Industrial Device Onboarding for Multi-Tenant Virtual Network Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for onboarding devices into multi-tenant virtual networks require specific device configurations and lack a standardized mechanism, making them inflexible and device-type dependent, with existing solutions often requiring preconfigured devices and proprietary integration methods.

Innovation Solution

A method involving an onboarding request received by an industrial network access network, where the device is identified and verified using an authentication module, and if authorized, a configuration file is sent to configure the device for access to the multi-tenant virtual network, allowing the device to register and gain access without pre-settings, using an access point for authorization checks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If devices are pre-configured with specific settings for virtual network access, then access authorization is ensured, but device flexibility and ease of integration are reduced

Engineering Contradiction:
Improveaccess authorizationVSAvoiddevice flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent applies preliminary action by pre-configuring the device with a client application and basic communication settings before onboarding. This allows the device to initiate onboarding requests and receive configuration files that contain specific virtual network access parameters, thus ensuring both pre-configured reliability and post-configuration flexibility

Inventive Principle:
Principle #10Preliminary action

2Ease of manufacture

If vendor-specific onboarding methods are used, then device integration is achieved, but standardization and interoperability are hindered

Engineering Contradiction:
Improvedevice integrationVSAvoidstandardization
Core Design Contradiction:
Ease of manufactureVSAdaptability or versatility

Solution Approach 1:

The patent implements universality by creating a standardized onboarding mechanism that works across different device types and vendor-specific networks. The method uses a common approach: receiving onboarding requests, verifying device identity, sending configuration files with virtual network parameters, and completing integration. This universal method eliminates the need for vendor-specific procedures while maintaining ease of integration

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If devices require specific pre-configurations, then network security is maintained, but onboarding complexity and time are increased

Engineering Contradiction:
Improvenetwork securityVSAvoidonboarding time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies self-service by enabling devices to autonomously complete the onboarding process. The device initiates the onboarding request, receives and processes the configuration file with virtual network access parameters, and configures itself without requiring manual intervention. This self-service approach maintains security through automated verification while significantly reducing onboarding time and complexity

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP3873052B1Onboarding of a device in a client-capable virtual network of an industrial network
Publication Date: 2022.08.03 SIEMENS AG
  • EP3873052B1 patent drawingFigure 1
  • EP3873052B1 patent drawingFigure 2
  • EP3873052B1 patent drawingFigure 3

AI summary

The invention relates to a method for onboarding a device (90) into a multi-tenant virtual network (20) of an industrial network (10). The method comprises the following steps: - receiving an onboarding request from the device (90) regarding access to the multi-tenant virtual network (20) of the industrial network (10), - identifying and verifying the device (90) using an authentication module (40) of the industrial network (10), - if the verification is successful, sending a configuration file to the device (90), - configuring the device (90), in particular a communication interface of the device (90), according to the configuration file received from the device (90), - verifying the access authorization of the configured device (90) in an access point (60) of the industrial network (10), and - if the verification is successful, granting the device (90) access to the multi-tenant virtual network (20).Furthermore, the invention relates to an industrial network (10) suitable for carrying out the said method.