DEVICE WITHIN A MAST AND METHOD

DE502020013378D1Active Publication Date: 2026-08-13CGF COUNSEL GRP FRANKFURT AG
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
DE502020013378
Authority / Receiving Office
DE · DE
Patent Type
Patents
Current Assignee / Owner
Priority Date
2019-10-10
Filing Date
2020-10-07
Publication Date
2026-08-13
Estimated Expiration
2040-10-07

AI Technical Summary

Technical Problem

Existing smart city network infrastructure is vulnerable to cyberattacks, with communication between remote network components and peripheral devices not adequately secured, leading to potential manipulation and unauthorized access to sensitive data.

Method used

A network component, such as a network switch or router, is integrated within a mast housing with a sensor and control unit to detect and alert remote network components of potential attacks, ensuring secure data communication and protecting sensitive information by deleting or overwriting data upon detection of tampering attempts.

Benefits of technology

Enhances network security by detecting and responding to potential attacks, preventing unauthorized data access and manipulation, while allowing reuse of existing infrastructure without structural modifications, and providing secure data communication.

✦ Generated by Eureka AI based on patent content.
Patent Text Reader
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL AREA OF INVENTION

[0001] The invention relates to a device, for example a network component, such as an active coupling element in a network, like a network switch or network router, which is arranged in a mast in a ready-to-use state by means of its housing. The invention further relates to a method for commissioning the device. The invention further relates to a method for operating a peripheral device by means of the device. The invention further relates to a computer program product. TECHNICAL BACKGROUND

[0002] A pole is a ubiquitous feature of the urban and rural landscape. For example, a lamppost might be positioned along a road or sidewalk to help drivers and / or pedestrians see and orient themselves better at night. Additionally or alternatively, a traffic sign, such as a traffic light or road sign, might be mounted on a pole to control the flow of traffic on the road or sidewalk. Additionally or alternatively, an observation or monitoring device, such as a camera or traffic counter, might be mounted on a pole for observing and monitoring public spaces or streets.

[0003] Such a mast is typically an element of a so-called "Smart City" concept. "Smart City" is a collective term for a holistic development concept that aims to design a landscape, especially cities, in an efficient, technologically advanced, ecologically sound, and socially inclusive manner. These concepts are intended to be energy-efficient, low-emission, safe, and cost-effective in order to enable future-oriented initiatives such as comprehensive broadband connectivity, widespread e-mobility, traffic monitoring and surveillance, and / or enhanced security.

[0004] For example, DE 10 2017 215 079 A1 describes a method for recording road users on a road.

[0005] For example, US 2019 / 0107273 A1 proposes a method for configuring a sensor platform of a street lamp to make lighting more energy-efficient, for example by counting or detecting road users.

[0006] In DE 20 2007 011 309 U1, masts of a street lighting system are equipped with publicly accessible sockets to allow, for example, traffic or transport vehicles to be charged. The system is designed to allow users to charge electric vehicles, or to charge devices such as laptops or smartphones, using the street lighting system. Access to the socket is initially blocked to prevent unauthorized access. Users can unlock the socket by authenticating themselves at a terminal or web portal, which then activates an electromechanical slider on the pole.

[0007] US patent 2019 / 0273313 A1 describes a mast that, in addition to lighting and traffic signs, also carries RF antennas and has a configurable grid structure inside for housing radio units and power supplies. A mast door is open to provide access to the housed units.

[0008] US Patent 2019 / 0226672 A1 proposes equipping a light pole with a communication module. This communication module enables network connectivity, allowing antennas on the light pole to be integrated into mobile communication networks such as WLAN, GSM, LTE, etc., and includes network switches, gateways, and routers. The light pole can also be equipped with a power module to provide power to peripheral devices, such as sensors, for example, via the power grid or via data lines using Power on Ethernet. The power module manages the energy supply. A lockable door on the light pole prevents pedestrians from accessing these modules.

[0009] WO 2017 / 200 627 A1 describes a configurable platform for sensors on a street light. A street light controller is attached to the street light.

[0010] US 2017 / 0301220 A1 shows a modular approach to equipping a street light unit with an optical sensor. The street light unit is mounted on a street light pole, and the optical sensor... outside attached to the lantern unit.

[0011] DE 20 2014 010323 U1 relates to a street lighting mast, comprising at least one sensor device for determining environmental and / or traffic data.

[0012] Anonymous: "R-2700 Series RUGGEDISED ROUTER for installation in street light poles and vehicles, September 23, 2016 (2016-09-23), pages 1-9, XP093137186 ​​concerns a hardware specification of a router for installation in a street light pole.

[0013] Smart city concepts always require a network. This network is a critical network that can be vulnerable to cyberattacks. A problem with existing solutions is that the communication between a remote network component, such as a server or a backbone component, and a peripheral device is not adequately secured. An attacker attempting to manipulate a peripheral device, for example, is not currently detected by the remote network component and can thus cause significant damage to the network. This could include manipulating lighting or traffic light controls, sabotaging an electric vehicle charging process, and / or illicitly intercepting sensor data. Furthermore, security-relevant data used in data communication, such as private keys, certificates, IP addresses, and passwords, could be accessed and compromised.

[0014] All previous solutions aim to better secure the light pole itself, particularly through mechanical locks and latches or sensors on the pole door. Such solutions are expensive and also inefficient, as the poles are often located in remote areas. SUMMARY OF THE INVENTION

[0015] The invention is defined in the attached claims.

[0016] The invention is based on the objective of creating a device that, for example, as a network component in a smart city environment, makes data communication between a remote network component and a peripheral device more secure. In particular, the device, for example a network switch or a router, is intended to ensure that an attack or manipulation attempt on the data communication is detected early and reported to the remote network component. Furthermore, confidential or security-relevant information, for example data from the device's memory or data provided by a peripheral device, should not be accessible.

[0017] Another task is compliance with data protection regulations, because publicly collected data is subject to confidentiality and must be protected from unauthorized access.

[0018] Furthermore, existing infrastructure should be able to be reused as much as possible, thus avoiding the replacement of already installed masts to provide additional functionality. No structural modifications, such as enlarging a mast door, installing sensors, or adding switching elements, should be necessary on the existing masts.

[0019] Additionally, maximum functionality should be achieved with minimal effort, meaning that cabling effort in the mast should be reduced.

[0020] The problem is solved by the features described in the independent claims. Advantageous embodiments of the invention are specified in the dependent claims.

