Function extension system, function extension method, management server, edge device, and function extension program
The function expansion system addresses the challenge of securing and configuring multiple devices by using edge devices and a management server for simultaneous authentication and configuration, enhancing security and efficiency.
Patent Information
- Authority / Receiving Office
- WO Β· WO
- Patent Type
- Applications
- Current Assignee / Owner
- MITSUBISHI ELECTRIC CORP
- Filing Date
- 2024-12-04
- Publication Date
- 2026-06-11
AI Technical Summary
Existing systems struggle to enhance security while simultaneously performing function settings for multiple devices, leading to inefficiencies and potential vulnerabilities.
A function expansion system comprising edge devices and a management server that authenticate and manage multiple devices using device identification and name identification information, allowing for simultaneous authentication and configuration while enhancing security.
Enables secure and efficient authentication and configuration of multiple devices by associating device IDs with permissions, reducing the need for repeated name ID verification and optimizing function settings.
Smart Images

Figure JP2024042924_11062026_PF_FP_ABST
Abstract
Description
Function Expansion System, Function Expansion Method, Management Server, Edge Device, and Function Expansion Program
[0001] The present disclosure relates to a function expansion system, a function expansion method, a management server, an edge device, and a function expansion program for setting functions for a plurality of devices.
[0002] In a management system having a plurality of devices and a management device for managing these plurality of devices, it is desirable that the management device authenticates the names of the devices to enhance security and then sets functions for each device.
[0003] The device setting management system described in Patent Document 1 identifies a plurality of devices one by one and sends a setting change request to the identified device to change the settings of the plurality of devices.
[0004] Japanese Patent Application Laid-Open No. 2010-218278
[0005] However, the technique of Patent Document 1 has a problem that it is impossible to enhance security for a plurality of devices and at the same time perform function setting.
[0006] The present disclosure has been made in view of the above, and an object thereof is to obtain a function expansion system that can enhance security for a plurality of devices and at the same time perform authentication and setting.
[0007] To solve the aforementioned problems and achieve the objective, the functional extension system disclosed herein comprises multiple edge devices that control controlled devices and extend their functionality by mounting functional extension objects, and a management server connected to the edge devices via a network and managing the edge devices. The edge devices transmit device identification information to the management server to identify the edge device. The management server stores an authentication information table in which multiple device identification information is associated with one name identification information that identifies the name. Furthermore, when the management server first receives name identification information corresponding to the device identification information, it authenticates the first edge device that transmitted the received name identification information as a legitimate contract device based on the name identification information, the device identification information, and the authentication information table, and transmits a functional extension object to the first edge device. Furthermore, for edge devices corresponding to device identification information associated with name identification information, the management server continues authentication only for the duration of the authentication period, and during the authentication period, it transmits a functional extension object to the edge device without requesting name identification information when the edge device transmits device identification information.
[0008] The functional enhancement system described in this disclosure has the effect of enabling simultaneous authentication and configuration of multiple devices while enhancing security.
[0009] A diagram illustrating the concept of the function extension processing performed by the function extension system according to the embodiment. A diagram showing the configuration of the function extension system according to the embodiment. A diagram illustrating the device number set by the function extension cloud according to the embodiment. A flowchart showing the processing procedure of the processing performed by the function extension system according to the embodiment. A diagram showing the first operation screen of the function extension cloud according to the embodiment. A diagram showing an example of the second operation screen of the function extension cloud according to the embodiment. A diagram showing another example of the configuration of the edge device according to the embodiment. A diagram showing an example of the configuration of the processing circuit when the processing circuit of the function extension cloud according to the embodiment is implemented with a processor and memory. A diagram showing an example of the configuration of the processing circuit when the processing circuit of the function extension cloud according to the embodiment is configured with dedicated hardware.
[0010] The following describes in detail, with reference to the drawings, the functional enhancement system, functional enhancement method, management server, edge device, and functional enhancement program according to the embodiments of this disclosure.
[0011] Embodiment. Figure 1 is a diagram illustrating the concept of the function enhancement process performed by the function enhancement system according to the embodiment. The function enhancement system 1A comprises a function enhancement cloud 3 and a plurality of edge devices 5A. Hereinafter, the plurality of edge devices 5A may be referred to as an edge device group.
[0012] In the function expansion system 1A, the function expansion cloud 3 at the platform layer and the group of edge devices at the edge device layer are connected, and data is sent and received between the function expansion cloud 3 and the group of edge devices. The function expansion cloud 3 is a computer that manages the edge devices 5A and performs various settings on them. The function expansion cloud 3 is connected to the edge devices 5A via a network (such as the Internet 10 described later) and is an example of a management server that manages the edge devices 5A.
[0013] The edge device 5A includes, for example, a device control unit (device control unit 6A, described later) that controls a controlled device (controlled device) such as a machine tool, and an edge unit (edge ββunit 7A, described later) that extends the functions of the device control unit 6A. The device control unit 6A is, for example, a PLC (Programmable Logic Controller).
[0014] The edge device 5A obtains a function extension object from the function extension cloud 3 to extend the functionality of the edge device 5A. The function extension object includes a container (container application) and container parameters (settings), and the edge device 5A extends the functionality of the device control unit 6A using the container and parameters.
[0015] In the following description, we will explain the case where the enhanced cloud 3 primarily provides containers to the edge device 5A. However, when the enhanced cloud 3 supplies containers to the edge device 5A, it may also provide parameters along with the containers.
[0016] In factories (production lines) where machine tools and other equipment are installed, there are cases where it is desirable to have the equipment control unit 6A collect data and use it for AI (Artificial Intelligence) analysis. In this embodiment, the function-enhanced cloud 3 provides function-enhanced objects to the edge devices 5A, which are legitimate contracted equipment, and the function-enhanced objects are used to perform data collection, data analysis, etc. Specifically, the function-enhanced cloud 3 authenticates that the edge devices 5A are legitimate contracted equipment and performs various settings (such as providing containers, updating containers, and setting container parameters) on each authenticated edge device 5A.
[0017] The enhanced cloud 3 causes each edge device 5A to perform data collection and data analysis, and also acquires the data collected and analyzed by each edge device 5A from each edge device 5A. In this way, the edge devices 5A collect data from the device control unit 6A using containers and perform AI analysis on the collected data using containers. Then, the enhanced cloud 3 uses the data collected and analyzed by each edge device 5A to perform production line management and control.
[0018] The data collected by the edge device 5A includes data for productivity management and data for quality management. The data collected by the edge device 5A may be transmitted to the enhanced cloud 3 and analyzed by the enhanced cloud 3.
[0019] The functional enhancement cloud 3 of this embodiment manages multiple edge devices 5A by associating their identification information (multiple authentication device IDs (IDentifications)) with the permissions granted to each edge device 5A under a single name. The device ID is identification information (edge ββdevice identification information) used to identify the edge device 5A. Permissions such as permitted functions are pre-configured for each edge device 5A.
[0020] The enhanced cloud 3 manages, for example, the device IDs of multiple edge devices 5A located on a single production line, a common name ID shared by these multiple edge devices 5A, and the permissions granted to each edge device 5A. The names managed by the enhanced cloud 3 include the owner, administrator, representative, etc., of the factory where the edge devices 5A are located.
