Wind Farm Communication Unit Server Intermediary Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Establishing a secure data connection for remote maintenance in wind farms is complex due to the need for extensive configuration and security measures, especially when multiple third-party components are involved, leading to increased costs and potential safety risks.
Innovation Solution
A method where a communication unit in the wind farm establishes a data connection only with a predefined server outside the farm, using this server to initiate and manage access requests from authorized participants, thereby filtering out unauthorized access and reducing the need for complex network address translation and continuous security measures.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If network address translation (NAT) is used to enable external access to components, then external accessibility is improved, but configuration complexity and security risk increase
Solution Approach 1:
The patent introduces a server as an intermediary between external participants and wind farm components. The server receives access requests from participants, obtains authorization from the wind farm operator, and then establishes connections to components. This mediator approach eliminates the need for complex NAT configuration while maintaining security, as the server handles all external communication through a controlled interface rather than requiring direct component exposure to the external network.
2Reliability
If firewalls and security systems are implemented to protect against unauthorized access, then security level is improved, but system complexity and operational costs increase
Solution Approach 1:
The server acts as a security intermediary that implements authorization checks before allowing connections to components. Instead of requiring complex firewall rules for each component, the server centralizes security management by verifying participant credentials and obtaining operator authorization through a controlled interface. This approach maintains high security while reducing system complexity compared to implementing firewalls at every component level.
3Ease of operation
If multiple third-party components are made accessible for remote maintenance, then maintenance capability is improved, but security risk and access control complexity increase
Solution Approach 1:
The server serves as a controlled intermediary that manages access to multiple third-party components. When a participant needs remote maintenance access, the server receives the request, verifies the participant's credentials, obtains authorization from the wind farm operator, and then establishes the connection to the specific component. This ensures that only authorized maintenance personnel can access specific components under controlled conditions, reducing security risks while maintaining remote maintenance capabilities.
4Adaptability or versatility
If all internal components are assigned public IP addresses, then external accessibility is improved, but network security and address management complexity increase
Solution Approach 1:
The server acts as an intermediary that enables external access without requiring public IP addresses for internal components. The server has a public IP address and handles all external communications, translating external access requests into internal network connections. This allows wind farm components to retain private IP addresses while still being accessible for authorized remote maintenance through the server, eliminating the need to consume public IP addresses for each component.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
The invention relates to a method for establishing a data connection (30) between a communication unit (12) of a wind farm (112) and a subscriber (18) via a data network (16) external to the wind farm (112), comprising the steps of establishing (48) a data connection (20) between the communication unit (12) and a predefined server (22) via the external data network (16) by the communication unit (12), receiving (50) at least one access planning request (24) from the predefined server (22) via the external data network (16) by the communication unit (12), wherein the access planning request (24) identifies a subscriber (18) of the external data network (16), and establishing (54) a data connection (30) between the communication unit (12) and the identified subscriber by the communication unit (12), wherein requests received from the external data network (16) for establishing a data connection (20,30) are rejected or dismissed (64) by the communication unit (12), or the communication unit (12) is not visible to participants (18) of the external data network (16) for requests to establish a data connection (30). Furthermore, the invention relates to a system with a communication unit, as well as a server and a wind farm with a system.