Method and apparatus for acquiring and managing information about available device artefacts and / or software artefacts in a heterogeneous industrial system, computer program product, and signal

A unified management system addresses the complexity of managing OT devices and software artifacts in heterogeneous industrial systems by utilizing an Inventory Service and gateway software for centralized reporting and inventory management, enhancing transparency and efficiency across different OT environments.

WO2025103904A1PCT designated stage expired Publication Date: 2025-05-22SIEMENS AG
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
PCT/EP2024/081734
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-11-13
Filing Date
2024-11-08
Publication Date
2025-05-22

AI Technical Summary

Technical Problem

Managing information about available device and/or software artifacts in heterogeneous industrial systems is complex due to varied tools, information sources, and lack of a comprehensive approach across manufacturers and device families.

Method used

A unified management system is introduced, utilizing a method that includes an Inventory Service with a database for extended asset information, and a gateway software for forwarding information and maintenance functions, enabling centralized reporting and inventory management across different OT environments.

Benefits of technology

This solution provides transparent and unified management of OT devices and software artifacts, enabling users to discover, inventory, and maintain devices independently of manufacturer and type, with centralized reporting and seamless integration into existing systems.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure EP2024081734_22052025_PF_FP_ABST
    Figure EP2024081734_22052025_PF_FP_ABST
Patent Text Reader

Abstract

When managing an OT fleet, the operator and the service engineer are confronted with the high complexity of the heterogeneous environment; they must, on the basis of the installations and devices used, deal with a large number of tools for processing and editing the information. The invention relates to an INVENTORY SERVICE in an overall system consisting of three main components: - a centrally hosted cloud service, which comprises and makes available all the functions for assisting the user; - a gateway software, which is hosted in the installation, for example, in order to forward information and maintenance functions to the backend service; - a selection of asset links, which function as a connector between the (asset) gateway and the OT field devices.
Need to check novelty before this filing date? Find Prior Art

