ITEA 4 page header azure circular

Capture: situation-aware remote software updates for industrial CPS fleets

Project
22007 Sa4CPS
Type
Enhancement
Description

Machine builders and operators increasingly update software on connected industrial machines remotely. An update started at the wrong moment, f.e. while a machine is running, can stop production, damage equipment or put operators at risk. Existing remote-update tools run updates immediately or on a fixed schedule, without knowing the machine's live state.

Within Sa4CPS, Vintecc extended its Capture IIoT platform with situation-aware updates. The operator attaches a policy of conditions to an update, for example "battery above 80% AND engine not running". Capture Edge evaluates these conditions continuously against the machine's live state, which is kept in a local digital twin. The update starts only when every condition holds.

Unique selling points:

  • Safety conditions are evaluated on the edge device, so a lost cloud connection cannot bypass them.
  • Conditions can be combined with AND/OR.
  • One portal and one workflow update Windows, Linux and container-based (Docker) machines.
  • The update flow maps onto the Sa4CPS situational awareness layers: status (live machine state), projection (policy evaluation) and action (controlled execution).
  • It is built into a platform developed under an ISO 27001-certified security process, with encrypted and signed cloud-edge communication.
Contact
Lander Vanhaverbeke, Vintecc
Email
lander.vanhaverbeke@vintecc.com
Research area(s)
Industrial IoT; cyber-physical systems; situational awareness; edge computing; digital twins; remote software and OTA updates; industrial cybersecurity
Technical features
  • Condition-based update engine on Capture Edge: update policies made of conditions combined with AND/OR (e.g. connectivity, charging state, battery level, machine running or idle, maintenance mode), evaluated continuously.
  • Local digital twin: Capture Edge keeps the last known hardware and software state of the machine (sensor values, machine state, software versions, connectivity) and uses it for policy evaluation, also when offline.
  • Automatic postponement: updates whose conditions are not met are held and started as soon as they are.
  • Multi-platform deployment: Windows, Linux and container-based (Docker) targets updated from one portal with the same workflow.
  • Real-time and batch synchronization: MQTTS streaming of live state, with automatic fallback to buffered batch upload so no data is lost.
  • Security: outbound-only, encrypted, authenticated and signed HTTPS/MQTTS communication between edge and cloud; device secrets; audit trail of user actions; data separated per customer.
Integration constraints
  • Edge runtime: Capture Edge runs on the machine or on an industrial PC next to it, on Windows, Linux or Docker-based environments.
  • Supported data sources (protocol plugins):
    • PLCs and controllers: Beckhoff ADS (symbolic and binary), Siemens S7, OPC UA, OPC DA (Windows), Modbus TCP, EtherNet/IP (Allen-Bradley / Rockwell)
    • Vehicle and mobile equipment: CAN bus (SocketCAN on Linux, Kvaser interfaces), GPS (NMEA over serial), Axotec telematics gateways (Linux)
    • IT and messaging: MQTT, HTTP/REST, gRPC, UDP, Apache Kafka, Redis (key-value, Pub/Sub, Streams)
    • Monitoring: Prometheus (query and remote write), system metrics of the edge device itself
  • Local storage and buffering: InfluxDB, TimescaleDB, Redis, SQLite queue or CSV, so data survives connectivity loss.
  • Local data sharing: data can be republished to third-party systems on the shop floor through an embedded OPC UA server, MQTT or Redis.
  • Cloud connectivity: outbound connections only, no inbound firewall ports needed. Real-time data, commands and status use MQTTS, falling back automatically to secure WebSocket and HTTPS when the MQTT port is blocked. Batch data and software updates are fetched over HTTPS.
  • Cloud deployment: Capture Cloud runs as a managed service, on the customer's own cloud (AWS, Azure, Google Cloud) or on-premises.
  • Integration with other systems: REST API, MQTT / Unified Namespace (UNS) and Grafana dashboards.
  • Capture Edge is designed to run inside the customer's protected OT network segment.
Targeted customer(s)
  • Industrial machine builders who manage the software and parameters of their machine fleets from a central cloud environment.
  • Production companies and system integrators running smart production lines, collaborative systems, vision systems and robots, where uncontrolled updates are not acceptable.
  • Operators of mobile or battery-powered equipment (e.g. vehicles, heavy equipment) where connectivity and charging state determine when an update is safe.

Vintecc is open to integration and distribution partners who deploy Capture to industrial customers in Europe.

Conditions for reuse

Available as part of the Capture platform under a commercial license from Vintecc bv. Not open source. Contact Vintecc for evaluation, pilots or partnership terms.

Confidentiality
Public
Publication date
14-10-2026
Involved partners
Vintecc bv (BEL)

Images

Links