EP4423638A1 - Behälterbehandlungsanlage mit wenigstens einer behälterbehandlungsmaschine zum behandeln von behältern und einem zentralen rechtezuweisungssystem - Google Patents
Behälterbehandlungsanlage mit wenigstens einer behälterbehandlungsmaschine zum behandeln von behältern und einem zentralen rechtezuweisungssystemInfo
- Publication number
- EP4423638A1 EP4423638A1 EP22809773.9A EP22809773A EP4423638A1 EP 4423638 A1 EP4423638 A1 EP 4423638A1 EP 22809773 A EP22809773 A EP 22809773A EP 4423638 A1 EP4423638 A1 EP 4423638A1
- Authority
- EP
- European Patent Office
- Prior art keywords
- user
- container treatment
- rights
- access
- central
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Pending
Links
Classifications
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/30—Authentication, i.e. establishing the identity or authorisation of security principals
- G06F21/31—User authentication
-
- B—PERFORMING OPERATIONS; TRANSPORTING
- B65—CONVEYING; PACKING; STORING; HANDLING THIN OR FILAMENTARY MATERIAL
- B65B—MACHINES, APPARATUS OR DEVICES FOR, OR METHODS OF, PACKAGING ARTICLES OR MATERIALS; UNPACKING
- B65B57/00—Automatic control, checking, warning, or safety devices
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/30—Authentication, i.e. establishing the identity or authorisation of security principals
- G06F21/31—User authentication
- G06F21/34—User authentication involving the use of external additional devices, e.g. dongles or smart cards
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F2221/00—Indexing scheme relating to security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F2221/21—Indexing scheme relating to G06F21/00 and subgroups addressing additional information or applications relating to security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F2221/2141—Access rights, e.g. capability lists, access control lists, access tables, access matrices
Definitions
- Container treatment system with at least one container treatment machine for treating containers and a central rights assignment system
- the present invention relates to a container treatment system comprising at least one container treatment machine for treating containers and a central rights assignment system according to independent claim 1, and a method for operating a container treatment system, comprising the container treatment machine and a central rights assignment system according to independent claim 8, and an identification element according to independent claim 15 .
- Container treatment systems with one or more container treatment machines are well known from the prior art.
- the container treatment machines include, in particular, machines that can produce or process containers from plastics, such as PET, or other materials, such as glass. Processing includes in particular the filling and decorating (e.g. labeling or printing) of parts of the container surface. Other container treatment machines that can inspect or pack containers or process them in some other way are known.
- container treatment systems comprising a number of container treatment machines
- access rights to each container treatment machine, which depend, for example, on their qualifications or on a corresponding security clearance by the user.
- the former may usually only access functions of a container treatment machine that are relevant for maintenance, with administrators usually having more extensive access rights that also allow, for example, the setting and changing of operating parameters of one or more container treatment machines.
- the technical problem to be solved is to specify a container treatment system that allows flexible granting of access rights to the container treatment machines of the container treatment system, but at the same time allows safe and less error-prone operation of the container treatment system.
- the container treatment system comprising at least one container treatment machine and a central rights assignment system according to claim 1, and the method for operating a container treatment machine of a container treatment plant comprising the container treatment machine and a central rights assignment system according to claim 8, and the identification element according to claim 15.
- Advantageous developments of the invention are included in the dependent claims.
- the container treatment system comprises at least one container treatment machine for treating containers and a central rights assignment system, the container treatment machine comprising a user interface for recognizing an identification element and for entering a user password, and the container treatment machine being designed based on a recognized identification element and/or a recognized user password identification data of a user to the central rights assignment system, the central rights assignment system being designed to send access data to the container treatment machine based on the identification data received from a user, the access data defining group-based and/or user-based access rights for the container treatment machine, and the container treatment machine being designed to grant access rights for a user depending on the access data received.
- the container treatment machine can be understood as any type of machine that enables containers to be treated. These include container treatment machines that are known in particular in the beverage processing industry and that produce containers from a raw material such as PET, for example. These can be, for example, stretch blow molding machines or injection molding machines or include them, the latter first creating preforms from PET and then the stretch blow molding machines, for example using a stretch blow molding process, form containers from the preforms. However, the container treatment machines also include filling machines that fill containers and cappers that enable a filled container to be sealed. The container treatment machines should also include any inspection machines for inspecting containers (regardless of whether they are already filled or unfilled), as well as decoration machines for applying decorative elements to such containers and other machines that enable the filled and closed and possibly decorated containers to be inspected or packed, to count.
- container treatment machines that are known in particular in the beverage processing industry and that produce containers from a raw material such as PET, for example. These can be, for example, stretch blow molding machines or injection molding machines or include them, the latter first creating preforms from PET
- the container treatment system is therefore fundamentally not limited in terms of the type of container treatment machines and the number of container treatment machines.
- the container treatment system comprises several container treatment machines of the same type.