[0021] According to the invention, a device, in particular a network component, is proposed which is arranged in a ready-to-use state within a mast by means of its housing. The device has a sensor on its housing for providing a sensor signal. The device also has a control unit inside the device. This control unit comprises at least one first data port configured for

[0022] Transmission of a data signal between the device and a network component located remote from the mast. This control unit includes at least one second data port configured for transmitting a data signal between the device and a peripheral device. This control unit includes a sensor signal port for receiving the sensor signal. This control unit is configured to forward data communication between the remote network component and the peripheral device. The control unit is also configured to evaluate the received sensor signal, detect changes in the sensor signal, and alert the remote network component when the control unit detects such a change.

[0023] The device is an active network component of a network, i.e., a physical device required for communication and interaction between the network component located remote from the mast and the peripheral device. The device can be, for example, a gateway, router, network bridge, modem, wireless access point, network switch, network hub, and / or repeater. The device can also be, or include, a hybrid network component such as a multilayer switch, protocol converter, bridge router, proxy server, firewall, network address translator, multiplexer, or network interface controller.

[0024] Preferably, the device is a network switch. The network is preferably a Metropolitan Area Network (MAN). The network can be configured in a specific bus topology, such as a star bus, or in series, so-called daisy-chaining. A daisy chain refers to a number of hardware components connected in series to form a network. The first component, the first mast, is directly connected to the remote network component. The subsequent components, the subsequent masts, are each connected to their predecessors (series connection principle), thus creating a chain, the daisy chain. The signal to and from a device in a mast then travels through its predecessors to the computer system.

[0025] The device comprises a housing. The housing contains the device with sensor and control unit. The housing protects the device against contact, ingress of foreign objects and water, and provides impact resistance. Preferably, the housing has an IP67 protection rating. The housing enables the device to operate in a

[0026] Ambient temperature range from -20 to +85°C, ambient humidity from 5 to 95%. The housing should have a cooling capacity of 1.0 K / W.

[0027] The housing preferably has maximum external dimensions that allow for easy installation and removal (uninstallation, maintenance, repair) of the device in a mast. The housing preferably has minimal external dimensions that allow it to serve as a heat sink for the device, thus eliminating the need for internal heat sinks, fans, or complex heat dissipation systems (heat pipes), thereby further miniaturizing the device and reducing its complexity.

[0028] The device is arranged within a stationary mast and fixed within the mast. A mast, in this context, is a structure with at least one hollow, pillar- or post-like section, whose base area may be relatively small compared to its height. The mast primarily serves to mount functional units, such as lighting fixtures (streetlights, floodlights, pathway lights, illuminated advertising) and / or units for monitoring and / or controlling traffic (signposts, traffic signals, traffic signs, toll gantries, traffic counters) and / or electrical components (power lines, antennas).

[0029] The device is, for example, an integral part of the mast or – preferably – can be installed and removed as an additional component within the mast. For this purpose, the mast has a hollow section accessible from the outside, which can be closed with a mast door or hatch. This ensures that the device is securely stowed within the mast and additionally protected against environmental influences such as moisture, cold, and heat. Furthermore, this approach allows the existing mast infrastructure to be reused and avoids the need to replace masts to provide additional functionality.

[0030] The device is installed in the mast and ready for operation. "Ready for operation" in this context means that the device is powered and permanently installed. Preferably, the power supply for the device within the mast is provided in addition to the power supply for a functional unit of the mast. For example, the power supply for the device could be branched off from the power supply of a functional unit of the mast.

[0031] The device includes a sensor, also known as a detector or (measurement or measuring) transducer or (measuring) probe. The sensor is a technical component that detects certain physical properties (e.g., heat quantity, temperature, humidity, pressure,

[0032] The sensor can qualitatively or quantitatively capture sound field quantities (brightness, acceleration) as a measured quantity. These quantities are detected using physical effects and converted into an electrical sensor signal that can be processed by the control unit. The control unit can perform the conversion for transmission, or the sensor itself can perform this conversion and provide the sensor signal.

[0033] The sensor is attached to the housing, for example. Preferably, the sensor is located inside the housing and configured for the property to be detected by means of a passage or a transparent section of the housing, so that the physical property prevalent on the outside of the housing can also be detected inside the housing. Alternatively, the sensor can also be located inside the housing if the detection of the physical property is not affected by the presence of the housing, for example, to detect movement of the device.

[0034] The control unit has at least one primary data port for transmitting a data signal. This data signal can also be used to receive power for the device or control unit, enabling it to operate within the mast. The data signal would then be combined, for example, with a Power-on Ethernet signal.

[0035] The first data connection, at least, serves to transmit a data signal between the device and a remote network component, for example, a component of a backbone network and / or a data center and / or a server. The distance between the mast and this remote network component can range from a few meters to several hundred kilometers.

[0036] Preferably, the at least first data port is connected to a first port of the device, wherein the control unit more preferably has at least two first data ports, each configured for transmitting a data signal between the device and at least the network component located away from the mast, and wherein further Preferably, each first data port is connected to a first port on the device. This allows the device to be connected to more than one remote network component or to provide greater data bandwidth for peripherals. The first port is, for example, a small form-factor plugabble (SFP) port to save space.

[0037] The control unit has at least one second data port for transmitting a data signal. This data signal can also be used to supply power to the peripheral device, ensuring its operational readiness, particularly its power supply. The data signal would then be combined, for example, with a Power-on Ethernet signal.

[0038] Preferably, at least the second data port is connected to a second port of the device. More preferably, the control unit has at least four second data ports, each configured to transmit a data signal between the device and a peripheral device. Even more preferably, every second data port is connected to a second port of the device. The number of second data ports is not limited and could be eight, twenty-four, or more. This allows a single device to offer a wide range of functionality on just one mast. The second port is, for example, an RJ45-compliant port.

[0039] A data signal over every second data port can be individually encrypted. The data signals of different second data ports are therefore mutually inaccessible; thus, different service providers can be connected to different peripheral devices via the same device 1 without the service providers being able to eavesdrop on each other's data traffic.

