IP Library Granted Patent US 12,228,897
Granted Patent B2
US 12,228,897 · App. 18/223,395 · Granted Feb 18, 2025

Securing access of a process control or automation system

Inventors: Brian Lamothe (Round Rock, TX); Narayanan Doraiswamy (Round Rock, TX); Mark J. Nixon (Thorndale, TX); Aaron C. Jones (Austin, TX); Antonio Ubach (Round Rock, TX); Sean Hernandez (Round Rock, TX); Sireesha Dakoju (Round Rock, TX); Krishna Joshi (Round Rock, TX); Matthew Villarrubia (Round Rock, TX)
Assignee: FISHER-ROSEMOUNT SYSTEMS, INC.
G05B15/02G05B19/4142G05B19/41835G05B19/4184G05B19/4185G05B19/41865G05B19/41885H04L63/0272H04L63/0428H04L63/08G05B2219/31368G05B2219/34447
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,228,897
App. No.
18/223,395
Filed
Jul 18, 2023
Granted
Feb 18, 2025
Kind
B2
Art Unit
2441
USPC
709/224
Abstract

A process plant and industrial control system architecture includes a generalized compute fabric that is agnostic or indifferent to the physical location at which the compute fabric is implemented, includes one or more physical control or field devices located at one or more specific sites at which a product or process is being manufactured and further includes a transport network that securely provides communications between the compute fabric and the pool of physical devices. The compute fabric includes an application layer that includes configured containers or containerized software modules that perform various control, monitoring and configuration activities with respect to one or more devices, control strategies and control loops, sites, plants, or facilities at which control is performed, and includes a physical layer including computer processing and data storage equipment that can be located at any desired location, including at or near a site, plant, or facility at which control is being performed, at a dedicated location away from the location at which control is being performed, in re-assignable computer equipment provided in the cloud, or any combination thereof. This control architecture enables significant amounts of both computer processing and IT infrastructure that is used to support a process plant, an industrial control facility or other automation facility to be implemented in a shared, in an offsite and/or in a virtualized manner that alleviates many of the communications and security issues present in current process and industrial control systems that attempt to implement control with shared or virtualized computing resources set up according to the well-known Purdue model. The industrial control system architecture is protected via more secure and customizable techniques as compared to those used in Purdue model-based control systems. For example, communications between any (and in some cases, all) endpoints of the system may be protected via one or more virtual private networks to which authenticated endpoints must be authorized to access. Endpoints may include, for example, containerized components, physical components, devices, sites or locations, the compute fabric, and the like, and the VPNs may include mutually-exclusive and/or nested VPNs. External applications and services, whether automated or executing under the purview of a person, may access information and services provided by the system via only APIs, and different sets of APIs may be exposed to different users that have been authenticated and authorized to access respective sets of APIs. A configuration system operates within the compute fabric to enable a user to easily make configuration changes to the compute fabric as the user does not generally need to specify the computer hardware within the compute fabric to use to make the configuration changes, making it possible for the user to deploy new configuration elements with simple programming steps, and in some cases with the push of a button.

Claims (63)

1. A method performed by a process control or automation system, the method comprising:

first authenticating and/or authorizing, by the process control or automation system, an identity of an instantiated micro-encapsulated execution environment (MEEE) to communicate with a physical device that performs a physical function utilized in control of an industrial or automation process provided by an enterprise, the instantiated MEEE and the physical device associated with a control loop that has a unique identity within the process control or automation system;

second authenticating and/or authorizing, by the process control or automation system, an identity corresponding to the physical device to communicate with the instantiated MEEE; and

when both the identity corresponding to the physical device and the identity of the instantiated MEEE are authenticated and/or authorized, granting permission for the instantiated MEEE and the physical device to communicatively connect to thereby deliver information between the instantiated MEEE and the physical device for controlling at least a portion of the industrial or automation process via the control loop.

2. The method of claim 1 , wherein:

the first authenticating and/or authorizing of the identity of the instantiated MEEE includes authenticating the identity of the instantiated MEEE and authorizing the identity of the instantiated MEEE responsive to the authenticating of the identity of the instantiated MEEE; and

the second authenticating and/or authorizing of the identity corresponding to the physical device includes authenticating the identity corresponding to the physical device and authorizing the identity corresponding to the physical device responsive to the authenticating of the identity of the instantiated MEEE.

