Enhancing security in a wireless network
First Claim
1. A method of enhancing security in a wireless mesh communication network operating in a process control environment and including a plurality of wireless network devices, comprising:
- processing a join request from a wireless device wishing to join the wireless mesh communication network, the wireless device configured to perform a physical control function within a process being controlled in the process control environment, and configured to communicate in the wireless mesh communication network using a wireless protocol that includes commands for transfer of data corresponding to the process, the processing the join request from the wireless device including;
establishing a direct wireless connection between the wireless device and at least one of the plurality of wireless network devices; and
propagating a join request from the wireless device via the at least one of the plurality of wireless network devices to a network manager responsible for managing the wireless communication network;
maintaining an absolute slot number at the network manager, the absolute slot number indicative of a number of communication timeslots scheduled since a start time of the wireless network, wherein each of the plurality of wireless network devices communicates with at least one other of the plurality of wireless network devices within a communication timeslot associated with a respective superframe having a repeating sequence of communication timeslots;
causing the wireless device to enter a quarantined state including providing a limited network functionality to the wireless device if the join request is granted, the providing the limited network functionality to the wireless device including;
providing the absolute slot number to the wireless device; and
exchanging a plurality of messages between the wireless device and the at least one of the plurality of wireless network devices, including a generating a message integrity code for at least one of the plurality of messages by including the absolute slot number in a nonce value used to generate the message integrity code;
while the wireless device is in the quarantined state, requesting a complete approval of the wireless device; and
causing the wireless device to exit the quarantined state and to enter an operational state including granting a full network functionality to the wireless device if the complete approval of the wireless device is received.
7 Assignments
0 Petitions
Accused Products
Abstract
A method of enhancing security in a wireless mesh communication network operating in a process control environment and including a plurality of wireless network devices includes processing a join request from a wireless device wishing to join the wireless mesh communication network, providing a limited network functionality to the wireless device if the join request is granted, requesting a complete approval of the wireless device; and granting a full network functionality to the wireless device if the complete approval of the wireless device is received.
-
Citations
10 Claims
-
1. A method of enhancing security in a wireless mesh communication network operating in a process control environment and including a plurality of wireless network devices, comprising:
-
processing a join request from a wireless device wishing to join the wireless mesh communication network, the wireless device configured to perform a physical control function within a process being controlled in the process control environment, and configured to communicate in the wireless mesh communication network using a wireless protocol that includes commands for transfer of data corresponding to the process, the processing the join request from the wireless device including; establishing a direct wireless connection between the wireless device and at least one of the plurality of wireless network devices; and propagating a join request from the wireless device via the at least one of the plurality of wireless network devices to a network manager responsible for managing the wireless communication network; maintaining an absolute slot number at the network manager, the absolute slot number indicative of a number of communication timeslots scheduled since a start time of the wireless network, wherein each of the plurality of wireless network devices communicates with at least one other of the plurality of wireless network devices within a communication timeslot associated with a respective superframe having a repeating sequence of communication timeslots; causing the wireless device to enter a quarantined state including providing a limited network functionality to the wireless device if the join request is granted, the providing the limited network functionality to the wireless device including; providing the absolute slot number to the wireless device; and exchanging a plurality of messages between the wireless device and the at least one of the plurality of wireless network devices, including a generating a message integrity code for at least one of the plurality of messages by including the absolute slot number in a nonce value used to generate the message integrity code; while the wireless device is in the quarantined state, requesting a complete approval of the wireless device; and causing the wireless device to exit the quarantined state and to enter an operational state including granting a full network functionality to the wireless device if the complete approval of the wireless device is received. - View Dependent Claims (2, 3, 4, 5, 6, 7, 9, 10)
-
-
8. A method of enhancing security in a wireless mesh communication network operating in a process control environment and including a plurality of wireless network devices, comprising:
-
processing a join request from a wireless device wishing to join the wireless mesh communication network, including; establishing a direct wireless connection between the wireless device and at least one of the plurality of wireless network devices; and propagating a join request from the wireless device via the at least one of the plurality of wireless network devices to a network manager responsible for managing the wireless communication network; providing a limited network functionality to the wireless device if the join request is granted; requesting a complete approval of the wireless device; granting a full network functionality to the wireless if the complete approval of the wireless device is received; and maintaining an absolute slot number at the network manager, the absolute slot number indicative of a number of communication timeslots scheduled since a start time of the wireless network, wherein each of the plurality of wireless network devices communicates with at least one other of the plurality of wireless network devices within a communication timeslot associated with a respective superframe having a repeating sequence of communication timeslots, wherein providing a limited network functionality to the wireless device includes; providing the absolute slot number to the wireless device; and exchanging a plurality of messages between the wireless device and the at least one of the plurality of wireless network devices, including a generating a message integrity code for at least one of the plurality of messages by including the absolute slot number in a nonce value used to generate the message integrity code.
-
Specification