Industrial Edge Gateway for Automated Compliant Data Sharing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for controlling data access between private automation networks and external applications are labor-intensive and lack automation, especially when multiple data protection guidelines need to be observed, leading to complex administration efforts.

Innovation Solution

A method and arrangement where a gateway component, such as an industrial Edge device, processes raw data from a data source and makes abstracted or anonymized data available to external applications, with automated negotiation of data access levels and fee structures, using work orders that include identity, role, and data processing details, and are checked against policies and certificates for compliance.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual administration of data access permissions and restrictions is used, then data protection compliance is achieved, but administrative effort and complexity increase significantly

Engineering Contradiction:
Improvedata protection complianceVSAvoidadministration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system enables automated self-service data access management where external applications can autonomously request, negotiate, and receive data access permissions based on predefined policies and work orders, eliminating the need for manual administrative intervention while ensuring compliance with data protection requirements

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

Data access permissions, restrictions, and processing parameters are pre-configured in work orders and policies before external applications need access. This preliminary setup includes defining data protection rules, access levels, and compensation terms in advance, allowing automated enforcement without manual administration during actual data access operations

Inventive Principle:
Principle #10Preliminary action

2Adaptability or versatility

If raw data are made available to external applications, then business model flexibility increases, but data security and confidentiality risks increase

Engineering Contradiction:
Improvebusiness model flexibilityVSAvoiddata security risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system transforms raw data into processed data by changing parameters such as aggregation levels, anonymization degrees, and transformation algorithms defined in work orders. This allows external applications to receive data in various processed forms suitable for different business models while maintaining security and confidentiality of the original raw data

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The data originator acts as an intermediary between the data source and external applications, controlling and mediating all data access operations. The intermediary enforces work orders and policies to ensure data security while enabling flexible business models through controlled data provision

Inventive Principle:
Principle #24Intermediary (Mediator)

3Manufacturing precision

If multiple data protection guidelines are observed, then compliance accuracy improves, but administrative burden increases

Engineering Contradiction:
Improvecompliance accuracyVSAvoidadministrative time
Core Design Contradiction:
Manufacturing precisionVSLoss of time

Solution Approach 1:

Multiple data protection guidelines and requirements are merged into unified work orders and policies that can be automatically enforced. The system consolidates various compliance requirements into a single automated framework that handles multiple guidelines simultaneously, improving compliance accuracy while reducing the time and effort needed for separate administrative management of each guideline

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS12039081B2Method and arrangement for providing data from an industrial automation arrangement to an external arrangement
Publication Date: 2024.07.16 SIEMENS AG
  • US12039081B2 patent drawing
  • US12039081B2 patent drawing

AI summary

A method and arrangement for providing data from an industrial automation arrangement to an external application operated in a data cloud and arranged outside a first data network, where an industrial Edge device processes raw data from the data source and makes the processed data available to the external application, the external application transmits a work order to the gateway component, the work order is checked by the gateway component, the raw data are captured and processed according to the work order, and the processed, abstracted and/or anonymized data are provided to the external application or a destination defined in the work order, such that an external user can automatically control access and hence use the data without accessing the underlying raw data because the level of data access is automatically negotiated and produced between the components involved (data source, gateway component) while taking into account requirements and rules.