Process Control or Automation System Architecture
A process plant and industrial control system architecture includes a generalized compute fabric that is agnostic or indifferent to the physical location at which the compute fabric is implemented, includes one or more physical control or field devices located at one or more specific sites at which a product or process is being manufactured and further includes a transport network that securely provides communications between the compute fabric and the pool of physical devices. The compute fabric includes an application layer that includes configured containers or containerized software modules that perform various control, monitoring and configuration activities with respect to one or more devices, control strategies and control loops, sites, plants, or facilities at which control is performed, and includes a physical layer including computer processing and data storage equipment that can be located at any desired location, including at or near a site, plant, or facility at which control is being performed, at a dedicated location away from the location at which control is being performed, in re-assignable computer equipment provided in the cloud, or any combination thereof. This control architecture enables significant amounts of both computer processing and IT infrastructure that is used to support a process plant, an industrial control facility or other automation facility to be implemented in a shared, in an offsite and/or in a virtualized manner that alleviates many of the communications and security issues present in current process and industrial control systems that attempt to implement control with shared or virtualized computing resources set up according to the well-known Purdue model. The industrial control system architecture is protected via more secure and customizable techniques as compared to those used in Purdue model-based control systems. For example, communications between any (and in some cases, all) endpoints of the system may be protected via one or more virtual private networks to which authenticated endpoints must be authorized to access. Endpoints may include, for example, containerized components, physical components, devices, sites or locations, the compute fabric, and the like, and the VPNs may include mutually-exclusive and/or nested VPNs. External applications and services, whether automated or executing under the purview of a person, may access information and services provided by the system via only APIs, and different sets of APIs may be exposed to different users that have been authenticated and authorized to access respective sets of APIs. A configuration system operates within the compute fabric to enable a user to easily make configuration changes to the compute fabric as the user does not generally need to specify the computer hardware within the compute fabric to use to make the configuration changes, making it possible for the user to deploy new configuration elements with simple programming steps, and in some cases with the push of a button.
1 . A process control or automation system, comprising:
a physical device that performs a physical function utilized in control of an industrial or automation process provided by an enterprise; and
an instantiated micro-encapsulated execution environment (MEEE) communicatively connected to the physical device and configured to at least one of transmit information to or receive information from the physical device, thereby controlling at least a portion of the industrial or automation process.
2 . The process control or automation system of claim 1 , wherein the physical device and the instantiated MEEE are communicatively connected via a secured point-to-point (PTP) or peer-to-peer (P2P) connection.
3 . The process control or automation system of claim 2 , wherein the secured PTP or P2P connection is a virtual private network (VPN) or other type of secured, encrypted PTP or P2P connection that exclusively services only (i) the instantiated MEEE, and (ii) one of the physical device or an intervening device communicatively disposed between the instantiated MEEE and the physical device.
4 . The process control or automation system of claim 1 , wherein the instantiated MEEE is included in a plurality of instantiated MEEEs of the process control or automation system, and each instantiated MEEE of the plurality of instantiated MEEEs is communicatively connected via a respective secured PTP or P2P connection with at least one of: a respective physical device, a respective intervening device communicatively disposed between the respective physical device and the each instantiated MEEE, or another instantiated MEEE.
5 . The process control or automation system of claim 4 , wherein each secured PTP or P2P connection included in two or more of the respective secured PTP or P2P connections is a respective secured encrypted PTP or P2P connection exclusively servicing the two endpoints of the respective secured encrypted PTP or P2P connection.
6 . The process control or automation system of claim 4 , wherein at least one of the respective secured PTP or P2P connections includes a virtual private network (VPN).
7 . The process control or automation system of claim 4 , wherein at least one of the respective secured PTP or P2P connections is a secured P2P connection.
8 . The process control or automation system of claim 4 , wherein the plurality of instantiated MEEEs and the plurality of secured PTP or P2P connections are a dynamic mesh of MEEEs of the process control or automation system, and at least one of the MEEEs of the process control system or automation mesh is dynamically reassigned and migrated, by the process control or automation system during run-time operations and based on a condition detected or predicted by the process control or automation system, to another node, another physical location, or another geographical location while the process control or automation system is executing in run-time to control the industrial or automation process.
9 . The process control or automation system of claim 4 , wherein the instantiated MEEE is a virtual process controller or a virtual safety controller, and the plurality of instantiated MEEEs further includes at least one of: another virtual process controller, another virtual safety controller; a virtual safety logic solver; a virtual I/O card, device, or node; a virtual wireless device; a virtual Ethernet device; a virtual operator workstation; a virtual user interface device; a virtual tool; a virtual gateway; a virtual electronic marshalling cabinet or system; a virtualization of another type of physical device or component disposed within a physical environment of the industrial process plant; a control service; a service providing a subsystem of the process control or automation system; or a service providing business logic of the process control or automation system.
