Device Authentication in Redundant HSR Communication Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing authentication methods for devices in communication networks, such as IEEE 802.1X, are not designed for redundant communication networks like IEC 62439-3 HSR, which are commonly used in industrial automation and energy supply networks, posing challenges in ensuring secure and reliable authentication.
Innovation Solution
A method where a device sends authentication requests through two communication ports to its neighbor devices in a communication ring, allowing the authentication server to verify the device's authenticity and admit or reject it, without modifying the existing HSR communication network, ensuring compatibility with IEEE 802.1X and IEC 62439-3 HSR standards.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If IEEE 802.1X authentication protocol is used in redundant communication networks like IEC 62439-3 HSR, then device authentication security is improved, but compatibility with existing HSR network architecture deteriorates
Solution Approach 1:
The authentication process is segmented into separate authentication requests sent through different communication ports (first and second ports) in the redundant HSR network. Each port independently transmits authentication information to the authentication server, allowing the authentication protocol to be adapted to the redundant network architecture without modifying the core HSR communication protocol.
Solution Approach 2:
The authentication mechanism is designed to work universally across both IEEE 802.1X standard networks and IEC 62439-3 HSR redundant networks. By implementing authentication requests that can be transmitted through multiple ports with different transmission directions, the system achieves multi-functionality that supports both standard authentication and redundant communication requirements.
2Reliability
If authentication requests are sent through multiple communication ports in redundant network, then authentication reliability is improved, but communication overhead increases
Solution Approach 1:
Authentication requests are preliminarily prepared and sent through multiple communication ports simultaneously at the start of the authentication process. This preliminary action ensures that authentication reliability is established before normal data transmission begins, preventing the need for repeated authentication attempts that would increase communication overhead.
3Reliability
If device authentication is implemented in HSR communication ring, then network security is improved, but complexity of authentication process increases
Solution Approach 1:
Instead of modifying the HSR network architecture to accommodate authentication, the authentication protocol is inverted to work within the existing HSR framework. Authentication requests are transmitted as data telegrams through the existing communication ports and ring structure, leveraging the existing network infrastructure rather than requiring separate authentication channels.
Data Source
AI summary
A method authenticates a device in a communication network of an automation installation, in which authentication information indicating the device is transmitted to an authentication server that admits or rejects the device in the communication network as a subscriber. To perform an authentication of the device in a communication network configured with redundancy, the communication network has a communication ring that, besides the device, has first and second neighbor devices. At the start of the authentication the device sends authentication requests containing the authentication information to the neighbor devices. The neighbor devices duplicate the authentication information and send it via the communication ring in both transmission directions to an authentication server which uses the authentication information to perform a respective check on the authenticity of the device and admits or rejects the device in the communication network as a subscriber as the result of the check.


