Industrial Network Edge Needs to be Prepared for Internet-Enabled Strategies

Author photo: Chantal Polsonetti
By Chantal Polsonetti

Table of Contents

  • Executive Overview
  • Concrete Business Value Propositions Driving Internet-enabled Strategies
  • Internet-enabled Business Strategies Rely Heavily on the Network Edge
  • The Impact on the Edge
  • Clustered Gateway Approach Can Provide Interim Solution
  • Recommendations

Executive Overview

The industrial network edge and the devices associated with it have emerged as a primary vehicle for delivering incremental business value via internet-enabled business strategies, such as the Industrial Internet of Things (IIoT) and Industrie 4.0 (I4.0).  Digitization, IIoT, and I4.0 are increasingly seen as the means to reduce production downtime, Industrial Network Edgeincrease production flexibility, and/or achieve a connected and secure infrastructure.  To improve manufacturing business performance and product quality, manufacturers must be able to dynamically access, monitor, manage, control, and optimize the associated machines, processes, and/or end products.

These prospects herald the dawning of a new age at the industrial network edge, one that manufacturers need to heed as they prepare for and implement internet-based business strategies.  This preparation extends to ensuring that what enterprise applications view as “the network edge” meets the requirements for successfully executing connectivity-enabled business strategies. 

It is important to begin by recognizing that internet-enabled strategies represent and necessitate a departure from the traditionally vertically siloed “us” vs. “them” (production/OT vs. enterprise/IT) mentality that has historically pervaded manufacturing firms.  Success with internet-enabled business improvement requires true convergence of information technology, operational technology, and engineering technology to enable the access, transparency, security, and execution capabilities needed to deliver on its significant promise.

This has numerous implications throughout the architecture.  This report is designed to prepare those responsible for the industrial network edge portion by highlighting current and prospective demands on edge devices and how to best fulfill them.  For the purposes of this discussion, industrial network edge devices include both network edge infrastructure products, (such as gateways, routers, and switches), as well as higher-level end devices that increasingly include edge capabilities (such as PLCs, HMIs, and other microprocessor-based automation stalwarts).

Concrete Business Value Propositions Driving Internet-enabled Strategies

While the technological components of internet-driven business improvement strategies are compelling to many of us, their importance lies in their ability to generate results.  In today’s manufacturing environment, target outcomes can range from reduced operations or maintenance costs to reduced machine downtime, increased production flexibility, or migration to a service-oriented product offering. 

It is apparent from this range of potential benefits or outcomes that companies pursue internet-enabled business strategies for a variety of purposes.  Many machine builders and other asset providers already recognize the inherent value of remote monitoring and access in areas such as troubleshooting, updating, and reducing the need for field service calls.  Remote access capabilities can be used to resolve upwards of two-thirds of these calls, particularly those relating to troubleshooting, programming, or updates; while eliminating the need for support personnel to travel to the site.

Some leading edge machine builders are also pursuing the potential for customers to subscribe to service-based outcomes, such as number of pieces produced per hour, rather than simply purchasing capital equipment.  These and other manifestations of internet-based strategies have the associated benefit of increasing “stickiness” within the supplier-customer relationship as their respective activities become more intertwined.

Reduced operations and maintenance costs enabled by remote monitoring and access is a low-hanging fruit that represents a logical entry point for many connectivity-enabled automation strategies.  Industry initiatives such as the IIoT and I4.0 take this value proposition even further into areas such as reduced machine downtime and ability to market products-as-a-service (IIoT) and/or increase production flexibility to improve manufacturers’ competitiveness (I4.0).

Internet-enabled strategies have the potential to impact and benefit virtually every member of the manufacturing chain, whether supplier, OEM, system integrator, or end customer.  The potential opportunities to reduce cost, increase revenues, and enable business innovation by moving from manufactured products to subscribed outcomes are some of the most compelling within the manufacturing environment.  Current activities reveal more of an evolutionary or incremental path to internet-enabled outcomes; one that often starts with an emphasis on cost reduction, but with the potential to move into revenue increases and, ultimately, business transformation.