[0021] The enhanced cloud 3 detects whether power has been turned on to the managed edge device 5A. When power is turned on to any of the edge devices 5A in the group of edge devices and the enhanced cloud 3 receives a device ID from the powered-on edge device 5A, it detects that power has been turned on to the edge device 5A. Upon receiving the device ID, the enhanced cloud 3 requests the name ID (name identification information), which is identification information to identify the name of the edge device 5A, from a device for verifying the name of the device ID (name ID verification device described later). When the enhanced cloud 3 first receives the name ID corresponding to the device ID from the name ID verification device outside of the authentication specified period described later, it determines whether the edge device 5A is a legitimate contracted device based on the name ID of the person who owns the edge device 5A that sent the received name ID.
[0022] Thus, when the extended cloud 3 first receives the name ID from the edge device 5A, it determines whether the edge device 5A that sent the received name ID is a legitimate contracted device.
[0023] For example, after the Functional Enhancement Cloud 3 has sent and received the device ID with the first edge device 5A, some malfunction may occur, causing an interruption in the sending and receiving of the name ID request or the sending and receiving of the name ID. In this case, the Functional Enhancement Cloud 3 will determine whether the second (not the first) edge device 5A is a legitimate contracted device. For example, when the Functional Enhancement Cloud 3 receives the device ID from the second edge device 5A, it requests the name ID of the edge device 5A from the name ID verification device corresponding to the second edge device 5A. When the Functional Enhancement Cloud 3 receives the name ID corresponding to the device ID from the name ID verification device, it determines, based on the name ID, whether the second edge device 5A, which sent the name ID that was first received outside the authentication specified period, is a legitimate contracted device.
[0024] When the enhanced cloud 3 authenticates that the powered-on edge device 5A is a legitimate contracted device, it continues to grant authentication permission to the group of edge devices associated with the name ID for a specific period (hereinafter sometimes referred to as the authentication specific period).
[0025] Since the authenticated edge devices retain their authentication permission only for the duration of the authentication period, the enhanced cloud 3 sends enhancement objects to the authenticated edge devices to download enhancement objects according to the permissions, without performing name ID authentication during the authentication period. Edge device 5A extends its functionality by activating the enhancement objects.
[0026] In this embodiment, since multiple authentication device IDs are associated with a single name ID, when the function enhancement cloud 3 authenticates that the first edge device 5A that is powered on is a legitimate contracted device, it continues to grant authentication permission to the name ID for the other edge devices 5A associated with the authenticated name ID, but only for the duration of the authentication period. In other words, the function enhancement cloud 3 also downloads the function enhancement object to the second and subsequent edge devices 5A that are powered on, but only for the duration of the authentication period. Once the authentication period has elapsed, the function enhancement cloud 3 verifies the name ID again.
[0027] The authentication period is, for example, a period set according to the number of edge devices 5A that make up the functional expansion system 1A (the number of edge devices 5A associated with the name ID). Other examples of setting the authentication period will be described later.
[0028] The edge device 5A builds a container environment on an operating system (OS) such as Linux (registered trademark). The container environment is a container configuration management system that configures and manages containers, and corresponds to the container management unit 71 described later. The container configuration management system configures and manages containers using container configuration management software. The edge device 5A is equipped with, for example, a container with data collection functionality, a container with AI analysis functionality, and so on.
[0029] When each edge device 5A is powered on, it sends information indicating that power has been turned on, along with its device ID, to the function enhancement cloud 3. Furthermore, if the edge device 5A is the first device to be powered on, it receives a request from the function enhancement cloud 3 to send its name ID, and then sends the name ID to the function enhancement cloud 3.
[0030] The permissions for each device ID managed by the Function Enhancement Cloud 3 include the names of containers that can be installed on edge device 5A. Furthermore, if the functionality of a container is restricted for edge device 5A, the permissions include the names of the functions that can be granted to edge device 5A. For example, if a function has variations based on price ranges such as license fees, the Function Enhancement Cloud 3 will restrict functionality based on the contractual variations, depending on the permissions.
[0031] The enhanced cloud 3 stores various containers. Based on the aforementioned name ID and device ID, it authenticates the target device, edge device 5A, and then downloads and installs (silently installs) the container corresponding to the device ID onto edge device 5A.
[0032] The enhanced cloud 3 automatically configures containers on edge device 5A when power is supplied to the edge device 5A. The automatic configuration of containers on edge device 5A by the enhanced cloud 3 includes supplying containers, adjusting container parameters, and assisting with adjusting container parameters.
[0033] In this embodiment, "support" refers to assistance to the user when adjusting and setting parameters. The function-enhanced cloud 3 provides parameter adjustment support to the user by displaying information for adjusting parameters on a display device (not shown) connected to the edge device 5A.
[0034] The enhanced cloud 3 adjusts the parameters of the container installed on edge device 5A and optimizes the container. Here, since multiple device IDs are associated with the name ID, the enhanced cloud 3 does not need to check the name ID each time a device ID is checked, as it only needs to check the name ID once. In other words, once the enhanced cloud 3 authenticates the name using the name ID, it continues to grant authentication permission to the name ID for the device IDs (edge ββdevice group) associated with the name ID for the duration of the authentication period, thus omitting the verification of the name ID.
[0035] Furthermore, the Name ID is not limited to the name of a legal entity or natural person, such as the subscriber of the Function Expansion Cloud 3 or the owner of equipment such as edge device 5A, but may also be the name of the factory introducing the new production line or the name of the new production line. In other words, since the Function Expansion System 1A efficiently performs equipment authentication in a production line equipped with equipment that can connect to the external internet 10, the Name ID can be any name that oversees the equipment IDs.
[0036] The enhanced cloud 3 performs the necessary processing for each edge device 5A during the authentication period in which authentication authorization is maintained. For example, the enhanced cloud 3 performs settings for each edge device 5A, such as supplying containers to each edge device 5A, adjusting container parameters, adjusting parameters for each edge device 5A, assisting with adjusting container parameters, and assisting with adjusting parameters for each edge device 5A. In other words, the enhanced cloud 3 automatically performs various settings (including updates) for each edge device 5A during the authentication period in which authentication authorization is maintained.
[0037] The edge device 5A is equipped with an equipment control unit 6A, such as a PLC, which controls the edge device 5A, and an edge unit 7A. The edge device 5A extends the functionality of the equipment control unit 6A by mounting a container on the edge unit 7A.
[0038] Figure 2 shows the configuration of a functional expansion system according to an embodiment. The functional expansion system 1A comprises a functional expansion cloud 3, multiple edge devices 5A, and a user PC (Personal Computer) 2 that runs the engineering tool 9.
[0039] In the function expansion system 1A, the function expansion cloud 3 and multiple edge devices 5A are connected via the internet 10. Each edge device 5A is connected to a user PC 2. The user PC 2 may also be connected to multiple edge devices 5A via the internet 10. In the following description, the fact that data is transmitted via the internet 10 may be omitted when describing the transmission and reception of data between the function expansion cloud 3 and the edge devices 5A.
[0040] Multiple edge devices 5A are, for example, devices placed on a production line and are associated with the same owner. Each edge device 5A performs its respective process, enabling the factory to manufacture processed goods using the edge devices 5A.
