IP Library Granted Patent US 12,556,540
Granted Patent B2
US 12,556,540 · App. 18/300,037 · Granted Feb 17, 2026

Industrial automation secure remote access

Inventors: Stephen C. Briant (Corapolis, PA); Nathaniel S Sandler (Mayfield Heights, OH); Scott A. Miller (Mayfield Heights, OH); Ryan P Dunn (Mayfield Heights, OH); Bruce T. McCleave, Jr. (Mayfield Heights, OH); Nabin Acharya (San Jose, CA); Julie Nguyen (Mayfield Heights, OH)
Assignee: ROCKWELL AUTOMATION TECHNOLOGIES, INC.
H04L63/102H04L12/4641H04L63/0272
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,556,540
App. No.
18/300,037
Granted
Feb 17, 2026
Kind
B2
Abstract

An industrial information hub (IIH) and an industrial development hub (IDH) serve as an industrial ecosystem platform where multiple participants can deliver repeatable and standardized services relevant to their core competencies. The IIH system is centered around the development of an ecosystem that creates and delivers value to users—including industrial enterprises, OEMs, system integrators, vendors, etc.—through the aggregation of digital content and domain expertise. The IIH system serves as a trusted information broker between the ecosystem and the OT environments of plant facilities, and provides a platform for connecting assets, contextualizing asset data and providing secure access to the ecosystem. As part of this ecosystem, the IIH system uses a secure remote access architecture to allow users to remotely access data on their plant floor assets via a virtual private network connection.

Claims (50)

1 . A system, comprising:

a memory that stores executable components; and

a processor, operatively coupled to the memory, that executes the executable components, the executable components comprising:

a device interface component configured to communicatively connect, via a cloud platform, to gateway devices deployed at one or more industrial facilities, wherein the gateway devices are communicatively connected to industrial assets that operate at the one or more industrial facilities, and the gateway devices respectively execute secure remote access runtime services;

a user interface component configured to, in response to verification of a user identity and credential information, render a list of the industrial assets on a client device for selection;

an access management component configured to, in response to selection of a subset of the industrial assets from the list, establish a virtual private network connection between the client device and the subset of the industrial assets via a gateway device, of the gateway devices, that is communicatively connected to the subset of the industrial assets without opening an inbound port through a firewall at an industrial facility in which the gateway device resides; and

an analytics component configured to apply analytics to contextualized industrial data obtained from the subset of the industrial assets based on a simulation of a virtualized plant that executes on the cloud platform and that comprises digital asset models of the subset of the industrial assets,

wherein

the contextualized industrial data comprises industrial data and contextual metadata added to the industrial data by the gateway device,

the contextual metadata defines a mathematical correlation between two or more items of the industrial data, and

the user interface component is further configured to render, on the client device via the virtual private network connection, a unified presentation of the subset of the industrial assets based on the industrial data and to render results of the analytics via the unified presentation.

2 . The system of claim 1 , wherein the user interface component is further configured to serve a front-end interface to the client device and to receive, via interaction with the front-end interface, request data comprising the user identity and credential information.

3 . The system of claim 1 , wherein the digital asset models define visual representations and functional specification data for their corresponding industrial assets.

4 . The system of claim 1 , wherein the industrial data comprises at least one of asset status data, asset operation data, asset performance data, asset diagnostic data, or production statistics.

5 . The system of claim 1 , wherein

the user interface component is further configured to receive, from the client device, a control instruction directed to an industrial asset of the subset of the industrial assets, and

the access management component is configured to send the control instruction to the industrial asset via the virtual private network connection.

6 . The system of claim 1 , wherein the access management component is configured to execute one or more algorithms that determine an optimal connection path from the client device to the gateway device for establishment of the virtual private network connection.

7 . The system of claim 1 , wherein the contextual metadata further at least one of identifies machines from which the industrial data was generated or applies a synchronized timestamp to the industrial data.

8 . The system of claim 1 , wherein the digital asset models define at least one of respective kinematic properties or respective mechatronic properties of the subset of the industrial assets.

