Active Directory Authentication for Historian Data Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Industrial processes generate overwhelming volumes of data from sensors and control elements, making it difficult to ensure efficient data management and accessibility for analysis and process improvement.

Innovation Solution

A system that stores data from multiple sources, enables access from various locations, and implements a user authentication directory for granular access control and advanced data visualization, using cloud storage and active directory technologies to streamline user access and authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Quantity of substance

If data from thousands of sensors and control elements is collected and stored, then the volume of available data for analysis increases, but the complexity of data management and accessibility increases

Engineering Contradiction:
Improvevolume of dataVSAvoiddata management complexity
Core Design Contradiction:
Quantity of substanceVSDevice complexity

Solution Approach 1:

The patent segments the authentication system into multiple components: Active Directory domain for user management, historian application for data storage, and distributed client applications for data access. This segmentation allows each component to handle specific tasks independently, reducing overall system complexity while managing large volumes of industrial data

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary authentication mechanism using Active Directory and credential verification. This intermediary layer manages user access to historical data without requiring direct access to the underlying data storage systems, simplifying data management while enabling controlled access to large datasets

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If user access control is made granular and secure, then data security is improved, but the complexity of authentication and access management increases

Engineering Contradiction:
Improvedata securityVSAvoidauthentication complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal authentication system using Active Directory that serves multiple functions: user credential verification, permission management, and access control across different client applications. This multi-functional approach maintains granular security while avoiding the need for separate authentication systems for each access point

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The authentication system enables self-service capabilities where users can authenticate themselves using their existing Active Directory credentials without requiring manual intervention from administrators. The system automatically verifies credentials against the directory and grants appropriate access levels, reducing administrative complexity while maintaining security

Inventive Principle:
Principle #25Self-service

3Ease of operation

If data is made accessible from multiple locations, then data accessibility and usability are improved, but the risk of unauthorized access increases

Engineering Contradiction:
Improvedata accessibilityVSAvoidunauthorized access risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent implements preliminary authentication actions before granting data access. Users must first authenticate through the Active Directory system and receive verified credentials before accessing historical data from any location. This preliminary security check enables multi-location access while preventing unauthorized entry

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The authentication system provides continuous feedback by verifying user credentials against the Active Directory database and monitoring access patterns. This feedback mechanism enables secure remote access while detecting and preventing unauthorized access attempts through real-time credential verification

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10003592B2Active directory for user authentication in a historization system
Publication Date: 2018.06.19 SCHNEIDER ELECTRIC SOFTWARE LLC
  • US10003592B2 patent drawing
  • US10003592B2 patent drawing
  • US10003592B2 patent drawing

AI summary

A user authentication system enables control of access to historian data through a historian application. The user authentication system creates a user authentication directory for storing user authentication information. The system populates the directory with user authentication information. The system links the directory to a historian application and receives credential data from a user. The system grants access to the historian application when it determines that the credential data from the user matches a portion of the user authentication information on the directory.