Method and apparatus for traffic probing
US-2024430168-A1 · Dec 26, 2024 · US
US9750083B2 · US · B2
| Field | Value |
|---|---|
| Publication number | US-9750083-B2 |
| Application number | US-201213693850-A |
| Country | US |
| Kind code | B2 |
| Filing date | Dec 4, 2012 |
| Priority date | Jun 11, 2010 |
| Publication date | Aug 29, 2017 |
| Grant date | Aug 29, 2017 |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
A method for communication between a wireless device node in a wireless sensor network and control apparatus or control processes of an industrial control system. The wireless network includes a plurality of device nodes and at least one gateway. The method includes receiving at a gateway an aggregated data packet or a final address in the ICS. The gateway processes the data packet, detects that it is an aggregated data packet and reconstructs the original data packets contained therein. The gateway then sends each of the original data packets as standard data packets to the intended final address in the ICS. In other aspects of the invention a method, system and a computer program for carrying out the method are described.
Opening claim text (preview).
What is claimed is: 1. A method for communication between a device node of a wireless sensor network and control equipment of an industrial control system, said network comprising a plurality of said device nodes and a gateway, said method comprising receiving a data packet from a said device node of said network, said data packet including at least one encrypted part, examining said received data packet received at the gateway from a said device node in said network and checking for presence of at least one indicator for data packet aggregation indicating an aggregated data packet, reconstructing, on finding at least one data packet aggregation indicator, a first data packet included in the aggregated data packet by a) retrieving a source address of the first data packet, and retrieving a decryption key associated with the source address, b) extracting data from the first data packet, and decrypting using said decryption key one or more encrypted data parts of the first data packet, and transmitting the reconstructed first data packet to the industrial control system. 2. The method according to claim 1 , characterised by checking for at least one indicator for data packet aggregation as shown by one or more bits or bytes in a field of a Network layer or Security layer of the received aggregated data packet. 3. The method according to claim 1 , characterised by checking for at least one indicator for data packet aggregation as shown by one or more bits or bytes in a field of an Application Layer or a Transport layer of the received aggregated data packet. 4. The method according to claim 1 , characterised by reconstructing, on finding a second data packet aggregation indicator, a second data packet contained in the aggregated data packet by a) retrieving a source address of the second data packet, and retrieving a decryption key associated with the source address, b) extracting data from the second data packet address, and decrypting using said decryption key one or more encrypted data parts of the second data packet, and transmitting the reconstructed second data packet to the industrial control system. 5. The method according to claim 4 , characterised by transmitting in turn the first data packet and the second data packet to the industrial control system as soon as each data packet contained in the aggregated data packet has been reconstructed. 6. The method according to claim 4 , characterised by transmitting the first data packet and the second data packet to the industrial control system after all data packets contained in the aggregated data packet have been reconstructed. 7. The method according to claim 1 , characterised by reconstructing, a first data packet for the first destination address contained in the aggregated data packet, extracting and decrypting data comprising control bytes or data from any of the Security Sub-Layer, Transport and Application layer from the first data packet and transmitting the first data packet to a final destination address. 8. The method according to claim 1 , characterised by reconstructing the first data packet and re-forming an Enciphered block from a Transport and Application Layer of the first data packet. 9. The method according to claim 1 , characterised by reconstructing a Network and Security sub-layer including fields from the first data packet. 10. A wireless gateway device arranged for communication between a device node in a wireless sensor network and control equipment of an industrial control system comprising a plurality of said device nodes, characterised in that the gateway is arranged for receiving data packets from said sensor network, which data packets include at least one encrypted part, and that the gateway comprises a circuit and a memory storage device arranged with suitable instructions to carry out a method of communication comprising: examining said received data packet at the gateway from a said device node in said network and checking for presence of at least one data packet aggregation indicator, indicating an aggregated data packet, reconstructing, on finding at least one data packet aggregation indicator, a first data packet included in the aggregated data packet by a) retrieving a source address of the first data packet, and retrieving a decryption key associated with the source address, b) extracting data from the first data packet, and decrypting using said decryption key one or more encrypted data parts of the first data packet, and transmitting the reconstructed first data packet to the industrial control system. 11. The gateway according to claim 10 , characterised in that the gateway is a device arranged as any from the group of: wireless field device, wireless sensor, wireless instrument, wireless meter, wireless adapter of one or more field devices, hub, router, access point, network manager device, security manager device. 12. The gateway according to claim 10 , characterised in that the gateway is arranged with a device arranged with a circuit and/or computer software for checking for at least one indicator for data packet aggregation as shown by one or more bits or bytes in a field of a Network layer or Security layer of the received aggregated data packet. 13. The gateway according to claim 10 , characterised in that gateway functions for detecting an aggregated data packet and reconstructing one, two or more data packets included in the aggregated data packet, are arranged as part of any device from the group of: access point, hub, router, network manager device, security manager device, gateway. 14. A computer program product with software code portions or computer code stored on a non-transitory computer usable medium, comprising computer readable program means for causing a computer or processor of a gateway in a wireless sensor network to carry out the steps of: examining said received data packet at the gateway from a said device node in said network and checking for presence of at least one data packet aggregation indicator, indicating an aggregated data packet, reconstructing, on finding at least one data packet aggregation indicator, a first data packet included in the aggregated data packet by a) retrieving a source address of the first data packet, and retrieving a decryption key associated with the source address, b) extracting data from the first data packet, and decrypting using said decryption key one or more encrypted data parts of the first data packet, and transmitting the reconstructed first data packet to the industrial control system. 15. A wireless sensor network system of an industrial control system comprising a plurality of wireless device nodes arranged for communication to a gateway, wherein the wireless communication is arranged for aggregating data originating from at least two data packets, characterised in that said data packets includes at least one encrypted part, that two or more wireless devices comprise a circuit and a memory storage device arranged with suitable instructions to carry out a method of data packet aggregation and the gateway is arranged for detecting and handling the aggregated data packets by carrying out the steps of examining said received data packet at the gateway from a node in said network and checking for presence of at least one data packet aggregation indicator, indicating an aggregated data packet, reconstructing, on finding at least one data packet aggregation byte, a first data packet included in the aggregated data packet by a) retrieving a source address of the first data packet, and retrieving a decryption key associated with the source addre
Cross-Sectional Technologies · mapped topic
Protecting privacy or anonymity, e.g. protecting personally identifiable information [PII] · CPC title
Parsing or analysis of headers · CPC title
Gateway arrangements · CPC title
of the user plane, e.g. user's traffic · CPC title
Related publications grouped by family.
Answers are generated from the same data shown on this page.