IP Library Patent Application 18223416
Patent Application
App. No. 18/223,416

Monitoring and Operational Functionalities for an Enterprise Using Process Control or Automation System

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
18/223,416
Filed
Jul 18, 2023
Art Unit
2116
USPC
700/2
Abstract

A process plant and industrial control system architecture includes a generalized compute fabric that is agnostic or indifferent to the physical location at which the compute fabric is implemented, includes one or more physical control or field devices located at one or more specific sites at which a product or process is being manufactured and further includes a transport network that securely provides communications between the compute fabric and the pool of physical devices. The compute fabric includes an application layer that includes configured containers or containerized software modules that perform various control, monitoring and configuration activities with respect to one or more devices, control strategies and control loops, sites, plants, or facilities at which control is performed, and includes a physical layer including computer processing and data storage equipment that can be located at any desired location, including at or near a site, plant, or facility at which control is being performed, at a dedicated location away from the location at which control is being performed, in re-assignable computer equipment provided in the cloud, or any combination thereof. This control architecture enables significant amounts of both computer processing and IT infrastructure that is used to support a process plant, an industrial control facility or other automation facility to be implemented in a shared, in an offsite and/or in a virtualized manner that alleviates many of the communications and security issues present in current process and industrial control systems that attempt to implement control with shared or virtualized computing resources set up according to the well-known Purdue model. The industrial control system architecture is protected via more secure and customizable techniques as compared to those used in Purdue model-based control systems. For example, communications between any (and in some cases, all) endpoints of the system may be protected via one or more virtual private networks to which authenticated endpoints must be authorized to access. Endpoints may include, for example, containerized components, physical components, devices, sites or locations, the compute fabric, and the like, and the VPNs may include mutually-exclusive and/or nested VPNs. External applications and services, whether automated or executing under the purview of a person, may access information and services provided by the system via only APIs, and different sets of APIs may be exposed to different users that have been authenticated and authorized to access respective sets of APIs. A configuration system operates within the compute fabric to enable a user to easily make configuration changes to the compute fabric as the user does not generally need to specify the computer hardware within the compute fabric to use to make the configuration changes, making it possible for the user to deploy new configuration elements with simple programming steps, and in some cases with the push of a button.

Claims (61)

1 . A process control or automation system comprising:

a first plurality of instantiated micro-encapsulated execution environments (MEEEs) communicatively connected to a plurality of physical devices located across a plurality of physical locations or sites, the plurality of physical devices performing respective physical functions to implement a plurality of industrial or automation processes of an enterprise at respective ones of the plurality of physical locations or sites.

2 . The process control or automation system of claim 1 , wherein the first plurality of instantiated MEEEs communicate with the plurality of physical devices via a first one or more secured point-to-point (PTP) or peer-to-peer (P2P) connections.

3 . The process control or automation system of claim 2 , wherein each the first one or more secured PTP or P2P connections comprise a first one or more virtual private networks (VPNs).

4 . The process control or automation system of claim 2 , wherein the first one or more secured PTP or P2P connections are a first plurality of secured PTP or P2P connections, wherein each respective one of the first plurality of secured PTP or P2P connections is exclusive to a respective one of the first plurality of instantiated MEEEs and a respective one of the plurality of physical devices.

5 . The process control or management functionality of claim 1 , wherein the first plurality of instantiated MEEEs execute at one or more of the plurality of physical locations or sites.

6 . The process control or automation system of claim 1 , wherein the first plurality of instantiated MEEEs execute to provide unidirectional or bidirectional communications between an enterprise computing device and the plurality of physical devices across the plurality of physical locations or sites.

7 . The process control or automation system of claim 6 , wherein the enterprise computing device is located at a further physical location or site remote from the plurality of physical locations or sites.

8 . The process control or automation system of claim 6 , wherein the enterprise computing device communicates with the first plurality of instantiated MEEEs via a second one or more secured point-to-point (PTP) or peer-to-peer (P2P) connections.

