In one embodiment, a
process plant and
industrial control system architecture includes a
general purpose computing fabric that is agnostic or irrelevant to a physical location that implements the computing fabric; comprising one or more
physical control or field devices located at one or more specific sites for manufacturing a product or process; and also includes a
transport network that securely provides communication between the computing fabric and the
pool of physical devices. The computing fabric includes an
application layer that includes a configuration container or containerized
software module that performs various control, monitoring and configuration activities regarding one or more devices, control policies and control loops, sites, plants or facilities that perform the control; the present invention relates to a
data storage system, and includes a
physical layer that includes
computer processing and data storage equipment that can be located at any desired location, the method may be applied to the cloud, including at or near
a site,
plant, or facility that performs the control, at a dedicated location remote from the location that performs the control, in reassignable
computer equipment provided in the cloud, or any combination thereof. The control architecture enables a large number of
computer processing and IT infrastructures for supporting process plants, industrial control facilities, or other
automation facilities to be implemented in a shared, off-site, and / or virtualized manner, this mitigates a number of communication and security issues present in current processes and industrial control systems that attempt to achieve control with shared or virtualized computing resources established according to a well-known Precious Model. The
industrial control system architecture is protected via techniques that are
safer and customizable compared to those used in a Pru Model-based
control system. For example, communications between any (and, in some cases, all) endpoints of the
system may be protected via one or more virtual private networks that the authenticated endpoint must be authorized to access. The endpoints may include, for example, containerized components, physical components, devices, sites or locations, computing structures, etc., and the VPNs may include mutually exclusive and / or nested VPNs. External applications and services, whether being automatic or executing under human rights, may access information and services provided by the
system only via APIs, and different sets of APIs may be exposed to different users that have been authenticated and authorized to access the respective sets of APIs. A
configuration system operates within the computing structure to enable a user to easily make a configuration change to the computing structure because the user does not generally need to specify
computer hardware within the computing structure for making the configuration change, this makes it possible for the user to deploy new configuration elements with simple
programming steps and in some cases with pressing of buttons.