10 . The process control system of claim 9 , wherein the plurality of instantiated MEEEs further includes at least one of: a monitoring application or service, an operational application or service, a diagnostic application or service, a dashboard application or service, a user interface application or service, an analytics application or service, a safety routine application or service, a reporting application or service, a historization application or service, a configuration application or service, a simulation application or service, a process control resource and/or resource management service, an automation resource and/or resource management service, an external communications application or service, an alarm application or service, a licensing application or service, a third-party application or service, a service life cycle management service, a discovery service, a security service, an encryptor service, a certificate authority subsystem service, a key management service, an authentication service, a time synchronization service, a resource and/or resource group management service, a service location service, or a console support service.
11 . The process control or automation system of claim 9 , wherein the plurality of instantiated MEEEs further includes a packet router or switch service and at least one of: a software defined compute service, a software defined storage service, or a software defined networking service.
12 . The process control or automation system of claim 1 , wherein the process control or automation system authenticates both an identifier of the physical device and an identifier of the instantiated MEEE, and delivery of the information between the physical device and the instantiated MEEE is based on the authentications.
13 . The process control or automation system of claim 12 , wherein:
subsequent to the authentications, the process control or automation system authorizes the physical device to at least one of send or receive communications within the process control or automation system, and the process control or automation system authorizes the instantiated MEEE to at least one of send or receive communications within the process control or automation system; and
the delivery of the information between the physical device and the instantiated MEEE is further based on the authorizations.
14 . The process control or automation system of claim 13 , wherein:
the physical device and the instantiated MEEE are communicatively connected via a secured point-to-point (PTP) or peer-to-peer (P2P) connection;
the authorization of the physical device to at least one of send or receive communications within the process control or automation system includes an authorization of the physical device or of an intervening device communicatively disposed between the physical device and the instantiated MEEE to communicate over the secured PTP or P2P connection; and
the authorization of the instantiated MEEE to at least one of send or receive communications within the process control or automation system the process control or automation system includes an authorization of the instantiated MEEE to communicate over the secured PTP or P2P connection.
15 . The process control or automation system of claim 1 , wherein:
the instantiated MEEE is included in a plurality of instantiated MEEEs of the process control or automation system;
the process control or automation system authenticates a respective identifier of each instantiated MEEE of the plurality of instantiated MEEEs; and
based on the authentication, the process control or automation system authorizes the each instantiated MEEE to communicate with at least one of: a respective physical device, a respective intervening device communicatively disposed between the respective physical device and the respective instantiated MEEE, or a respective other instantiated MEEE.
16 . The process control or automation system of claim 15 , wherein:
the authentication of the respective identifier of the each instantiated MEEE is a first authentication;
the respective physical device is included in a plurality of physical devices;
the process control or automation system second authenticates at least one of: a respective identifier of the respective physical device or a respective identifier of a respective intervening device communicatively disposed between the respective physical device and the each instantiated MEEE; and
based on the second authentication, the process control or automation system authorizes the each physical device to communicate with the each instantiated MEEE.
17 . The process control or automation system of claim 1 ,
further comprising:
a plurality of physical devices performing respective physical functions to control the industrial or automation process, the plurality of physical devices disposed across multiple physical locations or sites, and the physical device included in the plurality of physical devices; and
a compute fabric executing on a hardware platform that is disposed across one or more physical locations or sites, at least one of which is excluded from the multiple physical locations or sites at which the plurality of physical devices is disposed, and the compute fabric including a plurality of instantiated MEEEs in which the instantiated MEEE is included, and
wherein:
at least one instantiated MEEE of the plurality of MEEEs is a respective instantiation of a respective encapsulated software component configured by the process control or automation system based on a configuration database of the process control or automation system.
18 . The process control or automation system of claim 17 , wherein users of the process control or automation system include a user interface that is being operated by a human and an executing software application that is not being operated by any human, and the compute fabric further includes a set of exposed application programming interfaces (APIs) via which any user communicates with the process control or automation system.
19 . The process control or automation system of claim 15 , wherein the process control or automation system at least one of: creates the respective encapsulated software component, configures the respective encapsulated software component, or instantiates the respective, configured, encapsulated software component responsive to a respective condition detected or predicted by the process control or automation system.
20 . The process control or automation system of claim 15 , wherein:
a first portion of the plurality of physical devices is disposed in a first geographic location, a second portion of the plurality of physical devices is disposed in a second geographic location, and at least a portion of the hardware platform on which the compute fabric executes is disposed at one or more other geographic locations; and
the first portion of the plurality of physical devices is communicatively connected to the one or more other geographic locations via a first gateway disposed at the first geographic location, and the second portion of the plurality of physical devices is communicatively connected to the one or more other geographic locations via a second gateway disposed at the second geographic location.
21 . A process control or automation system, comprising:
a physical device that located at and utilized at a physical location in an industrial or automation process provided by an enterprise; and
an application environment comprising an application usage including a plurality of communicatively connected, instantiated, micro-encapsulated execution environments (MEEEs), wherein the plurality of MEEEs cooperate in real time to implement the application usage, wherein at least one of the plurality of MEEEs is communicatively connected to the physical device and is configured to at least one of transmit information to or receive information from the physical device, and wherein the at least one of the plurality of MEEEs obtains data for the application usage directly from the physical device at the physical location in real time while implementing the application usage.
