Graph-Based Industrial Plant Data Access Control by Scope and Role

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems struggle to efficiently manage access control to complex data in industrial plants, which are characterized by numerous processing elements and sensors, leading to challenges in high-level control, safety supervision, and maintenance scheduling.

Innovation Solution

A graph database plant model is employed to map industrial plant elements, define scopes, and associate authorization providers to grant access rights based on roles, using a role-based access control mechanism to determine data access permissions through a graph structure.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a traditional access control system is used to manage data in industrial plants, then the system structure is simple, but the system cannot efficiently handle the complex data relationships and access permissions required for modern industrial plants with numerous processing elements and sensors

Engineering Contradiction:
Improvedata access control capabilityVSAvoidaccess control system structure
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the industrial plant data model into a graph structure where data elements (sensors, processing elements, controllers) are represented as nodes and their relationships as edges. This segmentation allows complex data relationships to be systematically organized and accessed through defined scopes and paths, resolving the contradiction by making the complex system manageable through structured division.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a hierarchical scope dimension to the traditional flat access control model. By defining multiple scopes (plant scope, area scope, device scope) and allowing navigation through these dimensional layers, the system can handle complex data relationships without proportionally increasing structural complexity. This dimensional approach enables versatile data access control while maintaining system organization.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Productivity

If comprehensive data access is allowed for high-level control and safety supervision, then the data utility is improved, but the data security and access control become difficult to manage

Engineering Contradiction:
Improvedata access efficiencyVSAvoiddata security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent implements preliminary action by pre-defining scopes and access permissions in the graph database structure before data access operations. Roles and their associated permissions are established in advance, allowing the system to efficiently grant or deny access based on pre-configured rules rather than making security decisions in real-time, thus maintaining both security and efficiency.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces scopes as intermediary layers between the data storage structure and the access control mechanism. These scopes act as mediators that organize data elements and define access boundaries, allowing the system to provide comprehensive data access where needed while maintaining security through structured permission management at each scope level.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Measurement precision

If a detailed graph database plant model is created to represent all plant elements and relationships, then the data organization and access control precision are improved, but the system complexity and implementation difficulty increase

Engineering Contradiction:
Improvedata access control precisionVSAvoidsystem implementation ease
Core Design Contradiction:
Measurement precisionVSEase of manufacture

Solution Approach 1:

The patent applies universality by designing a graph database plant model that serves multiple functions simultaneously: it represents the physical plant structure, organizes data elements, defines access scopes, and enables query operations. This multi-functional approach allows detailed data organization without proportionally increasing implementation difficulty, as the same structure supports multiple operational requirements.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent utilizes parameter changes by allowing the graph database model to be configured with different levels of detail based on specific plant requirements. The scope hierarchy and node properties can be adjusted to match the complexity of the actual plant, enabling detailed precision where needed while simplifying the model where appropriate, thus balancing precision with implementation ease.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS20260003346A1Method and system for controlling access to data in an industrial plant or in a database associated to the industrial plant
Publication Date: 2026.01.01 BASF SE
  • US20260003346A1 patent drawing
  • US20260003346A1 patent drawing
  • US20260003346A1 patent drawing

AI summary

A method for controlling access to data an industrial plant is provided. Elements (11-18) of the industrial plant are mapped to elements of a graph structure. Scopes (S10-S30) are defined, which are associated to elements (11-18) in the graph structure. At least one authorization provider (31-33) is associated to one scope (S10-S30) and provides an authorization. Each scope comprises a signal provider. Each scope is associated to a minimum role requirement. A request from a requesting entity for data from at least one target entity is received. It is determined to which scope (S10-S30) the entity is related to. Authorization is provided by the authorization provider (31-33) associated to the scope (S10-S20). The authorization is performed based on the role associated to the entity and the target scope to which the requested data is related to.