Industrial Network Device Onboarding via Gateway Parameter Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current authentication methods for onboarding wireless industrial devices onto industrial networks are insecure, as they rely on simple checks like PINs or passwords, which are inadequate for protecting against unauthorized access.
Innovation Solution
A method that authenticates user devices by verifying network access parameters, such as identifiers associated with gateway devices and transmission channels, using network information to enhance security and authorize access based on detailed network parameters, and generates provisioning data for configuring user devices with varying privileges.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If simple authentication methods (PINs, passwords) are used for device onboarding, then the ease of operation is improved, but the security is worsened
Solution Approach 1:
The patent changes the authentication parameters from simple static credentials (PINs, passwords) to dynamic network access parameters including gateway identifiers, transmission channel identifiers, frequency band identifiers, and location information. These parameters are automatically extracted from the registration request and verified against network information, providing stronger security while maintaining ease of operation through automated verification.
2Reliability
If network access parameters are verified for authentication, then the security is improved, but the device complexity is worsened
Solution Approach 1:
The authentication system performs self-service by automatically extracting network access parameters from the incoming registration request and autonomously verifying them against stored network information. The onboarding device compares parameters such as gateway identifiers, transmission channel identifiers, and location information without requiring manual intervention, thereby reducing operational complexity despite enhanced security verification.
Solution Approach 2:
The authentication mechanism serves multiple functions simultaneously: it extracts network access parameters, verifies their validity against network information, authenticates the user device, and generates provisioning data. This multi-functional approach consolidates several processes into one unified authentication routine, reducing overall system complexity.
3Reliability
If detailed network parameters are used for access decisions, then the security is improved, but the loss of time is worsened
Solution Approach 1:
The system performs preliminary actions by pre-configuring network information containing all necessary access parameters (gateway identifiers, transmission channel identifiers, frequency bands, location data) before the onboarding process begins. During authentication, these pre-prepared parameters are quickly matched against the device's registration request, enabling rapid verification without time-consuming manual checks.
Solution Approach 2:
The patent replaces manual mechanical authentication processes with automated electronic verification of network access parameters. The system automatically extracts, compares, and validates parameters such as gateway identifiers and transmission channel identifiers through electronic processing, significantly reducing the time required for access decisions compared to manual authentication methods.
Data Source
AI summary
A method of onboarding a user device onto an industrial network includes receiving a registration request from the user device. The user device is connected to a gateway device associated with a first wireless network. The registration request includes one or more network access parameters associated with the user device. At least one network access parameter from the network access parameters is indicative of the gateway device and/or the first wireless network. The method includes authenticating the user device based on the received registration request. Authenticating includes verifying validity of network access parameters of the registration request. The method allows for utilization of network access data to evaluate if the user device is indeed an actual user device or an unauthorized device. Accordingly, an overall security associated with the onboarding process is improved.

