Network Filter Component for Secure Device Configuration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for including communication devices in a network often fail to ensure network security by allowing unauthorized access during the initial configuration phase, as they do not adequately limit access possibilities.

Innovation Solution

A method where a communication device is initially connected to a subset of configuration servers, and configuration data is used to assign access rights, ensuring that the device can only access selected productive servers, with a network filter component routing data to either a configuration or productive sub-network based on the device's identification data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a communication device is allowed full network access during initial configuration, then configuration can be completed, but network security is compromised due to unauthorized access possibilities

Engineering Contradiction:
Improveconfiguration capabilityVSAvoidunauthorized access
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The network is segmented into a configuration network area and a production network area. During initial configuration, the communication device is restricted to only the configuration network area, preventing access to production resources. After successful configuration, the device is moved to or granted access to the production network area, ensuring security while enabling configuration functionality.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A network filter component acts as an intermediary between the communication device and the network resources. This filter dynamically controls access based on the device's configuration state, allowing configuration traffic during the initial phase and transitioning to production traffic after configuration completion, thus mediating between security requirements and configuration needs.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If a communication device is restricted to configuration servers only during initial connection, then network security is maintained, but the device cannot access production servers

Engineering Contradiction:
Improveunauthorized access preventionVSAvoidnetwork access capability
Core Design Contradiction:
Object-affected harmful factorsVSProductivity

Solution Approach 1:

The network access rights of the communication device are dynamic rather than static. Initially, the device is assigned only configuration network access rights. Upon successful configuration verification, the system dynamically updates the device's access rights to include production network access, thereby adapting network permissions to the device's operational state.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The configuration phase is performed as a preliminary action before granting full network access. The system requires successful completion of configuration tasks (such as obtaining IP address, DNS settings, and other network parameters) before transitioning the device from configuration-only mode to full production access mode, ensuring security prerequisites are met.

Inventive Principle:
Principle #10Preliminary action

3Extent of automation

If configuration data is obtained from remote servers, then device configuration is automated, but the device may access unauthorized resources during the process

Engineering Contradiction:
Improveconfiguration automationVSAvoidnetwork security
Core Design Contradiction:
Extent of automationVSReliability

Solution Approach 1:

The network infrastructure is segmented into distinct configuration servers and production servers, with isolated network segments. The automated configuration process can only communicate with authorized configuration servers during the initial phase, preventing automated scripts or processes from inadvertently or maliciously accessing production resources, thus maintaining security while enabling automation.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentEP3092747B1Method for incorporating a communication device in a network, and arrangement having at least one network filter component and at least one configuration server
Publication Date: 2019.03.06 SIEMENS AG
  • EP3092747B1 patent drawingFigure 1~2
  • EP3092747B1 patent drawingFigure 3~4

AI summary

Method for incorporating a communication device in a network, and arrangement having at least one network filter component and at least one configuration server. The invention relates to a method for incorporating a communication device in a network - with a set of configuration servers having at least one configuration server, and - with a set of productive servers having at least one productive server, having the following steps: a) establishing a connection between the communication device and the network, which connection is restricted solely to a stipulated selection from the set of configuration servers; b) obtaining configuration data from the stipulated selection of configuration servers, which stipulate access rights of the communication device to a selection from the set of productive servers; c) configuring the communication device using the configuration data which have been obtained in such a manner that access by the communication device is restricted to the selection from the set of productive servers.