Industrial automation secure remote access

US12556540B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-12556540-B2
Application numberUS-202318300037-A
CountryUS
Kind codeB2
Filing dateApr 13, 2023
Priority dateJul 15, 2021
Publication dateFeb 17, 2026
Grant dateFeb 17, 2026

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

An industrial information hub (IIH) and an industrial development hub (IDH) serve as an industrial ecosystem platform where multiple participants can deliver repeatable and standardized services relevant to their core competencies. The IIH system is centered around the development of an ecosystem that creates and delivers value to users—including industrial enterprises, OEMs, system integrators, vendors, etc.—through the aggregation of digital content and domain expertise. The IIH system serves as a trusted information broker between the ecosystem and the OT environments of plant facilities, and provides a platform for connecting assets, contextualizing asset data and providing secure access to the ecosystem. As part of this ecosystem, the IIH system uses a secure remote access architecture to allow users to remotely access data on their plant floor assets via a virtual private network connection.

First claim

Opening claim text (preview).

What is claimed is: 1 . A system, comprising: a memory that stores executable components; and a processor, operatively coupled to the memory, that executes the executable components, the executable components comprising: a device interface component configured to communicatively connect, via a cloud platform, to gateway devices deployed at one or more industrial facilities, wherein the gateway devices are communicatively connected to industrial assets that operate at the one or more industrial facilities, and the gateway devices respectively execute secure remote access runtime services; a user interface component configured to, in response to verification of a user identity and credential information, render a list of the industrial assets on a client device for selection; an access management component configured to, in response to selection of a subset of the industrial assets from the list, establish a virtual private network connection between the client device and the subset of the industrial assets via a gateway device, of the gateway devices, that is communicatively connected to the subset of the industrial assets without opening an inbound port through a firewall at an industrial facility in which the gateway device resides; and an analytics component configured to apply analytics to contextualized industrial data obtained from the subset of the industrial assets based on a simulation of a virtualized plant that executes on the cloud platform and that comprises digital asset models of the subset of the industrial assets, wherein the contextualized industrial data comprises industrial data and contextual metadata added to the industrial data by the gateway device, the contextual metadata defines a mathematical correlation between two or more items of the industrial data, and the user interface component is further configured to render, on the client device via the virtual private network connection, a unified presentation of the subset of the industrial assets based on the industrial data and to render results of the analytics via the unified presentation. 2 . The system of claim 1 , wherein the user interface component is further configured to serve a front-end interface to the client device and to receive, via interaction with the front-end interface, request data comprising the user identity and credential information. 3 . The system of claim 1 , wherein the digital asset models define visual representations and functional specification data for their corresponding industrial assets. 4 . The system of claim 1 , wherein the industrial data comprises at least one of asset status data, asset operation data, asset performance data, asset diagnostic data, or production statistics. 5 . The system of claim 1 , wherein the user interface component is further configured to receive, from the client device, a control instruction directed to an industrial asset of the subset of the industrial assets, and the access management component is configured to send the control instruction to the industrial asset via the virtual private network connection. 6 . The system of claim 1 , wherein the access management component is configured to execute one or more algorithms that determine an optimal connection path from the client device to the gateway device for establishment of the virtual private network connection. 7 . The system of claim 1 , wherein the contextual metadata further at least one of identifies machines from which the industrial data was generated or applies a synchronized timestamp to the industrial data. 8 . The system of claim 1 , wherein the digital asset models define at least one of respective kinematic properties or respective mechatronic properties of the subset of the industrial assets. 9 . A method, comprising: communicatively connecting, via a cloud platform by a system comprising a processor, to gateway devices installed at one or more industrial facilities, wherein the gateway devices are communicatively connected to industrial assets that operate at the one or more industrial facilities, and the gateway devices respectively execute secure remote access runtime services; in response to verifying a user identity and credential information, rendering, by the system, a list of the industrial assets on a client device for selection; in response to receiving a selection of a subset of the industrial assets from the list, establishing, by the system, a virtual private network connection between a client device and the subset of the industrial asset via a gateway device, of the gateway devices, that is communicatively connected to the subset of the industrial assets without opening an inbound port through a firewall at an industrial facility in which the gateway device resides; applying, by the system, analytics to contextualized industrial data, received from the subset of the industrial assets, based on a simulation of a virtualized plant that executes on the cloud platform and that comprises digital asset models of the subset of the industrial assets, wherein the contextualized industrial data comprises industrial data and contextual metadata added to the industrial data by the gateway device, and the contextual metadata defines a mathematical correlation between two or more items of the industrial data; and rendering, by the system on the client device via the virtual private network connection, results of the analytics via a unified presentation of the subset of the industrial assets generated based on the contextualized industrial data. 10 . The method of claim 9 , wherein the verifying comprises: serving a front-end interface to the client device; and receiving, via interaction with the front-end interface, request data comprising the user identity and credential information. 11 . The method of claim 9 , wherein the contextual metadata further at least one of identifies machines from which the industrial data was generated or applies a synchronized timestamp to the industrial data. 12 . The method of claim 9 , further comprising: receiving, by the system from the client device, a control instruction directed to an industrial asset of the subset of the industrial assets; and sending, by the system, the control instruction to the industrial asset via the virtual private network connection. 13 . The method of claim 9 , wherein the establishing comprises executing one or more algorithms that determine an optimal connection path from the client device to the gateway device for establishing the virtual private network connection. 14 . The method of claim 9 , wherein the digital asset models define at least one of respective kinematic properties or respective mechatronic properties of the subset of the industrial assets. 15 . A non-transitory computer-readable medium having stored thereon instructions that, in response to execution, cause a system executing on a cloud platform and comprising a processor to perform operations, the operations comprising: communicatively connecting, via a cloud platform, to gateway devices installed at one or more industrial facilities, wherein the gateway devices are communicatively connected to industrial assets that operate at the one or more industrial facilities, and the gateway devices respectively execute secure remote access runtime services; in response to verifying a user identity and credential information, rendering a list of the industrial assets on a client device for selection; in response to receiving a selection of a subset of the industrial assets from the list, establishing a virtual private network connectio

Assignees

Inventors

Classifications

  • Virtual private networks · CPC title

  • Virtual LANs, VLANs, e.g. virtual private networks [VPN] (LAN interconnection over a bridge based backbone H04L12/462; encapsulation techniques H04L12/4633; routing of packets H04L45/00; packet switches H04L49/00; virtual private networks for security H04L63/0272) · CPC title

  • H04L63/102Primary

    Entity profiles · CPC title

  • using passwords (cryptographic mechanisms or cryptographic arrangements for entity authentication using a predetermined code H04L9/3226) · CPC title

  • for separating internal from external traffic, e.g. firewalls · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US12556540B2 cover?
An industrial information hub (IIH) and an industrial development hub (IDH) serve as an industrial ecosystem platform where multiple participants can deliver repeatable and standardized services relevant to their core competencies. The IIH system is centered around the development of an ecosystem that creates and delivers value to users—including industrial enterprises, OEMs, system integrators…
Who is the assignee on this patent?
Rockwell Automation Tech Inc
What technology area does this patent fall under?
Primary CPC classification H04L63/0272. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Feb 17 2026 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 12 related publications on this page (citations in our corpus or others sharing the same primary CPC).