9 . The process control or automation system of claim 8 , wherein each the second one or more secured PTP or P2P connections comprise a second one or more virtual private networks (VPNs).

10 . The process control or automation system of claim 8 , wherein the second one or more secured PTP or P2P connections are a second plurality of secured PTP or P2P connections, wherein each respective one of the second plurality of secured PTP or P2P connections is exclusive to the enterprise computing device and a respective one of the first plurality of instantiated MEEEs.

11 . The process control or automation system of claim 6 , wherein the first plurality of instantiated MEEEs provides, to the enterprise computing device, information associated with operation of the plurality of physical locations or sites, the information including one or more of process configuration information, process setpoints, real-time process measurements, historical process data, process quality metrics, physical device statuses, process alarms, network traffic information, site safety information, or site security information.

12 . The process control or automation system of claim 6 , wherein the first plurality of instantiated MEEEs enables the enterprise computing device to define one or more hardware or software configuration parameters for each of the plurality of physical locations or sites.

13 . The process control or automation system of claim 6 , wherein the first plurality of instantiated MEEEs provides, to the enterprise computing device, a process configuration functionality to define respective control routines for the plurality of industrial or automation processes.

14 . The process control or automation system of claim 13 , wherein the process configuration functionality enables a user of the enterprise computing device to use a library of template objects to configure control routines across the plurality of industrial or automation processes at the plurality of physical locations or sites.

15 . The process control or automation system of claim 6 , wherein the first plurality of instantiated MEEEs provides, to the enterprise computing device, a hierarchical representation of the plurality of physical locations or sites, the plurality of industrial or automation processes, or the plurality of physical devices.

16 . The process control or automation system of claim 6 , wherein the first plurality of instantiated MEEEs provides, to the enterprise computing device, a simulation or testing functionality to simulate or test operation of at least a first one of the plurality of industrial or automation processes.

17 . The process control or automation system of claim 16 , wherein the simulation or testing functionality simulates or tests operation of the first one of the plurality of industrial or automation processes according to a control routine or control parameter of a second one of the plurality of industrial or automation processes.

18 . The process control or automation system of claim 6 , wherein the first plurality of instantiated MEEEs provides, to the enterprise computing device, a personnel management functionality to view or configure personnel shift assignments, access permissions, task assignments, or instructions for personnel across the plurality of physical locations or sites.

19 . The process control or automation system of claim 6 , wherein the first plurality of instantiated MEEEs provides, to the enterprise computing device, a display creation functionality to configure one or more process displays for viewing information associated with operation of at least one of the plurality of industrial or automation processes.

20 . The process control or automation system of claim 6 , wherein the first plurality of instantiated MEEEs provides, to the enterprise computing device, a diagnostics or analytics functionality to perform diagnostics or analytics upon first data generated during operation of at least a first one of the plurality of industrial or automation processes.

21 . The process control or automation system of claim 20 , wherein the diagnostics or analytics functionality performs diagnostics or analytics upon the first data based upon comparison to data generated during operation of a second one or more of the plurality of industrial or automation processes across the plurality of physical locations or sites.

22 . The process control or automation system of claim 20 , wherein the diagnostics or analytics functionality recommends an application or service recommendation for one or more of the plurality of industrial or automation processes based upon the performed diagnostics or analytics.

23 . The process control or automation system of claim 6 , wherein the first plurality of instantiated MEEEs provides, to the enterprise computing device, an application or service marketplace functionality to obtain one or more applications or services and push the obtained one or more applications or services to one or more of the plurality of industrial or automation processes.

24 . The process control or automation system of claim 6 , wherein the first plurality of instantiated MEEEs provides, to the enterprise computing device, a data governance functionality to allow a user of the enterprise computing device to define data management policies for one or more of plurality of industrial or automation processes or one or more of the plurality of physical locations or sites.

25 . The process control or automation system of claim 6 , wherein the first plurality of instantiated MEEEs provides, to the enterprise computing device, a process commissioning functionality to commission or decommission at least one of the plurality of industrial or automation processes.

