Virtualized Machine Line Control With IPC DMZ and Load Sharing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing machine line networks in food and beverage technology face challenges with increased complexity, cost, and security vulnerabilities due to dedicated network switches and hardware routers, leading to high management complexity, scalability issues, and cyber threats.

Innovation Solution

Implementing a software-defined edge apparatus on industrial PCs (IPC) with a hypervisor to create modular, scalable, and secure machine line networks, utilizing a virtual operating platform to distribute workloads and integrate a demilitarized zone (DMZ) for enhanced security and flexibility.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If dedicated network switches and hardware routers are deployed for each production line, then network communication reliability is improved, but device complexity and management complexity increase significantly

Engineering Contradiction:
Improvenetwork communication reliabilityVSAvoidnetwork infrastructure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges network switching, routing, and security functions into a single integrated network gateway device. This consolidation eliminates the need for separate switches and routers on each production line, reducing device complexity while maintaining network communication reliability through the gateway's centralized management capabilities.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The network gateway is designed as a universal device that performs multiple functions including switching, routing, security management, and centralized control for the entire machine line network. This multi-functionality replaces multiple specialized devices, simplifying the network infrastructure while ensuring reliable communication across all production lines.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If separate network infrastructure is provided for each production line, then network security is improved, but hardware costs and maintenance costs increase

Engineering Contradiction:
Improvenetwork securityVSAvoidhardware resources
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

Security functions such as firewall protection, access control, and encryption are merged into the centralized network gateway, eliminating the need for separate security hardware on each production line. This consolidation reduces hardware resources while maintaining comprehensive network security through centralized management and monitoring.

Inventive Principle:
Principle #5Merging (Combining)

3Productivity

If traditional network configuration is used without intermediate layers, then system performance is improved, but flexibility and scalability are reduced

Engineering Contradiction:
Improvesystem performanceVSAvoidsystem flexibility and scalability
Core Design Contradiction:
ProductivityVSAdaptability or versatility

Solution Approach 1:

The network gateway acts as an intermediary device between the production line devices and the enterprise network. It provides virtualization capabilities and software-defined networking that enhance flexibility and scalability without compromising system performance, allowing dynamic configuration and easy adaptation to changing production requirements.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Ease of operation

If centralized network cabinet is deployed for multiple machines, then network management is improved, but initial investment costs exceed 10,000 euros

Engineering Contradiction:
Improvenetwork managementVSAvoidinitial investment
Core Design Contradiction:
Ease of operationVSQuantity of substance

Solution Approach 1:

The patent extracts the network management functions from the expensive centralized network cabinet and implements them in a virtualized environment on standard hardware. This extraction eliminates the need for specialized expensive equipment while maintaining centralized management capabilities, significantly reducing initial investment costs.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

Instead of deploying expensive physical network management infrastructure, the patent uses virtualization to create software-based copies of network management functions. This approach replicates the functionality of expensive hardware solutions using affordable software and standard hardware, reducing initial investment while maintaining ease of network management.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS20250298405A1Modular and dynamic control of machines in a network
Publication Date: 2025.09.25 KRONES AG
  • US20250298405A1 patent drawing
  • US20250298405A1 patent drawing
  • US20250298405A1 patent drawing

AI summary

The disclosure relates to a machine line and to a machine in the machine line, in particular in a machine line for filling and packaging food and/or beverages. The machine comprises an industrial PC that implements a software-defined edge apparatus for the machine and comprises a hypervisor. The hypervisor provides a virtual operating platform for hosting and/or operating corresponding services for the machine line operation. According to embodiments, the IPC or hypervisor implements a demilitarized zone with its own network segments in which the virtual operating platform is implemented. Furthermore, the IPC can establish a connection to a machine line network that connects a plurality of machines to one another, each of which comprises an IPC. The IPC is further configured to distribute workloads among the machine and at least one second machine in the machine line network.