SlideShare a Scribd company logo
Johan Arens - Conseiller, ingénierie de réseaux //CCIE#29341, CCNP Voice, CCDP
7 décembre 2016
Cisco Connect Montréal 2016
L’Internet des objets (IDO) dans
le secteur manufacturier
Équipe CCiQ Cisco au Québec
Etienne Simard Sylvain Denoncourt Johan Arens
• Vision de Cisco
• Réalité du monde manufacturier
• Architecture et Sécurité
• Edge Computing
• Conclusion
• Questions / Réponses
Agenda
“L’Internet des objets est une façon
intelligente de connecter des
équipements physiques pour aller
extraire des améliorations substancielles
dans notre efficacité, croissance d’affaire
et amélioration de la qualité de vie.”
Qu’est-ce que l’Internet des objets ?
Cisco Confidential 5© 2013-2014 Cisco and/or its affiliates. All rights reserved.
Converging Digital Disruptions
The Nexus of Forces
IoT = $1.9 Trillion
in 2020
The 3rd Platform
$462 Billion in
2013 (22% of total
ICT spending)
The Industrial Internet
$10 Trillion to $15
Trillion Over Next
20 Years
Cisco Confidential 6© 2013-2014 Cisco and/or its affiliates. All rights reserved.
Cisco Calls It The Internet of Everything (IoE)
Interconnexion des personnes, procédés, données et des objets
People
Connecting People in More Relevant,
Valuable Ways
Process
Delivering the Right Information
to the Right Person (or Machine)
at the Right Time
Data
Leveraging Data into
More Useful Information for Decision
Making
Things
Physical Devices and Objects Connected
to the Internet and
Each Other for Intelligent
Decision Making
IoE
Cisco Confidential 7© 2013-2014 Cisco and/or its affiliates. All rights reserved.
7.26.8 7.6
IoT Is Here Now – and Growing!
Rapid Adoption
Rate of Digital
Infrastructure:
5X Faster Than
Electricity and
Telephony
50 Billion
“Smart Objects”
50
2010 2015 2020
0
40
30
20
10
BILLIONSOFDEVICES
25
12.5
Inflection
Point
TIMELINE
Source: Cisco IBSG, 2011
World
Population
The New Essential Infrastructure
Cisco Confidential 8© 2013-2014 Cisco and/or its affiliates. All rights reserved.
The World Generates More Than 2 Exabytes of Data Every Day
Connected Objects Generate Big Data
3/4 millions smart meters in Quebec
90 millions data points > 2 TB / month !
10TB of data for every 30 minutes of flight
With >25,000 flights per day, petabytes daily
A large offshore field produces 0.75TB of data weekly
A large refinery generates 1TB of raw data per day
A single consumer packaged good manufacturing machine generates 13B
data samples per day
Opérations en silos
Pas de choix technologiques communs
Dépendance des OEM ou fabricants de lignes
Réalité du monde manufacturier
Musée des systèmes d’exploitation
Usines installées proche des matières premières
Centralisation des centres de données
Production sur demande
Faire plus avec moins
Réalité du monde manufacturier
Relations tendues entre IT et OT
Réalité du monde manufacturier
CIA AIC
Availability
Integrity
Confidentiality
Confidentiality
Integrity
Availability
Relations tendues entre IT et OT
Réalité du monde manufacturier
Marc, OT
Bernard, IT
Bernard, J’ai besoin d’un
adresse IP pour
remonter ma drive que
je viens de la remplacer.
Ma motion ne marche
plus !
Ah ! Il a des SAN lui
sur son plancher ?
Marc, donc pour bien
comprendre tu as
besoin de remonter ton
SAN pour pouvoir
bouger des VM d’un
SAN à un autre ?
Besoin d’un plan directeur et
d’une architecture !