- the type of container treatment machine or the type of container treatment machine can be understood in particular in such a way that all container treatment machines that can carry out the same treatment of a container belong to the same type of container treatment machine.
- blow molding machines can represent a type of container treatment machine while cappers represent a different type of container handling machine.
- a distinction can also be made between different versions of container treatment machines of the same type defined in this way.
- a first (sub)type of container treatment machines can comprise a group of blow molding machines that can produce containers of a certain type (size, shape or the like) from preforms.
- a second group or a second (sub)type of container treatment machines can then be formed by a second number of blow molding machines that produce a different type of container (possibly also from other preforms).
- the types of container treatment machines can be differentiated according to the technical specifications of the container treatment machines, so that the same or essentially the same container treatment machines are assigned to the same type.
- the central rights assignment system is preferably provided independently of each container treatment machine in the container treatment system (in particular physically and/or logically separately) and is connected to the container treatment machines in the container treatment system via suitable data transfer lines, such as Ethernet connections or WLAN connections. It can preferably be provided that direct access to the central rights assignment system via a container treatment machine is not possible.
- the identification element can preferably be embodied as a physical identification element and, for example, but not necessarily include an RFID chip or a transponder. These can advantageously be integrated into a user ID card. Furthermore, smartphones, smartwatches, devices in general that are equipped with an NFC chip, and all other devices that allow coding and reading of the coding can also be used as identification elements as identification elements.
- one of these two options for identification can also be replaced by a biometric characteristic of a user, for example an iris scan, a fingerprint, facial recognition or the like.
- Group-based access rights are to be understood below in such a way that these access rights are or are assigned to specific groups of users who, for example with regard to the tasks to be performed by them or their qualifications.
- a first group of users can be a group of people who are usually assigned maintenance tasks for container treatment machines. These can be assigned to a group, whereby each member of the group can then have the same access rights.
- User-based access rights should be understood as access rights that are assigned to a specific user, i.e. individualized in this sense. Provision can be made for a user to have user-based access rights or to have them assigned to them, and for the user to be assigned to a specific group of users at the same time, with the user-based access rights going beyond the specific access rights or otherwise belonging to the same group of users Restrict rights available to users.
- all access rights assigned to a user can be summarized or stored in an associated user profile, with the user profile preferably being stored in the central rights allocation system or an associated memory.
- the user in turn, can be stored in the central rights assignment system as belonging to a specific group. For this purpose, for example, an entry in the user profile can be provided or the name of the user or another identification of the user can be stored in a data structure that identifies the members of the group to which the user belongs.
- an individualization of the user interface after logging on to a container treatment machine can also be provided.
- an individualized user interface can be displayed after a specific user has logged on. It is also possible that with an already existing user interface, depending on the assigned access rights, certain user interface elements, such as menus or parts of menus, certain menu elements (such as interactive user interface elements) and/or certain information are not displayed or are displayed in addition to the existing elements of the user interface are displayed.
- the central rights assignment system in which the user's access data is stored, enables central assignment of access rights for each of the container treatment machines in a container treatment system, with individualization of user rights still being ensured.
- this central assignment of rights increases the security of the entire container treatment system, since access to the access rights assigned to users on individual container treatment machines is not possible, on the other hand, a change in circumstances, such as the loss of an identification element or react to a change in the access rights assigned to a user. In this way, for example, a user's access to all container treatment machines with his identification element can be blocked or adjusted in a comparatively short time.
- the identification element can also be made for the identification element to be an active or a passive identification element.
- An active identification element should be understood to be such identification elements that can actively send a signal to the user interface of the container handling machine. This can include, for example, a user's smartphones or tablets. Passive identification elements, on the other hand, should be understood as such identification elements that cannot actively transmit a signal. These include, for example, RFID chips, magnetically encoded tokens or barcodes or QR codes on or in ID cards or other identification cards that may be issued to operators.
- active or passive identification elements can be advantageous depending on the users and the work to be carried out by them on container handling machines.
- the central rights assignment system comprises a memory in which an identification element and/or a user password is assigned to a user and group-based and/or user-based access rights for a group of users and/or at least one user by means of an input device of the central rights assignment system Users can be entered and the central rights assignment system is designed to assign the group-based and / or user-based access rights to the identification element and / or the user password.
- a specific identification element and/or a user password can be assigned to a user, for example, in the form of a (coded and/or encrypted) user profile.
- This user profile in turn, can be accessed with this embodiment through the access the central rights assignment system and set the access rights of the user in a central way.
- the container treatment machine is designed to grant the access rights granted to a user for a preset session duration if an identification element is recognized and a user password has been entered, with the preset session duration of the container treatment machine optionally being sent by the central rights assignment system as part of the access data can.
- the preset session duration can enable an operator to carry out the work to be carried out on the container treatment machine as efficiently as possible without it being necessary at least to re-enter the user password during the preset session duration.
- a further embodiment provides that the container treatment machine is designed to grant group-based access rights for a user based on a recognized identification element if no access data is received from the central rights assignment system.
