Virtualized Machine-Line Control With IPC DMZ and Workload Sharing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current industrial manufacturing systems for beverage and food technology machinery face challenges such as increased complexity and cost in network management, lack of scalability and flexibility, and security vulnerabilities due to dedicated network switches and hardware routers, leading to high administrative burdens and cyber threats.

Innovation Solution

Implementing a software-defined edge device on an industrial PC (IPC) with a hypervisor to create a modular, scalable, and secure network architecture, utilizing a hypervisor for virtualization and a demilitarized zone (DMZ) to manage network components and ensure flexibility, security, and fault tolerance.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Speed

If dedicated network switches and hardware routers are used for each production line, then data transmission efficiency within lines is improved, but network management complexity and hardware costs increase significantly

Engineering Contradiction:
Improvedata transmission efficiencyVSAvoidnetwork management complexity
Core Design Contradiction:
SpeedVSDevice complexity

Solution Approach 1:

The patent merges multiple dedicated network switches and hardware routers into a single virtual network infrastructure. Virtual network functions (VNFs) are deployed on commercial off-the-shelf (COTS) servers, consolidating network switching, routing, and firewall capabilities into software rather than requiring separate hardware devices for each production line.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The virtual network infrastructure provides multi-functional capabilities through software-defined networking (SDN). A single physical network platform can dynamically allocate network resources and perform multiple network functions (switching, routing, security) for different production lines simultaneously, eliminating the need for line-specific dedicated hardware.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Ease of operation

If dedicated network switches are deployed for each production line, then communication within individual lines is facilitated, but scalability and modularity of the network system are reduced

Engineering Contradiction:
Improvecommunication facilitationVSAvoidnetwork scalability
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The network infrastructure becomes dynamic through virtualization. Network resources can be dynamically allocated, created, or removed based on production requirements without physical hardware changes. Virtual network functions can be migrated between physical hosts and scaled up or down by allocating more or fewer virtual instances on the COTS servers.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The network is segmented into virtual network functions that can be independently managed and deployed. Each production line gets its own virtual network segment through software configuration rather than physical separation, allowing logical segmentation while maintaining physical consolidation for scalability.

Inventive Principle:
Principle #1Segmentation

3Power

If bare-to-metal installations are used for network switches, then system performance is improved, but flexibility and scalability of the network system are limited

Engineering Contradiction:
Improvesystem performanceVSAvoidsystem flexibility
Core Design Contradiction:
PowerVSAdaptability or versatility

Solution Approach 1:

The patent introduces a virtualization layer (hypervisor) as an intermediary between the physical COTS server hardware and the network virtual functions. This allows the system to maintain high performance through direct hardware access while simultaneously providing flexibility through virtualized network functions that can be dynamically configured and managed without physical hardware changes.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Device complexity

If basic network configurations without firewalls are implemented, then system simplicity is maintained, but security vulnerabilities and compliance risks increase

Engineering Contradiction:
Improvesystem simplicityVSAvoidnetwork security
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The virtual network infrastructure provides security services automatically through software-based firewalls and security policies that are part of the virtualized network functions. Security is embedded in the virtualization layer itself, providing protection without requiring complex manual configuration or additional hardware security devices.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP4622178A1Modular and dynamic control of machines in a network
Publication Date: 2025.09.24 KRONES AG
  • EP4622178A1 patent drawingFigure 1
  • EP4622178A1 patent drawingFigure 2
  • EP4622178A1 patent drawingFigure 3

AI summary

The invention relates to a machine line and a machine in the machine line, in particular in a machine line for filling and packaging food and/or beverages. The machine comprises an industrial PC (IPC) that implements a software-defined edge device for the machine and comprises a hypervisor. The hypervisor provides a virtual operating platform for hosting and/or operating corresponding services for operating the machine line. According to embodiments, the IPC or hypervisor implements a demilitarized zone (DMZ) with its own network segments in which the virtual operating platform is implemented. Furthermore, the IPC can establish a connection to a network of the machine line that interconnects a plurality of machines, each of which comprises an IPC.The IPC is further designed to distribute workloads among the machine and at least one other machine in the machine line network.