Industrial Edge Data Filtering for Secure External Plant Data Sharing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

There is a conflict of interest between industrial plant operators and external data processing system providers regarding the sharing of sensitive production data, as operators are reluctant to expose confidential information while providers need access for billing and optimization purposes, necessitating a secure communication scheme in an untrusted industrial setting.

Innovation Solution

A method involving industrial edge devices generating data packets from industrial machines, signing them with a digital signature, and using a user-defined data filter to determine which packets to transmit, with the option for additional double-signing for enhanced authenticity and integrity, ensuring only non-sensitive data is shared with the external system.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If data is transferred from internal data processing system to external data processing system, then external entities can access production data for billing and optimization purposes, but sensitive and confidential information may be exposed

Engineering Contradiction:
Improvedata accessibilityVSAvoiddata security risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

An edge device acts as an intermediary between the internal data processing system and external entities. The edge device collects data from industrial machines, processes it locally, and selectively transfers only non-sensitive processed data to external systems, thereby enabling data accessibility while protecting sensitive information from exposure

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The edge device extracts and removes sensitive information from raw data before transferring data to external systems. By filtering out confidential production methods and processes while retaining useful operational data, the system enables external access to necessary information while eliminating security risks associated with sensitive data exposure

Inventive Principle:
Principle #2Taking out (Extraction)

2Object-affected harmful factors

If data is isolated in private industrial plant networks, then sensitive production data security is maintained, but external entities cannot access data for billing and optimization

Engineering Contradiction:
Improvedata securityVSAvoiddata accessibility
Core Design Contradiction:
Object-affected harmful factorsVSLoss of information

Solution Approach 1:

The edge device serves as a mediator that enables controlled information flow from isolated internal networks to external systems. It processes data within the private network and selectively exports non-sensitive information, thereby maintaining data security while preventing loss of information needed for external billing and optimization functions

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The data transfer process is segmented into multiple stages: data collection from machines, local processing and filtering at the edge device, and selective external transmission. This segmentation allows sensitive data to remain isolated in the internal network while non-sensitive processed data is transmitted externally, balancing security with accessibility

Inventive Principle:
Principle #1Segmentation

3Reliability

If digital signature and filtering mechanisms are implemented, then data authenticity and integrity are ensured, but system complexity increases

Engineering Contradiction:
Improvedata authenticityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The edge device automatically performs digital signature generation and data filtering without requiring manual intervention. The system self-manages authentication and data protection functions, ensuring data authenticity and integrity while minimizing the operational complexity burden on users

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS20230022849A1Methods and systems for providing data from an internal data processing system of an industrial plant to an external data processing system
Publication Date: 2023.01.26 SIEMENS AG
  • US20230022849A1 patent drawing
  • US20230022849A1 patent drawing
  • US20230022849A1 patent drawing

AI summary

Data are sent from an internal data processing system of an industrial plant to an external data processing system of the industrial plant by generating with an industrial edge device data packets from data related to an industrial machine, and generating therefrom signed data packets signed with a first digital signature. While the signed data packet are read, a user-defined data filter is applied, which lets either pass or rejects the signed data packets. The data packets that passed the user-defined data filter are then sent to the external data processing system.