- operation of the container treatment machine can be maintained at least even if the data connections to the central rights allocation system have failed.
- the group-based access rights can preferably be encoded by the identification element.
- the group-based access rights preferably only the group-based access rights, can be stored on the container handling machine (for example on a central control unit of the container handling machine, such as a computer) and retrieved depending on the recognized identification element. This embodiment ensures that at least the work to be carried out by a specific group of users can always be carried out on a container treatment machine.
- access can then be made possible, for example, by registering using a challenge/response method, for example via a technical customer service.
- access can also take place via a user password and user name defined for a specific container treatment machine, which, for example, are only communicated to persons with a particularly high degree of trustworthiness.
- a central rights assignment system is particularly advantageous if more than one container treatment machine is part of the container treatment system, since a central assignment of access rights then saves a great deal of time.
- access rights for each of the at least two container treatment machines can be stored in the central rights assignment system.
- different access rights for the same users can be stored for the two container handling machines, so that, for example, a user has a first group of access rights on the first container handling machine and a second group of access rights on the second container handling machine, with the second group of access rights not being identical to the first group is.
- access rights for users can be stored individually and for each container treatment machine with the help of the central rights assignment system, even in complex container treatment systems comprising several container treatment machines, which increases the flexibility in the assignment of access rights, while the security of the operation of the container treatment system is guaranteed.
- the method according to the invention for operating a container treatment machine of a container treatment system comprising the container treatment machine and a central rights assignment system comprises:
- the central rights assignment system comprises a memory in which an identification element and/or a user password is assigned to a user and group-based and/or user-based access rights for a group of users and/or by means of an input device of the central rights assignment system at least one user can be entered and the central rights assignment system assigns the group-based and/or user-based access rights to the identification element and/or the user password.
- the access rights granted to a user cannot be changed during the preset session duration, regardless of whether the access rights assigned to the user are changed in the central rights allocation system during the preset session duration, and/or the container handling machine can be locked for the user during the preset session duration if the access rights assigned to the user are changed in the central rights allocation system in such a way that the user receives fewer access rights for the container treatment machine.
- the access rights are not changed during the preset session duration, it is ensured that the respective user can reliably carry out the work assigned to him on the container handling machine.
- the embodiment in which the container treatment machine is blocked for the user even during the preset session duration makes it possible to ensure that no unauthorized users gain access to the functions of the container treatment machine.
- the container treatment machine can grant group-based access rights for a user if no access data is received from the central rights assignment system.
- the container treatment system comprises at least two container treatment machines and that the central rights assignment system is provided separately from the at least two container treatment machines.
- an identification element is also provided with information contained on the identification element which, when recognized by a container treatment machine of a container treatment system according to one of the above embodiments, causes access rights to be granted by means of a method according to one of the preceding embodiments.
- This identification element can be designed, for example, as a token or as an RFID chip(s) or also as a QR code. Data can preferably be encoded in the identification element in such a way that reading it out is only possible with difficulty, for example because the data is encrypted. This ensures the security of the container treatment system even if such an identification element is lost.
- FIG. 1 shows a container treatment system according to one embodiment.
- FIG. 2 shows a flow chart of a method for operating a container treatment machine of a container treatment system according to one embodiment.
- FIG. 3 shows a further embodiment of a method for operating a container treatment machine.
- FIG. 4 shows an embodiment of a user interface and an identification element.
- FIG. 1 shows an embodiment of a container treatment system 100 according to the invention.
- the container treatment system 100 in FIG. 1 comprises a series of container treatment machines 110, 120 and 130.
- the three container treatment machines shown here are not to be understood as limiting.
- the container treatment system can include any number of container treatment machines, in particular fewer than three, such as two or just one container treatment machine, but also more than three container treatment machines, such as 4, 5 or 10 or 20 container treatment machines.
- the container treatment machines can be organized in lines each consisting of more than 5, more than 10 or more than 15, in particular 15 to 20 container treatment machines. These lines or the container treatment machines of the individual lines do not have to all be stationed at the same location (e.g. in the same plant), but can also be distributed in different countries.
- the container treatment machines 110 to 130 can be technically different, so that they treat containers in different ways.
- the container treatment machines 110-130 of the container treatment system 100 can be arranged one after the other in the process directions of containers and can carry out the following treatment steps on containers one after the other.
- the container treatment machine 110 can be designed as a stretch blow molding machine that forms containers from preforms.
- the container treatment machine 120 can be arranged downstream of the container treatment machine 110 and can be embodied as a filler, for example. This can fill a liquid product into the containers, such as a drink.
- the container treatment machine 130 can then be connected to the container treatment machine 120 in the direction of transport of the containers, which can be embodied as a closing device, for example. This can provide the containers with a closure, for example a screw cap or a crown cap.
- container treatment machines such as decoration machines for applying printed images or labels or inspection machines or packaging machines, can also be part of the container treatment system 100 .
