Cloud-Orchestrated Secure Remote Access for Industrial Automation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Enabling secure and reliable remote access to industrial automation devices is challenging due to security concerns, legacy devices, complex network architectures, and proprietary communication protocols, which complicates the establishment of efficient and secure connections.

Innovation Solution

A method for establishing a secure remote access (SRA) connection between a cloud computing system (CCS) and an industrial automation system (IAS) using machine-to-machine communications, encrypted VPN tunnels, and tenant-specific connectivity, allowing manufacturers to securely connect remotely without the need for expensive hardware upgrades.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If remote access to industrial automation devices is enabled, then operational efficiency and productivity are improved, but security risks and system vulnerability increase

Engineering Contradiction:
Improveoperational efficiencyVSAvoidsecurity risks
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a gateway device as an intermediary component between the cloud computing system and industrial automation devices. This gateway establishes secure communication channels, acts as a trusted mediator that authenticates and authorizes remote access requests, thereby enabling productivity improvement while mitigating security risks through controlled access mediation

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system segments remote access functionality into modular components: cloud-based access requests, gateway-mediated authentication, and device-specific connection management. This segmentation allows security protocols to be applied at each layer independently, enabling efficient remote access while maintaining robust security boundaries across different system components

Inventive Principle:
Principle #1Segmentation

2Reliability

If secure communication protocols and encryption are implemented, then security and reliability are improved, but communication complexity and processing overhead increase

Engineering Contradiction:
Improvecommunication securityVSAvoidcommunication complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The gateway device serves as an intermediary that handles complex security protocols and encryption/decryption operations. By centralizing these complex functions in the gateway rather than distributing them across all devices, the system achieves high security and reliability while keeping individual device complexity manageable

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system uses virtualization to create virtual copies of automation devices and their communication interfaces. This allows secure encrypted communications to be established with virtual representations, simplifying the actual connection management while maintaining security protocols through the virtualized layer

Inventive Principle:
Principle #26Copying

3Ease of manufacture

If cloud-based access and virtualization are implemented, then hardware costs and device requirements are reduced, but network dependency and connection stability challenges increase

Engineering Contradiction:
Improvehardware costVSAvoidconnection stability
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The system establishes preliminary authentication and connection validation through the gateway before actual remote access operations begin. This preliminary action includes pre-configured security credentials, authorized access lists, and connection parameters that are validated in advance, ensuring connection stability and reliability while maintaining the cloud-based virtualized architecture

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The gateway implements feedback mechanisms that continuously monitor connection status, authentication validity, and system readiness. This real-time feedback allows the system to maintain reliable connections by detecting and responding to network conditions, ensuring connection stability despite the inherent network dependency of cloud-based access

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS20260012511A1Secure remote access for cloud-based industrial automation
Publication Date: 2026.01.08 SOFTWARE DEFINED AUTOMATION GMBH
  • US20260012511A1 patent drawing
  • US20260012511A1 patent drawing
  • US20260012511A1 patent drawing

AI summary

The present disclosure relates to a method for establishing a secure remote access, SRA, connection between a cloud computing system, CCS, and an industrial automation system, IAS, the method comprising: receiving, by an SRA server component of the CCS, a first SRA connection establishment message from a first SRA client of the CCS or from a second SRA client of a user device connected to the CCS; receiving, by a connection orchestrator component of the CCS, an indication to establish the SRA connection between the CCS and the IAS, sending, by the connection orchestrator component and based at least in part on the indication, a machine-to-machine network protocol message to a third SRA client of the IAS comprising information for establishing the SRA connection between the IAS and the CCS, and receiving, by the SRA server component of the CCS, a second SRA connection establishment message from the third SRA client of the IAS, and establishing, via the SRA server component, the secure SRA connection between the first SRA client of the CCS and the third SRA client of the IAS or between the second SRA client of the user device and the third SRA client of the IAS. The present disclosure also relates to a corresponding computing system and a computer program.