3. The method of claim 1 , wherein:

the identity of the instantiated MEEE and the identity corresponding to the physical device are unique identities within the process control and automation system; and

the identity corresponding to the physical device is the identity of the physical device or an identity of an intervening device that is communicatively disposed between the physical device and the instantiated MEEE.

4. The method of claim 3 , wherein the intervening device is a gateway, the physical device and the gateway are disposed at a first geographical location, and the instantiated MEEE executes on a hardware platform disposed at a second geographical location.

5. The method of claim 1 , wherein:

the identity of the instantiated MEEE is unique in the process control and automation system;

the process control or automation system further comprises I/O hardware that is communicatively disposed between the physical device and the instantiated MEEE;

the physical device is physically connected to a physical I/O interface included in the I/O hardware;

a combination of the physical device and the physical I/O interface is a physical component that is uniquely identified in the process control or automation system; and

the identity corresponding to the physical device is the identity of the physical component.

6. The method of claim 1 , wherein:

the first authenticating and/or authorizing of the identity of the instantiated MEEE to communicate with the physical device is based on the identity corresponding to the physical device; and

the second authenticating and/or authorizing of the identity corresponding to the physical device to communicate with the instantiated MEEE is based on the identity of the instantiated MEEE.

7. The method of claim 1 ,

further comprising, based on the granted permission, communicatively connecting, via a secured point-to-point (PTP) or peer-to-peer (P2P) connection, the instantiated MEEE and the physical device, the instantiated MEEE being a first endpoint of the secured PTP or P2P connection, and one of the physical device or an intervening device communicatively disposed between the instantiated MEEE and the physical device being a second endpoint of the secured PTP or P2P connection; and

wherein:

the first authenticating and/or authorizing of the identity of the instantiated MEEE includes authenticating and/or authorizing the identity of the instantiated MEEE to communicate with the one of the physical device or the intervening device via the secured PTP or P2P connection, and

the second authenticating and/or authorizing of the identity corresponding to the physical device includes authenticating and/or authorizing an identity of the one of the physical device or the intervening device to communicate with the instantiated MEEE via the secured PTP or P2P connection.

8. The method of claim 7 , wherein the secured PTP or P2P connection is a secured P2P connection.

9. The method of claim 1 , wherein the instantiated MEEE is included in a plurality of instantiated MEEEs of the process control or automation system, the physical device is included in a plurality of physical devices; and the method further comprises:

respectively authenticating and/or authorizing a respective identity of each instantiated MEEE of the plurality of instantiated MEEEs to communicate with at least one of: a respective physical device, a respective intervening device communicatively disposed between the respective physical device and the respective instantiated MEEE, or a respective other instantiated MEEE; and

respectively authenticating and/or authorizing, to communicate with a corresponding instantiated MEEE, an identity of each physical device of the plurality of physical devices or an identity of a corresponding intervening device corresponding to the each physical device.

10. The method of claim 9 , wherein:

the plurality of instantiated MEEEs includes at least one of: a virtual process controller, a virtual safety controller; a virtual safety logic solver; a virtual I/O card, device, or node; a virtual wireless device; a virtual Ethernet device; a virtual operator workstation; a virtual user interface device; a virtual tool; a virtual gateway; a virtual electronic marshalling cabinet or system; a virtualization of another type of physical device or component disposed within a physical environment of an industrial process plant; a control service; a service providing a subsystem of the process control or automation system; or a service providing business logic of the process control or automation system; and

the business logic of the process control or automation system includes at least one of: a monitoring application or service, an operational application or service, a diagnostic application or service, a dashboard application or service, a user interface application or service, an analytics application or service, a safety routine application or service, a reporting application or service, a historization application or service, a configuration application or service, a simulation application or service, a process control resource and/or resource management service, an automation resource and/or resource management service, an external communications application or service, an alarm application or service, a licensing application or service, or a third-party application or service.

11. The method of claim 1 , wherein:

the first authenticating and/or authorizing of the identity of the instantiated MEEE includes authenticating and/or authorizing the identity of the instantiated MEEE to at least one of send or receive communications with a first set of nodes of the process control or automation system and not authorizing the identity of the instantiated MEEE to at least one of send or receive communications with a second set of nodes of the process control or automation system;

the first set of nodes includes the physical device or an intervening node communicatively disposed between the instantiated MEEE and the physical device; and

the second set of nodes includes at least one of another instantiated MEEE or another physical device.