- more than one container treatment machine of the same type of container treatment machine for example stretch blow molding machine or filler
- a stretch blow molding machine can be provided as part of the container treatment system, but also two fillers for filling products. These can, for example, fill different products into the containers supplied to them.
- the container treatment system is not limited in terms of the design of the container treatment machines, either in terms of the number or the functions you can implement.
- a user interface 111 or 121 or 131 is assigned to each container treatment machine.
- a user of the container treatment machine can interact with (and preferably only with this) container treatment machine via this user interface.
- the user interface can be designed, for example, as a standard control device of a container treatment machine, in particular as a computer or the like. designed to be.
- the user interface can in particular include a keyboard and a display device (such as a screen), it being possible for the user to make inputs via the keyboard and for information to be output on the display device.
- a user can enter a password assigned to him via the user interface 111, 121, 131 in order to additionally or alternatively identify himself at the respective container treatment machine.
- the user interfaces are preferably connected via corresponding data connections 112, 122 and 132 to the respective container treatment machine 110 to 130 for the purpose of data exchange.
- These data connections e.g. Ethernet cable or also WLAN connections
- This allows the container treatment machine to be controlled by a user. For example, operating parameters of the container treatment machine can be changed or logs about the operation of the container treatment machine can be called up, for example if maintenance of the container treatment machine is necessary.
- the container treatment system 100 also includes a central rights assignment system 140.
- the central rights assignment system is preferably connected to each of the container treatment machines 110 to 130 via bidirectional data transmission devices 151 to 153.
- These data transmission devices 151 to 153 can be designed, for example, in the form of Ethernet connections or wireless connections, such as WLAN connections.
- the central rights assignment system 140 does not have to be provided at the same location as the container treatment machines 110 to 130 of the container treatment system 100 . It can also be arranged, for example, outside of factory buildings, for example in a company headquarters.
- the central rights assignment system 140 can be used accordingly to ensure communication and in particular the exchange of data with the container handling machines 110 to 130 and the associated user interfaces 111 to 131 have a suitable transceiver 142, which can be understood as part of the data transmission lines 151 to 153 or at least as connected to them.
- the central rights assignment system preferably includes a memory 141, which can be implemented, for example, as part of a server or a server architecture. According to the invention, data are stored in this memory which ensure an assignment of an identification element and/or a user password to a specific user. Furthermore, access rights for individual users or groups of users are stored in this memory or in another memory that is logically or physically separate from this memory.
- the central rights assignment system 140 can also include an input device 143 with which the data stored in the memory 141 can be accessed and, in particular, this data can also be changed so that, for example, a specific user or a specific identification element or a specific group of users is granted access rights or withdrawn or new users or new groups of users can be created.
- a group of users can include managerial staff who are generally granted far-reaching access rights to container treatment machines.
- a second group of users can be assigned to maintenance personnel, who are usually assigned less far-reaching access rights to the functions of individual machines.
- a further assignment of access rights can take place, for example, at the level of individual container treatment machines or groups of container treatment machines. Provision can thus be made for certain groups of users to be granted only certain access rights for certain types of container treatment machines, whereas other access rights are granted to the same group of users for other types of container treatment machines.
- membership in a specific group of users and thus the availability of corresponding access rights for a specific user is coded using a suitable identification element, such as a token.
- a suitable identification element such as a token.
- the access rights to individual container treatment machines that are individually available for this user can, however, be encoded with his user password.
- a user identifies himself at a container treatment machine, such as container treatment machine 110, with his identification element, membership in a specific group of users is thereby identified and the user can be granted the corresponding access rights of this group. If the user also identifies himself with his password, he can be granted further access rights, which depend on the identification with the corresponding password, in addition to the access rights that he is granted due to the membership in the specific group that is identified by means of the identification element.
- this embodiment is not mandatory. Thus, in some embodiments it can be provided that no user-related access rights are provided. In this case, the additional identification with the user password is used for secure identification of the operator.
- an operator can be assigned to a group “maintenance personnel” (or generally group A) and “operator reserve” (or generally group B), which have at least partially different access rights from one another.
- the access rights of both groups can then be assigned to this operator.
- the groups to which an operator is assigned define mutually exclusive access rights (in group A access to a specific function is permitted, in group B access to this specific function is permitted not allowed), the access rights assigned to the operator either allow access or deny access as far as access concerns mutually exclusive access rights. This can either lead to increased operational security (by denying access to a function that is blocked for one of the groups) or simplify interaction with the machine (by granting access despite mutually exclusive access rights).
- At least the specific user-related access rights or corresponding data that characterize these access rights are stored exclusively in the central rights assignment system 140, but not on the individual container handling machines 110 to 130.
- the group-specific access rights, which are granted in particular by the users can be encoded available identification elements can be stored on the container treatment machines and also in the central rights assignment system. This allows the group-related access rights to the individual container handling machines to be called up even if the data transmission lines 151 to 153 are interrupted or user-specific data cannot be transferred from the central rights allocation system to a specific container handling machine for some other reason.
