Dedicated Runtime Hardware for Secure Cloud Automation Execution
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Cloud computing in industrial automation poses security risks due to unreliable data security and difficulties in porting vendor-specific programs onto standard hardware, especially in sensitive applications like chemical and pharmaceutical production, where programs and data can be intercepted.
Innovation Solution
A secure execution method using dedicated computer hardware with a configured runtime environment for automation programs, connected via encrypted data connections to a cloud server, allowing monitoring and control of industrial automation arrangements without exposing the hardware to local access, and enabling secure execution of sensitive information like recipes and instructions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If automation programs are executed on cloud servers using virtualization technologies, then computing resources can be shared and accessed remotely, but data security and program confidentiality cannot be reliably guaranteed
Solution Approach 1:
The system segments the automation program execution environment by introducing a dedicated runtime environment that is isolated from the public cloud server infrastructure. This runtime environment is further segmented into protected memory spaces where programs and data are stored in an encrypted state, separating sensitive computational tasks from the general cloud computing resources.
Solution Approach 2:
The patent creates a composite execution environment that combines elements of both cloud computing and local execution. The system uses a hybrid architecture where the automation program runs in a dedicated runtime environment that is physically located in the cloud but logically isolated and protected like local hardware, combining the accessibility of cloud computing with the security of dedicated execution environments.
2Adaptability or versatility
If vendor-specific automation programs are ported onto standard cloud hardware, then cloud computing resources can be utilized, but the programs require emulation of dedicated hardware which introduces security vulnerabilities
Solution Approach 1:
Instead of emulating dedicated hardware through software layers that are vulnerable to interception, the patent creates a physical copy of the dedicated runtime environment within the cloud infrastructure. This dedicated hardware instance is provisioned specifically for executing the vendor-specific automation program, eliminating the need for emulation while maintaining hardware compatibility.
Solution Approach 2:
The patent applies local quality by providing a customized, dedicated runtime environment that is tailored specifically for the automation program's requirements. This dedicated environment has specialized security properties and hardware characteristics matched to the specific application, rather than using a generic emulated environment that must accommodate multiple different programs.
3Reliability
If dedicated computer hardware is used for automation program execution in the cloud, then security against interception is improved, but the device complexity and infrastructure requirements increase
Solution Approach 1:
The dedicated runtime environment is designed with multi-functionality to handle multiple automation programs and support various vendor-specific requirements. This universal dedicated infrastructure can be configured to run different types of automation programs while maintaining the same security properties, reducing the need for separate dedicated hardware for each application.
Solution Approach 2:
The patent introduces a cloud service provider as an intermediary that manages the dedicated runtime environments. This intermediary handles the complexity of provisioning, configuring, and securing the dedicated hardware infrastructure, shielding the end user from the underlying device complexity while maintaining high security standards.
Data Source
AI summary
Arrangement and method for securely executing an automation program in a cloud computing environment, wherein the automation program is installed on computer hardware in a public IT infrastructure, and wherein the computer hardware is connected via a data connection to a cloud server, where the connection and a dedicated runtime environment of the computer hardware are configured such that the automation program is transferrable onto the computer hardware and its execution can be monitored via the server and data connection, such that the automation program and sensitive information, i.e., recipes, instructions and/or method steps, contained therein can be executed in a protected environment, effective protection against interception is achieved and such that the dedicated hardware can be matched to a possibly pre-existing automation program so that existing automation programs can execute in the cloud or be made available without modification and further system tests, certifications and other costly adaptation steps.