[0041] The function expansion cloud 3 includes an authentication unit 31, an authentication information storage unit 32, a transmission / reception unit 33, a container management unit 34, a current container storage unit 35, an old container storage unit 36, and a parameter setting support unit 37.
[0042] The transmission / reception unit 33 transmits and receives data with the edge device 5A. Specifically, the transmission / reception unit 33 receives a device ID and the like from the edge device 5A, and transmits a transmission request for the nominal ID to the device on the edge device 5A side (the device in the edge device layer). Hereinafter, the device on the edge device 5A side to which the transmission / reception unit 33 transmits the transmission request for the nominal ID may be referred to as a nominal ID confirmation device. The nominal ID confirmation device may be the edge device 5A, the user PC 2, or the administrator PC (not shown) of the administrator of the edge device 5A.
[0043] In addition, the transmission / reception unit 33 receives the nominal ID corresponding to the device ID from the nominal ID confirmation device. In addition, the transmission / reception unit 33 transmits the received device ID and nominal ID to the authentication unit 31. In addition, the transmission / reception unit 33 transmits the container associated with the device ID to the edge device 5A corresponding to the device ID according to the instruction from the container management unit 34.
[0044] The authentication information storage unit 32 stores an authentication information table in which a plurality of device IDs and the authority contents (such as containers permitted to be used) associated with each device ID are associated with the nominal ID. The authentication information table is a table for managing the nominal ID, the device ID, and the authority contents of each device, and the nominal ID, the device ID, and the authority contents are associated with each other.
[0045] The authentication unit 31 authenticates the nominal ID (such as the nominal person) and the device ID (the edge device 5A) based on the nominal ID, the device ID, and the authentication information table. In addition, when the authentication of the nominal ID and the device ID is successful, the authentication unit 31 determines the function permitted to be used by the edge device 5A based on the device ID and the authentication information table. As a determination result, the authentication unit 31 transmits information (usage permission information) indicating the function permitted to be used by each edge device 5A to the container management unit 34.
[0046] The authentication unit 31 grants authentication permission to the edge device group only during the authentication specific period. That is, during the authentication specific period, when the authentication unit 31 receives the device ID, it transmits the usage permission information of the edge device 5A that has transmitted the device ID to the container management unit 34 without performing authentication of the nominal ID.
[0047] In addition, the authentication unit 31 may acquire information on the system configuration (system configuration information) of the production line from the engineering tool 9. In this case, the authentication unit 31 may change the authentication specific period based on the system configuration information. The system configuration information is information on the system configuration (connection configuration, etc.) of the production system including the controlled devices such as machine tools and the edge device group arranged on the production line.
[0048] The current container storage unit 35 stores the latest version of the container. The old container storage unit 36 stores containers of a version older (past version) than the latest container (for example, a container of the version one before the latest version).
[0049] The container management unit 34 manages the latest version of the container and the past version of the container based on the usage permission information received from the authentication unit 31. For example, when the latest version of the container is permitted for use in the usage permission information, the container management unit 34 reads out the latest version of the container from the current container storage unit 35. The container management unit 34 associates the device ID for which the latest version of the container is permitted for use with the read latest version of the container and transmits it to the transmission / reception unit 33. Thereby, the transmission / reception unit 33 transmits the latest version of the container to the edge device 5A corresponding to the device ID.
[0050] Furthermore, if the container management unit 34 receives a request from the edge device 5A via the transceiver unit 33 to transmit a past version of a container, it reads the previously transmitted past version of a container from the old container storage unit 36. The container management unit 34 associates the device ID corresponding to the past version of the container with the retrieved past version of the container and transmits it to the transceiver unit 33. As a result, the transceiver unit 33 transmits the past version of the container to the edge device 5A corresponding to the device ID.
[0051] The parameter setting support unit 37 assists in setting the parameters of the container installed on the edge device 5A, as well as assisting in setting the parameters of the edge device 5A itself. For example, the parameter setting support unit 37 assists in setting the parameters of the device control unit 6A itself and the parameters of the edge unit 7A itself.
[0052] The edge device 5A includes a device control unit 6A, which is equivalent to a PLC, an edge unit 7A that extends the functions of the device control unit 6A, a transmitting / receiving unit 8, and a bus 51. Thus, the edge device 5A has the functions of a PLC and the extended functions of a PLC, and the edge device 5A itself may be a PLC. The device control unit 6A, the edge unit 7A, and the transmitting / receiving unit 8 are connected via the bus 51.
[0053] The device control unit 6A, the edge unit 7A, and the transceiver unit 8 are each composed of separate, detachable units, and the edge device 5A is realized when each unit is connected to the bus 51. For example, if the device control unit 6A is a CPU (Central Processing Unit) unit, the edge unit 7A is a function expansion unit connected to the CPU unit, and the transceiver unit 8 is a transceiver unit connected to both the CPU unit and the function expansion unit. The device control unit 6A, the edge unit 7A, and the transceiver unit 8 may be realized by one or two units.
[0054] The edge device 5A, which is a Factory Automation (FA) device, is divided into a functional unit (edge ββunit 7A) that can be easily set up automatically and a functional unit (device control unit 6A) that is difficult to set up automatically. In the edge device 5A, after the edge unit 7A is automatically set up by the function extension cloud 3, the edge unit 7A assists in the automatic setting of parameters of the device control unit 6A.
[0055] In this embodiment, the parameter setting support unit 37 of the function-enhanced cloud 3 assists in setting the parameters of the container installed on the edge unit 7A. The parameter setting support unit 37 also adjusts and sets the parameters of the edge device 5A (edge ββunit 7A and device control unit 6A) in general terms. The edge unit 7A adjusts and sets the parameters of the device control unit 6A in detail. The general and detailed adjustments of parameters will be described later.
[0056] The device control unit 6A comprises a control unit 61, a control parameter management unit 62, and a device ID management unit 63A. The control unit 61 controls other devices such as machine tools and sensors. The control parameter management unit 62 manages the parameters (control parameters, etc.) used by the control unit 61 when controlling machine tools, etc. The parameters managed by the control parameter management unit 62 may be adjusted, readjusted, or set with assistance by the edge unit 7A. The device ID management unit 63A manages the device ID of its own device (edge ββdevice 5A).
[0057] The transmitting / receiving unit 8 transmits and receives data between the function expansion cloud 3, the user PC 2, the administrator PC, and other edge devices 5A. When power is turned on to an edge device 5A, the transmitting / receiving unit 8 sends power-on information to the function expansion cloud 3 indicating that power has been turned on to the edge device 5A. The power-on information that the transmitting / receiving unit 8 sends to the function expansion cloud 3 includes the device ID information of the edge device 5A.
[0058] Furthermore, the transmitting / receiving unit 8 receives containers from the function-enhancing cloud 3 and transmits them to the edge unit 7A. The transmitting / receiving unit 8 also receives various instructions for the edge device 5A from the user PC 2 and transmits them to the edge unit 7A or the device control unit 6A. For example, the transmitting / receiving unit 8 receives system configuration information from the engineering tool 9 on the user PC 2 and transmits it to the edge unit 7A.