- FIG. 2 shows a flow chart of a method according to an embodiment of the invention, as can be carried out, for example, by means of the embodiments of a container treatment plant described in FIG.
- the method 200 begins with step 201, in which an identification element and/or a password of a user is recognized on a specific container treatment machine, for example the container treatment machine 110 from FIG. Recognition of the identification element can be ensured in step 201, for example by placing a token on a corresponding reading device.
- the password can be entered via the user interface 111 already discussed in relation to FIG. 1, in particular a keyboard.
- Identification data can then be generated from the recognized identification element and/or the entered password, which data are at least indicative of the identification element that was put on and/or the entered password.
- these are then sent from the container handling machine or the user interface assigned to it to the central rights assignment system. This can be done in the form of an encrypted data stream so that access to the identification data by third parties is prevented. For example, end-to-end encryption can be used for this. Other encryption mechanisms are also conceivable here.
- the central rights assignment system then processes the identification data that it received in step 202 and derives access data from it, for example by basing access rights be taken from the memory 141 on the recognized identification element and/or the recognized password. This can be realized by identifying the user belonging to the identification element and the entered password and the user profile stored for this user and/or his group membership.
- step 203 the central rights assignment system then sends access data to the container handling machine.
- This access data preferably contains information that defines group-based and/or user-based access rights for the container treatment machine.
- the identification of a user with his identification element allows the identification of the group to which the user belongs. Based on this, corresponding access data can be transmitted from the central rights assignment system to the container handling machine, defining access rights that are available to the group of users to which the user belongs. User-based access rights and corresponding access data can be generated based on the password entered and are specific to that user.
- access to the functions of the container handling machine can then be granted on the container handling machine in accordance with the access rights defined by the access data.
- this can include, for example, that this user has access to maintenance functions for the container treatment machine after appropriate identification.
- another user can be granted access to settings of the container treatment machine and, again depending on his access rights, be allowed to change the operating parameters of the container treatment machine.
- FIG. 2 shows a second case of the method, in which, after identification data has been sent to the central rights assignment system in step 202, the container treatment machine does not receive any access data. This can be caused, for example, by an error in the data transmission lines, such as an interruption in the WLAN connection or another failure of the data connection.
- the container treatment machine does not receive any or not all of the necessary access data to ensure that a user has complete access to the container treatment machine.
- step 205 it can then be provided that in the event that in step 205 no access data to the container handling machine is received from the central rights assignment system, access rights are assigned to the user based on his group membership.
- membership of a user in a specific group of users and the associated access rights can be encoded by the identification element.
- the group-specific access rights that are available to every user who belongs to this group can be stored on the container handling machine.
- a user can at least be granted access to the container treatment machine as part of his group membership, even if his user-related data are not available on the container treatment machine.
- this embodiment is not mandatory and in some embodiments it can also be provided that if the container treatment machine does not receive any necessary access data from the central rights assignment system after the identification data was sent to the central rights assignment system in step 202, access to the container treatment machine is blocked.
- the group-based access rights are only granted for certain groups if no access data are received. For example, access can be granted if the identification element indicates a group membership that allows access to non-critical functions of the container treatment machines, for example for maintenance purposes. Critical functions, such as changing and setting operating parameters, which is usually reserved for other groups of users, can be denied in some embodiments if the identity of the User is not confirmed by the access data sent back from the central rights assignment system.
- FIG. 3 shows a further embodiment of a method that can be combined with the method according to FIG.
- the method 300 in FIG. 3 begins with step 301, in which access data are received at the container treatment machine. This corresponds to step 203 of the method described in FIG. 2, in which the access data are sent from the central rights assignment system to the container treatment machine.
- the embodiment of FIG. 3 provides that the access rights are only granted for a preset session duration if the user has previously identified himself with his identification element and his password. This is shown in step 302 schematically.
- the preset session duration can be configured separately on each container handling machine and can be, for example, one hour or two hours or four hours. Alternatively, the preset session duration can also be sent to the container handling machine as part of the access data, which allows the preset session duration to be changed by means of the central rights assignment system.
- the granting of access rights for the preset session duration advantageously includes at least that a user who has identified himself once with his identification element and his password does not have to re-enter the password at least during the preset session duration.
- a renewed identification with the identification element is not required during the preset session duration.
- the user also has to identify himself with the identification element during the preset session duration, for example as soon as he calls up another function of the container handling machine or when a certain period of time that is less than the preset session duration has elapsed.
- the access rights of a user or a group of users to the central rights assignment system are changed while a user is working on a container handling machine within the preset session duration.
- the access rights granted to the user are retained at least during the preset session duration. This is shown in step 305 and can be granted without further checking by the container handling machine.
- the central rights assignment system in the event that group-related access rights or user-related access rights are changed, outputs information to all container handling machines that specific access rights of a group or a specific user have been changed.