26 . The process control or automation system of claim 6 , further comprising a second one or more instantiated MEEEs, wherein the first plurality of instantiated MEEEs provides, to the enterprise computing device, a service allocation functionality to move or copy execution of the second one or more instantiated MEEEs across the plurality of physical locations or sites.

27 . The process control or automation system of claim 6 , wherein access of the enterprise computing device to at least a portion of the first plurality of instantiated MEEEs is enabled via a role-based authorization of the enterprise computing device or a first user thereof.

28 . The process control or automation system of claim 27 , wherein the first plurality of instantiated MEEEs provide a role-based authorization management functionality to transfer access to the at least the portion of the plurality of instantiated MEEEs from the enterprise computing device or first user to a second enterprise computing device or a second user thereof.

29 . The process control or automation system of claim 28 , wherein the enterprise computing device or first user is located remotely from the second enterprise computing device or second user, and wherein the role-based authorization management functionality is configured to transfer role-based authorization from the enterprise computing device or first user to the second enterprise computing device or second user at a predetermined time based upon locations of the first enterprise computing device and the second computing device.

30 . A method comprising:

instantiating a first plurality of micro-encapsulated execution environments (MEEEs) to communicatively connect to a plurality of physical devices located across a plurality of physical locations or sites, the plurality of physical devices performing respective physical functions to implement a plurality of industrial or automation processes of an enterprise at respective ones of the plurality of physical locations or sites.

31 . The method of claim 30 , wherein the first plurality of instantiated MEEEs communicate with the plurality of physical devices via a first one or more secured point-to-point (PTP) or peer-to-peer (P2P) connections.

32 . The method of claim 31 , wherein each the first one or more secured PTP or P2P connections comprise a first one or more virtual private networks (VPNs).

33 . The method of claim 31 , wherein the first one or more secured PTP or P2P connections are a first plurality of secured PTP or P2P connections, wherein each respective one of the first plurality of secured PTP or P2P connections is exclusive to a respective one of the first plurality of instantiated MEEEs and a respective one of the plurality of physical devices.

34 . The method of claim 30 , wherein the first plurality of instantiated MEEEs execute at one or more of the plurality of physical locations or sites.

35 . The method of claim 30 , further comprising, via the first plurality of instantiated MEEEs, providing unidirectional or bidirectional communications between an enterprise computing device and the plurality of physical devices across the plurality of physical locations or sites.

36 . The method of claim 35 , wherein the enterprise computing device is located at a further physical location or site remote from the plurality of physical locations or sites.

37 . The method of claim 35 , wherein the enterprise computing device communicates with the first plurality of instantiated MEEEs via a second one or more secured point-to-point (PTP) or peer-to-peer (P2P) connections.

38 . The method of claim 37 , wherein each the second one or more secured PTP or P2P connections comprise a second one or more virtual private networks (VPNs).

39 . The method of claim 37 , wherein the second one or more secured PTP or P2P connections are a second plurality of secured PTP or P2P connections, wherein each respective one of the second plurality of secured PTP or P2P connections is exclusive to the enterprise computing device and a respective one of the first plurality of instantiated MEEEs.

40 . The method of claim 35 , further comprising, via the first plurality of instantiated MEEEs:

providing, to the enterprise computing device, information associated with operation of the plurality of physical locations or sites, the information including one or more of process configuration information, process setpoints, real-time process measurements, historical process data, process quality metrics, physical device statuses, process alarms, network traffic information, site safety information, or site security information.

41 . The method of claim 35 , further comprising, via the first plurality of instantiated MEEEs, enabling the enterprise computing device to define one or more hardware or software configuration parameters for each of the plurality of physical locations or sites.

42 . The method of claim 35 , further comprising, via the first plurality of instantiated MEEEs, providing, to the enterprise computing device, a process configuration functionality to define respective control routines for the plurality of industrial or automation processes.

43 . The method of claim 42 , wherein the process configuration functionality enables a user of the enterprise computing device to use a library of template objects to configure control routines across the plurality of industrial or automation processes at the plurality of physical locations or sites.

