Virtualized Gateway for Secure Machine Remote Maintenance

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Modern machine tool and laser manufacturers face challenges in providing secure, reliable, and efficient remote maintenance due to compatibility issues with different VPN client software, hardware variants, and the need for standardized security measures, which can lead to increased infrastructure demands and vulnerability to attacks.

Innovation Solution

The implementation of a control computer system with virtual machines allows for the operation of multiple operating systems and applications in isolated environments, enabling secure and flexible remote communication through a central protected computer with a firewall, reducing compatibility problems and enhancing security by using virtualized hardware and VPN connections.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Speed

If remote maintenance connections are established through direct dialing-in via analog modem or ISDN, then compatibility with different connection types is achieved, but bandwidth and transmission speed are limited

Engineering Contradiction:
Improvetransmission speedVSAvoidcompatibility with different connection types
Core Design Contradiction:
SpeedVSAdaptability or versatility

Solution Approach 1:

A gateway computer is introduced as an intermediary between the service computer and the machine control. The gateway runs multiple VPN client software instances simultaneously, each compatible with different VPN protocols and authentication methods. This mediator handles the complexity of multiple connection types, allowing high-speed Internet-based connections while maintaining broad compatibility with various customer infrastructure configurations.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The gateway computer is designed to perform multiple functions: it acts as a VPN client to different machines, runs multiple operating systems with different VPN software, stores authentication data for various connection types, and manages multiple simultaneous connections. This multi-functional design allows a single system to replace multiple specialized connection devices.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If multiple VPN client software are used for different connection types, then adaptability to various networks is improved, but device complexity and infrastructure demands increase

Engineering Contradiction:
Improvesupport for different VPN standardsVSAvoidinfrastructure complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

Multiple VPN client software instances, different operating systems, and various authentication mechanisms are merged into a single gateway computer. Instead of requiring separate hardware devices or service computers for each connection type, the gateway consolidates all these functions into one system, reducing overall infrastructure complexity while maintaining support for diverse connection standards.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

Virtual machine technology is used to create copies of operating systems and VPN client software environments within the gateway. Each virtual machine can run independently with its own VPN client configuration, allowing multiple VPN protocols and authentication methods to coexist without conflict. This virtualization approach simplifies management compared to maintaining separate physical systems.

Inventive Principle:
Principle #26Copying

3Ease of operation

If centralized authentication data storage is implemented, then ease of access and management is improved, but vulnerability to attacks and security risks increase

Engineering Contradiction:
Improveaccess managementVSAvoidsecurity vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

Authentication data and machine control functions are segmented into separate virtual machines within the gateway. The authentication data is stored in a dedicated secure virtual environment with restricted access, while the machine control communication occurs in a separate virtualized environment. This segmentation limits the impact of potential security breaches to specific virtual machines rather than exposing the entire system.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The gateway creates a protected, isolated environment for storing and processing authentication data using virtualization technology. This inert environment separates sensitive authentication information from the external network and machine control operations, providing security through isolation while maintaining ease of access through centralized management.

Inventive Principle:
Principle #39Inert atmosphere (Inert environment)

Data Source

PatentUS8683004B2Apparatus for controlling a machine
Publication Date: 2014.03.25 TRUMPF WERKZEUGMASCHINEN GMBH & CO KG
  • US8683004B2 patent drawing
  • US8683004B2 patent drawing
  • US8683004B2 patent drawing

AI summary

An apparatus for controlling a machine includes a machine-sided control computer. The machine-sided control computer includes computer readable media on which a virtual computer is stored, and the virtual computer includes one or more computer programs selected from the group consisting of a machine operating computer program, a communication network connection computer program, and a communication network encryption computer program.