- a check can take place in step 304 as to whether the access rights for the user who is currently working on a specific container handling machine during the preset session duration have been changed. This check can be carried out on the container treatment machine itself, since it has the user's access data for the preset session duration or these have been transferred to the container treatment machine.
- step 306 the container treatment machine or specific functions of the container treatment machine be blocked.
- the user is thus denied further access to the container treatment machine or at least to specific functions of the container treatment machine during the preset session duration in order not to jeopardize the safety of the operation of the container treatment machine. Provision can be made here for certain functions to which a user initially had access based on his access data to be blocked or reset to a default setting during the preset session duration in order to prevent unauthorized persons from changing the operating parameters of the container treatment machine.
- the blocking of the entire container handling machine or the entire access to the container handling machine or the blocking of individual functions of the container handling machine can be dependent on the group membership or the original access rights of the user. For example, if the user had administrator rights when the access data was received on the container treatment machine in step 301, and if these access rights have changed during the preset session duration, it can be provided that all user access to the container treatment machine is blocked, otherwise a There can be a security risk for the operation of the container treatment machine if a user who no longer has the appropriate access rights has administrator rights to the container treatment machine.
- the user is a member of a group of users who in any case only have limited access to the container treatment machine, for example maintenance personnel, provision can be made for only certain functions to be blocked which are no longer covered by the changed access data .
- FIG. 4 shows an embodiment of a user interface 111, as can be assigned, for example, to a container treatment machine 110 corresponding to the embodiment described in FIG.
- the embodiments described in FIG. 4 can be combined with the embodiments described with reference to FIGS.
- the user interface shown here can generally be designed as a laptop or computer. These configurations are already known in principle and do not require any further explanation.
- a reading device or reading device which is designed to read information from an identification element 472, can be assigned to the user interface.
- the reader 471 can be a QR code reader.
- An RFID reader can also be provided as reader 471 .
- FIG. 4 also shows an identification element 472 (independently of the user interface 111 and the reading device 471).
- the identification element 472 is designed as an identity card. This identification card can be assigned to a user, for example, at the beginning of his employment and can contain his name and a picture of the user, but is not limited in this regard.
- a QR code or an RFID chip can be integrated into the identification element, which can then be recognized and read by the user interface when it is placed on or brought close to the reader 471 of the user interface in order to provide the data relevant to the identification to extract. This data can then be output to the central rights assignment system as part of the identification data in order to enable the user to be identified.
- the identification element can be provided as a token independently of the identification card shown in FIG. 4 or can be designed separately from the identification card as an additional identification card or as a check card.
- RFID elements or QR codes can be understood as "passive" identification elements.
- active identification elements can also be provided. Active identification elements are those identification elements that can actively output an identification signal, for example by pressing a button on the identification element. This can be a transponder, for example. Other active identification elements, such as a laptop or smartphone assigned to the user, can also be used. These can then have appropriately encoded data that they can transmit to the user interface in order to identify the user.
- identification with the identification element preferably only causes identification with regard to the group membership of a user.
- the user can also be individually identified by entering a password on the user interface.
- Alternatives are also conceivable for this, such as biometric identification of the user instead of entering a password.
