IP Library Granted Patent US 11,436,321
Granted Patent B2
US 11,436,321 · App. 16/448,301 · Granted Sep 6, 2022

Safe guard detection for unexpected operations in a MES system

Inventors: Matteo Bardini (Genoa, IT); Alessio Dellacha′ (Genoa, IT); Corrado Tasca (Genoa, IT); Davide Risso (Genoa, IT)
Assignee: Siemens Aktiengesellschaft
G06F21/554G05B19/41865G05B19/41885G06N20/00G05B2219/23317
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,436,321
App. No.
16/448,301
Granted
Sep 6, 2022
Kind
B2
Abstract

A method for performing a safe guard detection of unexpected operations launched by an operator for a manufacturing execution system (MED system) is based on a first database containing a set of operations, a set of operators, calendar information for a shift and calendar information for the equipment of the MES-system. The MES-systems further has a second database containing a login history of carried out logins of the operator. The detection of a malicious operation is carried out as to whether the operation complies with a set of rules defining allowed operations or with a learning module, in which specific roles of operators are contained and whether an operation complies with a specific role. In case of non-compliance, the operation is stored as an entry in an event trace file for generating alerts.

Claims (49)

1. A method for a safe guard detection of unexpected operations launched by an operator for a manufacturing execution system (MES-System), wherein the MES-System includes:

a first database including:

a set of operations;

a set of operators;

calendar information for a shift;

calendar information for equipment of the MES-System;

a second database including:

a login history of carried out logins of the operator;

a set of rules defining allowed combinations of operations being launched by the operator at a specific time according to a content of the first database;

which method comprises the steps of:

checking launched operations as to whether the launched operations comply with the set of rules;

storing a launched operation together with data identifying the operator and operator login data as an entry in an event trace file in case of non-compliance of the launched operation;

analyzing entries in the event trace file by an intrusion detection system;

generating alerts based on an analysis of the entries in the event trace file; and

wherein the step of checking launched operations includes at least one step selected from the group consisting of:

1) crosschecking of logins for detecting, whether the operator logs-in himself at different places at a same time where such simultaneous logins may not be expected,

2) determining whether an operation complies with an order scheduling being defined by the calendar information in the first database, and

3) performing a comparison of a login time of the operator with the calendar information for a shift stored in the first database.

2. The method according to claim 1 , wherein the step of checking launched operations includes the step of crosschecking of logins for detecting, whether the operator logs-in himself at different places at a same time where such simultaneous logins may not be expected.

3. The method according to claim 1 , wherein the step of checking launched operations includes the step of determining whether an operation complies with an order scheduling being defined by the calendar information in the first database.

4. The method according to claim 1 , wherein the step of checking launched operations includes the step of performing a comparison of a login time of the operator with the calendar information for a shift stored in the first database.

5. A method for a safe guard detection of unexpected operations launched by an operator for a manufacturing execution system (MES-System), where the MES-System includes:

a first database including:

a set of operations;

a set of operators;

calendar information for a shift;

calendar information for equipment of the MES-System;

a second database including a login history of carried out logins of the operator;

a machine learning model;

which method comprises the steps of:

cataloging the operator in a given role in the MES-System;

feeding, in a learning phase, a learning module being part of a machine learning model with launched operations for that role;

checking, in a run time phase, the launched operations as to whether the launched operations comply with the operations in the learning module;

storing a launched operation together with data identifying the operator and operator login data as an entry in an event trace file in case of non-compliance of the launched operation;

analyzing entries in the event trace repository by an intrusion detection system and based on an analysis generating alerts; and

wherein the step of checking the launched operations includes at least one step selected from the group consisting of:

1) crosschecking of logins for detecting, whether the operator logs-in himself at different places at a same time where such simultaneous logins may not be expected,

2) determining whether an operation complies with an order scheduling being defined by the calendar information in the first database, and

3) performing a comparison of a login time of the operator with the calendar information for a shift stored in the first database.

6. The method according to claim 5 , which further comprises repeating the learning phase in order to get a refinement of allowed operations.

7. The method according to claim 5 , wherein the machine learning model input comprises:

a user role;

operations to be performed or launched; and

a time frame.

8. The method according to claim 5 , wherein the step of checking launched operations includes the step of crosschecking of logins for detecting, whether the operator logs-in himself at different places at a same time where such simultaneous logins may not be expected.

9. The method according to claim 5 , wherein the step of checking launched operations includes the step of determining whether an operation complies with an order scheduling being defined by the calendar information in the first database.

10. The method according to claim 5 , wherein the step of checking launched operations includes the step of performing a comparison of a login time of the operator with the calendar information for a shift stored in the first database.

11. The method according to claim 10 , wherein the calendar information for the shift indicates whether the operator is meant to be at work and a geographical area at which the operator is expected to be at work.

12. The method according to claim 4 , wherein the calendar information for the shift indicates whether the operator is meant to be at work and a geographical area at which the operator is expected to be at work.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 16, 2019
From: SIEMENS INDUSTRY SOFTWARE S.R.L.
To: SIEMENS AKTIENGESELLSCHAFT
Reel/Frame 050069/0837 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 8, 2019
From: BARDINI, MATTEO; DELLACHA, ALESSIO; TASCA, CORRADO; RISSO, DAVIDE
To: SIEMENS INDUSTRY SOFTWRE S.R.L.
Reel/Frame 049683/0399 →
Priority Claims (1)
EP 18178935 · Jun 21, 2018 · regional
Continuity (1)
Related Publication 20190392141A1 · Dec 26, 2019