[0059] Furthermore, the transmitting and receiving unit 8 transmits and receives various data (such as information on the control status by the equipment control unit 6A) with other edge devices 5A. The information on the control status by the equipment control unit 6A includes control information when the equipment control unit 6A controls the machine tool, and information on the state of the machine tool being controlled.
[0060] The edge unit 7A is automatically configured with containers by the function-enhanced cloud 3. The edge unit 7A comprises a container management unit 71, a container storage unit 72, a parameter adjustment unit 73, a system information acquisition unit 74, a device ID management unit 75, and a setting readjustment unit 76.
[0061] The device ID management unit 75 manages the device ID of its own device (edge ββdevice 5A). When power is turned on to the edge device 5A, the device ID management unit 75 transmits power-on information, including the device ID of the edge device 5A, to the transmission / reception unit 8.
[0062] The device ID management unit 75 may also manage the name ID. In this case, when the device ID management unit 75 receives a request for the name ID from the function extension cloud 3, it transmits the name ID to the transmission / reception unit 8. The name ID may also be managed by a unit other than the device ID management unit 75 within the edge device 5A.
[0063] In this embodiment, the edge device 5A is configured with the edge unit 7A and the device control unit 6A as separate devices (units), so the edge device 5A has a device ID management unit 63A and a device ID management unit 75. That is, when the device control unit 6A and the edge unit 7A are detachable units, the device control unit 6A and the edge unit 7A each have a device ID management unit. The device ID management unit 63A and the device ID management unit 75 each manage the device ID.
[0064] Furthermore, if the edge unit 7A and the device control unit 6A are located within a single unit in the edge device 5A, the edge device 5A only needs to have one device ID management unit. That is, if the edge unit 7A and the device control unit 6A are implemented in a single unit, the edge device 5A only needs to have a common device ID management unit (a device ID management unit that executes the processing of both device ID management units 63A and 75) for both the device control unit 6A and the edge unit 7A.
[0065] The container management unit 71 sets whether to enable or disable containers obtained from the function-enhanced cloud 3. For example, the container management unit 71 sets whether to enable or disable containers according to instructions from the user PC 2. Alternatively, the container management unit 71 may automatically enable a container if it confirms that the obtained container is one received from the function-enhanced cloud 3.
[0066] The container of the functional expansion system 1A has multiple functions. If all functions are enabled at the same time as the container is installed on the edge device 5A, there is a possibility that the coordination between the edge device 5A and the container will proceed more than necessary, potentially causing malfunctions. For this reason, the edge device 5A does not immediately enable the container, but first stores it and then sets whether or not to enable the container. At that time, the edge device 5A does not enable all functions at once, but may enable only the functions desired by the user first. This allows the edge device 5A to customize the functions included in the container.
[0067] Note that even within the same container, the available features may differ depending on the license fee for each edge device 5A or for each user (by name ID) in the group of edge devices. In this case, edge device 5A may enable only the features for which the license fee has been paid. Activation of features is not limited to manual configuration by the user; edge device 5A may also automatically configure it according to instructions from the feature enhancement cloud 3.
[0068] The parameter adjustment unit 73 of the edge device 5A sets, for example, "1 (on)" as a parameter to enable a function and "0 (off)" as a parameter to disable a function. In addition, when the parameter adjustment unit 73 matches the data communication port of the container with that of the device control unit 6A, it sets information identifying the port as a data communication parameter.
[0069] The container storage unit 72 stores containers acquired by the edge unit 7A from the function-enhancing cloud 3. The system information acquisition unit 74 acquires system configuration information and other data from the engineering tool 9.
[0070] The parameter adjustment unit 73 obtains the parameters used by the equipment control unit 6A from the equipment control unit 6A. The parameters used by the equipment control unit 6A are the parameters used when the equipment control unit 6A controls the machine tool. Based on the container obtained from the function expansion cloud 3 and the system configuration information obtained by the system information acquisition unit 74, the parameter adjustment unit 73 adjusts and sets the parameters used by the control parameter management unit 62.
[0071] For example, the container acquired by the edge device 5A may include a function to collect data from a specific device (such as a machine tool), and the system configuration information may indicate that the edge device 5A is connected to this specific device. In this case, the parameter adjustment unit 73 adjusts the data collection parameters used by the control parameter management unit 62, thereby causing the device control unit 6A to collect data from the specific device.
[0072] The parameter adjustment unit 73 checks whether the parameters of the device control unit 6A are set to the parameters necessary to enable the container's functions after the parameter settings necessary to enable the container's functions have been made by the function expansion cloud 3.
[0073] If the parameters of the equipment control unit 6A are not set to the parameters necessary to enable the container's function, the parameter adjustment unit 73 checks, based on the system configuration information, whether enabling the container's function will cause problems in the production line system, etc.
[0074] In this embodiment, before acquiring a container from the function-enhanced cloud 3, the edge device 5A is controlled by the device control unit 6A without using a container. Once the edge device 5A acquires a container from the function-enhanced cloud 3, it executes operations using the acquired container. In this case, the device control unit 6A may change parameters or other settings when acquiring the container.
[0075] For example, when edge device 5A acquires a container, it may change parameters such as the timing of outputting control commands, the timing of switching controls on and off, and the output destinations of inputs and outputs, which may affect the operation of the production system, including the production line and the group of edge devices. Also, when a container is acquired, the control program used by the device control unit 6A may operate differently from its specifications. For example, a machine tool may transport or process a workpiece at a timing different from the desired timing specified in the control program.
[0076] Therefore, the parameter adjustment unit 73 determines that if there is an impact on the operation of the production system before and after acquiring the container, a problem will occur in the production system, etc. Based on the system configuration information, the parameter adjustment unit 73 confirms that enabling the functions of the container will not cause problems in the production system, etc. (i.e., will not have any impact), and then adjusts the necessary parameters according to the container, or assists in the adjustment. The parameter adjustment unit 73 may be located in the function expansion cloud 3. In other words, the function expansion cloud 3 may perform all parameter adjustments.
[0077] If a malfunction (such as a problem occurring in the production system) persists after the parameter adjustment unit 73 has adjusted and set the parameters, the setting readjustment unit 76 notifies the container management unit 34 of the function extension cloud 3. As a result, the container management unit 34 assumes, for example, that the latest version of the container is incompatible with the surrounding edge devices 5A, and reads out the older version of the container from the old container storage unit 36 ββand retransmits it to the edge devices 5A.
[0078] Here, we will explain the difference between the processing performed by the parameter setting support unit 37 of the function-enhanced cloud 3 and the processing performed by the parameter adjustment unit 73 of the edge device 5A. The parameter setting support unit 37 of the function-enhanced cloud 3 adjusts and sets the parameters of the edge device 5A in general terms based on the type of edge device 5A and the type of container. On the other hand, the parameter adjustment unit 73 of the edge device 5A adjusts the parameters of the edge device 5A in detail based on system configuration information, etc.
[0079] Here, we will explain the process by which the parameter setting support unit 37 of the function-enhancing cloud 3 adjusts parameters in a broad sense. The process by which the parameter setting support unit 37 adjusts parameters in a broad sense is the process by which the parameter setting support unit 37 of the function-enhancing cloud 3 adjusts the parameters of the edge device 5A (such as the device control unit 6A) that has been authorized to be adjusted from the outside. For example, as a broad parameter adjustment process for the edge device 5A, the parameter setting support unit 37 sets a device number that opens up information (data) to external access. The parameter setting support unit 37 may adjust parameters in a broad sense for any of the device control unit 6A, the edge unit 7A, and the transmitting / receiving unit 8.
