Network Switch Dynamic Device Group Assignment

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network switches lack flexibility in device assignment and security, leading to potential security issues and inefficient communication management, especially in complex networks like those in rail vehicles.

Innovation Solution

A method for dynamically assigning devices to device groups, the solution involves a network switch with a network switch that dynamically assigns devices to device groups, the solution involves a method for dynamically assigning devices to device groups based on authentication information, enabling flexible and secure communication management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If network switches use static device assignment, then configuration simplicity is maintained, but network flexibility and adaptability deteriorate

Engineering Contradiction:
Improvenetwork flexibilityVSAvoidconfiguration complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The network switch automatically detects authentication information from connecting devices and autonomously assigns them to appropriate device groups without requiring manual configuration. This self-service mechanism resolves the contradiction by providing dynamic adaptability while keeping the configuration process transparent to users.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent implements dynamic device group assignment where device ports are automatically assigned to different device groups based on real-time authentication information. This dynamic behavior enables the network to adapt to changing device connections while maintaining simple operation through automated processes.

Inventive Principle:
Principle #15Dynamics

2Reliability

If network switches allow unrestricted device communication, then ease of operation is improved, but network security deteriorates

Engineering Contradiction:
Improvenetwork securityVSAvoidcommunication management
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent divides the network into multiple isolated device groups where devices can only communicate within their assigned group. This segmentation provides security by preventing unauthorized cross-group communication while maintaining ease of operation through automated group assignment based on authentication information.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The network switch acts as an intermediary that automatically manages communication permissions between devices. It uses authentication information as a mediator to determine which devices should communicate, providing both security through controlled access and ease of operation through automated mediation without manual intervention.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If network switches implement dynamic device group assignment, then network security and communication efficiency are improved, but device complexity increases

Engineering Contradiction:
Improvenetwork securityVSAvoidswitch operation complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The network switch performs automatic device group assignment by detecting authentication information from connecting devices and autonomously determining appropriate groups. This self-service approach improves network security through dynamic assignment while avoiding increased operational complexity by eliminating the need for manual configuration.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary authentication information detection and device group assignment automatically when devices connect to the network. This preliminary action ensures security requirements are met before communication begins, improving network security while maintaining simple operation through automated preprocessing.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP3967017B1Method, apparatus, computer program, computer-readable storage medium, system and rail vehicle for operating a network switch, for example a switch or router
Publication Date: 2025.11.12 SIEMENS MOBILITY GMBH
  • EP3967017B1 patent drawingFigure 1~2
  • EP3967017B1 patent drawingFigure 3~4
  • EP3967017B1 patent drawingFigure 5~6

AI summary

In at least one embodiment of the method according to the invention for operating a network switch (1), in which the network switch (1) has a plurality of device terminals (11), the method comprises the steps: A) detecting a signalling connection of an electric first device (31) to a device terminal of the network switch; B) detecting authentication information (A), the authentication information being representative for the first device; C) determining a first device group (G1) for the first device in accordance with the authentication information; D) assigning the device terminal connected to the first device to the first device group; and, if one or more further device terminals are assigned to the first device group and are connected to further electric (32, 33) devices, E) activating a communication between the first device and the further devices of the first device group.