Industrial Wireless Packet Verification Through CPE-Terminal Correspondence
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Industrial field networks face security risks due to complex application environments and limited security mechanisms, posing threats to secure transmission of service packets in industrial terminal devices.
Innovation Solution
A wireless communication method involving a first device configuring and signing information about the correspondence between customer premise equipment and terminal devices, allowing a second device to verify the authenticity and validity of service packets, ensuring secure transmission by verifying the correspondence and role of terminal devices.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If an open network environment is used for industrial field networks, then network accessibility and ease of operation are improved, but information security and reliability deteriorate due to attacks and limited security mechanisms
Solution Approach 1:
The patent applies preliminary action by pre-configuring security credentials, device identifiers, and cryptographic keys in terminal devices before they access the network. The authentication server pre-establishes trust relationships and security policies, so that when devices connect to the open network, security verification is already in place, preventing unauthorized access while maintaining network accessibility
Solution Approach 2:
The authentication server acts as an intermediary between terminal devices and the network. It mediates access by verifying device identities, authenticating users, and controlling network resource access. This intermediary layer enables open network access while maintaining security through centralized authentication and authorization mechanisms
2Adaptability or versatility
If general-purpose protocols and hardware are used for industrial terminal devices, then adaptability and ease of operation are improved, but device complexity increases and security mechanisms become limited
Solution Approach 1:
The patent implements self-service by enabling terminal devices to autonomously perform security functions using pre-configured credentials. Devices can independently authenticate themselves, establish secure connections, and manage their own security contexts without requiring complex external security infrastructure, thus simplifying security mechanisms while maintaining adaptability
Solution Approach 2:
The patent applies parameter changes by dynamically adjusting security parameters such as authentication methods, encryption algorithms, and access rights based on device type, network context, and service requirements. This allows the system to maintain high adaptability across different protocols and devices while keeping individual device complexity low through parameter-based security configuration
3Ease of operation
If wireless communication is used for industrial field networks, then ease of operation and adaptability are improved, but information transmission security deteriorates due to complex application environments and distributed devices
Solution Approach 1:
The patent applies preliminary action by pre-establishing secure communication channels and configuring cryptographic parameters before wireless transmission begins. Security associations are set up in advance between authorized devices, ensuring that when wireless communication occurs in complex environments, the transmission security is already protected through pre-configured encryption and authentication
Data Source
Figure 1~3
Figure 4
Figure 5
AI summary
This application provides a wireless communication method and apparatus. The wireless communication method includes: A first device obtains first information, where the first information includes a correspondence between first customer premise equipment and at least one first terminal device, and a correspondence between the first terminal device and at least one second terminal device. The first device configures the first information on a second device, where the first information is used by the second device to verify that a received service packet is a service packet sent by the first terminal device to the second terminal device by using the first customer premise equipment. Therefore, accuracy of service packet transmission of an industrial terminal device can be ensured, an industrial terminal or customer premise equipment can be prevented from being attacked to some extent, a loss caused by the attack on the device is reduced, and information security of the industrial terminal device in an industrial field network and an entire industrial field network is improved.