[0080] Figure 3 is a diagram illustrating the device number set by the function-enhanced cloud according to the embodiment. Figure 3 shows a display screen 80, which is an example of a setting screen for setting a process. The display screen 80 is an operation screen for setting the process name (screw tightening), the name of the equipment control unit 6A that manages the process (for example, information that identifies the PLC), and the data device to be used for data acquisition.
[0081] The data devices to be acquired are specified by the process device number (sequence number), etc. Device numbers set by the function extension cloud 3 include, for example, the work completion sequence number (device number: D1000), the trouble occurrence sequence number (device number: D1002), and the trouble occurrence reset sequence number (device number: D1003), as shown in Figure 3.
[0082] In the function-enhanced cloud 3, the process name, the name of the equipment control unit 6A, and the data device to be acquired (such as the sequence number) are set, as displayed on the display screen 80. For example, the process name, the name of the equipment control unit 6A, and the device number are manually entered by the user into the display screen 80 and set in the function-enhanced cloud 3.
[0083] The device number may not only be manually set by the user in the Function Expansion Cloud 3, but may also be set automatically by the Function Expansion Cloud 3. When the Function Expansion Cloud 3 sets the device number automatically, the parameter setting support unit 37 analyzes the ladder program used to control the machine tool by the equipment control unit 6A to identify the device corresponding to the information (data) desired by the user. The parameter setting support unit 37 then automatically sets the device number of the identified device. The information (data) desired by the user is selected in advance by the user and set in the Function Expansion Cloud 3.
[0084] The process by which the parameter adjustment unit 73 of the edge device 5A adjusts the parameters in detail is a process in which the parameter adjustment unit 73 of the edge device 5 adjusts the parameters of the edge device 5A that are not permitted to be adjusted externally by the edge device 5A.
[0085] The parameter adjustment unit 73 may, for example, change the communication port by connecting the edge device 5A to the bus 51 as part of a detailed parameter adjustment process. In this way, the detailed parameter adjustment process performed by the parameter adjustment unit 73 is a parameter adjustment to enable the edge device 5A to perform a specific function. The parameter adjustment unit 73 may also assist in setting parameters in the device control unit 6A, or it may set parameters in the device control unit 6A.
[0086] Furthermore, the parameter adjustment unit 73 checks the operating status of the device control unit 6A, which has had its parameters automatically set, and adjusts or readjusts the parameters of the container, the parameters of the edge device 5A, etc., according to the operating status.
[0087] Furthermore, as mentioned above, the parameter adjustment unit 73, based on the system configuration information, confirms that the parameters of the equipment control unit 6A after the installation of a function extension object (such as a container) will not affect the production system including the production line and the group of edge equipment, and then sets the parameters of the equipment control unit 6A or assists in setting the parameters of the equipment control unit 6A. For example, when an edge device 5A installs a container, the equipment control unit 6A may change the initial value of its parameters. In this case, the parameters of the equipment control unit 6A will affect the production system. Therefore, based on the parameters of the equipment control unit 6A and the system configuration information, the parameter adjustment unit 73 confirms that no parameter changes have been made in the equipment control unit 6A that would affect the production system, and then sets or assists in setting the parameters of the equipment control unit 6A according to the container.
[0088] Figure 4 is a flowchart showing the processing steps of the functional expansion system according to the embodiment. Here, we will explain the process from when the functional expansion system 1A loads a container onto the edge device 5A.
[0089] When the edge device 5A is powered on (step S1), the device ID management unit 75 of the edge device 5A transmits power-on information to the transceiver unit 8, which includes the device ID of the edge device 5A and information indicating that the power has been turned on. The transceiver unit 8 then transmits the power-on information to the function expansion cloud 3 via the internet 10. In other words, when the edge device 5A is powered on, it transmits its device ID to the function expansion cloud 3 (step S2).
[0090] The function-enhanced cloud 3 requests the name ID verification device (name holder), which is a device on the edge device 5A side corresponding to the device ID, to send the name ID (step S3). The name ID verification device here may be the edge device 5A, or it may be an administrator PC that manages the edge device 5A. In other words, the function-enhanced cloud 3 may send the name ID transmission request to the edge device 5A, or it may send it to an administrator PC, etc. When the name ID verification device receives the name ID transmission request, it sends the name ID to the function-enhanced cloud 3 (step S4).
[0091] When the function-enhanced cloud 3 sends a request for the transmission of a name ID to the edge device 5A, the name ID is stored in the edge device 5A beforehand. When the edge device 5A receives a request for the transmission of a name ID, it sends the stored name ID to the function-enhanced cloud 3.
[0092] Furthermore, when the Function Enhancement Cloud 3 sends a request for the Name ID to the administrator's PC, the administrator enters the Name ID on the Name ID request screen displayed on the administrator's PC, and the administrator's PC sends the Name ID to the Function Enhancement Cloud 3.
[0093] The authentication unit 31 of the function-enhanced cloud 3 determines whether the name ID (name of the account holder) is correct based on the name ID and the authentication information table (step S5). If the authentication unit 31 determines that the name of the account holder corresponding to the name ID is not a legitimate authorized person (legitimate purchaser of edge device 5A) (step S5, No), the function-enhanced cloud 3 returns to the process in step S3.
[0094] On the other hand, if the authentication unit 31 determines that the name holder is a legitimate authorized person (a legitimate purchaser of edge device 5A) (step S5, Yes), it verifies the device ID of the group of edge devices corresponding to the name holder ID (step S6). The authentication unit 31 sets the device ID of the edge device 5A that has sent power-on information to the function extension cloud 3 from among the group of edge devices stored in the authentication information table as an authenticated device ID. In other words, after authenticating the name holder ID, the authentication unit 31 sets the device IDs of all edge devices 5A that have sent power-on information (device ID) from among the group of edge devices corresponding to the name holder ID as authenticated device IDs.
[0095] The authentication unit 31 may either use the device ID transmitted from edge device 5A when the power to edge device 5A is turned on as the authenticated device ID from the group of edge devices stored in the authentication information table, or it may send a request to send the device ID again to edge device 5A. If the authentication unit 31 sends a request to send the device ID to edge device 5A, it will use the device ID sent back from edge device 5A in response to this request as the authenticated device ID.
[0096] Thus, the authentication unit 31 may authenticate the device ID of the edge device 5A that has transmitted power-on information, or it may authenticate the device ID of the edge device 5A that has transmitted the device ID after sending a request to transmit the device ID.
[0097] The enhanced cloud 3 performs network configuration for the container and edge device 5A (step S7). Specifically, the enhanced cloud 3 identifies the edge device 5A corresponding to the authenticated device ID and the container to be provided to this edge device 5A based on the authentication information table. Then, the enhanced cloud 3 performs network configuration (connection configuration with the edge device 5A) to send the identified container to the identified edge device 5A. By performing network configuration, the enhanced cloud 3 sets the download destination for the container (address of the edge device 5A).