12. The method of claim 1 , wherein:

the second authenticating and/or authorizing of the identity corresponding to the physical device includes authenticating and/or authorizing the identity corresponding to the physical device to at least one of send or receive communications with a first set of nodes of the process control or automation system and not authorizing the identity corresponding to the physical device to at least one of send or receive communications with a second set of nodes of the process control or automation system;

the first set of nodes includes the instantiated MEEE; and

the second set of nodes includes at least one other instantiated MEEE.

13. The method of claim 1 , wherein:

the physical device is a field device configured to perform a physical function responsive to a control signal generated by the instantiated MEEE or by another instantiated MEEE; and

the instantiated MEEE is a virtual process controller or a virtual safety controller that (i) operates on received data to generate a control signal to which the physical device is operably responsive, or (ii) operates on the information received from the physical device to thereby generate a control signal to which the physical device or another physical device is operably responsive.

14. The method of claim 1 , further comprising discovering, by the process control and automation system, the identity of the instantiated MEEE and the identity corresponding to the physical device.

15. The method of claim 1 , wherein the first authenticating and/or authorizing of the identity of the instantiated MEEE is based on a first certificate, and the second authenticating and/or authorizing of the identity corresponding to the physical device is based on a second certificate.

16. The method of claim 1 , further comprising digitally signing and encrypting the information delivered between the instantiated MEEE and the physical device.

17. A method performed by a process control or automation system, the method comprising:

first authenticating and/or authorizing, by the process control or automation system, an identity of an instantiated micro-encapsulated execution environment (MEEE) to communicate, via one of a secured point-to-point (PTP or P2P) connection or at least one of another secured PTP or P2P connection, a secured point-to-multipoint (PTM) connection, or a secured multipoint-to-multipoint (MTM) connection, with a physical device that performs a physical function utilized in control of an industrial or automation process provided by an enterprise;

second authenticating and/or authorizing, by the process control or automation system, an identity corresponding to the physical device or to an intervening device communicatively disposed between the instantiated MEEE and the physical device to communicate with the instantiated MEEE via the other one of the secured PTP or P2P connection or the at least one of the another secured PTP or P2P connection, the secured PTM connection, or the secured MTM connection; when both the identity corresponding to the physical device and the identity of the instantiated MEEE are authenticated and/or authorized, granting permission for the instantiated MEEE and the physical device to communicatively connect to thereby deliver information between the instantiated MEEE and the physical device for controlling at least a portion of the industrial or automation process; and

based on the granted permission, communicatively connecting the physical device and the instantiated MEEE via the secured PTP or P2P connection and the at least one of the another secured PTP or P2P connection, the secured point-to-multipoint (PTM) connection, or the secured multipoint-to-multipoint (MTM) connection.

18. A method performed by a process control or automation system, the method comprising:

first authenticating and/or authorizing, by the process control or automation system, an identity of an instantiated micro-encapsulated execution environment (MEEE) to communicate, via a first virtual private network (VPN) of a plurality of VPNs, with a physical device that performs a physical function utilized in control of an industrial or automation process provided by an enterprise;

second authenticating and/or authorizing, by the process control or automation system, an identity corresponding to the physical device to communicate with the instantiated MEEE via the first VPN or a second VPN of the plurality of VPNs;

when both the identity corresponding to the physical device and the identity of the instantiated MEEE are authenticated and/or authorized, granting permission for the instantiated MEEE and the physical device to communicatively connect to thereby deliver information between the instantiated MEEE and the physical device for controlling at least a portion of the industrial or automation process; and

based on the granted permission, communicatively connecting the instantiated MEEE and the physical device via the plurality of VPNs.

19. A method performed by a process control or automation system, the method comprising:

first authenticating and/or authorizing, by the process control or automation system, an identity of an instantiated micro-encapsulated execution environment (MEEE) to communicate with a physical device that performs a physical function utilized in control of an industrial or automation process provided by an enterprise, the instantiated MEEE included in a plurality of instantiated MEEEs, and the plurality of instantiated MEEEs including a packet router or switch service;

second authenticating and/or authorizing, by the process control or automation system, an identity corresponding to the physical device to communicate with the instantiated MEEE; and

when both the identity corresponding to the physical device and the identity of the instantiated MEEE are authenticated and/or authorized, granting permission for the instantiated MEEE and the physical device to communicatively connect to thereby deliver information between the instantiated MEEE and the physical device for controlling at least a portion of the industrial or automation process.

