefore, due to network latency, it may not be possible to transfer such data in real time. By responding immediately to the user request, and thereby not potentially impacting the performance of plant 101 and / or asset 11 by being unable to transmit the desired data, the system can provide the user with one or more viable alternatives for accessing and / or transferring data from asset 11 by applying technical context data, which may include a priori determined parameters. In some cases, the technical context data may be generated using a machine learning ("ML") model. In this case, the system may learn, for example, via a second processing layer 116, when it may be possible to achieve such transfer rates. In addition, or alternatively, alternative paths that may enable access and / or transfer with the requested characteristics may be suggested. In some cases, the user may be provided with the possibility of running an analysis or application locally, for example, on a second processing layer 116, and thus providing the results to an external processing layer 150. Thus, the second processing layer 116 and / or the external processing layer 150 may be configured to host and / or organize process applications or analyses. In some cases, the second processing layer 116 may host and / or organize process applications related to core plant operations, and the external processing layer 30 may be configured to host and / or organize process applications related to non-core plant operations. Here, core plant operations may correspond to critical operations that enable plant 101 to operate in island mode without using an external network connection.

[0099] Data from pump 11, or asset data, may even be provided in multiple data packages delivered at different times. These data packages may be cached in a second processing layer, and / or an intermediate processing layer, and / or an external processing layer. In some cases, asset data may initially be provided to the external processing layer in a low-resolution or coarse form so that data processing can begin without waiting for the complete asset data to become available. The remaining asset data may be provided in one or more data packages, each data package progressively increasing the resolution of the asset data in the external processing layer. In some cases, the data packages may even have different resolutions depending on the relevance of the asset data or pump data to the analysis for which the data is required.

[0100] In some cases, one or more additional processing layers are also possible on the side of the first plant 101, or on the side of the second plant 102, or both. For example, an intermediate processing layer may be provided between the first processing layer 114 and the second processing layer 116. The intermediate processing layer may be communicatively coupled to the first processing layer 114 via the first firewall 118. Thus, the first processing layer 114 and the second processing layer 116 are communicatively coupled via the intermediate processing layer. An additional firewall may also be provided between the intermediate processing layer and the second processing layer 116. The intermediate processing layer can even enable improved data handling by, for example, reducing the data transfer rate to the external processing layer 150 through preprocessing and improving data quality through contextualization.

[0101] In some cases, ML models can be executed at least partially on the intermediate processing layer. Figure 2 shows a flowchart 200 of one aspect of this teaching. Technical context data related to an asset, e.g., pump 11, is generated, e.g., in a second processing layer 116 (201). The technical context data is provided, e.g., via the second processing layer 116 to an interface 126 (202). Interface 126 is connected to an external network 124. Thus, the technical context data may be provided to an external processing layer 150 that requires access to and / or transfer of data from pump 11 or asset data (203). The technical context data may be provided by transmission via the network interface 126. The technical context data includes one or more accessibility criteria for asset data. The accessibility criteria include one or more rules and / or parameters that can be complied with by the external processing layer 150 for access to and / or transfer of pump data or asset data. Optionally, asset data may be received in the external processing layer 150 according to one or more selected accessibility criteria selected by the external processing layer 150 from the technical context data (204). Furthermore, optionally, in addition to steps 201-204 described herein, further embodiments may be implemented, such as generating technical context data from at least one iteration parameter.

[0102] A system for managing asset data has been provided, a method for integrating asset data, and various examples for computer software products that implement any of the relevant method steps disclosed herein have been disclosed above. However, those skilled in the art will understand that changes and modifications can be made to these examples without departing from the spirit and scope of the appended claims and their equivalents. Furthermore, it will be understood that embodiments from the methods and products described herein can be freely combined. Specific exemplary embodiments of this teaching are summarized in the following sections.