Internet-enabled Business Strategies Rely Heavily on the Network Edge

Connectivity, transparency, and remote access are primary enablers of many of today’s internet-enabled business improvement strategies.  Cloud integration, IT/OT/ET convergence, and the overall need to feed data from the field to enterprise-level applications are central to achieving these business objectives, as is seamless horizontal and vertical integration throughout the architecture.  Ability to develop, share, and continuously refine a digitized view of both the product and the process is inherent in the emerging concept of a “digital twin” that follows a given product or process throughout its lifecycle.  Each of these concepts relies heavily on the industrial network edge as its information conduit.

Both IIoT and I4.0 require extensive integration of field and asset data with enterprise-level business improvement applications, many of which are resident in the cloud.  Cloud-based enterprise-level business improvement strategies in the Industrial Internet age need data from edge machines, processes, and other assets and components to feed data-driven activities such as analytics.  The migration to cloud-based enterprise and other applications down to the network and device management levels is one of the main pressures driving change at the industrial edge.

Cloud-based architectures rely on the network edge to provide data communications, application integration, and security, among other key roles.  Automation professionals, suppliers, system integrators, OEM machine builders, and other members of the manufacturing value chain increasingly face the integration demands these architectures represent and recognize their impact on the evolution of the network edge architecture.  With edge and fog computing, some of the actual functionality traditionally associated with the enterprise level is migrating into edge devices themselves, resulting in even further evolution.

Formerly isolated, OT-centric installations must now respond to the need to integrate data with IT and ET.  This emphasis on communication with enterprise and other higher-level applications is partially behind the term “network edge,” since a top-down perspective from the enterprise level results in machines and other production equipment appearing at the outer edge of the architecture.

The technologies associated with each of these previously separate activities are converging simultaneously, with COTS and standard IT technologies extending further into the architecture.  This includes to traditionally dedicated edge and end devices.  Central to this migration is the need to determine where and how data is sourced and processed within the architecture and how that impacts the functional requirements of edge and end devices going forward.

This trend is evident as end user companies are already escalating connectivity requirements in their RFPs and using these new capabilities to achieve initial benefits in areas such as remote monitoring, diagnostics, and energy management that typically require remote access and incremental data gathering.  New project requisitions around the world and across industries provide concrete evidence of the need for multifold increases in device and edge connectivity and the increasing convergence at multiple levels of the architecture.

Many automation professionals saw the initial activities surrounding the Industrial Internet as an extension of long-running activities in areas such as distributed control and SCADA, which required little or no change in the established way of doing things.  It may be helpful instead to view the evolution from the perspective of the enterprise, particularly regarding the cloud’s reach into production operations.  From this viewpoint, it may be easier to appreciate use of the term “network edge” and the evolution taking place there.

The Impact on the Edge

While automated machines, controllers, sensors, and similar equipment have been in use for decades, their core architecture has traditionally relied on dedicated, automation-specific systems largely characterized by proprietary processors, operating systems, programming languages, and networks.  Migrating controllers, HMIs, and other automation and infrastructure equipment to standard microprocessors, commercial off-the-shelf operating systems, and IP-based networks has been underway for some time; but the rise of internet-enabled business improvement strategies is leading to an evolution in how we perceive the role of the automation edge. 

This applies to both the ability to seamlessly communicate between edge and enterprise and the functions that should be performed at the edge vs. in the cloud.  It also raises the prospect of industrial network edge and infrastructure devices acting as field extensions of enterprise applications.  This represents one iteration of what is now known as “edge” or “fog” computing.

To that end, the following sections are designed to alert automation professionals to emerging and anticipated requirements for industrial network edge and intelligent end devices in context of the onset of the IIoT, I4.0, and related internet-enabled manufacturing strategies.   This is not an exhaustive list of all potential future requirements, but rather guidance as to what ARC anticipates as these concepts mature.  Not surprisingly, the overarching message is that more and more IT-oriented technology will migrate into the network edge and end devices as enterprise-level applications extend their reach into the data-intensive network edge.

Industrial Network Edge

Standard IP Connectivity

Industrial networking environments have traditionally been characterized by a layered architecture populated by automation-specific networks at the lower levels and commercial Ethernet at the top.  Today, easier integration via a single, typically IP-based network environment is helping leading manufacturers meet the need to seamlessly draw data from the field all the way to enterprise applications.  Among other benefits, this reduces the potential complexity, performance degradation, and management issues associated with a tiered network structure.