20. A method performed by a process control or automation system, the method comprising:

first authenticating and/or authorizing, by the process control or automation system, an identity of an instantiated micro-encapsulated execution environment (MEEE) to communicate with a physical device that performs a physical function utilized in control of an industrial or automation process provided by an enterprise, the instantiated MEEE included in a plurality of instantiated MEEEs, and the plurality of instantiated MEEEs including at least one of: a software defined compute service, a software defined storage service, or a software defined networking service;

second authenticating and/or authorizing, by the process control or automation system, an identity corresponding to the physical device to communicate with the instantiated MEEE; and

when both the identity corresponding to the physical device and the identity of the instantiated MEEE are authenticated and/or authorized, granting permission for the instantiated MEEE and the physical device to communicatively connect to thereby deliver information between the instantiated MEEE and the physical device for controlling at least a portion of the industrial or automation process.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 26, 2023
From: LAMOTHE, BRIAN; DORAISWAMY, NARAYANAN; NIXON, MARK J.; JONES, AARON C.; UBACH, ANTONIO; HERNANDEZ, SEAN; DAKOJU, SIREESHA; JOSHI, KRISHNA; VILLARRUBIA, MATTHEW
To: FISHER-ROSEMOUNT SYSTEMS, INC.
Reel/Frame 064381/0610 →
Continuity (5)
Provisional Application 63418006 · Oct 20, 2022
Provisional Application 63417861 · Oct 20, 2022
Provisional Application 63398441 · Aug 16, 2022
Provisional Application 63390238 · Jul 18, 2022
Related Publication 20240028011A1 · Jan 25, 2024
References Cited (217)
US 7281250B2 · Ohsawa et al. · 2007 [cited by applicant]
US 7293080B1 · Clemm et al. · 2007 [cited by applicant]
US 8924103B2 · Dammeyer et al. · 2014 [cited by applicant]
US 9183560B2 · Abelow et al. · 2015 [cited by applicant]
US 9451012B1 · Neill et al. · 2016 [cited by applicant]
US 9521115B1 · Woolward · 2016 [cited by applicant]
US 9934671B1 · Anderson et al. · 2018 [cited by applicant]
US 9992726B2 · Shepard et al. · 2018 [cited by applicant]
US 10303576B1 · Seymour et al. · 2019 [cited by applicant]
US 10360050B2 · He et al. · 2019 [cited by applicant]
US 10382203B1 · Loladia · 2019 [cited by examiner]
US 10547521B1 · Roy et al. · 2020 [cited by applicant]
US 10574729B2 · Hadfield et al. · 2020 [cited by applicant]
US 10663956B2 · Jundt et al. · 2020 [cited by applicant]
US 10915081B1 · Nixon et al. · 2021 [cited by applicant]
US 10977070B2 · Li et al. · 2021 [cited by applicant]
US 11126469B2 · Reque et al. · 2021 [cited by applicant]
US 11281492B1 · Rebeja et al. · 2022 [cited by applicant]
US 11513877B2 · Biernat et al. · 2022 [cited by applicant]
US 11541447B2 · Beyfuss et al. · 2023 [cited by applicant]
US 11637918B2 · Yarvis et al. · 2023 [cited by applicant]
US 11960588B2 · Amaro, Jr. et al. · 2024 [cited by applicant]
US 20020126620A1 · Heckel et al. · 2002 [cited by applicant]
US 20030023795A1 · Packwood et al. · 2003 [cited by applicant]
US 20040114605A1 · Karaoguz et al. · 2004 [cited by applicant]
US 20040260404A1 · Russell · 2004 [cited by applicant]
US 20050160413A1 · Broussard · 2005 [cited by applicant]
US 20050220127A1 · Cane et al. · 2005 [cited by applicant]
US 20060167886A1 · Kantesaria et al. · 2006 [cited by applicant]
US 20070006228A1 · Grobman et al. · 2007 [cited by applicant]
US 20070076742A1 · Du et al. · 2007 [cited by applicant]
US 20090083843A1 · Wilkinson, Jr. et al. · 2009 [cited by applicant]
US 20090327606A1 · Galloway et al. · 2009 [cited by applicant]
