US 12,483,556 B2
Method for logging an authorized user in to a device, in particular to a device for a power generation plant, and power generation plant with device
Marek Seeger, Bovenden (DE); Stefan Börger, Kassel (DE); Dirk Schlote, Kassel (DE); Jens Klein, Göttingen (DE); Raimund Thiel, Bad Zwesten (DE); Mirko Wischer, Bad Hersfeld (DE); and Ingo Hanke, Göttingen (DE)
Assigned to SMA Solar Technology AG, Niestetal (DE)
Filed by SMA Solar Technology AG, Niestetal (DE)
Filed on Oct. 10, 2023, as Appl. No. 18/483,544.
Application 18/483,544 is a continuation of application No. PCT/EP2022/059483, filed on Apr. 8, 2022.
Claims priority of application No. 10 2021 109 253.1 (DE), filed on Apr. 13, 2021.
Prior Publication US 2024/0039915 A1, Feb. 1, 2024
Int. Cl. H04L 9/40 (2022.01); H04L 9/08 (2006.01); H04L 9/32 (2006.01)
CPC H04L 63/0884 (2013.01) [H04L 9/0838 (2013.01); H04L 9/3226 (2013.01); H04L 63/061 (2013.01); H04L 63/166 (2013.01); H04L 2463/082 (2013.01)] 13 Claims
OG exemplary drawing
 
1. A method for logging a user into a device for a power generation plant, using a service gateway, wherein an access authorization of the user for the device is stored on the service gateway, comprising:
authenticating the user on the service gateway,
sending a device access request using an access device from the user to the service gateway specifying an identifier of the device for the power generation plant,
comparing a device secret stored on the service gateway with a copy of the device secret generated using the device secret and stored on the device, via an SRP protocol, wherein the comparison is carried out via a data connection between the access device of the user and the service gateway, and a data connection between the access device of the user and the device for the power generation plant, wherein, when the comparison is successful,
a session key is agreed between the device and the service gateway via the SRP protocol, and
the user logs into the device using the access device,
wherein the data connection between the access device of the user and the service gateway and/or the data connection between the access device of the user and the device is set up via an encrypted and authenticated TLS connection using a cipher suite ensuring Perfect Forward Secrecy.