Industrial automation architectures have already begun migrating toward IP connectivity via both Ethernet wireline and WiFi networks.  Industrial Ethernet continues to extend its reach from supervisory layers of the architecture into control and even I/O networks, while WiFi tends to play a greater role in remote access and mobility applications. Connectivity-dependent business improvement strategies will necessitate incremental communication capabilities at the lower levels, but a low cost per node is paramount. 

Incorporating standard IT network technology into the traditionally proprietary automation network environment provides value through network convergence across the architecture stack.  This opens the potential for a single network type throughout.  Industrial suppliers are responding to the resulting need in ways such as providing higher bandwidth devices that support appropriate form factors, standards, and protocols. 

Convergence of formerly application-specific networks onto industrial Ethernet streamlines integration, improves overall performance, and enables incremental cost savings in hardware, software, and associated personnel costs.  Reliance on a single network technology inherently entails common skill sets, training requirements, and knowledge base, a stark contrast to the formerly distinct IT and OT environments and organizations. 

Automation professionals with experience in Ethernet-based industrial networks know that not all support standard IP connectivity.  Continued use of non-standard industrial Ethernet automation networks will impede the integration necessary to achieve edge-to-cloud integration, resulting in higher costs and require more custom integration requirements. 

IEEE 802.1 TSN promises to eliminate the need for proprietary real-time implementations and potentially allow for multiple industrial application-layer protocols to run on the same network.  Many suppliers are similarly migrating their IPv4 devices to IPv6, but not all plant floor devices currently require it.

Standard Hardware/Software Platform

Extension of traditionally IT-oriented technologies into the automation network edge and end devices is true not only of networks, but also the hardware and operating system platforms resident on the devices.  Use of standard microprocessors and operating systems will be important in the internet era for those edge or end points that you anticipate may be charged with edge, fog, or overall local computing requirements beyond traditional automation or control.  Many automation suppliers have or are migrating their hardware to these standard platforms, which will be Industrial Network Edgerequired to run applications such as edge analytics and/or microservices.

As one example, a distinct new class of IoT or cloud gateways that support standard microprocessors and operating systems has emerged alongside the traditional, often serial-to-Ethernet, automation gateway.  Suppliers designing this new class of gateways increasingly incorporate Intel’s Quark, Atom, and other microprocessors in their new products.  Others have adopted standard microprocessors from ARM, Freescale, and other suppliers as low as the I/O level.

Use of the Linux operating system at the edge is another path for easing integration with the cloud.  Linux OS allows quick development of low-cost applications as suppliers offer features such as Java programmability and support of REST APIs, plus the platform benefits from a large ecosystem and developer community.  Linux adoption further enables support of the IPv6 protocol.  

Linux is already present in numerous network infrastructure devices, including gateways and switches.  Some environments, such as the Cisco IOx platform, include Linux containers to allow hosting of Linux applications.  Versions of the Linux OS environment have extended beyond network infrastructure equipment into end devices, such as PLCs and HMIs.  Some automation suppliers supply Linux-based devices with encrypted or authenticated channels or other means of appealing to the security concerns of OT professionals.

Some early IIoT network edge products also support the Microsoft Windows 10 environment.  ARC expects that most activity in the Windows 10 arena will be within that group of customers aligned with Microsoft’s architecture, particularly the Azure cloud platform that is growing in popularity in manufacturing.  Several providers of the new IoT or cloud gateway platforms, including those OEMing the Intel IoT platform, allow the customer to choose between several different OS platforms.

Standard Protocol Support

Support of numerous protocols for data and application integration are inherent in internet-enabled architectures.  Our intent here is to signal which protocols are emerging as particularly important for automation or OT devices to achieve edge-to-cloud integration.  Currently, for industrial automation applications, support for the MQTT protocol and REST Industrial Network EdgeAPIs are two important characteristics that distinguish a traditional automation device from one that is internet-ready.

While HTTP is the standard messaging protocol for internet communications, MQTT (Message Queuing Telemetry Transport) is emerging as a core enabler of IIoT and I4.0 applications.  This publish-subscribe protocol allows devices to be connected to infrastructure, rather than applications; enabling easier access to the data contained within.  A growing number of automation suppliers support MQTT in their hardware products, but customers should be aware that MQTT support alone does not guarantee interoperability.  AMQP is another consideration for more demanding messaging requirements.