US 20100235831A1 · Dittmer et al. · 2010 [cited by applicant]
US 20100263025A1 · Neitzel et al. · 2010 [cited by applicant]
US 20100290351A1 · Toepke et al. · 2010 [cited by applicant]
US 20110021131A1 · Chen · 2011 [cited by applicant]
US 20110125921A1 · Karenos et al. · 2011 [cited by applicant]
US 20110265077A1 · Collison et al. · 2011 [cited by applicant]
US 20120102492A1 · Iwata et al. · 2012 [cited by applicant]
US 20120259436A1 · Resurreccion et al. · 2012 [cited by applicant]
US 20130031249A1 · Gunzert et al. · 2013 [cited by applicant]
US 20130031294A1 · Feng et al. · 2013 [cited by applicant]
US 20130086594A1 · Cottrell · 2013 [cited by applicant]
US 20130212129A1 · Lawson et al. · 2013 [cited by applicant]
US 20140019491A1 · Hamel · 2014 [cited by applicant]
US 20140344269A1 · Dong et al. · 2014 [cited by applicant]
US 20150378356A1 · Hefeeda et al. · 2015 [cited by applicant]
US 20160019084A1 · Forestiero et al. · 2016 [cited by applicant]
US 20160033006A1 · Leverington · 2016 [cited by applicant]
US 20160043866A1 · Nixon · 2016 [cited by applicant]
US 20160134596A1 · Kovacs et al. · 2016 [cited by applicant]
US 20160164743A1 · Cimprich et al. · 2016 [cited by applicant]
US 20160299772A1 · Seenappa et al. · 2016 [cited by applicant]
US 20160373310A1 · Banikazemi et al. · 2016 [cited by applicant]
US 20170026677A1 · Kim et al. · 2017 [cited by applicant]
US 20170095405A1 · Afsarifard et al. · 2017 [cited by applicant]
US 20170149843A1 · Amulothu et al. · 2017 [cited by applicant]
US 20170279770A1 · Woolward · 2017 [cited by applicant]
US 20170308330A1 · Suresh et al. · 2017 [cited by applicant]
US 20170344408A1 · Tan et al. · 2017 [cited by applicant]
US 20170359245A1 · Dintenfass et al. · 2017 [cited by applicant]
US 20170366551A1 · Brandwine · 2017 [cited by applicant]
US 20180052628A1 · Endo et al. · 2018 [cited by applicant]
US 20180067848A1 · Baldwin et al. · 2018 [cited by applicant]
US 20180112795A1 · Anderson et al. · 2018 [cited by applicant]
US 20180113442A1 · Nixon et al. · 2018 [cited by applicant]
US 20180114414A1 · Law et al. · 2018 [cited by applicant]
US 20180144144A1 · Luo et al. · 2018 [cited by applicant]
US 20180164791A1 · Debes et al. · 2018 [cited by applicant]
US 20180227369A1 · DuCray et al. · 2018 [cited by applicant]
US 20180299849A1 · Martin et al. · 2018 [cited by applicant]
US 20180316729A1 · Chauvet et al. · 2018 [cited by applicant]
US 20180341241A1 · Song · 2018 [cited by applicant]
US 20180375936A1 · Chirammal et al. · 2018 [cited by applicant]
US 20190041824A1 · Chavez et al. · 2019 [cited by applicant]
US 20190041830A1 · Yarvis et al. · 2019 [cited by applicant]
US 20190042378A1 · Wouhaybi et al. · 2019 [cited by applicant]
US 20190109820A1 · Clark et al. · 2019 [cited by applicant]
US 20190140918A1 · Xu et al. · 2019 [cited by applicant]
US 20190294124A1 · Law et al. · 2019 [cited by applicant]
US 20190317465A1 · Wei et al. · 2019 [cited by applicant]
US 20190324431A1 · Cella et al. · 2019 [cited by applicant]
US 20190369574A1 · Val et al. · 2019 [cited by applicant]
US 20190379590A1 · Rimar et al. · 2019 [cited by applicant]
US 20200067789A1 · Bharat et al. · 2020 [cited by applicant]
US 20200092254A1 · Goeringer et al. · 2020 [cited by applicant]
US 20200092271A1 · Kumar et al. · 2020 [cited by applicant]
US 20200099531A1 · Chidambaram · 2020 [cited by examiner]
US 20200102507A1 · Sun et al. · 2020 [cited by applicant]
US 20200112442A1 · Wentz · 2020 [cited by applicant]
US 20200125721A1 · Antony · 2020 [cited by applicant]
US 20200174462A1 · Sirohi et al. · 2020 [cited by applicant]
US 20200209816A1 · Cebasek et al. · 2020 [cited by applicant]
US 20200225649A1 · Cahill et al. · 2020 [cited by applicant]
US 20200226123A1 · Nixon et al. · 2020 [cited by applicant]
