Remote Diagnostics at a Coca Cola Plant in Minnesota

May 23, 2012
Kai Mariappan, plant control specialist at the Egan, MN, plant of Coca Cola, shared an example of a successful remote diagnostics application for packaging and production during the Packaging portion of The Automation Conference.

Key points of emphasis made by Mariappan:

• Regardless of whose PLCs are on the discrete pieces of packaging equipment in a line, as long as those PLCs are networkable, remote access is possible. A key to making it all work is a central gateway, which in this application came from Rockwell; can lines, bottle lines, utilities, the syrup room, a plant alarm management system, line information system, and email servers all connect to this hub.
• Security is critical. The very word “remote” means out of sight, and when things are out of sight, how do you know they are secure?
There are so many ways an attack can occur:
- An attacker can capture or guess necessary credentials.
- Data can be injected into a network.
- An attacker can force his way into a network through coercion. 
- Communication can be listened to and hijacked.
• Good security practices include:
-Undertake a threat and risk assessment.
- Eliminate direct communication.
- Secure modem access beyond default.
- Establish user-specific authentication servers.
- Use multifactor authentication
- Use dedicated hardware and software to support the remote access solutions.
• Be sure to understand the differences between industrial networks and IT networks before launching into a remote diagnostics project. And once a project is launched, clearly identify the responsibilities of IT people compared to production and manufacturing people.
• Find a good way to show the plant manager and other key stakeholders a demo of some kind to gain their belief in the business benefits of remote diagnostics.
• Among the things that can be done with remote access:
- You can log into PLC ladder logic programs and troubleshoot from any secure access point.
- You can do online training.
- You can do remote HMI control.
- You can execute process monitoring to resolve deviations.
Mariappan showed photos of his Blackberry phone with a graphic showing real-time conditions on the plant floor in the Eden, MN, plant. Without remote access to the network over the Internet, this would not be possible. He also cautioned that when it comes to connectivity, VNC (Virtual Network Computing) is not as secure as VPN (Virtual Private Network). He provide an analogy to drive home his point about security.
“Picture a tunnel from your office to your home. If you drive through that tunnel, you can’t get carjacked. But if you drive on the highway, a public way, you can get hijacked.” His advice: If you connect to the network remotely, make sure it’s through a tunnel and not on the highway.
For more conference coverage, visit www.automationworld.com/tac2012

Sponsored Recommendations

Put the Plant Floor in Your Pocket with Ignition Perspective

Build mobile-responsive HTML applications that run natively on any screen.

Ignition: Industrial-Strength System Security and Stability

Ignition is built on a solid, unified architecture and proven, industrial-grade security technology, which is why industrial organizations all over the world have been trusting...

Iron Foundry Gains Competitive Edge & Increases Efficiency with Innovative Technology

With help from Artek, Ferroloy implemented Ignition to digitally transform their disconnected foundry through efficient data collection and analysis while integrating the new ...

Empowering Data Center Growth: Leveraging Ignition for Scalability and Efficiency

Data center growth has exploded over the past decade. Initially driven by organizations moving their computer assets to the cloud, this trend has only accelerated. With the rise...