[0040] According to the invention, any functional unit on the mast is considered a peripheral device. The peripheral device can be a sensor or an actuator. It can be a functional unit of the mast itself, such as a lighting element, a traffic signal system, a tolling component, and / or an antenna. In addition to or as an alternative to the mast's functional unit, the peripheral device can also be a device to be installed on the mast, such as a traffic monitoring unit, an additional traffic signal controller, a camera, a wireless network access point (WLAN AP), a mobile phone base station, an electric vehicle charging station, and the like.For example, the peripheral device can be a Smart City component, such as a component of a "Smart Real Laboratory", with additional intelligent sensors that enable the acquisition of diverse information about the environment, especially regarding traffic, weather and the environment, and equip a stationary light pole to become a multimodal object carrier with adaptive lighting, power supply and broadband connection for various types of sensors.

[0041] The peripheral device includes, for example, sensors for measuring temperature, humidity, emissions, pollutants, road surface, etc. The peripheral device provides, for example...

[0042] Traffic flow information serves as the basis for (central or local) traffic flow optimization. The peripheral device provides information such as assistance in finding available parking spaces or charging stations for electric vehicles, or for improved mode selection, also taking current weather conditions into account. The peripheral device also enhances safety through targeted camera surveillance. Furthermore, the peripheral device could be integrated into a gamification system.

[0043] The device's control unit is configured to forward data communication between the remote network component and the peripheral device. This forwarding can be unidirectional or bidirectional. A standardized forwarding method is preferred, for example, according to the IEEE 802.1x protocol, which uses a Media Access Control (MAC) address of a peripheral device to secure the data communication.

[0044] According to the invention, the control unit is configured to receive and evaluate the sensor signal from the sensor of the device. The control unit can itself perform a conversion of a physical effect detected by the sensor to obtain an electrical sensor signal for evaluation. Alternatively, the sensor is already equipped with a conversion unit and provides an electrical sensor signal that is simply interrogated by the control unit. The sensor is powered either by the control unit, by the device, or by the sensor itself. The sensor can also be powered by an energy harvesting process.

[0045] The control unit is further configured to detect changes in the sensor signal. This is achieved, for example, by comparing a value of the sensor signal, such as amplitude, frequency, phase, and / or duration, with a predefined reference value.

[0046] The control unit is also designed to alert the remote network component when a change in the sensor signal is detected.

[0047] This device according to the invention evaluates sensor signals from a sensor on the device's housing and alerts the remote network component in the event of a corresponding abnormality in the sensor signal. As a countermeasure, the network component can then immediately interrupt the forwarded data connection or move it to a quarantine zone in order to quickly counter a potential attack on the data connection and thus prevent the eavesdropping on data or information from the remote network component or the device. In particular, this device further secures a network node that is located far from a data center or a backbone but has full access to the provided data connection by providing sensors that immediately alert the user to a potential attack.

[0048] In a preferred embodiment, the sensor generates a sensor signal depending on the amount of light incident on the sensor, wherein the change in the sensor signal is a sudden or continuous increase in the sensor signal amplitude due to increased light incidence. The sensor is preferably a light sensor, also referred to as a photosensor or photodetector. With such a light sensor, the intensity of light with a suitable wavelength can be measured. The sensor converts light into an electrical signal by means of a photoelectric effect or exhibits an electrical resistance that depends on the incident radiation. Since the device is arranged inside the mast, the interior of the mast is not accessible during normal operation, for example, by a closed mast door or hatch, so that during normal operation a defined, nearly constant, low level of light incidence is detected by the sensor.When the mast is opened, for example by operating a mast door or hatch, the amount of light entering the mast increases sharply. The sensor detects this increase and alerts the remote network component.

[0049] In a preferred embodiment, the evaluation of the sensor signal includes averaging the sensor signal values ​​over a predefined period (so-called mini-hysteresis). This allows short-term fluctuations in the physical property being measured to be averaged out. For example, a flash of light (thunderstorm, etc.) near the mast will not necessarily trigger a (false) alarm from the remote network component due to abnormally high light levels. Similarly, a gust of wind (storm, etc.) at the mast will not necessarily trigger a (false) alarm from the remote network component due to abnormal movement of the housing.

[0050] In a further preferred embodiment, the sensor is a motion sensor, wherein the change in the sensor signal is a sudden or continuous increase in the sensor signal amplitude due to movement of the device's housing. The motion sensor can be, for example, an accelerometer, a tilt sensor, or a Global Positioning System (GPS) transmitter. Under normal operating conditions, the device is fixed in the stationary mast and thus not subject to any movement. The motion sensor detects any movement of the housing, for example, if an attacker attempts to tamper with the device's connections or a thief tries to steal it. The remote network component is then alerted.

[0051] In a further preferred embodiment, the sensor is a switching element, wherein the change in the sensor signal is a sudden or continuous increase in the sensor signal amplitude due to the opening of the device's housing. The switching element is arranged in or on the housing such that opening the housing causes a change in the switching state. The switching element is, for example, a microswitch, a reed contact, or a magnetic contact.

[0052] In a preferred embodiment, the control unit is configured to delete and / or overwrite at least safety-relevant information stored in the device's memory when the control unit detects a change in the sensor signal. In an improved embodiment, the entire memory content of the device is deleted or overwritten. This further increases safety, as the safety-relevant information in the device is now deleted upon detection of an abnormality triggered by a change in the sensor signal. Consequently, no data connection is forwarded, and each peripheral device loses its data connection to the remote network component. Preferably, the control unit also deactivates the power supply to the peripheral devices, thus preventing access to their data.

[0053] The confidential or security-relevant information concerns, on the one hand, configuration information of the device, in particular IP addresses of the remote network component, private cryptographic keys of the device, certificates of the device, signature keys of the device, a configuration file with connection parameter settings, and on the other hand, access passwords, configuration passwords, blacklists of or from other devices, whitelists of or from other devices, access settings, and the like. Usernames and passwords for authentication on the peripheral device also fall under the category of security-relevant information. The device is therefore completely unconfigured and can neither establish a data connection to the remote network component nor...

[0054] Forward data connections to / from a peripheral device. Manipulation through data interception or remote control of the peripheral device is therefore impossible.

[0055] In a further preferred embodiment, the control unit is configured to delete and / or overwrite the security-relevant information only when the sensor signal changes with a sudden or continuous increase in the sensor signal amplitude due to opening the device's housing and / or moving the device's housing. Moving the device or opening its housing is always interpreted as an attack, thus forcing the deletion. After the housing is opened or moved, the device is completely unconfigured and can therefore neither establish a data connection to the remote network component nor forward a data connection to / from a peripheral device. Manipulation by data theft or remote control of peripheral devices is thus prevented.