Description

[0001]202319546 Foreign version 1 Description Method and apparatus for determining and managing information about available device and / or software artifacts in a heterogeneous industrial system, computer program product and signal OT or Operational Technology refers to the use of hardware and software to control industrial equipment. OT generally includes specialized systems used, for example, in manufacturing, the energy sector, medicine, construction technology and other industries. More specifically, in the following we refer to all devices used in an industrial plant, from the control system to drives, sensors (e.g. cameras, thermometers, flow meters, speed meters...) and actuators (robots, conveyor belts, processing tools, etc.). OT represents a contrast to IT (Information Technology), which is responsible for data systems.OT systems are primarily deployed in the physical world, while IT systems are primarily used to solve business problems. Many aspects of OT and IT overlap, as OT systems are typically connected to networks and generate and use ever-increasing amounts of data. Managing an OT fleet confronts the operator and the respective service technicians with the high complexity of the heterogeneous environment; they must deal with the systems and devices used, as well as with a variety of tools for processing and manipulating the information. 202319546 Foreign Version 2 In addition, a variety of information sources are available for querying in order to collect, update, and manage the necessary data.The distribution of artifacts (i.e., all elements produced during the development process, such as data models, prototypes, workflow diagrams, design documents, or setup scripts) varies depending on the manufacturer or provider. Dependency management of artifacts also has to be handled manually to date, as information about dependencies is not provided in a common, machine-readable format. When distributing artifacts (firmware, BIOS, etc.) across heterogeneous environments, many requirements, including non-functional ones, must be considered. Currently, there is no comprehensive approach to addressing the problem across manufacturers and device families. Typically, updates to specific engineering tools are applied using specific information and distribution channels defined by the respective manufacturer / device family.Maintenance and technical service must handle a multitude of information. Service technicians and plant operators are responsible for finding the right artifacts using various means, comparing them, and applying them to the OT assets. For standard operating systems, such as MS Windows, for example, there is an operating system-specific service. US 2023 / 0017237 presents an Industrial Development Hub that offers a repository for (cloud-based) storage of project code, device configurations, and other aspects of automation projects. A repository is a managed directory for storing and describing digital objects for a digital archive. The managed objects can be, for example, programs (software repository), publications (document server), data models (metadata repository), or research data.A repository often also includes functions for versioning the managed objects. Therefore, the object of the invention is to provide a solution to the problem described above. The aim is to offer uniform management that is applied to heterogeneous OT environments in order to make information on the software and device families used usable across manufacturers. This object is achieved by a method according to the features of patent claim 1. Furthermore, the object is achieved by a computer program product having the features of patent claim 6 and a device according to the features of patent claim 7. Further advantageous embodiments are specified in the subclaims.The invention is presented below in an exemplary embodiment, wherein Figure 1 shows a detailed view of the device according to the invention, and Figure 2 shows an overview of the overall system in which the subject matter according to the invention comes into effect. 202319546 Foreign version 4 Figure 1 shows the INVENTORY SERVICE 10, which can advantageously be located centrally in a cloud 20. The INVENTORY SERVICE 10 comprises the INVENTORY DATABASE 12 with extended information on the scanned assets and enables the user to perform FUNCTIONS 11 such as: - running new scans in the system, - displaying assets, - applying filters, and - exporting asset information to other systems. An asset is the representation of a functional object with a known technical function. It can be, for example, a device with firmware and other software installed on it.Both devices and software have certain attributes, such as the respective device and software versions. The only attributes that an instance of this class must provide are a unique identifier (ID) that refers to it and the asset management status. For example, an artifact list can be designed as a table and contain the following information about the existing, managed assets: - Asset name - Asset type (e.g., gateway) - Manufacturer - Network address (IP, MAC, ...) - Serial number - Version (firmware, hardware, ...) - Security (key, password, ...) - Instance - Status 202319546 Foreign version 5 - Customer (tenant) An asset instance can represent a physical object (e.g., a Raspberry Pi or an application running on a system) or a virtual object (e.g., a router in a network topology, regardless of the physical device).In both cases, an identifier is required for the displayed object. Figure 2 shows this INVENTORY SERVICE 10 interacting with other components of the overall system. The described overall system consists of three main components: - A centrally hosted cloud service 20, which includes and makes available all functions to support users. These functions can be implemented via a web-based UI application and openly accessible APIs. This cloud service also contains the functionality already described in Figure 1. - A gateway software 30, which is hosted, for example, on-site, i.e. in the plant, to forward information and maintenance functions to the backend service. Communication between the (asset) gateway and the backend service is established using firewall-friendly protocols.- A selection of Asset Links that act as connectors / middleware between the (Asset) Gateway and the OT field devices 41, 42, 43. 