Industrial Edge Gateway for Automated Secure Data Sharing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing solutions for data access management between private industrial automation networks and external applications are cumbersome, requiring manual administration of access rules and authorizations due to differing data protection guidelines, and lack automation in negotiating data access levels.

Innovation Solution

A method and arrangement where a gateway component processes raw data from an industrial automation arrangement, receiving a work order with user identity, role, and abstraction/anonymization algorithms, automatically checking and implementing data access while adhering to rules, allowing dynamic negotiation of data processing levels and remuneration.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual administration of access rules and authorizations is used for data access between private industrial automation networks and external applications, then data protection compliance is achieved, but administrative effort and complexity increase

Engineering Contradiction:
Improvedata protection complianceVSAvoidadministrative complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system enables automated self-service data access management where external applications can autonomously request, negotiate, and receive data access rights based on predefined policies and algorithms, eliminating the need for manual administrative intervention while maintaining compliance

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

Access control policies, authorization rules, and data protection criteria are pre-configured and stored in the system before actual data access requests occur. This preliminary setup enables automated decision-making and execution without requiring manual administration during runtime operations

Inventive Principle:
Principle #10Preliminary action

2Reliability

If manual administration of access rules is used for different data protection guidelines, then data security is maintained, but time consumption and efficiency decrease

Engineering Contradiction:
Improvedata securityVSAvoidadministrative time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system implements automated feedback loops where data access requests are automatically evaluated against predefined policies, algorithms determine appropriate access levels, and the system responds by granting or denying access without human intervention, dramatically reducing administrative time while maintaining security

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system dynamically adjusts data access parameters such as authorization levels, data formats, and transmission frequencies based on predefined algorithms and policies, enabling automated adaptation to different data protection requirements without manual reconfiguration

Inventive Principle:
Principle #35Parameter changes

3Adaptability or versatility

If complete transfer of information from automation level to external parties is implemented, then data availability for external applications is improved, but data protection and confidentiality are compromised

Engineering Contradiction:
Improvedata availabilityVSAvoiddata protection
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system applies different data processing and protection measures to different data elements based on their sensitivity and the specific external application's needs. Each data access request receives a customized authorization level and data format that is locally optimized for that specific use case, enabling selective data sharing that protects confidential information while providing necessary access

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system introduces an automated intermediary layer that sits between the private automation network and external applications. This intermediary uses predefined algorithms to evaluate access requests, transform data into appropriate formats, and enforce data protection policies, enabling secure data sharing without direct access to sensitive information

Inventive Principle:
Principle #24Intermediary (Mediator)

4Productivity

If direct access from external entities to private automation network devices is permitted, then data access efficiency is improved, but security risks and network vulnerability increase

Engineering Contradiction:
Improvedata access efficiencyVSAvoidsecurity risks
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The system introduces an automated gateway component that acts as an intermediary between external applications and the private automation network. This gateway automatically evaluates access requests against predefined policies, authorizes legitimate requests, and blocks potentially harmful access attempts, enabling efficient data access while maintaining network security without requiring direct connections

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP3966723B1Method and arrangement for providing data from an industrial automation arrangement to an external arrangement
Publication Date: 2024.01.03 SIEMENS AG
  • EP3966723B1 patent drawingFigure 1
  • EP3966723B1 patent drawingFigure 2

AI summary

The invention relates to a method and an arrangement for providing data from a data source, in particular from an industrial automation arrangement (AA), to an external application (AW), the external application (AW) being arranged outside a first data network of the data source, in particular being operated in a data cloud, and raw data from the data source being processed by a gateway component (GK), in particular an industrial edge device, and the processed data being provided to the external application (AW). First, a work order is transmitted from the external application to the gateway component, the work order comprising at least information about an identity and/or role of the user of the external application, about the raw data to be processed from the data source, an algorithm for processing, abstracting and/or anonymising the raw data, and information for the frequency of the data processing; then the work order is checked by the gateway component; then the raw data is collected and processed according to the work order; and then the processed, abstracted and/or anonymised data is provided to the external application or to a destination defined in the work order. An external user is thus allowed automatically monitored access and thus the use of the data without having to have access to the underlying raw data. The degree of data access is negotiated automatically between the components involved (data source, gateway component) and is implemented taking into account requirements and rules.