[0056] It is preferred that at least two sensors be provided. This allows for redundancy of sensor signals to be used, making it more reliable to detect attacks on the device. Furthermore, a two-stage alarm system can be implemented. For example, if the first sensor detects an amplitude above a certain signal threshold, only the remote network component is alerted initially. If the second sensor detects an amplitude above a certain signal threshold, further measures are taken within the device itself, such as deleting or overwriting sensitive information.

[0057] In a preferred embodiment, the device further includes an energy storage device for providing power to the control unit in the event of a failure or removal of an external power supply. This ensures the continued functionality of the device's sensor and also guarantees energy for erasing or overwriting the device's memory. Thus, even if the device is disconnected for theft or maintenance, it remains operational without a power supply.

[0058] Deleting or overwriting is also referred to as "zeroizing".

[0059] In a further preferred embodiment, the device includes a power supply unit. The power supply unit has a first power connection (for example, the first data connection or an additional connection) for supplying power from an external source. The power supply has at least a second

[0060] The device features a power connection for tapping into a power supply for the peripheral device, with the second power connection providing a Power-on-Ethernet (PoE) power signal that is combined with the data signal to be transmitted between the device and the peripheral device. In this way, each peripheral device and each functional unit of the mast can be powered via one of the device's second data connections, thus reducing cabling effort within the mast and eliminating the need for a separate power supply for the peripheral devices. The power supply is preferably a power adapter whose energy consumption is monitored and logged.

[0061] In this way, abnormalities of the device itself or of the peripheral devices can be detected and reported to the remote network component.

[0062] In a preferred embodiment, the power supply unit has at least one third power connection for drawing power for the control unit. Thus, the energy for the control unit is generated by the device itself and does not need to be supplied externally.

[0063] In a further preferred embodiment, the control unit is arranged on a printed circuit board with a standard form factor, preferably PC / 104, and, even more preferably, the power supply unit is arranged on a second printed circuit board with a standard form factor, preferably PC / 104. This industry standard allows for miniaturization of the device so that it can be arranged in the mast without requiring any structural modifications to the mast. Furthermore, this form factor is suitable for providing a large surface area for the device components, thus enabling good heat dissipation.

[0064] Choosing the same form factor also allows multiple circuit boards to be stacked on top of each other and connected using connectors. This improves the electromagnetic compatibility between the components.

[0065] In a preferred embodiment, the peripheral device is authenticated for forwarding data communication between the remote network component and the peripheral device based on the peripheral device's MAC address. Furthermore, if authentication of the peripheral device fails, the forwarding of data communication is preferably blocked by the control unit. The data communication preferably follows the IEEE 802.1x protocol and enables secure communication. The MAC address of the peripheral device is preferably registered with the remote network component. This security measure prevents the interchangeability of a peripheral device connected to the device; a different peripheral device connected to the second data port leads to the deactivation of the data connection to the peripheral device.

[0066] The problem is also solved by a method for commissioning the device described herein, comprising the following steps: transmitting a data signal via at least one first data port of the device to receive configuration information from a remote network component, wherein the device is known at the remote network component; receiving the configuration information from the remote network component in the device, preferably by means of Trivial File Transfer Protocol (TFTP) to initialize the device; and establishing a data connection between the device and the remote network component using the configuration information.Preferably, the configuration file is transmitted cryptographically encrypted, whereby a corresponding key can be negotiated between the remote network component and the device, for example using a Diffie-Hellman method or other derived session keys.

[0067] The problem is also solved by a method for operating a peripheral device on a device described herein, wherein, after the commissioning of the device described herein, the following method steps are carried out: connecting a data signal to at least a second data port of the device for connecting the device to a peripheral device, wherein the peripheral device was registered with the remote network component before being connected; checking by the device whether the MAC address of the peripheral device matches a MAC address communicated by the remote network component; and forwarding a data connection from the remote network component to the peripheral device if the MAC address of the peripheral device matches the communicated MAC address.

[0068] Furthermore, the task is solved by a computer program product which is executably installed in a control unit of the apparatus described herein and has means for carrying out the process steps of the previously described procedures. BRIEF DESCRIPTION OF THE FIGURES

[0069] The invention, further embodiments, and advantages of the invention are explained in more detail below with reference to figures, which merely depict exemplary embodiments of the invention. Identical components in the figures are identified by the same reference numerals. Except where specifically marked, the figures are not to be considered as being drawn to scale; individual elements of the figures may be exaggerated in size or simplified. Fig. 1 shows an embodiment of a simplified block diagram of a device according to the invention within a schematically represented mast section; Fig. 2shows an exemplary embodiment of a simplified block diagram of a device according to the invention; Fig. 3 shows an exemplary embodiment of a simplified block diagram of a device according to the invention; Fig. 4 shows an exemplary embodiment of a block diagram of a device according to the invention; Fig. 5 shows an exemplary embodiment of a block diagram of a power supply unit of a device according to the invention; Fig. 6 shows an exemplary embodiment of a flowchart of a method according to the invention; Fig. 7 shows an exemplary embodiment of a flowchart of another method according to the invention; Fig. 8 shows a scale model of an exemplary mast in which a device according to the invention is arranged; Fig. 9 shows three scale examples of exemplary mast openings through which a device according to the invention is arranged in a mast; Fig. 10 shows an embodiment of a system according to the invention consisting of a mast with a device arranged therein; Fig. 11 Figure 1 shows an embodiment of a system according to the invention consisting of three masts in a traffic monitoring system in a star topology; and Fig. 12 shows an embodiment of a system according to the invention consisting of three masts in a traffic monitoring system in Dais-Chain topology. DETAILED DESCRIPTION OF EXAMPLES OF EXECUTION

[0070] Fig. 1 Figure 1 shows an exemplary embodiment of a simplified block diagram of a device 1 according to the invention within a schematically represented mast section of a mast 2. With this exemplary embodiment, it is possible to expand masts 2 of cities, municipalities and companies into communication and control nodes and thus enable a smart city concept.

[0071] Mast 2 is a light mast, such as those found in the following Figures 8 to 10This will be explained in more detail later. The mast is hollow inside and has a mast opening 21, which can preferably be closed almost light-tight by a flap or door (not shown). Inside the mast 2 is a device 1 according to the invention, here hereinafter referred to simply as switch 1, i.e., network switch.