US 20200228316A1 · Cahill · 2020 [cited by applicant]
US 20200228342A1 · Nixon et al. · 2020 [cited by applicant]
US 20200241903A1 · Wang et al. · 2020 [cited by applicant]
US 20200310394A1 · Wouhaybi et al. · 2020 [cited by applicant]
US 20200322286A1 · Mehta · 2020 [cited by examiner]
US 20200387136A1 · Pöschmann et al. · 2020 [cited by applicant]
US 20200387144A1 · Nixon et al. · 2020 [cited by applicant]
US 20200387145A1 · Nixon et al. · 2020 [cited by applicant]
US 20200387146A1 · Nixon et al. · 2020 [cited by applicant]
US 20200396225A1 · Bhatia et al. · 2020 [cited by applicant]
US 20200401116A1 · McLaughlin et al. · 2020 [cited by applicant]
US 20210004245A1 · Kamath · 2021 [cited by applicant]
US 20210011772A1 · Zhou et al. · 2021 [cited by applicant]
US 20210044564A1 · Victor et al. · 2021 [cited by applicant]
US 20210058399A1 · Kapoor et al. · 2021 [cited by applicant]
US 20210089015A1 · Law et al. · 2021 [cited by applicant]
US 20210089354A1 · Nixon et al. · 2021 [cited by applicant]
US 20210089526A1 · Nixon et al. · 2021 [cited by applicant]
US 20210089542A1 · Nixon et al. · 2021 [cited by applicant]
US 20210089592A1 · Nixon et al. · 2021 [cited by applicant]
US 20210089593A1 · Nixon et al. · 2021 [cited by applicant]
US 20210092173A1 · Nixon et al. · 2021 [cited by applicant]
US 20210109658A1 · Mallick et al. · 2021 [cited by applicant]
US 20210112090A1 · Rivera · 2021 [cited by applicant]
US 20210149637A1 · Hallman, Jr. et al. · 2021 [cited by applicant]
US 20210271489A1 · Singhal · 2021 [cited by applicant]
US 20210294659A1 · Amit · 2021 [cited by applicant]
US 20210356944A1 · Chauvet et al. · 2021 [cited by applicant]
US 20210384058A1 · Harada et al. · 2021 [cited by applicant]
US 20220012137A1 · Xiao et al. · 2022 [cited by applicant]
US 20220019475A1 · Dobson et al. · 2022 [cited by applicant]
US 20220058012A1 · Kaushik et al. · 2022 [cited by applicant]
US 20220070112A1 · Mazzitelli et al. · 2022 [cited by applicant]
US 20220091583A1 · Biernat et al. · 2022 [cited by applicant]
US 20220103580A1 · Manickam et al. · 2022 [cited by applicant]
US 20220108806A1 · Kommalapati et al. · 2022 [cited by applicant]
US 20220128982A1 · Mansfield · 2022 [cited by applicant]
US 20220229707A1 · Lange et al. · 2022 [cited by applicant]
US 20220283571A1 · Vieira et al. · 2022 [cited by applicant]
US 20220404788A1 · Amaro, Jr. et al. · 2022 [cited by applicant]
US 20220404798A1 · Amaro, Jr. et al. · 2022 [cited by applicant]
US 20220404812A1 · Amaro, Jr. et al. · 2022 [cited by applicant]
US 20240004688A1 · Shigemori · 2024 [cited by applicant]
US 20240031370A1 · Ubach et al. · 2024 [cited by applicant]
CN 115052033A · 2022 [cited by applicant]
DE 102019119714A1 · 2021 [cited by applicant]
EP 1492310A2 · 2004 [cited by applicant]
EP 2790101A1 · 2014 [cited by applicant]
EP 3382546A1 · 2018 [cited by applicant]
GB 2403043A · 2004 [cited by applicant]
GB 2410573A · 2005 [cited by applicant]
GB 2481753A · 2012 [cited by applicant]
GB 2575758A · 2020 [cited by applicant]
GB 2589710A · 2021 [cited by applicant]
WO WO2014124701A1 · 2014 [cited by applicant]
WO WO2016090292A1 · 2016 [cited by applicant]
WO WO2017064560A1 · 2017 [cited by applicant]
WO WO2017066304A1 · 2017 [cited by applicant]
WO WO2017121928A1 · 2017 [cited by applicant]
WO WO2018234741A1 · 2018 [cited by applicant]
WO WO2020202126A1 · 2020 [cited by applicant]
WO WO2020251828A1 · 2020 [cited by applicant]
WO WO2021079357A1 · 2021 [cited by applicant]
“Kubernetes—Web UI (Dashboard),” (2021). [cited by applicant]
Aftab et al., “Analysis of identifiers in IoT platforms”, Digital Communications and Networks, 6(3):333-340 (2019). [cited by applicant]
Alaasam et al., “Stateful Stream Processing for Digital Twins,” International Multi-Conference on Engineering, Computer and Information Sciences (Oct. 21, 2019). [cited by applicant]