Changing Industrial Automation Networks
Ethernet and IP Provide Foundation for Manufacturing 2.0 Initiatives
Robotics
Human
Machine
Interface PC-Based
Controllers
Motors,
Drives, and
Actuators
Programmable
Logic Controllers
Office Applications,
Internetworking,
Data Servers,
and Storage
Back-Office
Mainframes
and Servers
Sensors and Other Input/Output Devices
Corporate Network
Control Network
Gateway
Robotics
Human
Machine
Interface
PC-Based
Controllers
Motors,
Drives, and
Actuators
Programmable
Logic
Controllers
Office Applications,
Internetworking,
Data Servers,
and Storage
Back-Office
Mainframes
and Servers
Sensors
and Other
Input/Output
Devices
Corporate Network
Traditional Ethernet-Based
Control Network
Device-Level Network
Ethernet
Automation
Control
Logical Architecture
Built on Industry Standards
Enterprise Zone
DMZ
Manufacturing Zone
Cell/Area
Zone
Enterprise Network
Site Business Planning and
Logistics Network
Site Manufacturing Operations
and Control
Area Control
Basic Control
Process
Demilitarized Zone—
Shared Access
Level 5
Level 4
Level 3
Level 2
Level 1
Level 0
Converged Plantwide Ethernet
Network Architecture
Cell/Area Zone
Levels 0-2
Manufacturing
Zone
Level 3
Demilitarized
Zone
(DMZ)
Real-Time Control
<100ms Convergence
Multicast Traffic
Ease of Use
MFG Integration
Segmentation
Multi-Service Networks
Applications and Management
Security
Access Control
Threat Protection
Enterprise
Network
Levels 4-5
Gbps Link for
Failover
Detection
Firewall
(Active)
Firewall
(Standby)
FactoryTalk
Application
Servers
Cisco
ASA 5500
Cisco
Catalyst
Switch
Network Services
Cisco Catalyst
6800/4500
Cisco Cat. 3850
StackWise
Switch Stack
Patch Management
Terminal Services
Application Mirror
AV Server
Cell/Area #1
(Redundant Star Topology)
Drive
Controller
HMI Distributed I/O
Controller
DriveDrive
HMI
Distributed I/O
HMI
Cell/Area #2
(Ring Topology)
Cell/Area #3
(Bus/Star Topology)
Rockwell Automation
Stratix 8000
Layer 2 Access Switch
Controller
Enterprise/ IT Integration
Collaboration
Wireless
Application OptimizationWeb Apps DNS FTP
Internet
CPwE Industrial Network Security Framework
MCC
Enterprise Zone: Levels 4-5
Soft
Starter
I/O
Physical or Virtualized Servers
• Patch Management
• AV Server
• Application Mirror
• Remote Desktop Gateway Server
Level 0 - ProcessLevel 1 - Controller
Level 3 – Site Operations
Controller
Drive
Level 2 – Area Supervisory Control
FactoryTalk
Client
Controller
Industrial Demilitarized Zone (IDMZ)
Industrial Zone: Levels 0-3
Authentication, Authorization and Accounting (AAA)
LWAP
SSID
2.4 GHz
SSID
5 GHz
WGB
I/O
Active
Wireless LAN
Controller (WLC)
Standby
Core
Switches
Distribution
Switch Stack
Control System Engineers
Control System Engineers
in Collaboration with IT
Network Engineers
(Industrial IT)
IT Security Architects in
Collaboration with Control
Systems Engineers
Enterprise
Identity Services
External DMZ/
Firewall
Internet
IFW
Exemple de sécurisation niveau procédé
CPwE Industrial Network Security Framework
MCC
Enterprise Zone: Levels 4-5
Soft
Starter
I/O
Physical or Virtualized Servers
• Patch Management
• AV Server
• Application Mirror
• Remote Desktop Gateway Server
Level 0 - ProcessLevel 1 - Controller
Level 3 – Site Operations
Controller
Drive
Level 2 – Area Supervisory Control
FactoryTalk
Client
Controller
Industrial Demilitarized Zone (IDMZ)
Industrial Zone: Levels 0-3
Authentication, Authorization and Accounting (AAA)
LWAP
SSID
2.4 GHz
SSID
5 GHz
WGB
I/O
Active
Wireless LAN
Controller (WLC)
Standby
Core
Switches
Distribution
Switch Stack
Control System Engineers
Control System Engineers
in Collaboration with IT
Network Engineers
(Industrial IT)
IT Security Architects in
Collaboration with Control
Systems Engineers
Enterprise
Identity Services
External DMZ/
Firewall
Internet
IFW
Exemple d’acces à distance d’un entrepreneur
Martin T., Cossins Inc
Doit accéder usine Granby
CPwE Architectures
• Collection of Standalone Cisco Validated Design (CVD) Guides
CPwE
REP CVD
June 2014
CPwE
WLAN CVD
Nov. 2014
CPwE
IDMZ CVD
July 2015
CPwE
Resiliency
June 2016
CPwE CVD
Baseline
CPwE
NAT CVD
June 2015
CPwE
ISE CVD
July 2015
CPwE
Migration
Jan. 2016
CPwE
VPN CVD
March 2016
CPwE
Industrial
Firewall
August 2016
CPwE
Loc. Serv.
