Methods for the interaction of IoT nodes in a local network and local IoT node network

The decentralized IoT node interaction method with secure multicast communication and PKI ensures robust security and efficient automation in local networks by distributing application logic across nodes, eliminating the need for a central control entity and preventing replay attacks.

DE102024102789A1Pending Publication Date: 2025-07-31PERINET GMBH
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
DE102024102789
Authority / Receiving Office
DE · DE
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-01-31
Publication Date
2025-07-31

AI Technical Summary

Technical Problem

Existing methods for securing communication in local IoT networks are inadequate, particularly in the absence of a central control entity, leading to potential security vulnerabilities and inefficiencies.

Method used

A decentralized method for IoT node interaction in local networks using a group header IoT node to facilitate secure multicast communication via UDP/IP, leveraging a public key infrastructure (PKI) and symmetric encryption, with each node executing part of the application logic through macroblocks, and utilizing self-organization mechanisms for group formation.

Benefits of technology

Enables secure, decentralized automation of IoT nodes without a central computer, reducing costs and enhancing security against replay attacks by using a common time base and asymmetric encryption.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

A method is provided for the interaction of Internet-of-Things IoT nodes (110) in a local network (100), wherein the local network (100) represents an Ethernet network or a single pair Ethernet network and has a plurality of IoT nodes (110), and wherein each IoT node (110) has at least one sensor and / or one actuator (111) and a first interface (112) for communication with other IoT nodes (110) in the local network (120).The method comprises the steps of: creating a group (110a) of IoT nodes (110) from the plurality of IoT nodes (110), which together execute an application, wherein at least one of the IoT nodes (110) of the group (110a) each has a processing unit that is suitable for executing at least part of an application logic of the application; determining a group head IoT node (110b) from the IoT nodes (110) of the group (110a), wherein the group head IoT node (110b) is designed to ensure the necessary information for secure multicast communication between the IoT nodes (110) in the group (110a), wherein the multicast communication takes place via a User Datagram Protocol Internet Protocol UDP / IP, and executing the application logic for implementing at least part of the application via the processing units of the IoT nodes (110).
Need to check novelty before this filing date? Find Prior Art