9 . A method, comprising:

communicatively connecting, via a cloud platform by a system comprising a processor, to gateway devices installed at one or more industrial facilities, wherein the gateway devices are communicatively connected to industrial assets that operate at the one or more industrial facilities, and the gateway devices respectively execute secure remote access runtime services;

in response to verifying a user identity and credential information, rendering, by the system, a list of the industrial assets on a client device for selection;

in response to receiving a selection of a subset of the industrial assets from the list, establishing, by the system, a virtual private network connection between a client device and the subset of the industrial asset via a gateway device, of the gateway devices, that is communicatively connected to the subset of the industrial assets without opening an inbound port through a firewall at an industrial facility in which the gateway device resides;

applying, by the system, analytics to contextualized industrial data, received from the subset of the industrial assets, based on a simulation of a virtualized plant that executes on the cloud platform and that comprises digital asset models of the subset of the industrial assets, wherein the contextualized industrial data comprises industrial data and contextual metadata added to the industrial data by the gateway device, and the contextual metadata defines a mathematical correlation between two or more items of the industrial data; and

rendering, by the system on the client device via the virtual private network connection, results of the analytics via a unified presentation of the subset of the industrial assets generated based on the contextualized industrial data.

10 . The method of claim 9 , wherein the verifying comprises:

serving a front-end interface to the client device; and

receiving, via interaction with the front-end interface, request data comprising the user identity and credential information.

11 . The method of claim 9 , wherein the contextual metadata further at least one of identifies machines from which the industrial data was generated or applies a synchronized timestamp to the industrial data.

12 . The method of claim 9 , further comprising:

receiving, by the system from the client device, a control instruction directed to an industrial asset of the subset of the industrial assets; and

sending, by the system, the control instruction to the industrial asset via the virtual private network connection.

13 . The method of claim 9 , wherein the establishing comprises executing one or more algorithms that determine an optimal connection path from the client device to the gateway device for establishing the virtual private network connection.

14 . The method of claim 9 , wherein the digital asset models define at least one of respective kinematic properties or respective mechatronic properties of the subset of the industrial assets.

15 . A non-transitory computer-readable medium having stored thereon instructions that, in response to execution, cause a system executing on a cloud platform and comprising a processor to perform operations, the operations comprising:

communicatively connecting, via a cloud platform, to gateway devices installed at one or more industrial facilities, wherein the gateway devices are communicatively connected to industrial assets that operate at the one or more industrial facilities, and the gateway devices respectively execute secure remote access runtime services;

in response to verifying a user identity and credential information, rendering a list of the industrial assets on a client device for selection;

in response to receiving a selection of a subset of the industrial assets from the list, establishing a virtual private network connection between a client device and the subset of the industrial assets via a gateway device, of the gateway devices, that is communicatively connected to the subset of the industrial asset without opening an inbound port through a firewall at an industrial facility in which the gateway device resides;

applying analytics to contextualized industrial data, received from the subset of the industrial assets, based on a simulation of a virtualized plant that executes on the cloud platform and that comprises digital asset models of the subset of the industrial assets, wherein the contextualized industrial data comprises industrial data and contextual metadata added to the industrial data by the gateway device, and the contextual metadata defines a mathematical correlation between two or more items of the industrial data; and

rendering, on the client device via the virtual private network connection, an output of the analytics via a unified presentation of the subset of the industrial assets generated based on the contextualized industrial data.

16 . The non-transitory computer-readable medium of claim 15 , wherein the verifying comprises:

serving a front-end interface to the client device; and

receiving, via interaction with the front-end interface, request data comprising the user identity and credential information.

17 . The non-transitory computer-readable medium of claim 15 , wherein the digital asset models define at least one of respective kinematic properties or respective mechatronic properties of the subset of the industrial assets.

18 . The non-transitory computer-readable medium of claim 15 , wherein the contextual metadata further at least one of identifies machines from which the industrial data was generated or applies a synchronized timestamp to the industrial data.