White paper
CPwE
Resiliency
Dec. 2015
Design Zone manufacturing – Modular CVD’s
http://www.cisco.com/c/en/us/solutions/enterprise/design-zone-
manufacturing/landing_ettf.html
Edge Computing
Most IoT data is not used currently. For
example, only
1 percent of data from an oil
rig with 30,000 sensors is examined. The
data that
is used today is mostly
for anomaly detection and
control, not optimization and prediction,
which provide
the greatest value.
Leveraging Machine Generated Data and Networking
for Business Benefit
IoT Environments Need to Process and Analyze Data
Locally
In Many Cases, Data Issues Must be Handled
“In the Network” to Meet the Requirements
Hence…
Distributed Data Processing [across the] Network Fabric
The Case for Edge and Fog Computing
1. There’s too much data, so it has to be filtered,
aggregated, batched, etc.
2. Some of the consumers of the data are distributed.
3. The data is in the wrong format.
4. You want to analyze the data as soon as possible.
5. The data needs to be time stamped for time series
analysis or for compliance reasons.
6. You have thousands of devices, and it’s too
complicated for a single application in the cloud
to talk to them individually.
General Patterns
Data CenterEdge Processing Aggregation NodeOil Rig
Data Data Data
Local Feedback Data CenterFactory Device
Data Data
CloudIoT Device
2 Tier
3 Tier
4 Tier
Data
IoT Requires Distributed Computing
ENDPOINT
DATACENTER/CLOUD
FOG
App
App App App App
IoT Compute Model
(Local control loops, Data Volume, Security, Resiliency, Latency, Scale)
BYOI: Bring Your Own Interface
(Legacy interfaces, Industry-specific interfaces,
Partner-proprietary interfaces)
WiHart Zigbee PLC 802.15.4 Other
Domain Specific
Interfaces
Architecture FOG - IoX
Routers / Switches at the edge
App
Hosting
App Lifecycle
Management
App
Monitoring
App
Monitoring
Local Manager
Customer-built
App
Cisco-built
App
Partner-built
App
App Packaging
SDK
App Lifecycle App Management
Fog Director
IOx Services
(Alpha*)
Applications
(LXC*, PaaS, VM)
Network
(IOS)
IOx
Why is this Unique?
Bring Analytics to the Data
DATA DATA
Fog NodeEdge Node
DATA
AnalyticsIoT Devices
IoT Devices Analytics
DATA
Distributed Analytics
(Distributed, High Volume, Time Critical, Regulated)
Cloud Based Analytics
(Centralized, Low Volume, Non Perishable, Non Regulated)
Analytics Analytics
Pour résumer…
• Vision IoE de Cisco
• Défis du monde manufacturier
• Sécurité
• Edge Computing (Fog)
Merci !

More Related Content

PDF
Cisco hyperflex software defined storage and ucs unite
PDF
Introduction to Fog
PPTX
Internet of Things (IoT) Costs, Connectivity, Resources and Software
PPTX
The Enhanced Cisco Container Platform
PDF
Cloud Network Technology Development & Deployment Trends
PDF
Upgrade Your System’s Security - Making the Jump from Connext DDS Professiona...
PPTX
Weaving the Future - Enable Networks to Be More Agile for Services
PDF
Ccl basics
Cisco hyperflex software defined storage and ucs unite
Introduction to Fog
Internet of Things (IoT) Costs, Connectivity, Resources and Software
The Enhanced Cisco Container Platform
Cloud Network Technology Development & Deployment Trends
Upgrade Your System’s Security - Making the Jump from Connext DDS Professiona...
Weaving the Future - Enable Networks to Be More Agile for Services
Ccl basics

What's hot (20)

PPTX
Cybersecurity Spotlight: Looking under the Hood at Data Breaches and Hardenin...