[0098] After setting the download destination for the container, the function-enhanced cloud 3 checks the permissions corresponding to the device ID based on the authentication information table (step S8). The function-enhanced cloud 3 selects a container based on the permissions. The function-enhanced cloud 3 sends the container selected based on the permissions to the edge device 5A (step S9). In other words, the function-enhanced cloud 3 identifies the permissions corresponding to the device ID based on the authentication information table and sends the container corresponding to the permissions to the edge device 5A corresponding to the device ID.
[0099] Furthermore, the enhanced cloud 3 adjusts the container parameters based on the permissions (step S10) and adjusts the parameters of the edge device 5A based on the permissions (step S11).
[0100] In the function expansion system 1A, all edge devices 5A that have been powered on transmit power-on information, including their device IDs, to the function expansion cloud 3. After adjusting the parameters of the edge devices 5A, the function expansion cloud 3 checks whether it has received other device IDs (step S12).
[0101] If another device ID has been received (Step S12, Yes), the authentication unit 31 of the function extension cloud 3 checks whether the time of confirmation of receipt falls within the authentication specified period (Step S13).
[0102] The authentication period is explained below. The authentication period may be a specified period from the last notification from an edge device 5A to the function enhancement cloud 3 indicating that power has been turned on to any of the edge devices 5A in the group of edge devices, or it may be a specified period corresponding to the number of edge devices 5A that make up the function enhancement system 1A. The specified period from the last notification that power has been turned on to an edge device 5A is updated each time power is turned on to an edge device 5A.
[0103] Furthermore, the authentication specification period is, for example, the period obtained by multiplying the number of terminals of edge device 5A by the authentication time per edge device 5A. In this case, the authentication time per edge device 5A includes the time to authenticate the device ID of edge device 5A. The authentication time per edge device 5A may also include the time to supply containers to edge device 5A, the time to adjust the container parameters, etc. The authentication specification period may be set to an initial value in advance, or it may be set or changed by the user of the function extension cloud 3.
[0104] Furthermore, if users of the enhanced cloud 3 wish to shorten the authentication period for security reasons, they may set the authentication period for each network to which the edge device 5A is connected.
[0105] Furthermore, if the system configuration of the function expansion system 1A changes, or if the information (data) collected by the function expansion cloud 3 from the edge device 5A changes, the authentication period will be changed accordingly. Examples of situations where the information collected by the function expansion cloud 3 from the edge device 5A changes include, for example, a change in the purpose of using the information from productivity management to quality management, and a change in the device number of the information (data) to be collected.
[0106] The authentication unit 31 changes the authentication period when the reference information (information that may become an authentication burden) used to set the period required for authentication of the edge device 5A is changed. Specifically, the authentication unit 31 sets the authentication period according to changes in system configuration information, data acquisition information, or additional function information obtained from the engineering tool 9.
[0107] The data acquisition information is information about the edge device 5A that acquires data from controlled equipment such as machine tools (edge ββdevice information). The data acquisition information includes, for example, at least one of the specifications of the edge device 5A (CPU, memory) and the number of external devices connected to the edge device 5A. This data acquisition information is pre-stored in the edge device 5A.
[0108] The additional function information is information about the functions (applications) that are added to edge device 5A by downloading a container from the function enhancement cloud 3. The additional functions are added to edge device 5A by downloading a container from the function enhancement cloud 3 and enabling the functions of the container. Edge device 5A or other terminals (such as user PC 2) access the function enhancement cloud 3 and request the function enhancement cloud 3 to set a path to edge device 5A. As a result, the function enhancement cloud 3 sets a path to edge device 5A and downloads the container from function enhancement cloud 3 to edge device 5A using the path. The container sent by function enhancement cloud 3 to edge device 5A via the path is stored in the container storage unit 72. The container management unit 71 makes the container functional by configuring the stored container to be enabled.
[0109] If the time at which the reception of another device ID is confirmed falls within the authentication specified period (step S13, Yes), and the received other device ID is a device ID associated with a name ID that has already been confirmed (authenticated), the authentication unit 31 of the function expansion system 1A omits the confirmation of the name ID. That is, the authentication unit 31 omits the processing in steps S3 to S5. Then, the function expansion system 1A executes the processing in steps S6 to S12 for the edge device 5A corresponding to the other device ID. That is, the function expansion system 1A sends a container to the device ID associated with the name ID and adjusts the parameters of the container and the parameters of the edge device 5A.
[0110] As a result, the functional expansion system 1A can perform the necessary authentication for multiple edge devices 5A simultaneously, even for systems that have multiple edge devices 5A, such as a production line, without having to go through complicated authentication procedures.
[0111] On the other hand, if the time at which the reception of another device ID is confirmed is outside the authentication specified period (step S13, No), the authentication unit 31 returns to the process in step S3. The function-extended cloud 3 then requests the name ID verification device corresponding to the other device ID to send the name ID (step S3). The name ID verification device sends the name ID to the function-extended cloud 3 (step S4). The authentication unit 31 of the function-extended cloud 3 determines whether the name holder is correct based on the name ID and the authentication information table (step S5). Thus, if the time at which the reception is confirmed is outside the authentication specified period, the function-extended cloud 3 verifies the name ID again.
[0112] In this example, the enhanced cloud 3 determines whether the time of confirmation of receipt of the device ID falls within the authentication period. However, it is also possible to determine whether a different time from the time of confirmation of receipt falls within the authentication period.
[0113] The enhanced cloud 3 may, for example, determine whether the time when the device ID was transmitted from the edge device 5A falls within the authentication period, or it may determine whether the time when the device ID was received falls within the authentication period. In other words, the enhanced cloud 3 may determine whether the time when it falls within the authentication period is any of the following: the time when it confirms receipt of the device ID, the time when the device ID was transmitted, or the time when the device ID was received.
[0114] If the function expansion system 1A has not received any other device IDs in step S12 (step S12, No), it terminates the process of loading the container onto the edge device 5A.
[0115] Figure 5 is a diagram showing the first operation screen of the function-enhancing cloud according to the embodiment. In Figure 5, display screen 81A is shown as an example of an operation screen for loading a container from the function-enhancing cloud 3 onto the edge device 5A. Multiple index icons for containers that extend the functionality of the edge device 5A are displayed on display screen 81A of the display device provided by the function-enhancing cloud 3.
[0116] For example, when installing a data collection container on edge device 5A, the user selects the data collection index icon 82X from display screen 81A. Similarly, when installing a data analysis container on edge device 5A, the user selects the data analysis index icon 82Y from display screen 81A.
[0117] If the user selects the data collection index icon 82X, they set the download destination (address of edge device 5A) in the data collection container download destination input field 83X and select the download button 84.
[0118] Furthermore, if the user selects the data analysis index icon 82Y, they set the download destination (address of edge device 5A) in the data analysis container download destination input field 83Y and select the download button 84. Through these operations, the container desired by the user is downloaded to the edge device 5A of the user's choice.
[0119] Figure 6 shows an example of a second operation screen of the functional extension cloud according to the embodiment. In Figure 6, display screen 81B is shown as an example of an operation screen for making settings for the device control unit 6A.