Claims

1. A method for integrating asset data from industrial assets located within an industrial plant, wherein the industrial assets are communicatively coupled to a first processing layer, the asset data is provided to a second processing layer via the first processing layer, the first processing layer is communicatively coupled to the second processing layer, and the first and second processing layers are configured within a secure network, wherein the method is - In the second processing layer described above, technical context data related to the industrial asset is generated, - Provide the technical context data to the interface to the external network via the second processing layer described above, Includes, A method wherein the technical context data includes at least one accessibility criterion for the asset data, and the accessibility criterion includes at least one rule and / or parameter that can be conformed to by an external processing layer to receive the asset data.

2. The method according to claim 1, wherein the technical context data is at least partially generated using at least one of a priori determined parameters, including an asset network address, asset CPU load, asset memory such as random access memory ("RAM"), and a network path between the industrial asset and the external processing layer.

3. The aforementioned method also, - To generate at least a first partial request for accessing the asset data via the second processing layer, - Measuring at least the first response to the first partial request, wherein the first response indicates the impact of the first partial request on at least one computation and / or network resource, - Determining at least a first iteration parameter depending on the first response, Includes, The method according to claim 1 or 2, wherein the technical context data is at least partially generated using the first iteration parameter.

4. The aforementioned method also, - Depending on the response, generate a second partial request via the second processing layer to access the asset data, wherein the second partial request requests and generates more resources than the first partial request. - Measuring a second response to the second partial request, wherein the second response indicates the impact of the second partial request on the at least one computation and / or network resource, - Determining the at least first and / or second iteration parameters depending on the first response and / or the second response, The method according to claim 3, including the method described in claim 3.

5. The aforementioned method also, - The method according to any one of claims 1 to 4, comprising transmitting the technical context data to the external processing layer via the interface.

6. The aforementioned method also, - The second processing layer includes receiving at least one selected accessibility criterion, The method according to any one of claims 1 to 5, wherein the at least one selected accessibility criterion is selected from the technical context data, and the selection is performed by the external processing layer.

7. The aforementioned method also, - The external processing layer includes receiving the asset data, The method according to any one of claims 1 to 6, wherein the asset data is transmitted via the second processing layer in accordance with the at least one selected accessibility criterion.

8. The aforementioned method also, - To store at least a portion of the technical context data as historical context data via the external processing layer, - The second processing layer receives at least one pre-selected accessibility criterion, Includes, The method according to any one of claims 1 to 7, wherein the at least one pre-selected accessibility criterion is selected from the technical context data of the history, and the selection is performed by the external processing layer.

9. The aforementioned method also, - The method according to any one of claims 1 to 8, comprising receiving low-resolution asset data in the external processing layer, wherein the low-resolution asset data is a subset of the asset data requested by the external processing layer, and the low-resolution asset data is available to the external processing layer to initiate at least one data analysis.

10. The aforementioned method also, The method according to claim 9, comprising receiving a second low-resolution asset data in the external processing layer, wherein the second low-resolution asset data is a subset of the asset data requested by the external processing layer, and the second low-resolution asset data is available to the external processing layer in combination with the low-resolution asset data for further processing of at least one data analysis.

11. The method according to claim 10, wherein the low-resolution asset data and the second low-resolution asset data have different resolutions.

12. The method according to any one of claims 1 to 11, wherein the technical context data is generated using a machine learning ("ML") model, such as a trainable neural network, which is trained using historical access and / or transfer data related to the industrial asset, and / or data from at least one historical partial request used to determine the at least first and / or second iteration parameters.

13. A computer program including instructions, wherein the instructions cause the computer processor to perform the steps according to any one of claims 1 to 12 when the computer program is executed by a suitable computer processor.

14. An industrial plant system comprising a first processing layer and a second processing layer, wherein the first processing layer is communicatively coupled to the second processing layer, the first and second processing layers are configured within a secure network, at least one industrial asset is configured to be communicatively coupled to the first processing layer, the asset is configured to provide asset data to the second processing layer via the first processing layer, and the industrial plant system further comprises an interface to an external network. The second processing layer described above, - To generate technical context data related to the aforementioned industrial assets, - Providing the aforementioned technical context data to the interface, It is configured to do the following: An industrial plant system wherein the technical context data includes at least one accessibility criterion for the asset data, and the accessibility criterion includes at least one rule and / or parameter that can be conformed to by an external processing layer to receive the asset data.