[0072] Switch 1 is integrated into a metal housing with IP67 protection. Switch 1 provides at least one input port 11, which is connected within Switch 1 to a first data port 131 of a control unit 13. The first data port 131 is configured to transmit a data signal between Switch 1 and a network component located remote from mast 2, hereinafter referred to simply as data center 4 or backbone 4. The data signal at the first port 11 has a bit rate of, for example, 10 Gbit, but could also be only 1 Gbit or 100 Gbit. The data center is, for example, a city or state data center, which may be located several hundred kilometers from mast 2. The network is a Metropolitan Area Network (MAN). Preferably, the data signal is connected to the first port 11 via fiber optic cable.The data signal can be transmitted in a mono-mode method if the distance between device 1 and remote network component 4 exceeds a certain threshold. The data signal can be transmitted in a multi-mode method if the distance between device 1 and remote network component 4 falls below a certain threshold.

[0073] On the output side, switch 1 has at least one second port 12, which is connected to a second data port 132 of the control unit 13. The second data port 132 is configured to transmit a data signal between switch 1 and peripheral device 3. The data signal at the second port 12 is, for example, a 1 Gbit Ethernet interface. Preferably, this data signal has Power-on Ethernet (PoE) functionality, allowing a predefined maximum power, for example, 25 W, to be transmitted to the peripheral device 3. Preferably, the data signal is connected to the second port 12 via copper.

[0074] The Switch 2 has a sensor 14 built into its housing. This sensor 14 is in Fig. 1A light sensor is connected to a sensor signal port 133 on the control unit 13. The light sensor is mounted inside the housing of the switch 1 to detect incident light entering the mast opening 21. This makes a portion of the housing of the switch 1 transparent to the incident light, allowing the sensor 14 located behind this area inside the housing to detect it. Alternatively, the housing can have a hole through which the sensor 14 is placed to detect the incident light. The sensor 14 can also be mounted on the outside of the housing of the switch 1.

[0075] Under normal operating conditions, the mast opening is closed, resulting in a constant, very low level of light entering the mast. A mast door could also seal the mast opening 21 of mast 2 almost completely, blocking out light. If the mast opening 21 is now opened, for example, by unlocking or opening the mast door or mast hatch (not shown), significantly more light (even at night) penetrates the interior of mast 2. Sensor 14 detects this increased light level and generates a rise (for example, abrupt or gradual) in the sensor signal amplitude over a certain period. The control unit 13 evaluates the sensor signal and detects this increase. Control unit 13 interprets this as a deviation from normal operation and informs (alerts) the backbone 4 accordingly.The alarm to the remote network component 4 could be triggered if the light sensor 14 detects a predefined illuminance, for example, greater than 10 lux or greater than 7 lux. The control unit 13 incorporates a trigger delay or an averaging of the sensor values ​​(also known as mini-hysteresis) over a specific period. This prevents light fluctuations lasting, for example, a few hundred milliseconds from triggering an alarm. Thus, no false alarm is triggered during a thunderstorm.

[0076] An alert for Backbone 4 can be triggered by reporting the ID of Switch 1, the location of Mast 2, or both, along with a corresponding error code (e.g., light interference detected). Backbone 4 then decides on appropriate action. It might classify the incident as normal if maintenance is known to Backbone 4 on Mast 2. Alternatively, it could interpret the incident as an attack and move the existing data connection between Peripheral Device 3 and Backbone 4 to a quarantined area, thus monitoring the incident further in a secure environment. It could also disable the data connection to Switch 1 or instruct the switch to terminate the data connection between Backbone 4 and Peripheral Device 3. Finally, it could order the erasure of the memory area in Control Unit 13.

[0077] In any case, Switch 1 is better secured, and in particular the sensitive data (IP addresses, private keys, signature keys, configuration data, passwords) of Switch 1 are better protected. A mast 2 installed in a remote area, with Switch 1 located within it and directly connected to backbone 4, is therefore better protected against attacks.

[0078] The in Fig. 1 The sensor used (14) can alternatively or additionally be a motion sensor or a microswitch. These sensor types detect movement of the housing or the opening of the housing of switch 1. The control unit interprets these actions directly as an attack and triggers the immediate deletion of the aforementioned sensitive data in the switch's memory. The switch is then no longer configured and can no longer...

[0079] The data connection to a backbone 4 or to a peripheral device 3 cannot be established or forwarded. Therefore, removing or opening switch 1 does not lead to unauthorized manipulation of the data connection, and the reading of sensitive data or the interception of information by an attacker is effectively prevented.

[0080] Fig. 2 Figure 1 shows an exemplary embodiment of a simplified block diagram of a device 1 according to the invention. The device 1 of the Fig. 2 corresponds to device 1 of the Fig. 1 and only exhibits further elements, which will be referenced below. The in Fig. 1 Components already presented are not repeated here.

[0081] The device 1, hereinafter referred to as switch 1, has indicatively a first circuit board 1a, which comprises the control unit 13. The circuit board 1a is in Fig. 4described in more detail. Furthermore, Switch 1 has a second circuit board 1b, which includes a power supply unit 17. Circuit board 1b is in Fig. 5Described in more detail below. Both circuit boards 1a and 1b are connected to each other via a connector 174 and are jointly integrated into the metal housing of the switch 1. Preferably, both circuit boards 1a and 1b are standard form factor boards. Both circuit boards 1a and 1b preferably have the PC / 104 form factor. This PC / 104 form factor allows for a smaller design of the switch 1, and this smaller design simplifies the integration of the switch 1 into a mast 2 with a very small diameter. Both circuit boards 1a and 1b can each have a form factor other than the PC / 104 form factor. This form factor also allows for stacking multiple circuit boards and connecting them using connector 174. This improves the electromagnetic compatibility of the components.

[0082] Switch 1, for example, has a third port 18 to which a power supply is connected. This third port 18 is connected to a port 171 of the power supply unit 17. Alternatively, shown here as a dash-dot line, a power supply is provided via the first port 11, for example as a PoE signal. In this case, the third port 18 can be omitted and the setup is simplified.

[0083] The power supply unit 17 provides power to the peripheral device 3 via a power output 172. This power supply is connected as a PoE signal 19 to the second port 12 of the switch 1 and thus, together with the data signal from the second data port 132 of the control unit 13, is supplied to the peripheral device 3. By using the PoE signals 19, the cabling effort in the mast 2 is significantly simplified, and the peripheral devices 3 can be powered by the switch 1. Therefore, no additional external power source(s) are required to power the peripheral devices 3.