[0120] The display screen 81B shown in Figure 6 shows an input field 85 for the name (PLC name) of the device control unit 6A, a data input field 86 for setting the IP (Internet Protocol) address of the device control unit 6A, and a device input field 87 for identifying the connecting edge device 5A.
[0121] The user enters the name of the desired device control unit 6A in the name input field 85, the IP address of the device control unit 6A in the data input field 86, and the identification information of the connecting edge device 5A in the device input field 87.
[0122] Note that display screen 81B is the screen when the edge unit 7A is separated from the device control unit 6A. Therefore, display screen 81B is configured to show the edge device 5A controlled by the function expansion cloud 3 and the device control unit 6A controlled by the function expansion cloud 3 via the edge unit 7A.
[0123] The edge unit 7A and the device control unit 6A may be configured as a single unit. For example, the edge unit 7A may be located within the device control unit 6A. Figure 7 shows another example of the configuration of the edge device according to this embodiment.
[0124] The edge device 5B comprises a device control unit 6B and a transmitting / receiving unit 8. The device control unit 6B includes a control unit 61, a control parameter management unit 62, a device ID management unit 63B, and an edge unit 7B.
[0125] The edge unit 7B does not have the device ID management unit 75, unlike the edge unit 7A. In the edge device 5B, the device ID management unit 63B has the functions of both the device ID management unit 63A and the device ID management unit 75.
[0126] Thus, in the edge device 5B, the edge unit 7B is located within the device control unit 6B, and the device control unit 6B is configured as a single unit that has the functions of the edge unit 7B. In this case, when a container is mounted on the device control unit 6B, the edge device 5B will have the same configuration as the edge device 5A.
[0127] In the case of an edge device 5B, where the edge unit 7A and the device control unit 6A are integrated, only the information of the edge device 5B is displayed on the display screen 81B.
[0128] By the way, the device setting management system described in Patent Document 1 allows for setting changes to multiple devices, but it does not authenticate the owner or other relevant parties. Therefore, the device setting management system described in Patent Document 1 cannot enhance security for devices purchased by an unspecified number of people, such as the edge devices 5A and 5B in the embodiment, and smartphones.
[0129] Furthermore, with devices such as smartphones, authentication and initial setup are performed on an individual device. On the other hand, since multiple edge devices 5A and 5B are deployed on a factory production line, it is necessary to perform initial setup and other settings simultaneously on the edge devices 5A and 5B that constitute the desired production line. For this reason, when authentication technology such as that used on smartphones is used for devices deployed on a factory production line, authentication work is required for each device, making the authentication process cumbersome. For this reason, the device setting management system in Patent Document 1 could not simultaneously authenticate and set up devices that constitute a production line under a new owner.
[0130] In the functional expansion system 1A of this embodiment, the functional expansion cloud 3 continues to grant authentication permission to the edge device group only during the authentication specified period, so that authentication and configuration (such as function settings) can be performed simultaneously on multiple edge devices 5A and 5B with enhanced security.
[0131] Next, the hardware configuration of the function-enhanced cloud 3 and edge devices 5A and 5B will be described. The function-enhanced cloud 3 and edge devices 5A and 5B are implemented by processing circuits. At least one of the device control units 6A and 6B and the edge units 7A and 7B may also be implemented by processing circuits. The processing circuit may be a processor and memory that executes a program stored in memory, or it may be dedicated hardware. When the function-enhanced cloud 3, edge devices 5A and 5B, device control units 6A and 6B, and edge units 7A and 7B are implemented by processing circuits, each processing circuit has a similar hardware configuration, so here we will describe the hardware configuration of the function-enhanced cloud 3.
[0132] Figure 8 is a diagram showing an example of the configuration of a processing circuit when the processing circuit of the functional enhancement cloud according to the embodiment is realized with a processor and memory. The processing circuit 90 shown in Figure 8 comprises a processor 91 and memory 92. When the processing circuit 90 is composed of a processor 91 and memory 92, each function of the processing circuit 90 is realized by software, firmware, or a combination of software and firmware. The software or firmware is written as a functional enhancement program and stored in memory 92. In the processing circuit 90, each function is realized by the processor 91 reading and executing the functional enhancement program stored in memory 92. In other words, the processing circuit 90 includes memory 92 for storing the functional enhancement program, which will ultimately be executed by the processing of the functional enhancement cloud 3. This functional enhancement program can also be said to be a program that causes the functional enhancement cloud 3 to execute each function realized by the processing circuit 90. This functional enhancement program may be provided on a computer-readable recording medium on which the functional enhancement program is recorded, or it may be provided by other means such as a communication medium.
[0133] The above-mentioned function extension program can also be described as a program that causes the function extension cloud 3 to execute the processes in steps S3, S5 to S13 of Figure 4. Here, the processor 91 is, for example, a CPU, processing unit, arithmetic unit, microprocessor, microcomputer, or DSP (Digital Signal Processor). The memory 92 is, for example, a non-volatile or volatile semiconductor memory such as RAM (Random Access Memory), ROM (Read Only Memory), flash memory, EPROM (Erasable Programmable ROM), EEPROM (Registered Trademark) (Electrically EPROM), magnetic disk, flexible disk, optical disk, compact disk, minidisc, or DVD (Digital Versatile Disc).
[0134] Figure 9 shows an example of the configuration of a processing circuit when the processing circuit of the functional extension cloud according to the embodiment is configured with dedicated hardware. The processing circuit 93 shown in Figure 9 may be, for example, a single circuit, a composite circuit, a programmed processor, a parallel programmed processor, an ASIC (Application Specific Integrated Circuit), an FPGA (Field Programmable Gate Array), or a combination thereof. The processing circuit 93 may be partially implemented with dedicated hardware and partially implemented with software or firmware. In this way, the processing circuit 93 can realize each of the above functions by dedicated hardware, software, firmware, or a combination thereof.
[0135] In this embodiment, when the function enhancement cloud 3 first receives a name ID corresponding to a device ID, it authenticates the edge device (first edge device) 5A that sent the received name ID as a legitimate contracted device and sends a function enhancement object to the first edge device. The function enhancement cloud 3 then continues authentication for edge devices 5A and 5B corresponding to the device IDs associated with the name ID only for the duration of the authentication period, and during the authentication period, it sends the function enhancement object to edge devices 5A and 5B without requesting a name ID when they send a device ID. As a result, the function enhancement system 1A can perform simultaneous authentication and configuration for multiple edge devices 5A and 5B with enhanced security.
[0136] The configurations shown in the above embodiments are merely examples, and can be combined with other known technologies. It is also possible to omit or modify parts of the configuration without departing from the gist of the invention.
[0137] 1A Function expansion system, 2 User PC, 3 Function expansion cloud, 5A, 5B Edge devices, 6A, 6B Device control unit, 7A, 7B Edge unit, 8, 33 Transmit / receive unit, 9 Engineering tool, 10 Internet, 31 Authentication unit, 32 Authentication information storage unit, 34, 71 Container management unit, 35 Current container storage unit, 36 Old container storage unit, 37 Parameter setting support unit, 51 Bus, 61 Control unit, 62 Control parameter management unit, 63A, 63B, 75 Device ID management unit, 72 Container storage unit, 73 Parameter adjustment unit, 74 System information acquisition unit, 76 Setting readjustment unit, 80, 81A, 81B Display screen, 82X, 82Y Index icon, 83X, 83Y Download destination input field, 84 Download button, 85 Name input field, 86 Data input field, 87 Device input field, 90, 93 Processing circuit, 91 processor, 92 memory.