Bellini et al., “High Level Control of Chemical Plant by Industry 4.0 Solutions,” Journal of Industrial Information Integration, vol. 26 (Sep. 2, 2021). [cited by applicant]
Computer and Information Security Handbook, 3rd Edition (2017). Select pages. [cited by applicant]
Dobaj et al., “A Microservice Architecture for the Industrial Internet-of-Things”, Computational Biology and Bioinformatics (Jul. 4, 2018). [cited by applicant]
Emerson & PreScouter, “Software Defined Architecture for Embedded Applications,” Research Support Service (2020). [cited by applicant]
Greevenbosch, “Use Cases and Requirements for Authentication, Authorisation and Revocation in the Internet of Things; draft-greevenbrosch-dice-authent-author-revoc-00.txt,” Standardworkingdraft, Internet Society (2013). [cited by applicant]
Hmaity et al. “Virtual Network Function Placement for Resilient Service Chain Provisioning”, 978-4673-9023-1, 2016, IEEE (Year: 2016). [cited by applicant]
Houmani et al., “Enhancing microservices architectures using data-driven service discovery and QoS guarantees”, 2020 20th IEEE/ACM International Symposium on Cluster, Cloud and Internet Computing (CCGRID), IEEE (May 11,… [cited by applicant]
International Search Report and Written Opinion for Application No. PCT/US2023/027978, dated Dec. 11, 2023. [cited by applicant]
International Search Report and Written Opinion for Application No. PCT/US2023/027988, dated Oct. 25, 2023. [cited by applicant]
International Search Report and Written Opinion for Application No. PCT/US2023/028003, dated Oct. 25, 2023. [cited by applicant]
International Search Report and Written Opinion for Application No. PCT/US2023/028005, dated Oct. 26, 2023. [cited by applicant]
International Search Report and Written Opinion for Application No. PCT/US2023/028027, dated Nov. 7, 2023. [cited by applicant]
International Search Report and Written Opinion for Application No. PCT/US2023/028029, dated Oct. 27, 2023. [cited by applicant]
International Search Report and Written Opinion for Application No. PCT/US2023/033926, dated Mar. 18, 2024. [cited by applicant]
International Search Report and Written Opinion for Application No. PCT/US2023/034272, dated Jan. 22, 2024. [cited by applicant]
International Search Report and Written Opinion for Application No. PCT/US2023/034349, dated Jan. 18, 2024. [cited by applicant]
International Search Report and Written Opinion for Application No. PCT/US2023/034351, dated Jan. 22, 2024. [cited by applicant]
International Search Report and Written Opinion for Application No. PCT/US2023/035611, dated Jan. 25, 2024. [cited by applicant]
International Search Report and Written Opinion for Application No. PCT/US2023/035613, dated Jan. 26, 2024. [cited by applicant]
International Search Report and Written Opinion for Application No. PCT/US2023/035618, dated Mar. 21, 2024. [cited by applicant]
Jairo et al., “Deliverable D1.1. Review of Reference Architectures for IoT Enabled Agriculture Development. Consultandy Design of a reference architecture for an IoT sensor network. Company International Center for Trop… [cited by applicant]
Jin et al., “Secure Edge Computing Management Based on Independent Microservices Providers for Gateway-Centric IoT Networks”, IEEE Access, IEEE, 8:187975-187990 (2020). [cited by applicant]
Kashyap: “Yokogawa Cloud Architecture for Smart Manufacturing”, Yokogawa technical report (Nov. 10, 2023). [cited by applicant]
Khalyly et al., “Smart Agent Edge Microservices Deployment pproach”, 2020 International Conference on Decision Aid Ciences and Application (DASA), IEEE (Nov. 8, 2020). [cited by applicant]