- the user interface can have a camera or a fingerprint scanner. With this, certain biometric characteristics of the user, such as his fingerprint, his face, his palm, his eyes or the like can be recognized and on the basis of this an identification of the user can be realized analogous to an identification with a password.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Theoretical Computer Science (AREA)
- Computer Hardware Design (AREA)
- Software Systems (AREA)
- Physics & Mathematics (AREA)
- General Engineering & Computer Science (AREA)
- General Physics & Mathematics (AREA)
- Mechanical Engineering (AREA)
- Details Of Rigid Or Semi-Rigid Containers (AREA)
- Storage Device Security (AREA)
- Management, Administration, Business Operations System, And Electronic Commerce (AREA)
Abstract
Description
Claims
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| DE102021127963.1A DE102021127963A1 (de) | 2021-10-27 | 2021-10-27 | Behälterbehandlungsanlage mit wenigstens einer Behälterbehandlungsmaschine zum Behandeln von Behältern und einem zentralen Rechtezuweisungssystem |
| PCT/EP2022/080046 WO2023073083A1 (de) | 2021-10-27 | 2022-10-27 | Behälterbehandlungsanlage mit wenigstens einer behälterbehandlungsmaschine zum behandeln von behältern und einem zentralen rechtezuweisungssystem |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| EP4423638A1 true EP4423638A1 (de) | 2024-09-04 |
Family
ID=84361903
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| EP22809773.9A Pending EP4423638A1 (de) | 2021-10-27 | 2022-10-27 | Behälterbehandlungsanlage mit wenigstens einer behälterbehandlungsmaschine zum behandeln von behältern und einem zentralen rechtezuweisungssystem |
Country Status (5)
| Country | Link |
|---|---|
| US (1) | US20240419767A1 (de) |
| EP (1) | EP4423638A1 (de) |
| CN (1) | CN118159965A (de) |
| DE (1) | DE102021127963A1 (de) |
| WO (1) | WO2023073083A1 (de) |
Family Cites Families (26)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20040133797A1 (en) * | 2003-01-06 | 2004-07-08 | International Business Machines Corporation | Rights management enhanced storage |
| US7761382B2 (en) * | 2003-03-14 | 2010-07-20 | Siemens Aktiengesellschaft | Method and system to protect electronic data objects from unauthorized access |
| KR101067691B1 (ko) * | 2003-07-14 | 2011-09-27 | 소니 주식회사 | 통신장치 및 통신장치의 통신방법 |
| AT502371A2 (de) | 2005-09-14 | 2007-03-15 | Leopold Dr Gallner | System für die identifizierung und die vergabe von benutzungsberechtigungen in einer datenverarbeitungseinrichtung |
| US7552467B2 (en) * | 2006-04-24 | 2009-06-23 | Jeffrey Dean Lindsay | Security systems for protecting an asset |
| DE102007005638B4 (de) | 2007-02-05 | 2014-10-09 | Siemens Aktiengesellschaft | Verfahren zur Autorisierung des Zugriffs auf mindestens eine Automatisierungskompente einer technischen Anlage |
| US20090320125A1 (en) * | 2008-05-08 | 2009-12-24 | Eastman Chemical Company | Systems, methods, and computer readable media for computer security |
| DE102009018187B4 (de) | 2009-04-22 | 2022-10-06 | Trützschler Group SE | Vorrichtung zum Betrieb von Bedien- und Anzeigeeinheiten an Textilmaschinen und Anlagen, insbesondere im Bereich Spinnereimaschinen und -anlagen, z. B. Spinnereivorbereitungsmaschinen und -anlagen |
| DE102009037224A1 (de) * | 2009-08-12 | 2011-02-17 | Repower Systems Ag | Verfahren und Vorrichtung zur Zugriffsregelung auf Anlagensteuerungen von Windenergieanlagen |
| DE202010015629U1 (de) | 2010-06-01 | 2011-04-21 | Krones Ag | Behälterbehandlungsanlage und Qualitätssicherungsverfahren für mit einer Behälterbehandlungsanlage hergestellten Behältern |
| US8893215B2 (en) * | 2010-10-29 | 2014-11-18 | Nokia Corporation | Method and apparatus for providing distributed policy management |
| US8769642B1 (en) * | 2011-05-31 | 2014-07-01 | Amazon Technologies, Inc. | Techniques for delegation of access privileges |
| EP2560124A1 (de) * | 2011-08-02 | 2013-02-20 | Tata Consultancy Services Limited | Zugangsrechteverwaltung in Systemen zur digitalen Rechteverwaltung von Unternehmen |
| US9613222B2 (en) * | 2011-09-02 | 2017-04-04 | Tata Consultancy Services | Assigning access rights in enterprise digital rights management systems |
| KR20130046155A (ko) * | 2011-10-27 | 2013-05-07 | 인텔렉추얼디스커버리 주식회사 | 클라우드 컴퓨팅 서비스에서의 접근제어 시스템 |
| EP2675106A1 (de) * | 2012-04-23 | 2013-12-18 | ABB Technology AG | Benutzerzugang für industrielle Automatisierungs- und Steuervorrichtung |
| US9154507B2 (en) * | 2012-10-15 | 2015-10-06 | International Business Machines Corporation | Automated role and entitlements mining using network observations |
| IN2013MU01874A (de) * | 2013-05-27 | 2015-05-29 | Tata Consultancy Services Ltd | |
| US9471798B2 (en) * | 2013-09-20 | 2016-10-18 | Oracle International Corporation | Authorization policy objects sharable across applications, persistence model, and application-level decision-combining algorithm |
| FR3014583A1 (fr) * | 2013-12-05 | 2015-06-12 | Orange | Procede d'etablissement d'une relation de confiance entre deux locataires dans un reseau en nuage |