[0084] The power supply unit 17 also provides power to the control unit 13 via a power output 173. This power supply is enabled, for example, via a connector 174. Therefore, no further external power source(s) are required to power the control unit 13.

[0085] Fig. 3 Figure 1 shows an exemplary embodiment of a simplified block diagram of a device 1 according to the invention. The device 1 of the Fig. 3 corresponds to device 1 of the Fig. 1 and the first circuit board 1a of the Fig. 2 and exhibits further elements, which will be referenced below. The in Fig. 1 and Fig. 2 Components already presented are not repeated here.

[0086] Unlike the Fig. 1 or Fig. 2 are in Fig. 3Now, two initial ports, 11a and 11b, are provided on Switch 1. A first backbone, 4a, is connected to the first port, 11a. A second backbone, 4b, is connected to the second port, 11b. This increases the bandwidth of Switch 1 and consequently leads to improved functionality of the peripheral devices 3a to 3d. Alternatively - in Fig. 3 As shown by a dot-dash line, a first backbone 4a is connected to the second port 11b. This increases the bandwidth of switch 1 and consequently leads to improved functionality of peripheral devices 3a to 3d. For example, two 10Gbit SFP modules are used as ports 11a and 11b. The first two ports 11a and 11b are each connected to the first data ports 131a and 131b of the control unit 13.

[0087] In further contrast to Fig. 1 or Fig. 2 are in Fig. 3Switch 1 now has four secondary ports 12a, 12b, 12c, and 12d. A first peripheral device 3a is connected to, or can be connected to, the second port 12a. A second peripheral device 3b is connected to, or can be connected to, the second port 12b. A third peripheral device 3c is connected to, or can be connected to, the second port 12c. A fourth peripheral device 3d is connected to, or can be connected to, the second port 12d. The four secondary ports 12a, 12b, 12c, and 12d are each connected to secondary data ports 132a, 132b, 132c, and 132d of the control unit 13. Therefore, up to four peripheral devices 3 can be connected to Switch 1 simultaneously. According to the invention, the number of connectable peripheral devices 3 is not limited; up to 24 peripheral devices 3 can be connected to a switch 1. For example, each peripheral device 3 is provided with a 1 Gbit connection as ports 12a, 12b, 12c, 12d.

[0088] In further contrast to Fig. 1 or Fig. 2 are in Fig. 3 Now at least two sensors 14 and 15 are provided in Switch 1. The first sensor, 14, is the one in Fig. 1 The light sensor already described, whose sensor signal is connected to the sensor signal terminal 133 of the control unit 13. The second sensor 15 is the one described in the Fig. 1 The microswitches already mentioned, whose sensor signal (or switching signal) is connected to a second sensor signal terminal 134 of the control unit 13. By using two sensors 14, 15 and correspondingly evaluating the sensor signals at terminals 133, 134 of the control unit 13, a two-stage alarm or protection procedure can be applied. Thus, if increased light incidence is detected by the light sensor 14 (=first stage of the attack), only the backbones 4a, 4b could be alarmed accordingly, and the [unclear] Fig. 1The measures already described can be taken. For example, if switching element 15 detects that the housing has been opened (the second stage of the attack), the sensitive data in switch 1's memory could be deleted / overwritten. This would maintain network operation for as long as possible, preventing the data connection from being automatically interrupted if mast 2 is opened. This also allows for the observation of unannounced maintenance activities and preserves network functionality. However, if the second stage of an attack is detected, the sensitive data can be reliably deleted.

[0089] In further contrast to Fig. 1 or Fig. 2 is in Fig. 3An energy storage device 16 is now provided. This energy storage device 17, for example a storage capacitor with a capacity of several hundred millifarads to several farads, ensures the operation of the switch 1 even during short-term fluctuations in the power supply and enables the detection of an attack even when the power supply is remote. This allows sensitive data to be reliably deleted even if the power supply has already been switched off.

[0090] Fig. 4 Figure 1 shows an exemplary embodiment of a block diagram of a first circuit board 1a of a device 1 according to the invention. The device 1 of the Fig. 4 corresponds to device 1 of the Fig. 3 and exhibits further elements, which will be referenced below. The in Figs. 1 to 3 The components already presented are only hinted at here. Shown in Fig. 4 This is a block diagram of the components on the first board 1a of Switch 1, the so-called "Carrier Board".

[0091] The first circuit board 1a is connected to the second circuit board 1b via a connector 174 ( Fig. 5 ) is connected and receives three different voltages via the connector: 50V, 5V, and 3.3V from the second board 1b. A power microcontroller uses these voltages to provide a supply voltage for the control unit 13 and PoE signals for the four secondary connections 12a, 12b, 12c, and 12d. Connections 11a and 11b are also powered. The two sensors are not located on board 1a but are placed at suitable locations on the housing and connected to the control unit 13 via wired connections using "Sensor I / O" connectors. As already described in Fig. 3 As shown, the control unit 13 is connected with two first connections 11a, 11b and four second connections 12a, 12b, 12c, 12d.

[0092] Additionally, four status LEDs are provided to visualize the status of Switch 1 externally (outside the Switch 1 housing). One status LED indicates whether power is supplied, another indicates whether the switch is switched on, a third status LED is bicolor and indicates whether a data connection to backbone 4a exists, and a fourth status LED is bicolor and indicates whether a data connection to backbone 4a or 4b exists (depending on the wiring configuration). Four additional LEDs are provided to indicate the connection status with the respective peripheral devices 3a, 3b, 3c, and 3d. These LEDs are visible from the outside through openings in the housing or transparent sections within the housing.

[0093] The circuit board 1a has a service port via which the control unit 13 can be updated and maintained using a driver module.

[0094] Fig. 5Figure 1 shows an exemplary embodiment of a block diagram of a second circuit board 1b of a device 1 according to the invention. The circuit board 1b of the Fig. 5 corresponds to the indicated circuit board 1b of the Fig. 2 and exhibits further elements, which will be referenced below. The in Figs. 1 to 3 Components already presented are not repeated here. Shown in Fig. 5 This is a block diagram of the components on the second circuit board 1b of Switch 1, the so-called "Power Board".

[0095] The second circuit board 1b, for example, has a third connection 18, to which a power supply, for example 110VAC to 230VAC at 50Hz or 60Hz, is connected. This third connection 18 is connected to a connection 171 of the power supply unit 17.