REST (Representational State Transfer) APIs are similarly emerging as the technology of choice for integrating web-based applications.  REST is increasingly preferred to SOAP for this task because REST leverages less bandwidth.  The Industrial Internet Consortium’s Reference Architecture, for example, supports a REST-based architecture.  Support for RESTful APIs is currently a must to enable integration with cloud-based applications.

While not restricted to internet-enabled systems, OPC UA is also increasingly supported in Internet-enabled manufacturing architectures.  OPC UA is designed to provide multi-vendor interoperability for moving information vertically from the plant or factory floor up through the enterprise.  OPC UA is also being positioned with the emerging TSN standard to provide a unified hardware-software data integration platform.

Embedded Cloud Agent

The ability for a given device or application to integrate with cloud-based applications does not rely solely on support for the common integration protocols listed above.  Support for embedded cloud agents within the edge or end device itself provides another means, one that typically aligns with the clouds supported by your automation or infrastructure supplier of choice.

The “race to the cloud” now encompasses a battle of internet platforms extending to the industrial edge.  Suppliers are migrating cloud platform agents onto their gateways and other devices to deliver filtered output to the cloud and extend the cloud architecture to the edge.   

This is resulting in a “battle to the edge,” one that is currently most prominent between the GE Predix and the Cisco/IBM IOx/Watson IoT environments.  These suppliers are bringing their platforms to edge devices via field agents embedded in both their own and their partners’ products.  Examples include the Predix Machine agent used in network gateways from GE, Dell, and HPE, as well as the IBM Watson IoT agent resident on Cisco routers.  Leading automation supplier Siemens also offers an enterprise cloud, MindSphere, but we have yet to see evidence of its migration into end devices.

Support for embedded cloud platform agents is part of the conversation around what devices should perform what tasks and the overall edge or fog computing ability.  Depending on your choice of automation supplier, however, it may not be something you need to specify in your automation requisitions.  Some suppliers, like GE, are moving to embed the agents in all devices and then turn them on when customers subscribe to them as a service.

Visualization

While the previous sections have focused on preparing the industrial network edge for the connectivity and computing demands needed to execute internet-enabled strategies, it is important to also recognize the associated universal requirements for visualization.  This is another key flashpoint where IT and OT orientations must pursue a cohesive approach while respecting individual domain requirements.

Industrial Network EdgeThe focus here should be on ease of data integration, role-based access and visibility of performance data generated throughout the IIoT architecture.  OT stakeholders may require device management capabilities to respond to alerts, anomalies, device health issues and the like, while enterprise customers will likely require more robust reporting capabilities.  Regardless of the specifics of role-based access and visualization, a universal approach to meet the need to “present anywhere” must be shared throughout the enterprise, and even beyond to trusted suppliers.

Specific requirements include support for text, touch, and voice inputs as well as standard ways to present data and perform search queries.  These visualization standards should extend across device types from desktops to smartphones and tablets.

Security

Concerns about the security integrity of the internet-based strategies, connected devices, and unauthorized access to proprietary information are the most oft-cited obstacles to widespread adoption.  As noted in numerous ARC deliverables, security issues can undermine the primary industrial IoT value proposition of reduced unplanned downtime.

Manufacturer’s concerns about the security implications of internet-enabled strategies frequently stem from their universal connectivity and potential for access, reliance on internet technology (including cloud platforms and commercial networks), concerns about publicized breaches of internet-based solutions, and data export restrictions.  Robust cybersecurity to protect sensitive data and proprietary information is paramount. 

Other ARC reports provide extensive coverage of the industrial cybersecurity threat, including current and potential strategies for technology suppliers and users alike.  Some highlights of cybersecurity considerations at the network edge follow.  We encourage readers interested in pursuing more in-depth information on cybersecurity strategies to contact ARC or visit https://www.arcweb.com/technologies/cyber-security.

Current approaches to industrial cybersecurity emphasize stringent ac-count management and a layered approach by architecture tier.  Embedded device suppliers looking to serve internet-enabled applications focus on addressing the issue of device security through a variety of means.  These include role-based access, account management and use of commercially available anti-virus packages from suppliers such as McAfee and Symantec.  Conventional network protection products such as basic or advanced firewalls are also widely used to guard network connectivity. 

Automation software suppliers currently employ standard schemes such as https over SSL, VPNs, and 256-bit encryption.  Frequent use of mechanisms such as USB drives to introduce malicious software means that industrial cybersecurity strategies must address this form of ingress.  Industrial cybersecurity issues are also being pursued individually and collectively by organizations such as the IEC, NIST, NERC, and industry organizations such as ISA and Industrial IP Advantage.

