Industrial Network Device Onboarding via Gateway Parameter Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current authentication methods for onboarding wireless industrial devices onto industrial networks are insecure, as they rely on simple checks like PINs or passwords, which are inadequate for protecting against unauthorized access.

Innovation Solution

A method that authenticates user devices by verifying network access parameters, such as identifiers associated with gateway devices and transmission channels, using network information to enhance security and authorize access based on detailed network parameters, and generates provisioning data for configuring user devices with varying privileges.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If simple authentication methods (PINs, passwords) are used for device onboarding, then the ease of operation is improved, but the security is worsened

Engineering Contradiction:
Improveease of onboardingVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent changes the authentication parameters from simple static credentials (PINs, passwords) to dynamic network access parameters including gateway identifiers, transmission channel identifiers, frequency band identifiers, and location information. These parameters are automatically extracted from the registration request and verified against network information, providing stronger security while maintaining ease of operation through automated verification.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If network access parameters are verified for authentication, then the security is improved, but the device complexity is worsened

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication system performs self-service by automatically extracting network access parameters from the incoming registration request and autonomously verifying them against stored network information. The onboarding device compares parameters such as gateway identifiers, transmission channel identifiers, and location information without requiring manual intervention, thereby reducing operational complexity despite enhanced security verification.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The authentication mechanism serves multiple functions simultaneously: it extracts network access parameters, verifies their validity against network information, authenticates the user device, and generates provisioning data. This multi-functional approach consolidates several processes into one unified authentication routine, reducing overall system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If detailed network parameters are used for access decisions, then the security is improved, but the loss of time is worsened

Engineering Contradiction:
Improveaccess control securityVSAvoidonboarding time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by pre-configuring network information containing all necessary access parameters (gateway identifiers, transmission channel identifiers, frequency bands, location data) before the onboarding process begins. During authentication, these pre-prepared parameters are quickly matched against the device's registration request, enabling rapid verification without time-consuming manual checks.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent replaces manual mechanical authentication processes with automated electronic verification of network access parameters. The system automatically extracts, compares, and validates parameters such as gateway identifiers and transmission channel identifiers through electronic processing, significantly reducing the time required for access decisions compared to manual authentication methods.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS20240236671A1Method of onboarding a user device
Publication Date: 2024.07.11 SIEMENS AG
  • US20240236671A1 patent drawing
  • US20240236671A1 patent drawing

AI summary

A method of onboarding a user device onto an industrial network includes receiving a registration request from the user device. The user device is connected to a gateway device associated with a first wireless network. The registration request includes one or more network access parameters associated with the user device. At least one network access parameter from the network access parameters is indicative of the gateway device and/or the first wireless network. The method includes authenticating the user device based on the received registration request. Authenticating includes verifying validity of network access parameters of the registration request. The method allows for utilization of network access data to evaluate if the user device is indeed an actual user device or an unauthorized device. Accordingly, an overall security associated with the onboarding process is improved.