Redundant Network Node Authentication Using Spanning Tree Ports

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing authentication methods for nodes in communication networks, such as IEEE 802.1X, are not designed to handle redundant communication networks like those using the Rapid Spanning Tree protocol (RSTP), which are common in industrial automation installations, leading to challenges in ensuring secure and failsafe authentication.

Innovation Solution

A method where nodes with multiple communication ports execute a spanning tree protocol, allowing them to block or activate ports for operational data traffic, and use mutual ports for authentication requests sent to an authentication server, enabling port-based authentication that is compatible with IEEE 802.1X and RSTP standards without proprietary changes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If port-based authentication according to IEEE 802.1X is used in communication networks, then security against unauthorized access is improved, but compatibility with redundant communication networks using spanning tree protocol deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidcompatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments the authentication process by introducing a dedicated authentication server that handles authentication requests separately from the spanning tree protocol operations. This allows the authentication function to be isolated and integrated into the redundant network without disrupting the existing spanning tree protocol, thereby maintaining both security and compatibility.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The authentication server acts as an intermediary between nodes in the redundant communication network. It receives authentication requests from nodes, verifies credentials, and grants access without requiring modifications to the spanning tree protocol itself. This mediator approach enables IEEE 802.1X authentication to function within RSTP networks while preserving backward compatibility.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If authentication information is transmitted to an authentication server in redundant networks, then secure authentication is achieved, but communication delays during authentication process increase

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication delay
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements preliminary action by pre-configuring authentication credentials and server connections before authentication is actually needed. Nodes have their authentication information ready and the authentication server is pre-established, allowing the authentication process to proceed quickly when required without significant delays.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The authentication server maintains continuous availability and readiness to handle authentication requests. By keeping the authentication infrastructure continuously operational and pre-synchronized with the spanning tree protocol state, the system minimizes interruptions and delays when authentication needs to occur during network operations.

Inventive Principle:
Principle #20Continuity of useful action

3Reliability

If nodes with multiple ports execute spanning tree protocol to block ports, then redundancy and failsafety are maintained, but authentication complexity increases

Engineering Contradiction:
ImprovefailsafetyVSAvoidauthentication complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the authentication logic from the spanning tree protocol itself and places it in a separate authentication server. This extraction allows the spanning tree protocol to continue handling redundancy and failsafety independently, while the authentication server manages the authentication complexity separately. Nodes simply participate in both protocols without the complexities being intertwined.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS11863544B2Authenticating a node in a communication network of an automation installation
Publication Date: 2024.01.02 SIEMENS AG
  • US11863544B2 patent drawing
  • US11863544B2 patent drawing
  • US11863544B2 patent drawing

AI summary

A method authenticates nodes in a communication network of an automation installation. Respective authentication information is transmitted to an authentication server, which takes the authentication information as a basis for admitting or rejecting the nodes in the communication network as subscribers. In order to be able to perform an authentication of a node even in a communication network configured with redundancy, the communication network contains multiple nodes, each of which has at least two communication ports. The communication network executes a spanning tree protocol and at least two of the nodes use their mutually facing communication ports to interchange authentication requests and send the respective received authentication information to an authentication server, connected to the communication network, that uses the respective received authentication information to perform a check on the authenticity of the node and admits or rejects the node in the communication network based on the check.