Description

The present invention relates to a method for interaction of loT nodes in a local network and to a local loT node networkTo improve automation, more and more sensors and actuators are used, which are network-capable. Such networks are referred to as the Internet of Things or the Internet of Things loT or the industrial Internet of Things Industrial Internet of Things IIoT. Communication between the sensors and the actuators is typically based on an IP protocol. In this case, these sensors and actuators can be used in a local network (smart home or in a factory). Alternatively, these IoT sensors and actuators may also be directly connected to the Internet.In particular when using loT sensors or actuators in a local network, the safety of the internal communication must be ensured.It is therefore an object of the present invention to enable an improved method for interaction of loT nodes in a local network, in particular with improved security.This object is achieved by a method for interaction of loT nodes or loT devices in a local area network according to claim 1 and by a local Internet of things loT network according to claim 10.Thus, a method for interacting loT nodes in a local area network is provided. The local area network (e.g., a local area network LAN) represents an Ethernet network or a single pair Ethernet network. Each loT node includes at least one sensor and / or actuator and a first interface for communication with other loT nodes in the local area network. A group of IoT nodes is created from the plurality of IoT nodes, which together execute an application. At least one of the loT nodes of the group comprises a processing unit suitable for performing at least part of application logic of the application (e.g. macroblocks). A group head loT node is determined from the group's loT nodes during a self-organization phase. The group header loT node is configured to provide the members of the group with the necessary information for secure multicast communication. The multicast communication then takes place via a user datagram protocol internet protocol UDP / IP. The application logic for executing at least a portion of the application is executed via the processing units of the IoT nodes. The application logic can thus be executed decentrally by the loT nodes of the group.According to one aspect, the loT nodes of the group can belong to a public key infrastructure PKI, which can issue, distribute and check digital certificates. The digital certificates are used to secure the communication of the IoT nodes of the group.According to one aspect, in a self-organization phase, the determination of a group header IoT node can take place via self-organization mechanisms using decentralized service discovery methods and secure 1-to-1 communication, in particular according to a TCP.In one aspect, macroblocks of the loT nodes are coupled via messages exchanged among the loT nodes of the group via the secure multicast communication.According to one aspect, the loT nodes each have a processing unit which are suitable for executing part of the application logic of the application. The processing unit can be part of the interface and / or part of the sensor / actuator.The group header can optionally be determined dynamically at runtime by the group (self-organization). In a self-organization phase (i.e. the formation of the group), secure point-to-point communication (e.g. according to the TCP protocol) is used, wherein the associated loT nodes of a group are found via service discovery mechanisms.The application-related communication after the self-organization phase then takes place via secure multicast communication via user datagram protocol internet protocol UDP / IP.The header of the group can be determined, for example, on the basis of the assigned IP addresses of the IoT nodes. If the selected node is already part of another group and does not represent the header, then that IoT node can pass the information to the other multicast group.The header of the group may output the following information to the other members of the group: a synchronous key, a multicast address and time information. By means of the time information, the other nodes of the group can likewise be set to a time base. By means of the time information it can also be established whether a received message or a received packet is a current message or a current packet.Instead of a central computer for controlling the application, the application is implemented in a decentralized manner by the loT nodes. The basic idea here is that loT nodes, according to their nature, (capable of communication) have the necessary computing power for the implementation of typical applications and thus a central processing entity, e.g. an PLC, can be dispensed with.The application is therefore not implemented centrally but rather decentrally, wherein the application logic is divided between distributed processing units, e.g. function blocks or macro, whereby the central control that is usual hitherto is superfluous. For example, in response to external circumstances or by actuation of an actuator, an IoT node (e.g., a button) sends a message over the multicast channel.This loT node can perform macro operations and can generate a message based on the environmental influences or the actuation of the element, which message is multicasted to the members of the group. The receiving IoT nodes also typically have macro operations. Here, a corresponding control of the loT node can then take place on the basis of the received message.The respective loT nodes may be configured by a user such that a message initializes a macro function.Application logic for carrying out an application can optionally be implemented decentralized to the loT node itself by means of so-called macroblocks. Sensors may, for example, send certain messages to be defined by the user in the presence of events. Actuators may perform actions determined on such messages. It is possible in particular by multicast communication that a so-called n-to-m interaction takes place, i.e. one sensor controls a plurality of actuators and one actuator can be controlled by a plurality of sensors. Optionally, an loT node can be configured as a multi-sensor actuator.Optionally, all IoT nodes of the group may have a common time base. The group header loT node determines the shared time base during the self-assembly phase. loT nodes can insert the current time into the sent messages, whereby the bit sequence transmitted on the line changes automatically with time. An attacker cannot thereby easily send the message again later, e.g. for opening a door, or this is recognized as an attack by the received nodes. It is particularly advantageous, through the use of a time base, that each node can update the time independently.A one-loT node may be configured to sign a message to be transmitted. The received IoT nodes are configured to check the message for the origin on the basis of the signature contained.The first interface of the loT node can be designed display-free and control-element-free.According to an example, at least one of the IoT nodes is a dynamic loT node that is at least temporarily part of the network (120). The dynamic loT node is excluded from selection as a group header loT node.Each IoT node or