US 11,863,544 B2
Authenticating a node in a communication network of an automation installation
Andrej Goerbing, Berlin (DE); and Jonas Hurrelmann, Berlin (DE)
Assigned to Siemens Aktiengesellschaft, Munich (DE)
Filed by Siemens Aktiengesellschaft, Munich (DE)
Filed on Mar. 15, 2022, as Appl. No. 17/695,247.
Claims priority of application No. 21162798 (EP), filed on Mar. 16, 2021.
Prior Publication US 2022/0303255 A1, Sep. 22, 2022
Int. Cl. G06F 11/10 (2006.01); H03M 13/29 (2006.01); G11C 29/52 (2006.01); H03M 13/35 (2006.01); G11C 29/00 (2006.01); G11C 29/44 (2006.01); G11C 29/04 (2006.01); H04L 9/40 (2022.01)
CPC H04L 63/064 (2013.01) [H04L 63/1433 (2013.01)] 13 Claims
OG exemplary drawing
 
1. A method for authenticating nodes of a communication network of an automation installation, the communication network containing the nodes in a form of Ethernet bridges and electronic devices, each of the nodes having at least two communication ports, which comprises the steps of:
transmitting respective authentication information indicating the nodes to an authentication server and the authentication server taking the respective authentication information as a basis for admitting or rejecting the nodes in the communication network as subscribers, the transmitting step including the substeps of:
executing, via the communication network, a spanning tree protocol, which involves at least one of the nodes being instructed to take an operating state of the communication network as a basis for blocking or activating at least one of the communication ports for operational data traffic, at least two of the nodes use mutually facing said communication ports to interchange authentication requests containing the respective authentication information;
sending, via the at least two nodes, the respective authentication information received to the authentication server connected to the communication network; and
using, via the authentication server, the respective authentication information received to perform a respective check on an authenticity of a respective node of the nodes and admits or rejects the respective node in the communication network as the subscriber as a result of the respective check.