19 . The non-transitory computer-readable medium of claim 15 , further comprising:

receiving, from the client device, a control instruction directed to an industrial asset of the subset of the industrial assets; and

sending the control instruction to the industrial asset via the virtual private network connection.

20 . The non-transitory computer-readable medium of claim 15 , wherein the establishing comprises executing one or more algorithms that determine an optimal connection path from the client device to the gateway device for establishing the virtual private network connection.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 13, 2023
From: BRIANT, STEPHEN C; SANDLER, NATHANIEL S; MILLER, SCOTT A; DUNN, RYAN P; MCCLEAVE, BRUCE T, JR.; ACHARYA, NABIN; NGUYEN, JULIE
To: ROCKWELL AUTOMATION TECHNOLOGIES, INC.
Reel/Frame 063316/0629 →
Continuity (2)
Continuation 17376909 · Jul 15, 2021
Related Publication 20230300140A1 · Sep 21, 2023
References Cited (74)
US 8763091B1 · Singh et al. · 2014 [cited by applicant]
US 8990804B1 · Lissack et al. · 2015 [cited by applicant]
US 9148408B1 · Glazemakers · 2015 [cited by examiner]
US 9471352B1 · Mauer et al. · 2016 [cited by applicant]
US 9766912B1 · Jorgensen · 2017 [cited by applicant]
US 9858105B1 · Upadhyay et al. · 2018 [cited by applicant]
US 9996381B1 · Raju et al. · 2018 [cited by applicant]
US 10317868B2 · Schroeter et al. · 2019 [cited by applicant]
US 10965737B1 · Parulkar et al. · 2021 [cited by applicant]
US 20070142926A1 · Hopsecger · 2007 [cited by examiner]
US 20110046754A1 · Bromley · 2011 [cited by examiner]
US 20120226786A1 · Nekkar et al. · 2012 [cited by applicant]
US 20130133043A1 · Barkie et al. · 2013 [cited by applicant]
US 20130227089A1 · McLeod et al. · 2013 [cited by applicant]
US 20140280433A1 · Messerli et al. · 2014 [cited by applicant]
US 20150058467A1 · Douglas et al. · 2015 [cited by applicant]
US 20160179993A1 · Maturana et al. · 2016 [cited by applicant]
US 20160234186A1 · Leblond et al. · 2016 [cited by applicant]
US 20160274553A1 · Strohmenger · 2016 [cited by examiner]
US 20160274930A1 · Mani et al. · 2016 [cited by applicant]
US 20170025040A1 · Maturana et al. · 2017 [cited by applicant]
US 20170076235A1 · Noto et al. · 2017 [cited by applicant]
US 20170192414A1 · Mukkamala et al. · 2017 [cited by applicant]
US 20170195332A1 · Wu et al. · 2017 [cited by applicant]
US 20180024537A1 · Chauvet et al. · 2018 [cited by applicant]
US 20180262388A1 · Johnson · 2018 [cited by examiner]
US 20180316729A1 · Chauvet et al. · 2018 [cited by applicant]
US 20190041824A1 · Chavez et al. · 2019 [cited by applicant]
US 20190041830A1 · Yarvis et al. · 2019 [cited by applicant]
US 20190182106A1 · Gibson et al. · 2019 [cited by applicant]
US 20190245856A1 · Irwan · 2019 [cited by examiner]
US 20190266497A1 · Yuan et al. · 2019 [cited by applicant]
US 20190268322A1 · Leblond et al. · 2019 [cited by applicant]
US 20190317481A1 · Glas · 2019 [cited by examiner]
US 20190340269A1 · Biernat et al. · 2019 [cited by applicant]
US 20200057664A1 · Durham et al. · 2020 [cited by applicant]
US 20200125352A1 · Kannan et al. · 2020 [cited by applicant]
US 20200310849A1 · Laurence et al. · 2020 [cited by applicant]
US 20200389437A1 · Miller · 2020 [cited by examiner]
US 20210058473A1 · Yerli · 2021 [cited by applicant]
US 20210138651A1 · Mcgregor et al. · 2021 [cited by applicant]
US 20210377018A1 · Lawrence · 2021 [cited by examiner]
US 20220206470A1 · Wallace · 2022 [cited by examiner]
CA 2796554A1 · 2011 [cited by applicant]
