Reverse Proxy Virtual Networks for Time-Critical Services

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Industrial automation systems face challenges with interruptions in communication connections leading to unnecessary retransmissions and potential failure to maintain a safe operating state, especially when network resources are concurrently used for real-time and non-real-time data transmission.

Innovation Solution

A method and system that utilize a scheduling environment with dedicated virtual communication networks for each server component, enabling secure decoupling of services and automated network isolation through a reverse proxy, without requiring high resource administration.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If network resources are shared between real-time and non-real-time data transmission, then resource utilization is improved, but transmission reliability and quality of service for real-time data deteriorate

Engineering Contradiction:
Improveresource utilizationVSAvoidquality of service for real-time data
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The network is segmented into separate virtual communication networks: a first virtual communication network for time-critical services and a second virtual communication network for non-real-time services. This segmentation isolates real-time traffic from non-real-time traffic, ensuring that real-time data transmission maintains high reliability and quality of service while non-real-time services utilize available network resources without interfering with critical operations.

Inventive Principle:
Principle #1Segmentation

2Ease of operation

If virtualized control applications are integrated into existing infrastructure, then ease of operation is improved, but system complexity and administration requirements increase

Engineering Contradiction:
Improveintegration of virtualized control applicationsVSAvoidadministration requirements
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

A reverse proxy is introduced as an intermediary component that automatically integrates virtualized control applications with the existing infrastructure. The reverse proxy handles service access requests, forwards them to appropriate server components, and manages communication protocols. This intermediary approach simplifies integration for users while the automated configuration processes minimize administration requirements, resolving the contradiction between ease of operation and system complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If secure separation between virtualized control applications is implemented, then reliability is improved, but device complexity increases

Engineering Contradiction:
Improvesecure separation between applicationsVSAvoidnetwork configuration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The network is segmented into isolated virtual communication networks for different server components, with each component having its dedicated network namespace. This segmentation provides secure separation between virtualized control applications, preventing critical repercussions from spreading across the system. The automated configuration processes manage this segmentation without requiring complex manual setup, thus achieving reliable isolation while minimizing the perceived complexity for users.

Inventive Principle:
Principle #1Segmentation

4Ease of operation

If automated integration with reverse proxy is implemented, then ease of operation is improved, but resource requirements increase

Engineering Contradiction:
Improveautomatic integrationVSAvoidresource requirements
Core Design Contradiction:
Ease of operationVSUse of energy by moving object

Solution Approach 1:

The system implements self-service automation where the reverse proxy and configuration processes automatically detect, configure, and integrate virtualized control applications without requiring extensive manual intervention or high resource consumption. The automated processes handle service registration, network configuration, and request forwarding autonomously, reducing both operational complexity and resource requirements compared to manual integration approaches.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP4356596B1Method and system for providing time-critical services by means of a process control environment
Publication Date: 2025.05.28 SIEMENS AG
  • EP4356596B1 patent drawing

AI summary

The invention relates to a method for providing time-critical services by means of a flow control environment, in which each service is assigned a server component (113) that comprises at least one application instance and which is formed by a flow control component that can be loaded into the flow control environment (112) and executed there. An individual virtual communication network (114) is made available for each server component by means of the flow control environment. A reverse proxy (101) of a subnetwork (100), comprising the flow control environment, forwards service access requests (11) for use of the services outside of the subnetwork in accordance with predefined forwarding rules (121), to the respective server component via its virtual communication network. The virtual communication networks are used for all application instances of the respective server component for forwarding the service access requests.