Clustered Gateway Approach Can Provide Interim Solution

The recommendations conveyed in previous sections of this report are predicated on universal enablement throughout the manufacturing architecture, but an interim approach is emerging that can potentially offset the need to outfit the entire network edge.  This interim “hour-glass” architecture relies on gateways and routers to provide cloud integration, edge computing capabilities, robust and secure separation of the IT and OT environments, and support of many of the requirements listed previously.  Reliance on gateways for cloud integration helps offset the immediate need for other network edge devices to migrate to the standard microprocessors and operating systems necessary to achieve cloud integration, support IT-oriented integration protocols, and - ultimately - host IIoT platform agents and edge computing applications. 

One approach to what may be an interim strategy includes using the gateway or router as the focal point for IT/OT convergence, cloud integration, IP-based connectivity, and security.  We see evidence of this in the popularity of products such as the Intel IoT gateway platform, OEMed by providers such as Advantech, Dell, GE, HPE, etc., where the gateway plays a crucial role in providing these functionalities. 

Industrial Network Edge

While some traditional automation gateways are moving toward incorporating these capabilities, in some cases these IoT or cloud gateways are inserted as an interim architectural tier at a layer above.  We saw one example of this at the 2017 ARC Industry Forum in Orlando, where an Emerson steam trap monitoring application was depicted with the Dell Edge Gateway residing above an Emerson wireless automation gateway.  The Emerson gateway performed the HART-IP-to-wireless conversion while the Dell box handled the IIoT integration.

It is relatively simple in today’s market to specify and outfit devices for use in an internet-enabled architecture, but the gateway approach will be instrumental to incorporating the large number of legacy installed devices that cannot currently be accessed.  Gateways can perform the network and protocol conversion necessary to expose and make use of stranded data in existing devices and to cost-effectively add new devices to existing systems that could ultimately extend their life and value.  The new IIoT or cloud gateways can further provide legacy installations with the protocol support, edge computing platforms, and requisite security mechanisms necessary to incorporate them into the IIoT or I4.0.

Recommendations

This report is intended to provide an entry point for OT professionals evaluating emerging requirements for industrial network edge devices given the advent of internet-enabled strategies such as IIoT and I4.0.  ARC publishes numerous technology selection guides that provide detailed requirements for a given type of hardware or software that should be also consulted when making purchase decisions. 

The following recommendations expand upon the overall principles emphasized in this report:

  • Begin by evaluating how to approach edge-to-cloud integration, including support of fundamental standards such as MQTT and REST APIs as well as the potential to incorporate embedded cloud platform agents at the edge.
  • Pursue IT/OT/ET collaboration as soon as possible, not only to harmonize data access and visualization requirements, but also to rationalize what data should be processed where.  This, in turn, will drive any edge computing requirements necessary to support enterprise applications while maintaining OT environment integrity.
  • Security schemes that protect the interests of all stakeholders must be part of the IT/OT/ET discussion.  All parties need to be assured that their operations are not interrupted, their people are not exposed to undue risk, and their intellectual property and critical data are not compromised.  As noted in ARC’s extensive cybersecurity coverage, we endorse a defense-in-depth approach that recognizes that there’s no single solution for securing industrial control systems.  Given the preponderance of partnership offerings, it is also important that your supplier security requirements extend across their value chain.
  • In addition to ARC’s selection guides, leverage the numerous industry activities relevant to IIoT and I4.0 adoption.  Examples include the Reference Architecture, Industrial Connectivity Framework, testbed results, and other activities of the Industrial Internet Consortium (http://www.iiconsortium.org); the internet connectivity skills training offered by Industrial IP Advantage (http://www.industrial-ip.org) and many other OT-specific activities.
  • Make every effort to reduce the complexity associated with implementing internet-enabled strategies for OT professionals.  This includes insulating them by relying on universal visualization tools and common industry standards throughout the architecture.
  • Watch for cloud integration’s emergence as the next vendor lock on automation systems.  This will be of concern as embedded cloud agents continue to forge their way further into edge devices.

 

If you would like to buy this report or obtain information about how to become a client, please  Contact Us

Engage with ARC Advisory Group

Representative End User Clients
Representative Automation Clients
Representative Software Clients