44 . The method of claim 35 , further comprising, via the first plurality of instantiated MEEEs, providing, to the enterprise computing device, a hierarchical representation of the plurality of physical locations or sites, the plurality of industrial or automation processes, or the plurality of physical devices.

45 . The method of claim 35 , further comprising, via the first plurality of instantiated MEEEs, providing, to the enterprise computing device, a simulation or testing functionality to simulate or test operation of at least a first one of the plurality of industrial or automation processes.

46 . The method of claim 45 , wherein the simulation or testing functionality simulates or tests operation of the first one of the plurality of industrial or automation processes according to a control routine or control parameter of a second one of the plurality of industrial or automation processes.

47 . The method of claim 35 , further comprising, via the first plurality of instantiated MEEEs, providing, to the enterprise computing device, a personnel management functionality to view or configure personnel shift assignments, access permissions, task assignments, or instructions for personnel across the plurality of physical locations or sites.

48 . The method of claim 35 , further comprising, via the first plurality of instantiated MEEEs, providing, to the enterprise computing device, a display creation functionality to configure one or more process displays for viewing information associated with operation of at least one of the plurality of industrial or automation processes.

49 . The method of claim 35 , further comprising, via the first plurality of instantiated MEEEs, providing, to the enterprise computing device, a diagnostics or analytics functionality to perform diagnostics or analytics upon first data generated during operation of at least a first one of the plurality of industrial or automation processes.

50 . The method of claim 49 , wherein the diagnostics or analytics functionality performs diagnostics or analytics upon the first data based upon comparison to data generated during operation of a second one or more of the plurality of industrial or automation processes across the plurality of physical locations or sites.

51 . The method of claim 49 , wherein the diagnostics or analytics functionality recommends an application or service recommendation for one or more of the plurality of industrial or automation processes based upon the performed diagnostics or analytics.

52 . The method of claim 35 , further comprising, via the first plurality of instantiated MEEEs, providing, to the enterprise computing device, an application or service marketplace functionality to obtain one or more applications or services and push the obtained one or more applications or services to one or more of the plurality of industrial or automation processes.

53 . The method of claim 35 , further comprising, via the first plurality of instantiated MEEEs, providing, to the enterprise computing device, a data governance functionality to allow a user of the enterprise computing device to define data management policies for one or more of plurality of industrial or automation processes or one or more of the plurality of physical locations or sites.

54 . The method of claim 35 , further comprising, via the first plurality of instantiated MEEEs, providing, to the enterprise computing device, a process commissioning functionality to commission or decommission at least one of the plurality of industrial or automation processes.

55 . The method of claim 35 , further comprising, via the first plurality of instantiated MEEEs, providing, to the enterprise computing device, a service allocation functionality to move or copy execution of a second one or more instantiated MEEEs across the plurality of physical locations or sites.

56 . The method of claim 35 , wherein access of the enterprise computing device to at least a portion of the first plurality of instantiated MEEEs is enabled via a role-based authorization of the enterprise computing device or a first user thereof.

57 . The method of claim 56 , wherein the first plurality of instantiated MEEEs provide a role-based authorization management functionality to transfer access to the at least the portion of the plurality of instantiated MEEEs from the enterprise computing device or first user to a second enterprise computing device or a second user thereof.

58 . The method of claim 57 , wherein the enterprise computing device or first user is located remotely from the second enterprise computing device or second user, and wherein the role-based authorization management functionality is configured to transfer role-based authorization from the enterprise computing device or first user to the second enterprise computing device or second user at a predetermined time based upon locations of the first enterprise computing device and the second computing device.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 21, 2023
From: CAPOCCIA, BRIAN M.; LAMOTHE, BRIAN; DORAISWAMY, NARAYANAN; NIXON, MARK J.; HARTMANN, PETER
To: FISHER-ROSEMOUNT SYSTEMS, INC.
Reel/Frame 064337/0234 →