Node Authentication in Redundant Automation Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing authentication methods for devices in communication networks are not designed to handle redundant communication networks, particularly those using the IEEE 802.1Q RSTP standard, which can lead to issues with node authentication and network reliability.

Innovation Solution

A method where nodes with multiple communication ports exchange authentication requests through their facing ports and send the information to an authentication server, allowing or rejecting nodes based on their authenticity, while maintaining compatibility with IEEE 802.1X and IEEE 802.1Q standards by not requiring proprietary changes to the RSTP protocol.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If IEEE 802.1X port-based authentication is used in redundant communication networks with RSTP protocol, then network security is improved, but network reliability and seamless operation are worsened due to authentication blocking during link failures

Engineering Contradiction:
Improvenetwork reliabilityVSAvoidunauthorized access
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary action by performing authentication checks on spanning tree protocol configuration messages before they are processed and applied. The authentication server verifies the authenticity of nodes attempting to modify the spanning tree topology, and only authenticated messages are executed. This prevents unauthorized nodes from disrupting network reliability while allowing legitimate reconfiguration during link failures.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an authentication server as an intermediary between nodes and the spanning tree protocol execution. This mediator verifies authentication information contained in configuration messages before allowing them to affect the network topology. The intermediary ensures that only authenticated nodes can trigger reconfiguration events, thereby preventing unauthorized access while maintaining network reliability.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If authentication information is verified for every configuration message in redundant networks, then network security is improved, but communication overhead and processing time are worsened

Engineering Contradiction:
Improvenetwork securityVSAvoidauthentication processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies local quality by implementing authentication verification selectively rather than universally. Authentication is performed specifically on spanning tree protocol configuration messages that can trigger topology changes, while routine operational messages are processed without additional authentication overhead. This localized approach enhances security for critical operations while minimizing time loss for常规 communications.

Inventive Principle:
Principle #3Local quality

Data Source

PatentEP4060947B1Authentification of a node in a communication network of an automation system
Publication Date: 2024.08.14 SIEMENS AG
  • EP4060947B1 patent drawingFigure 1
  • EP4060947B1 patent drawingFigure 2
  • EP4060947B1 patent drawingFigure 3

AI summary

The invention relates to a method for authenticating nodes (31, 32a-c) in a communication network (30) of an automation system, in which a respective authentication information is transmitted to an authentication server (34), which, based on the authentication information, allows or rejects the nodes (31, 32a-c) as participants in the communication network (30).In order to be able to authenticate a node even in a redundantly designed communication network, it is proposed that the communication network (30) comprises several nodes (31, 32a-c), each of which has at least two communication ports, that the communication network (30) executes a spanning tree protocol, and that at least two of the nodes (31, 32a-c) exchange authentication requests via their mutually facing communication ports and send the respective received authentication information to an authentication server (34) connected to the communication network (30), which uses the respective received authentication information to check the authenticity of the respective node (31, 32a-c) and, as a result of the check, allows or rejects the respective node (31, 32a-c) as a participant in the communication network (30).The invention also relates to a node (31, 32a-c) and a communication network (30) with such a node (31, 32a-c).