202319546 Foreign Version 6 The (Asset) Gateway 30 and one or more Asset Links are hosted, for example, on Industrial Edge devices or as Docker Compose on any machine on which containers can be run. The Asset Link is the software component that can find and communicate with assets using a specific protocol, as well as providing the standard information for the inventory service. Later, firmware updates or certificates can also be rolled out via a link. Container registries (e.g., from the "Docker" software) are already known, with supporting functionalities. Container technology simplifies the deployment of applications and ensures the separation and management of the resources used on a computer.Docker provides a repository, which is a set of images with the same name and different tags, usually versions. Docker also provides a registry for managing the repositories. The OT PROTOCOL SCANNER SERVICE 21 maintains a large number of OT PROTOCOL SCANNERS in a registry 22. The registry can be securely expanded with additional PROTOCOL SCANNERS from various manufacturers. The registry also contains metadata about the correspondence between the scanners and the OT devices for which the scanner is tailored. To ensure secure data exchange in the cloud 20, suitable SECURITY 23 measures are also provided in the service. Communication from the cloud is controlled via a suitably configured network gateway. The gateway 30 represents, generally speaking, the bridge for communication between multiple internal or external network sections.The FIELD MANAGEMENT GATEWAY 30 used here is the link between the two previously described elements 10, 21 in the cloud and the OT devices 41, 42, 43 on-site. The FIELD MANAGEMENT GATEWAY 30 contains the following functionalities: - INVENTORY CLIENT 31 - OT PROTOCOL SCANNER MANAGER 32 - OT SCANNER SERVICE 34 - OT PROTOCOL SCANNER 35, 35' A scan of OT devices in the network is typically performed when there is a corresponding scan job assigned in the cloud service 11. Executing the scan involves actively scanning the network with OT-specific protocols to detect devices in the network and collect the information. Information about - the (OT) device type, - the device manufacturer, - the software version of the device, - the MAC address of the device and - the IP address of the device is collected in the INVENTORY CLIENT 31.Based on the detected device types, additional OT PROTOCOL SCANNERS 35, 35' may be requested and downloaded from the OT PROTOCOL SCANNER SERVICE 34. These scanners, based on their metadata, are better suited for the device 41, 42, 43. These scanners can, for example, be provided for the device or asset by the manufacturer itself. The scan is then automatically repeated using the newly downloaded OT PROTOCOL SCANNERS 35, 35'. The scan results are converted into a common format in the INVENTORY CLIENT / Inventory Client 31 Discovery application and sent via the FIELD MANAGEMENT GATEWAY 30 to the INVENTORY DATABASE 12 in the INVENTORY SERVICE 10.The initial scan in the OT SCANNER SERVICE 34 can first be performed with a generic network scanner to identify basic information, whether any devices (manufacturer and type) are present, and what type of device and software they are. Based on the retrieved information, the OT PROTOCOL SCANNER MANAGER 32 queries the OT PROTOCOL SCANNER REGISTRY 22 of available protocol scanners in the cloud application for a protocol scanner that can extract further information from the specific vendors found in the network. An OT PROTOCOL SCANNER SERVICE 22 provides OT PROTOCOL SCANNERs tailored to OT devices 41, 42, 43 of different manufacturers and types. The OT PROTOCOL REGISTER in the OT PROTOCOL SCANNER SERVICE can be populated and updated by various vendors to provide software components that extract the most information from the specific devices.The identity information and properties of OT devices from different manufacturers and types are converted into a common format in the INVENTORY CLIENT and stored in the INVENTORY DATABASE in the INVENTORY Service, allowing users to view and filter general information based on this information. 202319546 Foreign Version 9 The described device and the associated method enable users to discover all OT devices that can be reached by a gateway device in the respective on-site installation of the industrial manufacturer. Discovery is independent of device type and manufacturer, with the service centrally reporting status and inventory information to the user in a device-specific format via a common and stable programming interface and a cloud-based web user interface. The (Asset) Gateway also polls gateway-specific discovery requests if necessary. There can be multiple Asset Gateways.The gateway instances, as well as asset links, are managed via the cloud service, so that, for example, a scan / discover job can be initiated only for a specific asset link. Asset links must implement a device discovery API to discover the connected, indirectly managed devices on the network. The asset gateway delegates the discovery request to the correct asset link via the device discovery API. The gateway provides a suitable interface for connecting asset links. This can be distributed across device boundaries (indirectly managed) or fully integrated into the native managed device. The OT protocol scanners can be deployed as Docker containers, for example. After discovery, users can identify the devices via the respective discovered asset link based on comprehensive device and status information.This device and status information includes manufacturer, device type (e.g., PLC, HMI, network router), order number, serial number, MAC addresses of the network interfaces, as well as software, firmware, and hardware versions. All information is collected in the centralized inventory list in the INVENTORY DATABASE 12, which can also be expanded by the user with custom fields. The inventory list is optionally made accessible via a web dashboard application, but can also be seamlessly integrated into any existing dashboard solution, central IT asset management system, or other suitable system using an API. This provides users with transparency over the device inventory and allows them to access device status information and installed firmware versions anytime, anywhere in the world, simply by accessing the appropriate APIs.

