Edge Compute Module Secure Backplane Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing industrial automation systems face challenges in efficiently configuring and managing compute modules, particularly in ensuring secure and authenticated access to industrial devices across a data backplane.

Innovation Solution

The implementation of an embedded edge compute (EEC) module that communicates directly with a data backplane, utilizing an add-on profile (AOP) to configure operating parameters and enable secure remote access through a virtual private network (VPN).

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If an embedded edge compute module is integrated into the data backplane, then data exchange efficiency between devices is improved, but system security and access control become more complex

Engineering Contradiction:
Improvedata exchange efficiencyVSAvoidsystem security and access control
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The system is segmented into distinct functional components: the embedded edge compute module handles data processing and exchange, while the authentication module separately manages security and access control. This segmentation allows the compute module to operate efficiently without being burdened by security complexity, as authentication is handled by a dedicated component.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The authentication module acts as an intermediary between remote devices and the data backplane. It verifies authentication credentials and establishes secure communication sessions before allowing access to the compute module and industrial devices, thereby simplifying the security architecture while maintaining robust access control.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If secure authentication and VPN access are implemented, then system security is improved, but the complexity of configuring and managing compute modules increases

Engineering Contradiction:
Improvesystem securityVSAvoidconfiguration and management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The embedded edge compute module is designed to self-configure and self-manage secure connections. It automatically handles authentication protocols, VPN establishment, and communication session management without requiring manual configuration or intervention, thereby maintaining high security while reducing operational complexity.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The authentication and security management functions are merged into the embedded edge compute module itself, rather than being separate external systems. This integration allows the module to autonomously handle security protocols and access control, simplifying the overall system architecture while maintaining robust security.

Inventive Principle:
Principle #5Merging (Combining)

3Adaptability or versatility

If dynamic definition of communication parameters is enabled, then adaptability is improved, but programming complexity of compute modules increases

Engineering Contradiction:
Improvecommunication parameter flexibilityVSAvoidprogramming complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The embedded edge compute module implements dynamic configuration capabilities that allow communication parameters to be adjusted in real-time based on operational requirements. The module can adapt its communication protocols, data formats, and transmission parameters without requiring reprogramming, thereby providing flexibility while maintaining simplicity through automated parameter management.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS20250036786A1Providing secure gateway to backplane-connected devices via an edge compute module
Publication Date: 2025.01.30 ROCKWELL AUTOMATION TECH INC
  • US20250036786A1 patent drawing
  • US20250036786A1 patent drawing
  • US20250036786A1 patent drawing

AI summary

A method may include receiving, via a computing system, a request to access an industrial device within an industrial system. The computing system may be communicatively coupled to the industrial device via a data backplane, and the request may be received from a remote device separate from the data backplane. The method may also include determining whether the remote device is authenticated for accessing the computing system, establishing a secure communication session with the remote device in response to the remote device being authenticated, and routing data from the remote device to the industrial device via the data backplane.