PDF
The Inside Story: Leveraging the IIC's Industrial Internet Security Framework
PPTX
Acceleration_and_Security_draft_v2
PPTX
Docker:- Application Delivery Platform Towards Edge Computing
PDF
OpenStack for EDGE computing
PDF
IoT Architecture - are traditional architectures good enough?
PPTX
Why is DDS the Right Technology for the Industrial Internet?
PPTX
The Inside Story: How OPC UA and DDS Can Work Together in Industrial Systems
PDF
VMWare NSX Ecosystem Overview
PDF
The Enterprise Internet of Things: Think Security First
PDF
Accelerating Edge Computing Adoption
PDF
Fog Computing is the Future of the Industrial Internet of Things
PDF
Cisco Connect Toronto 2018 model-driven programmability for cisco ios xr-v1
PDF
Effective IoT System on Openstack
PDF
101 Use Cases for IoT
PDF
06 - VMUGIT - Lecce 2018 - Rodolfo Rotondo, VMware
PPTX
Developing Mission-Critical Avionics and Defense Systems with Ada and DDS
PDF
ciscounifiedcomputingsystemucschangingtheeconomicsdatacenter-130514165541-php...
PDF
JCConf 2017 - Next Generation of Cloud Computing: Edge Computing and Apache E...
PDF
Create New Value for You - Huawei Agile Network
Cybersecurity Spotlight: Looking under the Hood at Data Breaches and Hardenin...
The Inside Story: Leveraging the IIC's Industrial Internet Security Framework
Acceleration_and_Security_draft_v2
Docker:- Application Delivery Platform Towards Edge Computing
OpenStack for EDGE computing
IoT Architecture - are traditional architectures good enough?
Why is DDS the Right Technology for the Industrial Internet?
The Inside Story: How OPC UA and DDS Can Work Together in Industrial Systems
VMWare NSX Ecosystem Overview
The Enterprise Internet of Things: Think Security First
Accelerating Edge Computing Adoption
Fog Computing is the Future of the Industrial Internet of Things
Cisco Connect Toronto 2018 model-driven programmability for cisco ios xr-v1
Effective IoT System on Openstack
101 Use Cases for IoT
06 - VMUGIT - Lecce 2018 - Rodolfo Rotondo, VMware
Developing Mission-Critical Avionics and Defense Systems with Ada and DDS
ciscounifiedcomputingsystemucschangingtheeconomicsdatacenter-130514165541-php...
JCConf 2017 - Next Generation of Cloud Computing: Edge Computing and Apache E...
Create New Value for You - Huawei Agile Network
Ad

Similar to L'Internet des objets (IDO) (20)

PPTX
Discrete MFG IoT Factory of the Future
PDF
Industrial IoT and the emergence of Edge Computing Navigating the Technologic...
PDF
General io t_concepts
PDF
Device to Intelligence, IOT and Big Data in Oracle
PDF
Splunk App for Stream - Einblicke in Ihren Netzwerkverkehr
PDF
IoT and the Oil & Gas industry at M2M Oil & Gas 2014 in London
PDF
Re-Imagining the Data Center with Intel
PDF
Walking through the fog (computing) - Keynote talk at Italian Networking Work...
PDF
IRJET - Importance of Edge Computing and Cloud Computing in IoT Technolog...
PPTX
PDF
Cloud-Ready Networks
PDF
PIF2019 - A06 - Rodrigo M Tutilo - Advantech
PDF
Meetup 4/2/2016 - Functionele en technische architectuur IoT
PDF
Design & Implementation Of Fault Identification In Underground Cables Using IOT
PPTX
Presentation1.pptx
PDF
Real World IoT Architectures and Projects with Eclipse IoT
PDF
Eurotech and Red Hat collaboration simplifies Internet of Things integration ...
PDF
AI for Manufacturing (Machine Vision, Edge AI, Federated Learning)
PDF
InterDrone 2017 Las Vegas - Keynote Address
PPTX
Building Converged Plantwide Ethernet
Discrete MFG IoT Factory of the Future
Industrial IoT and the emergence of Edge Computing Navigating the Technologic...
General io t_concepts
Device to Intelligence, IOT and Big Data in Oracle
Splunk App for Stream - Einblicke in Ihren Netzwerkverkehr
IoT and the Oil & Gas industry at M2M Oil & Gas 2014 in London
Re-Imagining the Data Center with Intel
Walking through the fog (computing) - Keynote talk at Italian Networking Work...