Claims

202319546 Foreign version 11 Patent claims 1. Method for determining and managing information about available device and / or software artifacts (41, 42, 43) in a heterogeneous industrial system, wherein a plurality of suitable artifact scanners are kept in a centrally stored register (22), and after receiving a scan order from a protocol scanner manager (30) from the centrally stored register (22) on the basis of recognized meta data, suitable specific artifact scanners (35, 35') are requested from the register (22) and used, and desired information about determined artifact scanners (35, 35') is recognized, and recognized information about devices and / or software artifacts (41, 42, 43) is converted into a predetermined format and stored in an inventory client (31) and is transmitted from the inventory client (31) to a centrally managed Inventory database (12) for central storage. 2.Method according to claim 1, characterized in that devices and / or software artifacts (41, 42, 43) present in the heterogeneous industrial system are previously determined using a first, generic scanner and are recognized using metadata present in the device and software artifacts.

3. Method according to one of the preceding claims, characterized in that recognized information includes data about. 202319546 Foreign Version 12 - Device type and / or type of software artifact (41, 42, 43) - Manufacturer of the device and / or software artifact (41, 42, 43) - Current version of the device and / or software artifact (41, 42, 43) - Network address of the device and / or software artifact (41, 42, 43).

4. Method according to one of the preceding claims, characterized in that devices and / or software artifacts are identified via a determined asset link based on device and status information, wherein at least one of the following information is included: - Manufacturer, - Device type, - Order number, - Serial number, - MAC addresses of the network interfaces - Software, firmware, and hardware version. 5.Method according to one of the preceding claims, characterized in that the information about devices and / or software artifacts (41, 42, 43) converted and stored in the specified format is presented in a sortable, filterable, and queryable manner.

6. A computer program product suitable for carrying out a method according to the features of one of claims 1 to 5. 202319546 Foreign version 13 7. Signal suitable and arranged for transmitting a method according to the features of one of patent claims 1 to 6. 8.Device (10) for determining and managing information about available device and / or software artifacts in a heterogeneous industrial system, with a centrally managed inventory database (12) for central storage, and with communication means (11) - for accessing a plurality of suitable artifact scanners which are kept in a register (22), and after receiving a scan order - for requesting and using suitable specific artifact scanners (35, 35') determined from the register (22) on the basis of recognized metadata, by a protocol scanner manager (30), - recognizing desired information by the determined artifact scanners (35, 35'), - converting recognized information about devices and / or software artifacts (41, 42, 43) into a predetermined format and storing it in an inventory client (31) and - receiving from the inventory client (31) to the Inventory database (12) for central storage. 9.Device (10) according to claim 8, characterized in that with communication means (11) information on devices and / or software artifacts (41, 42, 43) present in the heterogeneous industrial system is previously requested by a first, generic scanner, determined and recognized by means of metadata present in the device and software artifacts. 202319546 Foreign version 14 10. Device (10) according to one of the preceding patent claims 8 or 9, characterized in that recognized information includes data about - device type and / or type of software artifact (41, 42, 43) - manufacturer of the device and / or software artifact (41, 42, 43) - current version of the device and / or software artifact (41, 42, 43) - network address of the device and / or software artifact (41, 42, 43).

11. Device (10) according to one of the preceding claims 8 to 10, characterized in that the devices and / or software artifacts are identified via a determined asset link based on device and status information, wherein at least one of the following information is included: - manufacturer, - device type, - order number, - serial number, - MAC addresses of the network interfaces, - software, firmware, and hardware version. 12.Device (10) according to one of the preceding claims 8 to 11, characterized in that the information converted and stored in the predetermined format is about devices and / or software artifacts. 202319546 Foreign version 15 (41, 42, 43) are offered in a sortable, filterable and queryable format.

Citation Information

Patent Citations

  • Digital engineering virtual machine infrastructure

    US20230017237A1