Wind Turbine Controller Access Groups for Adaptive User Rights
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing access management systems for wind turbines are complex and inefficient, particularly when it comes to adjusting user rights in response to changes in operating hardware or software, and they lack effective mechanisms to manage access based on user location and priority.
Innovation Solution
A simplified access management method that allows user rights to be easily adjusted by assigning users to access groups, which are then allocated to authorization groups controlling input and output value storage locations in the wind turbine's operating software. This method also incorporates localization identifiers to manage access based on user location and priority, ensuring secure and efficient access control.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If user rights are managed locally in the wind turbine access manager, then access control is maintained, but adjusting user rights becomes very complicated when operating hardware or software changes
Solution Approach 1:
The patent introduces a server as an intermediary between the wind turbine and users. The server stores access groups and authorization groups centrally, acting as a mediator that manages user rights remotely. When hardware or software changes occur, the wind turbine controller communicates with the server to update access rights without requiring local reconfiguration, thus reducing complexity while maintaining adaptability.
Solution Approach 2:
The patent segments access management into distinct hierarchical levels: users are assigned to access groups, which are further divided into authorization groups, each with specific rights for different wind turbine components. This segmentation allows granular control and enables independent modification of specific access rights without affecting the entire system, simplifying adjustments when hardware or software changes.
2Ease of operation
If centralized access manager is used for multiple wind turbines, then external organization is achieved, but individual wind turbine requirements cannot be satisfied due to frequent hardware and software adjustments
Solution Approach 1:
The patent implements a dynamic access management system where access rights are not statically configured but can be dynamically updated. The wind turbine controller maintains communication with the external server, allowing access groups and authorization groups to be modified in real-time based on individual wind turbine requirements. This dynamic approach enables centralized management while accommodating frequent hardware and software adjustments at the individual turbine level.
Solution Approach 2:
The patent uses parameter changes to adapt access rights to individual wind turbine requirements. The system stores and retrieves different sets of access parameters (access groups and authorization groups) based on the specific wind turbine identifier. When hardware or software parameters change at an individual turbine, the corresponding access parameters can be updated by communicating with the external server, maintaining both centralized organization and individual adaptability.
3Adaptability or versatility
If multiple users are granted different access rights, then specific user needs are met, but managing rights for multiple users becomes complicated when framework conditions change
Solution Approach 1:
The patent merges multiple users with similar access requirements into common access groups. Instead of managing individual user rights separately, users are consolidated into groups that share the same authorization profile. When framework conditions change, rights are updated at the group level, automatically applying to all members simultaneously. This merging approach maintains user-specific needs while dramatically reducing the time required to adjust rights across multiple users.
Data Source
AI summary
A method for the access management of a wind turbine controller of a wind turbine with an operating software. The method comprises receiving a user identification with one of several user interfaces and assigning the user identification or a portion of the user identification to an access group. One or several authorization groups of an overall number of authorization groups is allocated to the access group, and one or several output value storage locations and/or input value storage locations are allocated to each authorization group. The method further encompasses allowing an access from the user interface to all output value storage locations and/or input value storage locations that are allocated to the assigned access group via the authorization groups. The disclosure further relates to a computer product, a wind turbine controller, and a wind turbine with a wind turbine controller.

