Field Bus Aggregator for Centralized Multi-Segment Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing field bus systems with multiple network segments require separate access authorizations and configurations for host computers, leading to increased administrative effort and complexity, especially in large automation networks.

Innovation Solution

An aggregator apparatus that forms data connections to field access devices across multiple network segments, allowing centralized access and routing of data traffic between host computers and field bus components, reducing the need for individual registrations and configurations on each segment.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If separate access authorizations are configured for each network segment, then system reliability is improved, but administrative effort and device complexity increase

Engineering Contradiction:
Improvesystem reliabilityVSAvoidaccess configuration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an aggregator device as an intermediary between host computers and multiple network segments. The aggregator centralizes access authorization management, eliminating the need to configure firewalls and access rights on each individual network segment. This mediator handles all access requests centrally while maintaining the segmented network structure, thus preserving reliability while reducing administrative complexity

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent merges multiple distributed access control functions into a single centralized authorization management system at the aggregator. Instead of managing separate access configurations across multiple network segments, all access authorizations are combined and managed centrally, significantly reducing the administrative effort and complexity associated with configuring and maintaining access rights across segmented networks

Inventive Principle:
Principle #5Merging (Combining)

2Object-affected harmful factors

If separate firewall configurations are made on each field access device, then security is improved, but transparency and ease of management deteriorate

Engineering Contradiction:
Improvesecurity protectionVSAvoidfirewall management ease
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The patent combines multiple distributed firewall configurations into a single centralized firewall at the aggregator device. This unified firewall provides security protection for all network segments while enabling transparent and simplified management. Administrators can configure and monitor security policies in one location rather than accessing and configuring each field access device individually, significantly improving ease of operation while maintaining comprehensive security

Inventive Principle:
Principle #5Merging (Combining)

3Manufacturing precision

If host computers are registered on each field access device individually, then access control precision is improved, but time consumption and productivity decrease

Engineering Contradiction:
Improveaccess control precisionVSAvoidregistration efficiency
Core Design Contradiction:
Manufacturing precisionVSProductivity

Solution Approach 1:

The aggregator acts as an intermediary that handles host computer registration centrally. Instead of registering each host computer on every field access device individually, the registration process is performed once at the aggregator, which then manages access permissions across all network segments. This maintains precise access control while dramatically improving registration efficiency by eliminating redundant registration operations

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary centralized registration of host computers at the aggregator before access to specific network segments is required. This preliminary action establishes access permissions in advance at a central location, eliminating the need for repeated registration operations at each field access device and significantly improving productivity while maintaining access control precision

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11848796B2Aggregator apparatus for standardized access to a plurality of network segments of a field bus system
Publication Date: 2023.12.19 ENDRESS HAUSER PROCESS SOLUTIONS AG
  • US11848796B2 patent drawing
  • US11848796B2 patent drawing
  • US11848796B2 patent drawing

AI summary

An aggregator is designed to form first data connections to field access devices. The field access devices are connected to different network segments of a field bus system. The aggregator forms a second data connection to a host computer. The aggregator receive first data traffic from the host computer via the second data connections and to forward the first data traffic, via the first data connections to a field access device of that network segment in which the particular field bus component, to which the first data traffic is directed, is situated. The aggregator is also designed to receive second data traffic from a field bus component in one of the network segments via at least one of the first data connections and to forward the second data traffic to at least one of the host computers via at least one of the second data connections.