device can authenticate itself to the other loT nodes of a communication group by means of an asymmetric encryption method. The provision of the key pairs and certificates necessary for this purpose is described, for example, in WO 2021 / 0644096. Such a cryptographic method allows secure autonomous connection establishment of loT nodes.The sensors can be designed, for example, as operator control elements, push buttons, rotary controllers, threshold value switches, for example fill level, movement, environmental sensors, temperature sensor, moisture sensor, CO2sensor, light sensor, wind sensor, vibration sensor, and / or current sensor systems.The actuators can be configured, for example, as lamps, louvers, valves, mixers, pumps, actuating drives, door open / closeers and / or heating / cooling element.The communication can take place as network-based communication via UDP / IP or TCP / IP.The IoT nodes may be used in local area networks without routing among each otherThe loT nodes have control elements necessary only for the function (no displays and buttons for configuration).The loT nodes are deeply embedded systems (systems with low computing power and memory compared to conventional computers (laptops, mobile telephones).The loT nodes are optionally batteryless.The interaction of the IoT nodes can take place in a decentralized manner.Further embodiments of the invention are the subject matter of the dependent claims.Advantages and exemplary embodiments of the invention are explained in more detail below with reference to the drawings. FIG. 1 shows a schematic illustration of a local area network, and Fig. 2 is an enlarged view of a portion of the local area network of Fig. 1.FIG. 1 is a schematic diagram of a local area network according to a first embodiment of the invention, and FIG. 2 is an enlarged view of a part of the local area network of FIG. 1. A local area network 100 includes a plurality of Internet of Things (loT) nodes 110 connected to each other by an Ethernet network or a single pair Ethernet network 120. The loT nodes 110 may communicate with other IoT nodes 110 only within the local area network 100. Each node 110 may include a sensor and / or actuator 111 and an interface 112 for communication with other loT nodes 110 in the network 100.In order to implement an application, a group 110 ais formed from the loT nodes 110 required for this purpose. The exchange of group information (time base, multicast address, and / or encryption information) can take place based on a TCP / IP connection secured by mTLS. Communication between the IoT nodes 110 of the group 100 ain the network 100 then takes place on the basis of a user datagram protocol internet protocol UDP / IP, which is secured via symmetrical encryption. One of the loT nodes of group 100a represents a group header 110b, it provides the necessary information for secured multicast communication to the other nodes (e.g., the multicast address to be used, the symmetric connection keys to be used, and optionally the common time base to be used). The application logic may be based on processing macroblocks. This allows decentral control of the application by the IoT nodes themselves to be achieved.Typical sensors are, for example, operator control elements, pushbuttons, rotary controllers, threshold value switches, for example fill level, movement, ambient sensors, temperature, humidity, CO2, light, wind, vibration, and current sensor systems.Typical actuators are e.g. lamps, louvers, valves, mixers, pumps, actuators, door open / closeers and heating / cooling elements.As protection against replay attacks, the UDP / IP communication can use a common time base. Since the data are transmitted in encrypted form, an attacker can thereby not again later send a valid message repeatedly and thus trigger undesirable actions.Thus, automated machine-to-machine communication can also be enabled even in local networks with a very high number of loT nodes 110.According to the first exemplary embodiment, an automatic possibility of authenticating the loT nodes 110 within the local area network 100 is to be made possible without a continuous active internet connection, for example to a root certificate server 210, having to be present in this case. This is achieved by moving all security mechanisms into the local area network without an active Internet connection having to be present during authentication.The loT nodes or IoT devices represent devices that are designed to be display-free and operator-free. This can reduce the cost of the loT nodes or loT devices. The loT nodes or loT devices can be controlled only via the local network. For example, parameters can be set via a browser on the computer 130.The loT node according to the invention has neither a display nor operating elements nor a reset button. The loT node has only a first interface for communication with the network 120. A second interface may be used to communicate with devices coupled to the IoT node 110.According to one aspect of the present invention, the loT nodes can represent network-capable smart home devices, devices of building automation or industrial devices.During the initialization of the multicast group, a public key infrastructure PKI may be used. Using a service discovery as described, for example, in WO 2021 / 0644096, those IoT nodes can be determined which should be part of the group. During the initialization of the multicast group, one of the loT nodes is selected as a group header. The group header serves to output all nodes of the group with the information necessary for secure multicast communication (symmetric key, multicast address and time info).According to one example, a method for interaction of Internet of Things loT nodes (110) in a local network (100) is provided, wherein the local network (100) represents an Ethernet network or a single pair Ethernet network and comprises a plurality of loT nodes (110), and wherein each loT node (110) comprises at least one sensor and / or an actuator (111) and a first interface (112) for communication with other loT nodes (110) in the local network (120). The method comprises the steps of:creating a group (110a) of loT nodes (110) from the plurality of loT nodes (110), which together execute an application, wherein all nodes belong to a common public key infrastructure PKI,determining a group header IoT node (110b) from the loT nodes (110) of the group (110a) via self-organization mechanisms using decentralized service finding methods and secure 1-to-1 communication, wherein the group header IoT node (110b) is configured to ensure the necessary information for secure multicast communication of the loT nodes (110) in the group (110a) among one another via a user datagram protocol internet protocol UDP / IP,executing application logic on macroblocks executable on the IoT node that are coupled via messages exchanged via the secure multicast communication.References included in the specificationThis list of documents cited by the applicant has been produced in an automated manner and is only included for the better information of the reader. The list is not part of the German patent application or utility model application. The DPMA does not take any adhesion for any faults or omissions.Patent Literature citedWO 2021 / 0644096 [0024, 0045]

