Reverse Proxy Virtual Networks for Time-Critical Services
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Industrial automation systems face challenges with interruptions in communication connections leading to unnecessary retransmissions and potential failure to maintain a safe operating state, especially when network resources are concurrently used for real-time and non-real-time data transmission.
Innovation Solution
A method and system that utilize a scheduling environment with dedicated virtual communication networks for each server component, enabling secure decoupling of services and automated network isolation through a reverse proxy, without requiring high resource administration.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If network resources are shared between real-time and non-real-time data transmission, then resource utilization is improved, but transmission reliability and quality of service for real-time data deteriorate
Solution Approach 1:
The network is segmented into separate virtual communication networks: a first virtual communication network for time-critical services and a second virtual communication network for non-real-time services. This segmentation isolates real-time traffic from non-real-time traffic, ensuring that real-time data transmission maintains high reliability and quality of service while non-real-time services utilize available network resources without interfering with critical operations.
2Ease of operation
If virtualized control applications are integrated into existing infrastructure, then ease of operation is improved, but system complexity and administration requirements increase
Solution Approach 1:
A reverse proxy is introduced as an intermediary component that automatically integrates virtualized control applications with the existing infrastructure. The reverse proxy handles service access requests, forwards them to appropriate server components, and manages communication protocols. This intermediary approach simplifies integration for users while the automated configuration processes minimize administration requirements, resolving the contradiction between ease of operation and system complexity.
3Reliability
If secure separation between virtualized control applications is implemented, then reliability is improved, but device complexity increases
Solution Approach 1:
The network is segmented into isolated virtual communication networks for different server components, with each component having its dedicated network namespace. This segmentation provides secure separation between virtualized control applications, preventing critical repercussions from spreading across the system. The automated configuration processes manage this segmentation without requiring complex manual setup, thus achieving reliable isolation while minimizing the perceived complexity for users.
4Ease of operation
If automated integration with reverse proxy is implemented, then ease of operation is improved, but resource requirements increase
Solution Approach 1:
The system implements self-service automation where the reverse proxy and configuration processes automatically detect, configure, and integrate virtualized control applications without requiring extensive manual intervention or high resource consumption. The automated processes handle service registration, network configuration, and request forwarding autonomously, reducing both operational complexity and resource requirements compared to manual integration approaches.
Data Source
AI summary
The invention relates to a method for providing time-critical services by means of a flow control environment, in which each service is assigned a server component (113) that comprises at least one application instance and which is formed by a flow control component that can be loaded into the flow control environment (112) and executed there. An individual virtual communication network (114) is made available for each server component by means of the flow control environment. A reverse proxy (101) of a subnetwork (100), comprising the flow control environment, forwards service access requests (11) for use of the services outside of the subnetwork in accordance with predefined forwarding rules (121), to the respective server component via its virtual communication network. The virtual communication networks are used for all application instances of the respective server component for forwarding the service access requests.
