Industrial automation secure remote access

US11863560B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-11863560-B2
Application numberUS-202117376909-A
CountryUS
Kind codeB2
Filing dateJul 15, 2021
Priority dateJul 15, 2021
Publication dateJan 2, 2024
Grant dateJan 2, 2024

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

An industrial information hub (IIH) and an industrial development hub (IDH) serve as an industrial ecosystem platform where multiple participants can deliver repeatable and standardized services relevant to their core competencies. The IIH system is centered around the development of an ecosystem that creates and delivers value to users—including industrial enterprises, OEMs, system integrators, vendors, etc.—through the aggregation of digital content and domain expertise. The IIH system serves as a trusted information broker between the ecosystem and the OT environments of plant facilities, and provides a platform for connecting assets, contextualizing asset data and providing secure access to the ecosystem. As part of this ecosystem, the IIH system uses a secure remote access architecture to allow users to remotely access data on their plant floor assets via a virtual private network connection.

First claim

Opening claim text (preview).

What is claimed is: 1. A system for providing secure remote access to industrial assets, comprising: a memory that stores executable components; and a processor, operatively coupled to the memory, that executes the executable components, the executable components comprising: a device interface component configured to communicatively connect, via a cloud platform, to gateway devices deployed at one or more industrial facilities, wherein the gateway devices are communicatively connected to industrial assets that operate at the one or more industrial facilities, and the gateway devices respectively execute secure remote access runtime services; a user interface component configured to serve, via the cloud platform, a front-end interface to a client device and to receive, via interaction with the front-end interface, request data comprising a user identity and credential information; an access management component configured to, in response to determining that the user identity and the credential information permit access to a subset of the industrial assets, establish a virtual private network connection between the client device and the subset of the industrial assets via a gateway device, of the gateway devices, that is communicatively connected to the subset of the industrial assets; and an analytics component configured to apply analytics to contextualized industrial data obtained from the subset of the industrial assets based on a virtualized plant that executes on the cloud platform and that comprises digital asset models of the subset of the industrial assets, wherein the contextualized data comprises industrial data and contextual metadata added to the industrial data by the gateway device, and the user interface component is configured to render, on the client device via the virtual private network connection, a unified presentation of the subset of the industrial assets based on the industrial data and to render results of the analytics via the unified presentation. 2. The system of claim 1 , wherein the access management component is configured to establish the virtual private network connection without opening an inbound port through a firewall at an industrial facility in which the gateway device resides. 3. The system of claim 1 , wherein the user interface component is further configured to render, on the client device, data stored on the subset of the industrial assets via the virtual private network connection. 4. The system of claim 3 , wherein the data is at least one of asset status data, asset operation data, asset performance data, asset diagnostic data, or production statistics. 5. The system of claim 1 , wherein the user interface is configured to, in response to the determining that the user identity and the credential information permits access to the subset of the industrial assets, render a list of the subset of the industrial assets for selection, and in response to selection of an industrial asset from the list, deliver a presentation of data retrieved from the industrial asset to the client device. 6. The system of claim 1 , wherein the user interface component is further configured to receive, from the client device, a remote control instruction directed to an industrial asset of the subset of the industrial assets, and the access management component is configured to send the remote control instruction to the industrial asset via the virtual private network connection. 7. The system of claim 1 , wherein the access management component is configured to execute one or more algorithms that determine an optimal connection path from the client device to the gateway device for establishment of the virtual private network connection. 8. The system of claim 1 , wherein the contextual metadata at least one of defines a correlation between two or more items of the industrial data, identifies machines from which the industrial data was generated, or applies a synchronized timestamp to the industrial data. 9. The system of claim 1 , wherein the digital asset models define visual representations and functional specification data for their corresponding industrial assets. 10. A method, comprising: communicatively connecting, via a cloud platform by a system comprising a processor, to gateway devices installed at one or more industrial facilities, wherein the gateway devices are communicatively connected to industrial assets that operate at the one or more industrial facilities, and the gateway devices respectively execute secure remote access runtime services; serving, by the system via the cloud platform, a front-end interface to a client device; receiving, by the system via interaction with the front-end interface, request data comprising a user identity and credential information; in response to determining that the user identity and the credential information permit access to a subset of the industrial assets, establishing, by the system, a virtual private network connection between the client device and the subset of the industrial assets via a gateway device, of the gateway devices, that is communicatively connected to the subset of the industrial assets; applying, by the system, analytics to contextualized industrial data received from the subset of the industrial assets based on a virtualized plant that executes on the cloud platform and that comprises digital asset models of the subset of the industrial assets, wherein the contextualized data comprises industrial data and contextual metadata added to the industrial data by the gateway device, and rendering, by the system on the client device via the virtual private network connection, results of the analytics via a unified presentation of the subset of the industrial assets generated based on the industrial data. 11. The method of claim 10 , wherein the establishing comprises establishing the virtual private network connection without opening an inbound port through a firewall at an industrial facility in which the gateway device resides. 12. The method of claim 10 , further comprising rendering, on the client device, data stored on the subset of the industrial assets via the virtual private network connection. 13. The method of claim 12 , wherein the rendering of the data comprises rendering at least one of asset status data, asset operation data, asset performance data, asset diagnostic data, or production statistics. 14. The method of claim 10 , further comprising: in response to the determining that the user identity and the credential information permits access to the subset of the industrial assets, rendering, on the client device by the system, a list of the subset of the industrial assets for selection, and in response receiving, from the client device, an indication of a selection of an industrial asset from the list, delivering, by the system, a presentation of data retrieved from the industrial asset to the client device. 15. The method of claim 10 , further comprising: receiving, by the system from the client device, a remote control instruction directed to an industrial asset of the subset of the industrial assets; and sending, by the system, the remote control instruction to the industrial asset via the virtual private network connection. 16. The method of claim 10 , wherein the establishing comprises executing one or more algorithms that determine an optimal connection path from the client device to the gateway device for establishing the virtual private network connection. 17. A non-transitory computer-readable medium having stored thereon instructions that, in response

Assignees

Inventors

Classifications

  • H04L63/102Primary

    Entity profiles · CPC title

  • Virtual LANs, VLANs, e.g. virtual private networks [VPN] (LAN interconnection over a bridge based backbone H04L12/462; encapsulation techniques H04L12/4633; routing of packets H04L45/00; packet switches H04L49/00; virtual private networks for security H04L63/0272) · CPC title

  • Virtual private networks · CPC title

  • Arrangements for connecting between networks having differing types of switching systems, e.g. gateways · CPC title

  • for authentication of entities (cryptographic mechanisms or cryptographic arrangements for entity authentication H04L9/32) · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US11863560B2 cover?
An industrial information hub (IIH) and an industrial development hub (IDH) serve as an industrial ecosystem platform where multiple participants can deliver repeatable and standardized services relevant to their core competencies. The IIH system is centered around the development of an ecosystem that creates and delivers value to users—including industrial enterprises, OEMs, system integrators…
Who is the assignee on this patent?
Rockwell Automation Tech Inc
What technology area does this patent fall under?
Primary CPC classification H04L63/102. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Jan 02 2024 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 8 related publications on this page (citations in our corpus or others sharing the same primary CPC).