22 . The process control or automation system of claim 21 , wherein the physical device and the at least one of the plurality of instantiated MEEEs are communicatively connected via a secured point-to-point (PTP) or peer-to-peer (P2P) connection and the at least one of the plurality of MEEEs obtains data for the application usage directly from the physical location in real time while implementing the application usage using the secured PTP or P2P connection.
23 . The process control or automation system of claim 22 , wherein the secured PTP or P2P connection is a secured, encrypted PTP or P2P connection.
24 . The process control or automation system of claim 22 , wherein at least one of plurality of instantiated MEEEs is an endpoint of the secured PTP or P2P connection.
25 . The process control or automation system of claim 21 , wherein the secured PTP or P2P connection includes a virtual private network (VPN).
26 . The process control or automation system of claim 21 , wherein the application usage is a control or automation application that controls one or more physical devices at the physical location to control the operation of a process or an automation system.
27 . The process control or automation system of claim 21 , wherein the application usage is a maintenance application that uses data from the one or more physical devices at the physical location to perform one or more device maintenance functions with respect to the one or more physical devices.
28 . The process control or automation system of claim 21 , wherein the application usage is a fleet management application that uses data from the one or more physical devices at the physical location to perform one or more fleet tracking or management functions with respect to the one or more physical devices.
29 . The process control or automation system of claim 21 , wherein the application usage is an operations tracking or logging application that uses data from the one or more physical devices at the physical location to perform one or more process tracking or data logging functions with respect to a process implemented by the one or more physical devices.
30 . The process control or automation system of claim 21 , wherein at least one of the plurality of instantiated MEEEs includes a data reference to one or more data objects generated in one or more of the physical devices at the physical location where the one or more data objects are stored, wherein the data reference enables the at least one of the plurality of instantiated MEEEs to obtain the data objects directly from the one or more physical devices at the physical location where the one or more data objects are stored in real time during execution of the application usage.
31 . The process control or automation system of claim 30 , wherein the at least one of the plurality of instantiated MEEEs obtains the one or more data objects directly from the one or more physical devices at the physical location where the one or more data objects are stored in real time during execution of the application usage using publish/subscribe communications.
32 . The process control or automation system of claim 30 , wherein the at least one of the plurality of instantiated MEEEs obtains the one or more data objects directly from the one or more physical devices at the physical location where the one or more data objects are stored in real time during execution of the application usage using one or more addressed or direct data calls.
33 . The process control or automation system of claim 21 , wherein at least one of the plurality of instantiated MEEEs obtains the one or more data objects directly from the one or more physical devices at the physical location where the one or more data objects are stored in real time during execution of the application usage using publish/subscribe communications.
34 . The process control or automation system of claim 21 , wherein at least one of the plurality of instantiated MEEEs obtains the one or more data objects directly from the one or more physical devices at the physical location where the one or more data objects are stored in real time during execution of the application usage using one or more addressed or direct data calls.
35 . The process control or automation system of claim 21 , wherein the at least one of the plurality of instantiated MEEEs is executed in hardware in a compute fabric located remote for the physical location.
36 . The process control or automation system of claim 35 , wherein the compute fabric comprises a cloud computing environment.
37 . The process control or automation system of claim 35 , wherein the at least one of the plurality of instantiated MEEEs obtains the one or more data objects directly from the one or more physical devices at the physical location where the one or more data objects are stored in real time during execution of the application usage without first storing the one or more data objects in a computing device within the compute fabric.
38 . The process control or automation system of claim 21 , wherein the physical device at the physical location comprises a server device.
39 . The process control or automation system of claim 21 , wherein the physical device at the physical location comprises a communications gateway device.
40 . The process control or automation system of claim 21 , wherein the physical device at the physical location performs a physical function at the physical location.
41 . The process control or automation system of claim 21 , wherein the physical device at the physical location comprises an input/output device at the physical location connected to a field device.
42 . The process control or automation system of claim 21 , wherein the physical device at the physical location comprises a field device that performs a physical function at the physical location.
43 . The process control or automation system of claim 21 , wherein the physical device at the physical location comprises a database device coupled to one or more field devices.
44 . The process control or automation system of claim 21 , wherein multiple ones of the plurality of instantiated MEEEs are executed in hardware in a compute fabric located remote from the physical location, wherein each of the multiple ones of the plurality of instantiated MEEEs obtains data in real time from data sources not co-located with the instantiated MEEEs, and wherein at the least one of the plurality of MEEEs obtains data from a physical device at the physical location.
45 . The process control or automation system of claim 44 , wherein the multiple ones of the plurality of instantiated MEEEs operate in real time together to implement one of a control function, a maintenance function, a data logging or tracking function or a fleet management function.
46 . The process control or automation system of claim 44 , wherein the multiple ones of the plurality of instantiated MEEEs includes the at least one of the plurality of instantiated MEEEs and the at least one of the plurality of instantiated MEEEs operates to implement one of a control function, a maintenance function, a data logging or tracking function or a fleet management function.