Claims
1. A function extension system comprising: a plurality of edge devices that extend the functionality of a controlled device, which is a controlled device, by mounting a function extension object that controls and extends the functionality of the controlled device; and a management server that is connected to the edge devices via a network and manages the edge devices, wherein the edge devices transmit device identification information that identifies the edge device to the management server; the management server stores an authentication information table in which a plurality of device identification information are associated with a single name identification information that identifies a name; when it first receives the name identification information corresponding to the device identification information, it authenticates the first edge device that transmitted the received name identification information as a legitimate contract device based on the name identification information, the device identification information, and the authentication information table, and transmits the function extension object to the first edge device; and for the edge device corresponding to the device identification information associated with the name identification information, it continues the authentication only for the duration of the authentication period, which is the period during which the authentication is continued, and during the authentication period, it transmits the function extension object to the edge device without requesting the name identification information when the edge device transmits the device identification information.
2. The function extension object includes a container for extending the function and parameters of the container, and the edge device has an edge section where the container is set by the management server and a device control unit that controls the controlled device, and the edge section and the device control unit each consist of a separate, detachable unit, as described in claim 1.
3. The function expansion system according to claim 2, characterized in that the edge unit, based on system configuration information which is information on the system configuration of the production line in which the controlled equipment is located and the production system including the edge equipment, confirms that the parameters of the equipment control unit after the container is mounted will not affect the production system, and then sets parameters corresponding to the container to the equipment control unit, or assists in setting parameters to the equipment control unit.
4. The function extension system according to any one of claims 1 to 3, characterized in that the setting of the function extension object on the edge device by the management server is triggered by the power being turned on to the edge device.
5. The function extension system according to claim 2, characterized in that the edge portion checks the operating status of the device control unit after the function extension object has been set and adjusts the function extension object according to the operating status.
6. The function extension system according to claim 3, characterized in that the management server sets the authentication specified period in response to changes in the system configuration information, changes in edge device information which is information of edge devices that acquire data from the controlled devices, or changes in additional function information which is information of functions added to the edge devices by the function extension object.
7. The functional extension system according to any one of claims 1 to 6, characterized in that the authentication specification period is a specified period from the last notification to the management server indicating that power has been turned on to any of the multiple edge devices.
8. The functional expansion system according to any one of claims 1 to 6, characterized in that the authentication specified period is a specified period set according to the number of edge devices associated with the name identification information.
9. The function extension system according to any one of claims 1 to 8, characterized in that the edge device extends the function by activating the function extension object.
10. The function expansion system according to any one of claims 1 to 9, characterized in that each edge device transmits the device identification information to the management server when power is turned on.
11. A first transmission step in which multiple edge devices that extend the functionality of a controlled device, which is a controlled device, by mounting a function extension object that controls and extends the functionality of the controlled device, transmit device identification information that identifies the edge device to a management server connected to the edge device via a network and managing the edge device; a storage step in which the management server stores an authentication information table in which multiple device identification information is associated with one name identification information that identifies the name; and a second transmission step in which, when the management server first receives the name identification information corresponding to the device identification information, the management server authenticates the first edge device that transmitted the received name identification information as a legitimate contract device based on the name identification information, the device identification information, and the authentication information table, and transmits the function extension object to the first edge device. A method for extending functionality, comprising: a third transmission step in which the management server continues authentication for the edge device corresponding to the device identification information associated with the name identification information for the duration of the authentication specified period, and during the authentication specified period, transmits the function extension object to the edge device without requesting the name identification information when the edge device transmits the device identification information.
12. A management server connected via a network to a plurality of edge devices that control a controlled device and extend its functionality by mounting a function extension object, the management server managing the edge devices, comprising: a transmitting / receiving unit that receives device identification information identifying the edge devices from the edge devices; an authentication information storage unit that stores an authentication information table in which a plurality of device identification information are associated with a single name identification information that identifies a name; and an authentication unit that, when the transmitting / receiving unit first receives the name identification information corresponding to the device identification information, authenticates the first edge device that transmitted the received name identification information as a legitimate contract device based on the name identification information, the device identification information, and the authentication information table, wherein the transmitting / receiving unit transmits the function extension object to the authenticated first edge device, and the authentication unit continues the authentication for the edge device corresponding to the device identification information associated with the name identification information only for the duration of the authentication specified period, which is the period during which the authentication is continued. The transmission / reception unit is characterized in that, during the authentication specification period, when the edge device transmits the device identification information, it transmits the function extension object to the edge device without requesting the name identification information.
13. An edge device that controls a controlled device, which is a device to be controlled, and extends its functionality by mounting a function extension object that extends the functionality of the controlled device, comprising: a device control unit that controls the controlled device; an edge unit that mounts the function extension object; a management server connected to the edge device via a network and managing the edge device; and a transmitting / receiving unit that transmits device identification information that identifies the edge device to a management server connected to a group of edge devices including the edge device via a network and managing the group of edge devices, wherein each device identification information of the group of edge devices is associated with and managed to identify a single name identification piece that identifies a name, and after the transmitting / receiving unit transmits the device identification information to the management server, during the authentication specification period, which is the period during which the authentication continues after other edge devices included in the group of edge devices have been authenticated as legitimate contract devices, the transmitting / receiving unit does not transmit the name identification information to the management server and receives the function extension object from the management server.
14. A function extension program for a management server that is connected via a network to a plurality of edge devices that control a controlled device and extend its functionality by mounting a function extension object that extends the functionality of the controlled device, and manages the edge devices and provides the function extension object to the plurality of edge devices, wherein the program causes a computer to execute the following steps: an authentication information storage step which stores an authentication information table in which one name identification information that identifies a name and a plurality of device identification information that identifies each of the edge devices are associated; a receiving step which receives the device identification information from the edge device; and an authentication step which, upon first receiving the name identification information corresponding to the device identification information, authenticates the first edge device that transmitted the received name identification information as a legitimate contract device based on the name identification information, the device identification information, and the authentication information table, A function extension program characterized in that, in the authentication step, the function extension object is transmitted to the authenticated first edge device, and for the edge device corresponding to the device identification information associated with the name identification information, the authentication is continued only for the duration of the authentication specified period, which is the period during which the authentication is continued, and during the authentication specified period, the function extension object is transmitted to the edge device without requesting the name identification information when the edge device transmits the device identification information.
15. A function extension program for an edge device that controls a controlled device and extends its functionality by mounting a function extension object, the program comprising: a device control step for controlling the controlled device; a mounting step for mounting the function extension object; and a transmission step for causing a computer to execute device identification information for identifying the edge device, which is connected to the group of edge devices including the edge device via a network and manages the group of edge devices, wherein each device identification information of the group of edge devices is associated with and managed to identify a single name identification piece of information that identifies the name, and after the transmission step, the program receives the function extension object from the management server without transmitting the name identification information to the management server during the authentication specification period, which is the period during which the authentication continues after other edge devices included in the group of edge devices have been authenticated as legitimate contract devices.