Method for updating message filter rules of a network access control unit of an industrial communication network address management unit, and converter unit

US2015215232A1 · US · A1

Patent metadata
FieldValue
Publication numberUS-2015215232-A1
Application numberUS-201514608919-A
CountryUS
Kind codeA1
Filing dateJan 29, 2015
Priority dateJan 30, 2014
Publication dateJul 30, 2015
Grant date

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Method and system of updating message filter rules of a network access control unit of an industrial communication network. At least one address-based message filter rule is assigned to the first communication device. The first communication device is replaced with the second communication device, and the second communication device is registered in the address management unit in response to the replacement of the first communication device with the second communication device. Upon determining that a communication device with an identical communication device description is already registered, the address management unit transmits a change message to the network access control unit or to the converter unit. The communication network address of the first communication device is replaced with the communication network address of the second communication device based on the at least one address-based message filter rule.

First claim

Opening claim text (preview).

What is claimed is: 1 . A method of updating message filter rules of a network access control unit of an industrial communication network including a first communication device, a second communication device, an address management unit, and a converter unit, the method comprising: assigning at least one address-based message filter rule to the first communication device; registering the at least one address-based message filter rule with a corresponding communication network address and a communication device description in the address management unit upon identifying an activation, wherein the communication device description comprises at least one of a function indication and a topology indication; replacing the first communication device with the second communication device, and registering the second communication device in the address management unit in response to the replacement of the first communication device with the second communication device, thereby acquiring a communication network address and a communication device description of the second communication device; checking, by the address management unit, during the registration of the second communication device, whether a communication device with an identical communication device description is already registered; upon determining that there is a positive check result by the address management unit, the address management unit transmitting a change message relating to the registration of the second communication device with a communication device description that is identical to that of the first communication device to the network access control unit or to the converter unit, wherein the change message comprises at least the communication network address and the communication device description of the second communication device; and upon receiving the change message, replacing the communication network address of the first communication device with the communication network address of the second communication device based on the at least one address-based message filter rule. 2 . The method as claimed in claim 1 , wherein the address-based message filter rules are applied by the network access control unit. 3 . The method as claimed in claim 2 , further comprising: defining the message filter rules on the basis of communication device descriptions; converting the message filter rules into address-based message filter rules by the converter unit; and transmitting the converted message filter rules to the network access control unit. 4 . The method as claimed in claim 3 , further comprising transmitting to the converter unit the change message relating to the registration of the second communication device having a communication device description that is identical to that of the first communication device. 5 . The method as claimed in claim 3 , further comprising: connecting the converter unit to a memory unit for message filter rules that are defined on the basis of communication device descriptions; accessing and reading the memory unit, by the converter unit; and updating the address-based message filter rules in response to the accessing and reading the memory unit. 6 . The method as claimed in claim 5 , wherein the message filter rules that are defined on the basis of the communication device descriptions remaining unchanged upon replacing a communication device. 7 . The method as claimed in claim 1 , further comprising deleting the registration of the first communication device upon detecting a correspondence between the device descriptions of the first and second communication devices. 8 . The method as claimed in claim 1 , further comprising automatically defining the communication network addresses of the first and second communication devices, respectively, within the industrial communication network. 9 . The method as claimed in claim 1 , wherein the communication network addresses of the first and second communication devices are IPv6 addresses. 10 . The method as claimed in claim 1 , wherein the network access control unit is a firewall for at least one of data frames and data packets. 11 . The method as claimed in claim 1 , wherein: the replacement of the first communication device with the second communication device takes place logically; the first communication device differs from the second communication device only in its communication network address; and the replacement of the first communication device with the second communication device comprises a change of address. 12 . The method as claimed in claim 1 , wherein: a group of first communication devices and a group of second communication devices are provided; the groups of first communication devices and second communication devices differ only in a network address prefix; a replacement of the first group of communication devices with the second group of communication devices comprises a change of a network address prefix for a group of communication devices; and the change of the network address prefix is registered in the address management unit by the communication device that is assigned to the respective group. 13 . An address management unit for an industrial communication network, the network comprising: a first communication device; a second communication device; and a converter unit, wherein: the address management unit is configured to register the communication devices, upon activation of the respective communication device; each communication device has a respective communication network address and a device description; the device description comprises at least one of a function indication and topology indication; the address management unit is configured to check whether a registered second communication device has a device description that is identical to that of the first communication device that is registered earlier; the address management unit is configured to transmit a change message to one of a network access control unit and to a converter unit upon determining a positive check result; and the change message comprises at least the communication network address and the device description of the second communication device. 14 . A converter unit for message filter rules of a network access control unit within an industrial communication network, the industrial communication network comprising: a first communication device having a communication network address; a second communication device having a communication network address; and an address management unit, wherein: the converter unit is configured to replace the communication network address of the first communication device based on at least one address-based message filter rule, with a communication network address of the second communication device with an identical device description, upon receiving a change message from the address management unit; the device description comprises at least one of a function indication and topology indication; and the change message comprises at least the communication network address and the device description of the second communication device.

Assignees

Inventors

Classifications

  • characterised by the network communication · CPC title

  • Filtering by address, protocol, port number or service, e.g. IP-address or URL · CPC title

  • Address table lookup; Address filtering · CPC title

  • H04L47/70Primary

    Admission control; Resource allocation · CPC title

  • H04L41/082Primary

    the condition being updates or upgrades of network functionality · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US2015215232A1 cover?
Method and system of updating message filter rules of a network access control unit of an industrial communication network. At least one address-based message filter rule is assigned to the first communication device. The first communication device is replaced with the second communication device, and the second communication device is registered in the address management unit in response to th…
Who is the assignee on this patent?
Siemens Ag
What technology area does this patent fall under?
Primary CPC classification H04L47/70. Mapped technology areas include Electricity.
When was this patent published?
Publication date Thu Jul 30 2015 00:00:00 GMT+0000 (Coordinated Universal Time) (A1). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 4 related publications on this page (citations in our corpus or others sharing the same primary CPC).