Method for updating message filter rules of a network access control unit of an industrial communication network address management unit, and converter unit
First Claim
1. A method of updating message filter rules of a network access control unit within a firewall system of an industrial communication network including a first communication device, a second communication device, the firewall system further including an address management unit and a converter unit, the method comprising:
- assigning at least one address-based message filter rule defined symbolically based on device descriptions to the first communication device;
registering the at least one address-based message filter rule defined symbolically based on device descriptions with a corresponding communication network address and a communication device description in the address management unit of the firewall system further including the network access control unit and the converter unit upon identifying an activation, the communication device description comprising at least one of a function indication and a topology indication;
replacing the first communication device with the second communication device, and registering the second communication device in the address management unit of the firewall system further including the network access control unit and the converter unit in response to the replacement of the first communication device with the second communication device such that a communication network address and a communication device description of the second communication device are acquired;
checking, by the address management unit of the firewall system further including the network access control unit and the converter unit, during the registration of the second communication device, whether a communication device with an identical communication device description is already registered;
upon determining that there is a positive check result by the address management unit of the firewall system further including the network access control unit and the converter unit, the address management unit of the firewall system transmitting a change message relating to the registration of the second communication device with a communication device description that is identical to that of the first communication device to the network access control unit or to the converter unit, the change message comprising at least the communication network address and the communication device description of the second communication device; and
upon receiving the change message, replacing the communication network address of the first communication device with the communication network address of the second communication device based on the at least one address-based message filter rule defined symbolically based on device descriptions to update the message filter rules of the firewall system including the address management unit, the network access control unit and the converter unit of the industrial communication network.
1 Assignment
0 Petitions
Accused Products
Abstract
Method and system of updating message filter rules of a network access control unit of an industrial communication network. At least one address-based message filter rule is assigned to the first communication device. The first communication device is replaced with the second communication device, and the second communication device is registered in the address management unit in response to the replacement of the first communication device with the second communication device. Upon determining that a communication device with an identical communication device description is already registered, the address management unit transmits a change message to the network access control unit or to the converter unit. The communication network address of the first communication device is replaced with the communication network address of the second communication device based on the at least one address-based message filter rule.
-
Citations
13 Claims
-
1. A method of updating message filter rules of a network access control unit within a firewall system of an industrial communication network including a first communication device, a second communication device, the firewall system further including an address management unit and a converter unit, the method comprising:
-
assigning at least one address-based message filter rule defined symbolically based on device descriptions to the first communication device; registering the at least one address-based message filter rule defined symbolically based on device descriptions with a corresponding communication network address and a communication device description in the address management unit of the firewall system further including the network access control unit and the converter unit upon identifying an activation, the communication device description comprising at least one of a function indication and a topology indication; replacing the first communication device with the second communication device, and registering the second communication device in the address management unit of the firewall system further including the network access control unit and the converter unit in response to the replacement of the first communication device with the second communication device such that a communication network address and a communication device description of the second communication device are acquired; checking, by the address management unit of the firewall system further including the network access control unit and the converter unit, during the registration of the second communication device, whether a communication device with an identical communication device description is already registered; upon determining that there is a positive check result by the address management unit of the firewall system further including the network access control unit and the converter unit, the address management unit of the firewall system transmitting a change message relating to the registration of the second communication device with a communication device description that is identical to that of the first communication device to the network access control unit or to the converter unit, the change message comprising at least the communication network address and the communication device description of the second communication device; and upon receiving the change message, replacing the communication network address of the first communication device with the communication network address of the second communication device based on the at least one address-based message filter rule defined symbolically based on device descriptions to update the message filter rules of the firewall system including the address management unit, the network access control unit and the converter unit of the industrial communication network. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12)
-
-
13. An address management unit within a firewall system of an industrial communication network, the network comprising:
-
a first communication device; a second communication device; and a converter unit; wherein the address management unit within the firewall system is configured to register the communication devices, upon activation of the respective communication device; wherein each communication device includes a respective communication network address and a device description; wherein the device description comprises at least one of a function indication and topology indication; wherein the address management unit within the firewall system is configured to check whether a registered second communication device has a device description that is identical to that of the first communication device that is registered earlier; wherein the address management unit within the firewall system is configured to transmit a change message to one of a network access control unit within the firewall system and to the converter unit upon determining a positive check result to update message filter rules of the network access control unit defined symbolically based on the device description within the firewall system of the industrial communication network; and wherein the change message comprises at least the communication network address and the device description of the second communication device.
-
Specification