×

Method for updating message filter rules of a network access control unit of an industrial communication network address management unit, and converter unit

  • US 10,341,249 B2
  • Filed: 01/29/2015
  • Issued: 07/02/2019
  • Est. Priority Date: 01/30/2014
  • Status: Active Grant
First Claim
Patent Images

1. A method of updating message filter rules of a network access control unit within a firewall system of an industrial communication network including a first communication device, a second communication device, the firewall system further including an address management unit and a converter unit, the method comprising:

  • assigning at least one address-based message filter rule defined symbolically based on device descriptions to the first communication device;

    registering the at least one address-based message filter rule defined symbolically based on device descriptions with a corresponding communication network address and a communication device description in the address management unit of the firewall system further including the network access control unit and the converter unit upon identifying an activation, the communication device description comprising at least one of a function indication and a topology indication;

    replacing the first communication device with the second communication device, and registering the second communication device in the address management unit of the firewall system further including the network access control unit and the converter unit in response to the replacement of the first communication device with the second communication device such that a communication network address and a communication device description of the second communication device are acquired;

    checking, by the address management unit of the firewall system further including the network access control unit and the converter unit, during the registration of the second communication device, whether a communication device with an identical communication device description is already registered;

    upon determining that there is a positive check result by the address management unit of the firewall system further including the network access control unit and the converter unit, the address management unit of the firewall system transmitting a change message relating to the registration of the second communication device with a communication device description that is identical to that of the first communication device to the network access control unit or to the converter unit, the change message comprising at least the communication network address and the communication device description of the second communication device; and

    upon receiving the change message, replacing the communication network address of the first communication device with the communication network address of the second communication device based on the at least one address-based message filter rule defined symbolically based on device descriptions to update the message filter rules of the firewall system including the address management unit, the network access control unit and the converter unit of the industrial communication network.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×