Claims

Method for interaction of Internet of Things loT nodes (110) in a local network (100), wherein the local network (100) represents an Ethernet network or a single pair Ethernet network and comprises a plurality of loT nodes (110), and wherein each loT node (110) comprises at least one sensor and / or an actuator (111) and a first interface (112) for communication with other loT nodes (110) in the local network (120), comprising the steps of: - creating a group (110a) of loT nodes (110) from the plurality of loT nodes (110), which together execute an application, wherein at least one of the loT nodes (110) of the group (110a) comprises in each case a processing unit which is suitable for the purpose of:, at least part of application logic for executing the application, - determining a group header IoT node (110b) from the loT nodes (110) of the group (110a), wherein the group header IoT node (110b) is configured to ensure the necessary information for secure multicast communication of the IoT nodes (110) in the group (110a) among one another, wherein the multicast communication takes place via a user datagram protocol internet protocol UDP / IP, and - executing the application logic for executing at least part of the application via the processing units of the loT nodes (110).The method for interacting IoT nodes (110) in a local area network (100) according to claim 1, wherein at least all IoT nodes (110) of the group (110a) belong to a common public key infrastructure, which can issue, distribute and verify digital certificates used for safeguarding the communication of the loT nodes (110) of the group (110a).Method for interaction of loT nodes (110) in a local network (100) according to claim 1 or 2, wherein in a self-organization phase, the determination of a group header IoT node (110b) takes place via self-organization mechanisms using decentralized service discovery methods and a secure 1-to-1 communication, in particular according to a TCP.Method for interaction of IoT nodes (110) in a local network (100) according to one of claims 1 to 3, wherein execution of the application logic, in particular macroblocks, is coupled by the processing units of the loT nodes via messages exchanged via the secure multicast communication among the loT nodes (110) of the group (110a).Method for interaction of loT nodes (110) in a local network (100) according to one of Claims 1 to 4, wherein all loT nodes (110) of the group (100a) have a common time base, wherein the loT nodes (110) embed the time base in the messages transmitted by them and receiving loT nodes can check the up-to-dateness of the messages on the basis of the time base contained therein.The method for interacting loT nodes (110) in a local area network (100) of claim 2, wherein the loT nodes (110) are capable of self-updating the time base.Method for interaction of Internet-of-things loT nodes (110) in a local network (100) according to one of the preceding claims, wherein the loT nodes (110b) are designed to sign a message to be transmitted, wherein the received loT nodes (110) are designed to check the origin of the message on the basis of the signature contained.The method for interaction of Internet of things loT nodes (110) in a local area network (100) according to claim 7, wherein the received IoT nodes (110) are configured to implement different rights within the application based on the contained signature.Method for interaction of Internet-of-things loT nodes (110) in a local network (100) according to one of the preceding claims, wherein the first interface (112) of the loT nodes (110) is designed to be display-loose and operator-free.The method for interaction of Internet of things loT nodes (110) in a local area network (100) according to any one of the preceding claims, wherein each IoT node (110) comprises a first public cryptographic key and a first private cryptographic key, wherein the first private key is pre-stored or generated by the IoT node (110) itself.The method for interacting Internet of Things IoT nodes (110) in a local area network (100) according to any one of the preceding claims, wherein the information necessary for secure multicast communication of the loT nodes (110) includes a multicast address, a symmetric key and a common time base.The method for interacting Internet of Things loT nodes (110) in a local area network (100) according to any of the preceding claims, wherein the multicast communication of the loT nodes within the group represents an n-m communication.LoT node local area network (100), wherein the local area network (100) represents an Ethernet network or a single pair Ethernet network, comprising a plurality of loT nodes (110), wherein each loT node (110) comprises at least one sensor and / or an actuator (111) and a first interface (112) for communication with other loT nodes (110) in the local area network (120), wherein a group (110a) of IoT nodes (110) from the plurality of loT nodes (110) is configured to together execute an application, wherein a group head IoT node (110b) from the group of loT nodes (110a) is configured to:, The method of ensuring the necessary information for secure multicast communication of the loT nodes (110) in the group (110a) among one another via a user datagram protocol internet protocol UDP / IP, wherein at least one of the loT nodes (110) of the group (110a) has in each case a processing unit which is suitable for executing at least part of application logic of the application.

Citation Information

Patent Citations

  • Secure communications using organically derived synchronized processes

    US20180083785A1

  • Methods, apparatus, and systems for supporting coordinated transmissions for collaborative user equipment (UES)

    WO2023154333A1