[0096] The power supply unit 17 provides power to the peripheral device 3 via a power output 172. For this purpose, a power supply unit with a wide-range input and an output voltage of 50V and 3A is implemented. The heat generated by the power supply unit is dissipated by directly mounting the power supply module to the metal housing. The housing of the switch 1 thus also acts as a heat sink for the power supply unit. The cooling capacity of the switch housing is at least 1K / W. Therefore, additional fans or heat pipes are unnecessary. This power supply is connected as a PoE signal 19 via connector 174 to the second port 12 of the switch 1 and thus, together with the data signal from the second data port 132 of the control unit 13, is provided to the peripheral device 3.

[0097] The power supply unit 17 also provides power to the control unit 13 via a power output 173. For this purpose, a DC-DC switching regulator with an output voltage of 5V and 6A is implemented, which is powered by the aforementioned power supply unit. The power supplies are routed, for example, to the first circuit board 1a via connector 174. Therefore, no further external power source(s) are required to power the control unit 13 or the peripheral devices 3.

[0098] Fig. 6Figure 1 shows an exemplary embodiment of a flowchart of a method 100 according to the invention for commissioning a device 1 of the type described above. In a first step 103, a data signal is transmitted via at least one first data port 11 of the device 1 to receive configuration information from a remote network component 4, wherein the device 1 is known to the remote network component 4. For this purpose, for example, an ID of the device 1 has been stored in the backbone 4. If the device 1 is known in the backbone, the backbone 4 sends configuration information. In the device 1, the configuration information is stored in the

[0099] Step 102 receives the configuration information, preferably using Trivial File Transfer Protocol (TFTP) to initialize Device 1. Step 103 establishes a data connection between Device 1 and the remote network component 4 using the configuration information. This configuration information includes, in particular, IP addresses, SSH keys, policy settings, and, if applicable, blacklists / whitelists of Device 1.

[0100] Fig. 7 Figure 1 shows an embodiment of a flowchart of a further method 200 according to the invention for operating a peripheral device 3 on a device 1 described herein. The device was commissioned in accordance with Fig. 6In step 201, a data signal is connected to at least one second data port 12 of the device 1 to connect the device 1 to a peripheral device 3, wherein the peripheral device 3 was registered with the remote network component 4 before being connected. This registration is carried out, for example, by reading a QR code of the peripheral device 3, which transmits a MAC address of the peripheral device 3 to the backbone 4. In step 202, the MAC address of the peripheral device 3 is checked for compatibility.

[0101] with a MAC address communicated by the remote network component 4 through the device 1. In step 203, a data connection from the remote network component 4 is forwarded to the peripheral device 3 if the MAC address of the peripheral device 3 matches the communicated MAC address.

[0102] Fig. 8Figure 1 shows a scale model of an exemplary mast 2 in which a device 1 according to the invention is arranged. The mast has three mast openings 21 arranged one above the other, each lockable by means of a triangular door lock. Each mast opening 21 can be closed with a mast door measuring 100 x 400 millimeters. The housing of the device must be able to be inserted into the interior of the mast 2 through this mast door size, so that the external dimensions of the housing are limited to these mast opening dimensions. The diameter of the mast 2 at its base is 246 millimeters. Inside the mast, a mounting rail runs, for example, designed as a DIN rail or a track. The housing of the device is mounted on this mounting rail.

[0103] Fig. 9Figure 1 shows three scaled examples of exemplary mast openings 21 in masts 2, through which a device 1 according to the invention is arranged in a mast 2. It is intended to provide only one housing for the device 1, so that the dimensions of the smallest mast opening 21, here that of mast type LM3-SC, limit the external dimensions of the device housing. For mast type LM3-SC, the diameter is...

[0104] The height of the mast opening 21 is between 130.85 and 136.07 millimeters; the mast opening 21 has dimensions of 85x300 millimeters.

[0105] Fig. 10 Figure 1 shows an embodiment of a system according to the invention, consisting of a mast 2 with a device 1 arranged therein. The mast 2 is preferably a mast such as those found in the Fig. 8 or 9 The device 1 corresponds to one of the devices of the Figs. 1 to 7The device 1 is inserted into the interior of the mast 2 through the mast opening 21 and mechanically fastened there to a DIN rail 24, for example by a claw, clamp, and / or screw connection. Alternatively, in a well-secured environment, a magnetic connection can also be used to fasten the device 1 inside the mast 2.

[0106] The mast 2 has two lighting devices 23 as a functional unit. These lighting devices 23, for example LED lights, are either connected to their own power supply 25 or to a PoE supply 26 of the device 1 and are supplied with power accordingly.

[0107] A peripheral device 3b, for example a traffic sensor, is attached to the mast 2 and connected to a backbone via the device 1 using data connection 29, see indicated data connection 27 to the backbone.

[0108] A peripheral device 3a, for example a camera or a WLAN AP, is attached to the mast 2 and connected to a backbone via data connection 29 through the device 1, see indicated data connection 27 to the backbone.

[0109] A peripheral device 3c, for example an electric vehicle charging station, is attached to the mast 2 and connected to a backbone via data connection 29 through the device 1, see indicated data connection 27 to the backbone.

[0110] Fig. 11Figure 1 shows an embodiment of a system according to the invention, consisting of three masts 2, each with a device 1, in a traffic monitoring system, interconnected in a star-bus topology. The masts 2 serve as street lighting elements and are each equipped with a device 1. Each mast 2 also has a traffic sensor as a peripheral device 3. The data from the traffic sensors are forwarded via the device 1 to the data center 4. The data center 4 is in turn connected to a server 5, which enables road users to receive the data recorded by the traffic sensors or the resulting information, for example, via suitable interfaces in a vehicle (navigation device) or a user device (smartphone), and to adjust their route accordingly.