IRJET - Importance of Edge Computing and Cloud Computing in IoT Technolog...
Cloud-Ready Networks
PIF2019 - A06 - Rodrigo M Tutilo - Advantech
Meetup 4/2/2016 - Functionele en technische architectuur IoT
Design & Implementation Of Fault Identification In Underground Cables Using IOT
Presentation1.pptx
Real World IoT Architectures and Projects with Eclipse IoT
Eurotech and Red Hat collaboration simplifies Internet of Things integration ...
AI for Manufacturing (Machine Vision, Edge AI, Federated Learning)
InterDrone 2017 Las Vegas - Keynote Address
Building Converged Plantwide Ethernet
Ad

More from Cisco Canada (20)

PDF
Cisco connect montreal 2018 net devops
PDF
Cisco connect montreal 2018 iot demo kinetic fr
PPTX
Cisco connect montreal 2018 - Network Slicing: Horizontal Virtualization
PDF
Cisco connect montreal 2018 secure dc
PDF
Cisco connect montreal 2018 enterprise networks - say goodbye to vla ns
PDF
Cisco connect montreal 2018 vision mondiale analyse locale
PDF
Cisco Connect Montreal 2018 Securité : Sécuriser votre mobilité avec Cisco
PDF
Cisco connect montreal 2018 collaboration les services webex hybrides
PDF
Integration cisco et microsoft connect montreal 2018
PDF
Cisco connect montreal 2018 compute v final
PDF
Cisco connect montreal 2018 saalvare md-program-xr-v2
PDF
Cisco connect montreal 2018 sd wan - delivering intent-based networking to th...
PDF
Cisco Connect Toronto 2018 DNA automation-the evolution to intent-based net...
PDF
Cisco Connect Toronto 2018 an introduction to Cisco kinetic
PDF
Cisco Connect Toronto 2018 IOT - unlock the power of data - securing the in...
PDF
Cisco Connect Toronto 2018 DevNet Overview
PDF
Cisco Connect Toronto 2018 DNA assurance
PDF
Cisco Connect Toronto 2018 network-slicing
PDF
Cisco Connect Toronto 2018 the intelligent network with cisco meraki
PDF
Cisco Connect Toronto 2018 sixty to zero
Cisco connect montreal 2018 net devops
Cisco connect montreal 2018 iot demo kinetic fr
Cisco connect montreal 2018 - Network Slicing: Horizontal Virtualization
Cisco connect montreal 2018 secure dc
Cisco connect montreal 2018 enterprise networks - say goodbye to vla ns
Cisco connect montreal 2018 vision mondiale analyse locale
Cisco Connect Montreal 2018 Securité : Sécuriser votre mobilité avec Cisco
Cisco connect montreal 2018 collaboration les services webex hybrides
Integration cisco et microsoft connect montreal 2018
Cisco connect montreal 2018 compute v final
Cisco connect montreal 2018 saalvare md-program-xr-v2
Cisco connect montreal 2018 sd wan - delivering intent-based networking to th...
Cisco Connect Toronto 2018 DNA automation-the evolution to intent-based net...
Cisco Connect Toronto 2018 an introduction to Cisco kinetic
Cisco Connect Toronto 2018 IOT - unlock the power of data - securing the in...
Cisco Connect Toronto 2018 DevNet Overview
Cisco Connect Toronto 2018 DNA assurance
Cisco Connect Toronto 2018 network-slicing
Cisco Connect Toronto 2018 the intelligent network with cisco meraki
Cisco Connect Toronto 2018 sixty to zero

Recently uploaded (20)

PDF
CIFDAQ's Market Insight: SEC Turns Pro Crypto
PDF
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
PDF
Agricultural_Statistics_at_a_Glance_2022_0.pdf
PPTX
Effective Security Operations Center (SOC) A Modern, Strategic, and Threat-In...
PDF
Encapsulation theory and applications.pdf
PDF
Review of recent advances in non-invasive hemoglobin estimation
PDF
NewMind AI Monthly Chronicles - July 2025
PDF
Electronic commerce courselecture one. Pdf
PDF
Empathic Computing: Creating Shared Understanding
DOCX
The AUB Centre for AI in Media Proposal.docx
PPTX
Digital-Transformation-Roadmap-for-Companies.pptx
PPT
Teaching material agriculture food technology
PDF
Spectral efficient network and resource selection model in 5G networks
PDF
Architecting across the Boundaries of two Complex Domains - Healthcare & Tech...