| US10084795B2 (en) * | 2014-07-14 | 2018-09-25 | Cisco Technology, Inc. | Network-based real-time distributed data compliance broker |
| US10554644B2 (en) * | 2016-07-20 | 2020-02-04 | Fisher-Rosemount Systems, Inc. | Two-factor authentication for user interface devices in a process plant |
| US10375162B2 (en) | 2016-07-22 | 2019-08-06 | Fisher-Rosemount Systems, Inc. | Process control communication architecture |
| DE102018210625A1 (de) | 2018-06-28 | 2020-01-02 | Deckel Maho Pfronten Gmbh | Werkzeugmaschine mit Steuervorrichtung |
| US12292987B2 (en) * | 2020-03-06 | 2025-05-06 | Cambia Health Solutions, Inc. | Methods and systems for purpose-based access control |
| US11811771B2 (en) * | 2020-11-19 | 2023-11-07 | Tetrate.io | NGAC graph evaluations |
-
2021
- 2021-10-27 DE DE102021127963.1A patent/DE102021127963A1/de active Pending
-
2022
- 2022-10-27 WO PCT/EP2022/080046 patent/WO2023073083A1/de not_active Ceased
- 2022-10-27 EP EP22809773.9A patent/EP4423638A1/de active Pending
- 2022-10-27 US US18/704,857 patent/US20240419767A1/en active Pending
- 2022-10-27 CN CN202280072181.1A patent/CN118159965A/zh active Pending
Also Published As
| Publication number | Publication date |
|---|---|
| US20240419767A1 (en) | 2024-12-19 |
| DE102021127963A1 (de) | 2023-04-27 |
| CN118159965A (zh) | 2024-06-07 |
| WO2023073083A1 (de) | 2023-05-04 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| EP2034378B1 (de) | Werkzeugmaschine mit Zugriffssteuereinrichtung | |
| EP2820623B1 (de) | Verfahren zum identifizieren einer person | |
| DE102008004656A1 (de) | Verfahren zur Verwaltung der Benutzungsberechtigungen bei einem Datenverarbeitungsnetzwerk und ein Datenverarbeitungsnetzwerk | |
| DE102014101495B4 (de) | Verfahren zum Zugang zu einem physisch abgesicherten Rack sowie Computernetz-Infrastruktur | |
| DE3018945A1 (de) | Datenbehandlungsgeraet und verfahren zum sichern der uebertragung von daten | |
| DE60309575T2 (de) | System und verfahren zum verhindern eines unbefugten betriebs von identifikations- und finanzdokumenterstellungsgeräten | |
| EP2678795B1 (de) | Verfahren zur öffentlichen bereitstellung geschützter elektronischer dokumente | |
| DE102017011464A1 (de) | Bedieneridentifikationssystem | |
| EP3649625A1 (de) | Verfahren zur delegation von zugriffsrechten | |
| EP1282846B2 (de) | Smartcards zur authentisierungsprüfung in maschinensteuerungen | |
| EP2820624B1 (de) | Verfahren zum identifizieren einer person | |
| WO2023073083A1 (de) | Behälterbehandlungsanlage mit wenigstens einer behälterbehandlungsmaschine zum behandeln von behältern und einem zentralen rechtezuweisungssystem | |
| DE102017000514B3 (de) | Vorrichtungen, systeme und verfahren zum entriegeln eines schlosses eines schloss-systems | |
| WO1998034201A1 (de) | Verfahren zum betrieb einer fernwirkeinrichtung und fernwirkeinrichtung | |
| DE10347431B4 (de) | Fernwartungssystem unter Zugriff auf autorisierungsbedürftige Daten | |
| EP3657750A1 (de) | Verfahren zur authentifizierung einer datenbrille in einem datennetz | |
| WO2019105666A1 (de) | Verfahren und system zum bereitstellen einer datentechnischen funktion mittels eines datenverarbeitungssystems eines spurgebundenen fahrzeugs | |
| DE102006006804B4 (de) | Autorisierung eines Anwenders für ein Automatisierungsgerät | |
| DE4010094A1 (de) | Verfahren zur ueberpruefung der zugangsberechtigung eines benutzers zu einem prozess | |
| DE102017000906A1 (de) | Spritzgiesszelle und Spritzgiesszellen-Verwaltungssystem | |
| DE102004022828A1 (de) | Automatische Zugangskontrolle | |
| DE102020123755B4 (de) | Verfahren zum Authentifizieren mit einem optoelektronisch lesbaren Code sowie Funktionsfreigabeeinrichtung und Computerprogramm hierzu | |
| EP4231256A1 (de) | Zugangssystem zu einer maschine | |
| EP4648058A1 (de) | Bedienerlevel und rollenspezifische autorisation zur bedienung einer infusionspumpe | |
| DE102010048894B4 (de) | Verfahren und System zum Erzeugen einer Zugangsberechtigung in einer zugangsbeschränkten elektronisch angesteuerten Einrichtung |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: UNKNOWN |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: THE INTERNATIONAL PUBLICATION HAS BEEN MADE |
|
| PUAI | Public reference made under article 153(3) epc to a published international application that has entered the european phase |
Free format text: ORIGINAL CODE: 0009012 |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: REQUEST FOR EXAMINATION WAS MADE |
|
| 17P | Request for examination filed |
Effective date: 20240417 |
|
| AK | Designated contracting states |
Kind code of ref document: A1 Designated state(s): AL AT BE BG CH CY CZ DE DK EE ES FI FR GB GR HR HU IE IS IT LI LT LU LV MC ME MK MT NL NO PL PT RO RS SE SI SK SM TR |
|
| DAV | Request for validation of the european patent (deleted) | ||
| DAX | Request for extension of the european patent (deleted) | ||
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: EXAMINATION IS IN PROGRESS |
|
| 17Q | First examination report despatched |
Effective date: 20260331 |