[0111] Fig. 12Figure 1 shows an embodiment of a system according to the invention, consisting of three masts 2, each with a device 1, in a traffic monitoring system, connected in a daisy-chain topology. The mast 2 closest to the remote network component 4 is connected to the remote network component 4. The remaining masts 2 are connected in series with each other. The signal to and from a device 1 in a mast 2 then passes through its preceding device(s) to the remote network component 4. An important aspect of this connection of the devices 1 is that priorities can be assigned. This allows it to be specified, for example, that information can only be transmitted when the line is free, or that some devices 1 have absolute priority over others. This prevents conflicts and malfunctions. REFERENCE MARK LIST

[0112] 1 Device, network component, network switch 1a First board 1b Second board 11, 11a, 11b First data port 12, 12a, 12b, 12c, 12d Second data port 13 Control unit 131, 131a, 131b First data port 132, 132a, 132b, 132c, 132d Second data port 133 Sensor signal port 134 Second sensor signal port 14 Sensor 15 Second sensor 16 Energy storage 17 Power supply unit 171 First power port 172 Second power port 172 Third power port 174 Connection port 18 First power port 19 Power signal, PoE 2 Mast 21 Mast opening 22 Mast door 23 Light source, signal, traffic light 24 DIN rail 25 Power supply for light source / charging station 26 Power over Ethernet 27 Data connection to the backbone 28 Power supply 29 Data connection Peripheral device 3, 3a, 3b, 3c, 3d Peripheral device, P1, P2, P3, P4 4, 4a, 4b Network component 5 Server

Claims

1. An active network component, namely a network gateway, a network router, a network bridge, a modem, a network switch and / or a network distributor, which is arranged operationally within a tower (2) by means of a housing and comprises: - a sensor (14, 15) arranged on the housing of the network component for providing a sensor signal; and - a control unit (13) in the interior of the network component with: - at least one first data connection (131) arranged for transmitting a data signal between the network component and a network component (4) remote from the tower (2); - at least one second data connection (132) arranged for transmitting a data signal between the network component and a peripheral device (3); - a sensor signal connection (133, 134) for receiving the sensor signal; - wherein the control unit (13) is arranged for forwarding a data communication between the remote network component (4) and the peripheral device (3); - wherein the control unit (13) is arranged for: - evaluating the received sensor signal; - detecting a change in the sensor signal; and - alerting the remote network component (4) if the change in the sensor signal is detected by the control unit (13).

2. The network component according to claim 1, wherein the sensor (14) generates a sensor signal depending on a light incident on the sensor (14), wherein the change in the sensor signal is an increase in the sensor signal amplitude due to an increased incidence of light, and / or wherein the evaluation of the sensor signal comprises an averaging of the values of the sensor signal over a predefined time period.

3. The network component according to one of the preceding claims, wherein the sensor (15) is a motion sensor, wherein the change in the sensor signal is an increase in the sensor signal amplitude due to a movement of the housing of the device (1).

4. The network component according to one of the preceding claims, wherein the sensor (15) is a switching element, wherein the change in the sensor signal is an increase in the sensor signal amplitude due to an opening of the housing of the device (1).

5. The network component according to one of the preceding claims, wherein the control unit (13) is arranged for deleting and / or overwriting at least safety-relevant information stored in a memory of the device (1) if the change in the sensor signal is detected by the control unit (13).

6. The network component according to claim 5, wherein the control unit (13) is arranged for first deleting and / or overwriting at least the safety-relevant information if the change in the sensor signal is an increase in the sensor signal amplitude due to the opening of the housing of the network component and / or due to a movement of the housing of the network component.

7. The network component according to one of the preceding claims, further comprising an energy store (16) for temporarily providing a supply energy for the control unit (13) in the event of the omission or removal of a device-external energy supply.

8. The network component according to one of the preceding claims, wherein the at least one first data connection (131) is connected to a first connection (11) of the network component, wherein preferably the control unit (13) has at least two first data connections (131a, 131b) each arranged for transmitting a data signal between the device (1) and at least the network component (4a, 4b) remote from the tower (2) and wherein further preferably each first data connection (131a, 131b) is connected to a first connection (11a, 11b) of the network component.

9. The network component according to one of the preceding claims, wherein the at least one second data connection (132) is connected to a second connection (12) of the network component, wherein preferably the control unit (13) has at least four second data connections (132a, 132b, 132c, 132d) each arranged for transmitting a data signal between the device (1) and a peripheral device (3a, 3b, 3c, 3d) and wherein further preferably each second data connection (132a, 132b, 132c, 132d) is connected to a second connection (12a, 12b, 12c, 12d) of the network component.

10. The network component according to one of the preceding claims, wherein the network component comprises an energy supply unit (17), wherein the energy supply unit (17) comprises: - a first energy connection (171) for supplying a device-external supply energy; - at least one second energy connection (172) for tapping a supply energy for the peripheral device (3), wherein the second energy connection (172) provides a Power-on-Ethernet, PoE, energy signal which is combined with the data signal to be transmitted between the network component and the peripheral device (3), and / or - at least one third energy connection (173) for tapping a supply energy for the control unit (13).

11. The network component according to one of the preceding claims, wherein the control unit (13) is arranged on a printed circuit board (1a) with standard form factor, preferably PC / 104, and wherein preferably the energy supply unit (17) is arranged on a second printed circuit board (1b) with standard form factor, preferably PC / 104.

12. The network component according to one of the preceding claims, wherein an authentication of the peripheral device (3) for forwarding the data communication between the remote network component (4) and the peripheral device (3) takes place on the basis of a media access control, MAC, address of the peripheral device (3), wherein preferably in the event of a failed authentication of the peripheral device (3) the forwarding of the data communication is prevented by the control unit (13).

13. A method (100, 200) for operating a peripheral device (3) on a network component according to one of claims 1 to 12 by the network component with the following method steps for starting up the network component: - transmitting (101) a data signal via the at least one first data connection (131) of the network component for receiving a configuration information from the remote network component (4), wherein the network component is known at the remote network component (4); - receiving (102) the configuration information from the remote network component (4) in the network component, wherein preferably the receiving (102) takes place by means of trivial file transfer protocol, TFTP, for initializing the network component; and - establishing (103) a data connection between the network component and the remote network component (4) using the configuration information, wherein after the starting up of the network component the following method steps take place: - connecting (201) a data signal to the at least one second data connection (132) of the network component for connecting the network component to the peripheral device (3), wherein the peripheral device (3) was made known at the remote network component (4) before the connection; - checking (202) the match of the MAC address of the peripheral device (3) with a MAC address communicated by the remote network component (4) by the network component; and - forwarding (203) a data connection of the remote network component (4) to the peripheral device (3) if the MAC address of the peripheral device (3) matches the communicated MAC address.

14. A computer program product installed in a control unit (13) of the network component according to one of claims 1 to 12 and comprising means for carrying out the method steps (101, 102, 103, 201, 202, 203) of the method (100, 200) according to claim 13.