PDF
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf
PDF
Bridging biosciences and deep learning for revolutionary discoveries: a compr...
PDF
Advanced methodologies resolving dimensionality complications for autism neur...
PPTX
VMware vSphere Foundation How to Sell Presentation-Ver1.4-2-14-2024.pptx
PDF
Network Security Unit 5.pdf for BCA BBA.
PDF
Dropbox Q2 2025 Financial Results & Investor Presentation
CIFDAQ's Market Insight: SEC Turns Pro Crypto
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
Agricultural_Statistics_at_a_Glance_2022_0.pdf
Effective Security Operations Center (SOC) A Modern, Strategic, and Threat-In...
Encapsulation theory and applications.pdf
Review of recent advances in non-invasive hemoglobin estimation
NewMind AI Monthly Chronicles - July 2025
Electronic commerce courselecture one. Pdf
Empathic Computing: Creating Shared Understanding
The AUB Centre for AI in Media Proposal.docx
Digital-Transformation-Roadmap-for-Companies.pptx
Teaching material agriculture food technology
Spectral efficient network and resource selection model in 5G networks
Architecting across the Boundaries of two Complex Domains - Healthcare & Tech...
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf
Bridging biosciences and deep learning for revolutionary discoveries: a compr...
Advanced methodologies resolving dimensionality complications for autism neur...
VMware vSphere Foundation How to Sell Presentation-Ver1.4-2-14-2024.pptx
Network Security Unit 5.pdf for BCA BBA.
Dropbox Q2 2025 Financial Results & Investor Presentation

L'Internet des objets (IDO)

  • 1. Johan Arens - Conseiller, ingénierie de réseaux //CCIE#29341, CCNP Voice, CCDP 7 décembre 2016 Cisco Connect Montréal 2016 L’Internet des objets (IDO) dans le secteur manufacturier
  • 2. Équipe CCiQ Cisco au Québec Etienne Simard Sylvain Denoncourt Johan Arens
  • 3. • Vision de Cisco • Réalité du monde manufacturier • Architecture et Sécurité • Edge Computing • Conclusion • Questions / Réponses Agenda
  • 4. “L’Internet des objets est une façon intelligente de connecter des équipements physiques pour aller extraire des améliorations substancielles dans notre efficacité, croissance d’affaire et amélioration de la qualité de vie.” Qu’est-ce que l’Internet des objets ?
  • 5. Cisco Confidential 5© 2013-2014 Cisco and/or its affiliates. All rights reserved. Converging Digital Disruptions The Nexus of Forces IoT = $1.9 Trillion in 2020 The 3rd Platform $462 Billion in 2013 (22% of total ICT spending) The Industrial Internet $10 Trillion to $15 Trillion Over Next 20 Years
  • 6. Cisco Confidential 6© 2013-2014 Cisco and/or its affiliates. All rights reserved. Cisco Calls It The Internet of Everything (IoE) Interconnexion des personnes, procédés, données et des objets People Connecting People in More Relevant, Valuable Ways Process Delivering the Right Information to the Right Person (or Machine) at the Right Time Data Leveraging Data into More Useful Information for Decision Making Things Physical Devices and Objects Connected to the Internet and Each Other for Intelligent Decision Making IoE
  • 7. Cisco Confidential 7© 2013-2014 Cisco and/or its affiliates. All rights reserved. 7.26.8 7.6 IoT Is Here Now – and Growing! Rapid Adoption Rate of Digital Infrastructure: 5X Faster Than Electricity and Telephony 50 Billion “Smart Objects” 50 2010 2015 2020 0 40 30 20 10 BILLIONSOFDEVICES 25 12.5 Inflection Point TIMELINE Source: Cisco IBSG, 2011 World Population The New Essential Infrastructure
  • 8. Cisco Confidential 8© 2013-2014 Cisco and/or its affiliates. All rights reserved. The World Generates More Than 2 Exabytes of Data Every Day Connected Objects Generate Big Data 3/4 millions smart meters in Quebec 90 millions data points > 2 TB / month ! 10TB of data for every 30 minutes of flight With >25,000 flights per day, petabytes daily A large offshore field produces 0.75TB of data weekly A large refinery generates 1TB of raw data per day A single consumer packaged good manufacturing machine generates 13B data samples per day
  • 9. Opérations en silos Pas de choix technologiques communs Dépendance des OEM ou fabricants de lignes Réalité du monde manufacturier
  • 10. Musée des systèmes d’exploitation Usines installées proche des matières premières Centralisation des centres de données Production sur demande Faire plus avec moins Réalité du monde manufacturier
  • 11. Relations tendues entre IT et OT Réalité du monde manufacturier CIA AIC Availability Integrity Confidentiality Confidentiality Integrity Availability
  • 12. Relations tendues entre IT et OT Réalité du monde manufacturier Marc, OT Bernard, IT Bernard, J’ai besoin d’un adresse IP pour remonter ma drive que je viens de la remplacer. Ma motion ne marche plus ! Ah ! Il a des SAN lui sur son plancher ? Marc, donc pour bien comprendre tu as besoin de remonter ton SAN pour pouvoir bouger des VM d’un SAN à un autre ?