Koziolek et al., “Self-Commissioning Industrial IoT—Systems in Process Automation,” IEEE International Conference on Software Architecture, pp. 196-205 (2018). [cited by applicant]
Madiwalar et al., “Plug and produce for Industry 4.0 using software-defined networking and OPC UA”, 24th IEEE International Conference on Emerging Technologies and Factory Automation (ETFA), pp. 126-133 (Sep. 2019). [cited by applicant]
Malakuti et al., “A Four-Layer Architecture Pattern for Constructing and Managing Digital Twins,” Advances in Databases and Information Systems, 231-246 (2019). [cited by applicant]
NAMUR Recommendation, NAMUR Open Architecture NOA Concept (2020). [cited by applicant]
Pontarolli et al., “Towards Security Mechanisms for an Industrial Microservice-Oriented Architecture,” 14th IEEE International Conference on Industry Applications (2021). [cited by applicant]
Pribis et al., “An Industrial Communication Platform for Industry 4.0—Case Study,” Cybernetics & Informatics, pp. 1-8 (2020). [cited by applicant]
Profanter et al., “OPC UA for Plug & Produce: Automatic Device Discovery Using LDS-ME,” 22nd IEEE Interational Conference on Emerging Technologies and Factory Automation, pp. 1-8 (2017). [cited by applicant]
Radchenko et al., “Micro-Workflow: Kafka and Keplar Fusion to Support Digital Twins of Industrial Processes,” IEEE/ACM International Conference on Utility and Cloud Computing Companion (Dec. 17, 2018). [cited by applicant]
Search Report for Application No. GB2208755.5, dated Feb. 10, 2023. [cited by applicant]
Search Report for Application No. GB2208756.3, dated Feb. 23, 2023. [cited by applicant]
Search Report for Application No. GB2208757.1, dated Feb. 10, 2023. [cited by applicant]
Search Report for Application No. GB2208758.9, dated Dec. 16, 2022. [cited by applicant]
Search Report for Application No. GB2208759.7, dated Dec. 16, 2022. [cited by applicant]
Search Report for Application No. GB2208766.2, dated Feb. 16, 2023. [cited by applicant]
Search Report for Application No. GB2208768.8, dated Dec. 7, 2022. [cited by applicant]
Search Report for Application No. GB2208769.6, dated Dec. 7, 2022. [cited by applicant]
Search Report for Application No. GB2208770.4, dated Dec. 7, 2022. [cited by applicant]
Search Report for Application No. GB2208771.2, dated Dec. 12, 2022. [cited by applicant]
Search Report for Application No. GB2208780.3, dated Feb. 22, 2023. [cited by applicant]
Search Report for Application No. GB2208794.4, dated Jan. 17, 2023. [cited by applicant]
Search Report for Application No. GB2208795.1, dated Jan. 17, 2023. [cited by applicant]
Search Report for Application No. GB2208796.9, dated Nov. 10, 2022. [cited by applicant]
Search Report for Application No. GB2208797.7, dated Dec. 1, 2022. [cited by applicant]
Search Report for Application No. GB2208821.5, dated Mar. 31, 2023. [cited by applicant]
Search Report for Application No. GB2208856.1, dated Jan. 18, 2023. [cited by applicant]
Search Report for Application No. GB2208857.9, dated Nov. 18, 2022. [cited by applicant]
Search Report for Application No. GB2208858.7, dated Nov. 18, 2022. [cited by applicant]
Steindl et al., “Semantic Microservice Framework for Digital Twins,” Applied Sciences, 11(12):1-19 (2021). [cited by applicant]
Sung et al., “Description lookup based UPnP extension for wireless sensor networks”, Proceedings of the 2009 6th annual international mobile and ubiquitous systems: Networking & Services, MobiQuitous (Jul. 2009). [cited by applicant]
Tomarchio et al., “TORCH: A TOSCA-Based Orchestrator of Multi-Cloud Containerised Applications,” Journal of Grid Computing (2021). [cited by applicant]
Tundo et al., “Declarative Dashboard Generation,” IEEE Internation Symposium on Software Reliability Engineering Workshops (2020). [cited by applicant]
Cited By (1)
US 12,578,983