WO2018024809A1

Industrial software defined networking architecture for deployment in a software defined automation system

Abstract

An industrial software defined network (SDN) architecture, system and methods for centralized and simplified management of an industrial network is disclosed. The industrial SDN architecture comprises of an infrastructure plane including physical and virtual devices, a control plane comprising controllers to control and manage the physical and virtual devices in the infrastructure plane, the logically centralized controllers including a network controller, a virtualization management controller and a cybersecurity controller, an application plane comprising one or more end user industrial applications, and a platform plane comprising a set of software services and application programming interfaces (APIs) to define a communication interface to the application plane to the north and the control plane to the south to provide an industrial application in the application plane programmatic access to one or more of the plurality of the controllers in the control plane for simplified and centralized management of the industrial network.

WO2018024809A1, drawing sheet 1
Sheet 1 of 43

Term

No projected expiry on record.

  1. Priority
  2. Filed
  3. Published
  4. Today

24 claims: 5 independent, 19 dependent

  1. 1
    CLAIMSWe claim:1. An industrial network architecture for centralized and simplified management of an industrial network comprising: an infrastructure plane including physical and virtual devices connected to an industrial network;a control plane comprising a plurality of controllers to control and manage the physical and virtual devices in the infrastructure plane, the plurality of logically centralized controllers including a network controller, a virtualization management controller and a cybersecurity controller;an application plane comprising one or more end user industrial applications;and a platform plane comprising a set of software services and application programming interfaces (APIs) to define a communication interface to the application plane to the north and the control plane to the south to provide an industrial application in the application plane programmatic access to one or more of the plurality of the controllers in the control plane for simplified and centralized management of the industrial network.
  2. 2
    The industrial network architecture of claim l, wherein the cybersecurity controller is communicatively coupled to the network controller and the virtualization management controller, wherein the cybersecurity controller through the network controller controls accessibility, usage and content of communication handled by the physical and virtual devices in the infrastructure plane.
  3. 11
    A method for simplifying network infrastructure deployment and maintenance in an industrial domain comprising:receiving by an industrial software defined networking application (ISDNA) at least one user- defined communication criteria for an automation system deployment, the user- defined communication criteria being received from an industrial application, wherein the automation system deployment includes at least a first industrial device and a second industrial device connected to an industrial software defined network (SDN);coordinating with an SDN controller to determine a communication path between the first industrial device and the second industrial device of the automation system deployment, the communication path being determined based on the at least one user-defined communication criteria;and interacting with one or more network devices to define the communication path to enable communication between the first industrial device and the second industrial device.
  4. 12
    The method of claim n, wherein the at least one user-defined communication criteria includes load, quality of service, network device capabilities or time-sensitivity.
  5. 15
    A method for simplifying management of an industrial network comprising:detecting presence of a new industrial device in an industrial network;determining by an authentication service that the new industrial device is authorized to participate in the industrial network;determining attributes of the new industrial device and its industrial function;identifying based on the attributes of the new industrial device at least one resource required by the new industrial device to perform its industrial function;and provisioning a network path to the at least one resource to enable the new industrial device to perform its industrial function in the industrial network.