  • 13. Besoin d’un plan directeur et d’une architecture !
  • 14. Changing Industrial Automation Networks Ethernet and IP Provide Foundation for Manufacturing 2.0 Initiatives Robotics Human Machine Interface PC-Based Controllers Motors, Drives, and Actuators Programmable Logic Controllers Office Applications, Internetworking, Data Servers, and Storage Back-Office Mainframes and Servers Sensors and Other Input/Output Devices Corporate Network Control Network Gateway Robotics Human Machine Interface PC-Based Controllers Motors, Drives, and Actuators Programmable Logic Controllers Office Applications, Internetworking, Data Servers, and Storage Back-Office Mainframes and Servers Sensors and Other Input/Output Devices Corporate Network Traditional Ethernet-Based Control Network Device-Level Network Ethernet Automation Control
  • 15. Logical Architecture Built on Industry Standards Enterprise Zone DMZ Manufacturing Zone Cell/Area Zone Enterprise Network Site Business Planning and Logistics Network Site Manufacturing Operations and Control Area Control Basic Control Process Demilitarized Zone— Shared Access Level 5 Level 4 Level 3 Level 2 Level 1 Level 0
  • 16. Converged Plantwide Ethernet Network Architecture Cell/Area Zone Levels 0-2 Manufacturing Zone Level 3 Demilitarized Zone (DMZ) Real-Time Control <100ms Convergence Multicast Traffic Ease of Use MFG Integration Segmentation Multi-Service Networks Applications and Management Security Access Control Threat Protection Enterprise Network Levels 4-5 Gbps Link for Failover Detection Firewall (Active) Firewall (Standby) FactoryTalk Application Servers Cisco ASA 5500 Cisco Catalyst Switch Network Services Cisco Catalyst 6800/4500 Cisco Cat. 3850 StackWise Switch Stack Patch Management Terminal Services Application Mirror AV Server Cell/Area #1 (Redundant Star Topology) Drive Controller HMI Distributed I/O Controller DriveDrive HMI Distributed I/O HMI Cell/Area #2 (Ring Topology) Cell/Area #3 (Bus/Star Topology) Rockwell Automation Stratix 8000 Layer 2 Access Switch Controller Enterprise/ IT Integration Collaboration Wireless Application OptimizationWeb Apps DNS FTP Internet
  • 17. CPwE Industrial Network Security Framework MCC Enterprise Zone: Levels 4-5 Soft Starter I/O Physical or Virtualized Servers • Patch Management • AV Server • Application Mirror • Remote Desktop Gateway Server Level 0 - ProcessLevel 1 - Controller Level 3 – Site Operations Controller Drive Level 2 – Area Supervisory Control FactoryTalk Client Controller Industrial Demilitarized Zone (IDMZ) Industrial Zone: Levels 0-3 Authentication, Authorization and Accounting (AAA) LWAP SSID 2.4 GHz SSID 5 GHz WGB I/O Active Wireless LAN Controller (WLC) Standby Core Switches Distribution Switch Stack Control System Engineers Control System Engineers in Collaboration with IT Network Engineers (Industrial IT) IT Security Architects in Collaboration with Control Systems Engineers Enterprise Identity Services External DMZ/ Firewall Internet IFW Exemple de sécurisation niveau procédé