CN 103514023A · 2014 [cited by applicant]
CN 104423370A · 2015 [cited by applicant]
CN 107589727A · 2018 [cited by applicant]
CN 113075909A · 2021 [cited by applicant]
EP 2846208A2 · 2015 [cited by applicant]
EP 3121667A1 · 2017 [cited by applicant]
WO 2011128596A1 · 2011 [cited by applicant]
WO 2020198539A1 · 2020 [cited by applicant]
Notice of Allowance received for U.S. Appl. No. 17/374,193 dated Apr. 23, 2024. [cited by applicant]
Non-Final office action received for U.S. Appl. No. 17/374,162 dated Nov. 8, 2023, 72 pages. [cited by applicant]
Communication Pursuant to Article 94(3) EPC received for EP Patent Application Serial No. 22184684.3 dated Oct. 16, 2023, 4 pages. [cited by applicant]
Zhao et al., “Liquid: A Scalable Deduplication File System for Virtual Machine Images”, IEEE, Transactions on Parallel and Distributed Systems, vol. 25, No. 5, May 2014, pp. 1257-1266. [cited by applicant]
Extended European Search Report received for European Patent Application Serial No. 22184683.5 dated Nov. 30, 2022, 9 pages. [cited by applicant]
Extended European Search Report received for European Patent Application Serial No. 22184689.2 dated Dec. 1, 2022, 8 pages. [cited by applicant]
Extended European Search Report received for European Patent Application Serial No. 22185306.2 dated Nov. 24, 2022, 7 pages. [cited by applicant]
Communication pursuant to Rule 69 EPC received for European Patent Application Serial No. 22184689.2 dated Jan. 23, 2023, 2 pages. [cited by applicant]
Communication pursuant to Rule 69 EPC received for European Patent Application Serial No. 22184683.5 dated Jan. 23, 2023, 2 pages. [cited by applicant]
Communication pursuant to Rule 69 EPC received for European Patent Application Serial No. 22184684.3 dated Jan. 23, 2023, 2 pages. [cited by applicant]
Notice of Allowance received for U.S. Appl. No. 17/376,909 dated Feb. 1, 2023, 39 pages. [cited by applicant]
Extended European Search Report received for European Patent Application Serial No. 22184684.3 dated Dec. 9, 2022, 8 pages. [cited by applicant]
Communication pursuant to Rule 69 EPC received for European Patent Application Serial No. 22185306.2 dated Jan. 23, 2023, 2 pages. [cited by applicant]
Notice of Allowance received for U.S. Appl. No. 17/374,122 dated Jan. 31, 2024, 141 pages. [cited by applicant]
Notice of Allowance received for U.S. Appl. No. 17/374,162 dated Feb. 15, 2024, 38 pages. [cited by applicant]
Pandey et al., “An Approach for Virtual Machine Image Security”, International Conference on Signal Propagation and Computer Technology, 2014, pp. 616-623. [cited by applicant]
Non Final Office Action received for U.S. Appl. No. 17/374,193 dated Jan. 30, 2024, 51 pages. [cited by applicant]
First Office Action received for Chinese Patent Application Serial No. 202210825325.8 dated Jul. 1, 2025, 12 pages (Including English Translation). [cited by applicant]
Communication Pursuant to Article 94(3) EPC received for EP Patent Application Serial No. 22185306.2 dated Aug. 26, 2025, 6 pages. [cited by applicant]
First Office Action received for Chinese Patent Application Serial No. 202210821542.X dated Jul. 17, 2025, 17 pages (Including English Translation). [cited by applicant]
Communication Pursuant to Article 94(3) EPC received for EP Patent Application Serial No. 22184684.3 dated Feb. 27, 2025, 6 pages. [cited by applicant]
Communication Pursuant to Article 94(3) EPC received for EP Patent Application Serial No. 22184689.2 dated Feb. 18, 2025, 7 pages. [cited by applicant]