  • 18. CPwE Industrial Network Security Framework MCC Enterprise Zone: Levels 4-5 Soft Starter I/O Physical or Virtualized Servers • Patch Management • AV Server • Application Mirror • Remote Desktop Gateway Server Level 0 - ProcessLevel 1 - Controller Level 3 – Site Operations Controller Drive Level 2 – Area Supervisory Control FactoryTalk Client Controller Industrial Demilitarized Zone (IDMZ) Industrial Zone: Levels 0-3 Authentication, Authorization and Accounting (AAA) LWAP SSID 2.4 GHz SSID 5 GHz WGB I/O Active Wireless LAN Controller (WLC) Standby Core Switches Distribution Switch Stack Control System Engineers Control System Engineers in Collaboration with IT Network Engineers (Industrial IT) IT Security Architects in Collaboration with Control Systems Engineers Enterprise Identity Services External DMZ/ Firewall Internet IFW Exemple d’acces à distance d’un entrepreneur Martin T., Cossins Inc Doit accéder usine Granby
  • 19. CPwE Architectures • Collection of Standalone Cisco Validated Design (CVD) Guides CPwE REP CVD June 2014 CPwE WLAN CVD Nov. 2014 CPwE IDMZ CVD July 2015 CPwE Resiliency June 2016 CPwE CVD Baseline CPwE NAT CVD June 2015 CPwE ISE CVD July 2015 CPwE Migration Jan. 2016 CPwE VPN CVD March 2016 CPwE Industrial Firewall August 2016 CPwE Loc. Serv. White paper CPwE Resiliency Dec. 2015 Design Zone manufacturing – Modular CVD’s http://www.cisco.com/c/en/us/solutions/enterprise/design-zone- manufacturing/landing_ettf.html
  • 21. Most IoT data is not used currently. For example, only 1 percent of data from an oil rig with 30,000 sensors is examined. The data that is used today is mostly for anomaly detection and control, not optimization and prediction, which provide the greatest value.
  • 22. Leveraging Machine Generated Data and Networking for Business Benefit IoT Environments Need to Process and Analyze Data Locally
  • 23. In Many Cases, Data Issues Must be Handled “In the Network” to Meet the Requirements Hence… Distributed Data Processing [across the] Network Fabric
  • 24. The Case for Edge and Fog Computing 1. There’s too much data, so it has to be filtered, aggregated, batched, etc. 2. Some of the consumers of the data are distributed. 3. The data is in the wrong format. 4. You want to analyze the data as soon as possible. 5. The data needs to be time stamped for time series analysis or for compliance reasons. 6. You have thousands of devices, and it’s too complicated for a single application in the cloud to talk to them individually.
  • 25. General Patterns Data CenterEdge Processing Aggregation NodeOil Rig Data Data Data Local Feedback Data CenterFactory Device Data Data CloudIoT Device 2 Tier 3 Tier 4 Tier Data
  • 26. IoT Requires Distributed Computing ENDPOINT DATACENTER/CLOUD FOG App App App App App IoT Compute Model (Local control loops, Data Volume, Security, Resiliency, Latency, Scale) BYOI: Bring Your Own Interface (Legacy interfaces, Industry-specific interfaces, Partner-proprietary interfaces) WiHart Zigbee PLC 802.15.4 Other Domain Specific Interfaces
  • 27. Architecture FOG - IoX Routers / Switches at the edge App Hosting App Lifecycle Management App Monitoring App Monitoring Local Manager Customer-built App Cisco-built App Partner-built App App Packaging SDK App Lifecycle App Management Fog Director IOx Services (Alpha*) Applications (LXC*, PaaS, VM) Network (IOS) IOx
  • 28. Why is this Unique? Bring Analytics to the Data DATA DATA Fog NodeEdge Node DATA AnalyticsIoT Devices IoT Devices Analytics DATA Distributed Analytics (Distributed, High Volume, Time Critical, Regulated) Cloud Based Analytics (Centralized, Low Volume, Non Perishable, Non Regulated) Analytics Analytics
  • 30. • Vision IoE de Cisco • Défis du monde manufacturier • Sécurité • Edge Computing (Fog)