NETWORKED CONTROL SYSTEM AND DEVICE FOR A NETWORKED CONTROL SYSTEM
    13.
    发明申请
    NETWORKED CONTROL SYSTEM AND DEVICE FOR A NETWORKED CONTROL SYSTEM 审中-公开
    网络化控制系统及网络控制系统设备

    公开(公告)号:WO2008099308A3

    公开(公告)日:2008-11-13

    申请号:PCT/IB2008050446

    申请日:2008-02-07

    CPC classification number: G06F9/542 G06F2209/544 G06F2209/546 H04L67/04

    Abstract: The invention relates to a networked control system including comprising a resource limited device (102) and an assigned proxy device (104). The resource limited device (102) comprises a device logic (122) for providing a change notification message to the assigned proxy device (104) on a change of a device state of the resource limited device, wherein each device state of the resource limited device (102) is defined by a corresponding state variable and wherein the change notification message comprises a state variable corresponding to an actual device state of there source limited device (102). The assigned proxy device (104) comprises means (142) for receiving a change notification message from an assigned resource limited device (102), wherein the change notification message comprises a state variable which defines an actual device state of the resource limited device and means (144) for distributing a state variable change notification, comprising the state variable which defines the actual device state of the resource limited device, within the networked control system according to requirements of a control application (162) of the networked control system.

    Abstract translation: 本发明涉及包括资源受限设备(102)和分配的代理设备(104)的联网控制系统。 资源受限设备(102)包括设备逻辑(122),用于在资源受限设备的设备状态改变时向分配的代理设备(104)提供改变通知消息,其中资源受限设备的每个设备状态 (102)由相应的状态变量定义,并且其中所述改变通知消息包括与所述源受限设备(102)的实际设备状态相对应的状态变量。 所分配的代理设备(104)包括用于从分配的资源受限设备(102)接收改变通知消息的装置(142),其中所述改变通知消息包括定义所述资源受限设备的实际设备状态的状态变量, (144),用于根据所述联网控制系统的控制应用(162)的要求在所述联网控制系统内分发包括限定所述资源受限设备的实际设备状态的状态变量的状态变量改变通知。

    A METHOD FOR OPERATING A NETWORK, A SYSTEM MANAGEMENT DEVICE, A NETWORK AND A COMPUTER PROGRAM THEREFOR
    14.
    发明申请
    A METHOD FOR OPERATING A NETWORK, A SYSTEM MANAGEMENT DEVICE, A NETWORK AND A COMPUTER PROGRAM THEREFOR 审中-公开
    一种运行网络的方法,系统管理设备,网络及其计算机程序

    公开(公告)号:WO2010041164A3

    公开(公告)日:2010-08-19

    申请号:PCT/IB2009054229

    申请日:2009-09-28

    Abstract: The present invention relates to a method for operating a network comprising communicating devices representing nodes of the network. More precisely, the invention relates to a method for operating a network (1), comprising a node (D1) and a system management device (3), the system management device comprising a root keying material being a set of alpha-secure functions having a degree of complexity of,and the node being provided with a node keying material share of degree of complexity a derived from the root keying material. The method comprises the following steps, upon receipt at the system management device of a request for an external user (4) to gain access to the node (D1): the system management device generates an external user keying material share of degree of complexity a from the root keying material and an access identifier, the system management device generates an access keying material of degree of complexity less than a, from the external user keying material share and an identifier of the node, the system management device provides the external user with the access keying material share and the access identifier, the external user derives a key from the access keying material share, and transmitting this key and the access certificate to the node, the node computes a key from the access identifier and the node keying material share, and the node compares the key transmitted by the external user and the key computed by the node, so as to authenticate the external user.

    Abstract translation: 本发明涉及一种用于操作网络的方法,包括:传送代表网络节点的设备。 更准确地说,本发明涉及一种用于操作网络(1)的方法,所述网络(1)包括节点(D1)和系统管理设备(3),所述系统管理设备包括根密钥材料,所述根密钥材料是一组α安全功能, 复杂度的一部分,并且节点被提供有从根密钥材料导出的复杂程度的节点密钥材料份额。 该方法包括以下步骤:在系统管理装置接收对外部用户(4)的请求以获得对节点(D1)的访问时:系统管理设备生成复杂程度的外部用户密钥材料份额a 从根密钥材料和访问标识符,系统管理设备生成复杂度小于根据外部用户密钥材料共享和节点标识符的复杂度的访问密钥材料,系统管理设备向外部用户提供 访问密钥材料共享和访问标识符,外部用户从访问密钥材料共享中导出密钥,并将该密钥和访问证书发送给节点,节点根据访问标识符和节点密钥资源共享来计算密钥 ,并且节点将外部用户发送的密钥与节点计算的密钥进行比较,以便对外部用户进行认证。

    METHOD OF COMMISSIONING A DEVICE ARRANGEMENT
    15.
    发明申请
    METHOD OF COMMISSIONING A DEVICE ARRANGEMENT 审中-公开
    调试设备安排的方法

    公开(公告)号:WO2009128001A2

    公开(公告)日:2009-10-22

    申请号:PCT/IB2009051505

    申请日:2009-04-09

    CPC classification number: H04L12/2809 H04L2012/2841

    Abstract: The invention describes a method of commissioning a device arrangement comprising a number of devices (L1, L2, L3,) communicating with each other over a wireless networked control system (WN). This method comprises the steps of - reading a unique identifier (ID1, ID2, ID3) from an electronic identification tag (T) which is tagged to a device (L1, L2, L3) currently to be installed by means of a reading device (3) carried by an installer who is to install the device (L1, L2, L3), and - compiling an inventory (IV) of the installed devices (L1, L2, L3) using the read unique identifiers (ID1, ID2, ID3), - commissioning of the devices (L1, L2, L3) using the inventory (IV). The invention further describes a commissioning system (100) for commissioning such a device arrangement, a data logger and an installation tool (1) for installing devices (L1, L2, L3,) usable in such a commissioning system (100).

    Abstract translation: 本发明描述了调试包括通过无线网络控制系统(WN)相互通信的多个设备(L1,L2,L3)的设备装置的方法。 该方法包括以下步骤: - 从电子识别标签(T)中读取唯一标识符(ID1,ID2,ID3),该电子标签标签(T)被标记到当前将通过读取设备(L1,L2,L3) (L1,L2,L3)安装的安装者所携带的安装设备(L1,L2,L3)的库存(IV),以及 - 使用所读取的唯一标识符(ID1,ID2,ID3) ) - 使用库存(IV)调试设备(L1,L2,L3)。 本发明还描述了用于调试这种设备装置的调试系统(100),数据记录器和用于安装可用于这种调试系统(100)中的设备(L1,L2,L3)的安装工具(1)。

    NETWORK AND METHOD FOR ESTABLISHING A SECURE NETWORK
    16.
    发明申请
    NETWORK AND METHOD FOR ESTABLISHING A SECURE NETWORK 审中-公开
    建立安全网络的网络和方法

    公开(公告)号:WO2009031110A2

    公开(公告)日:2009-03-12

    申请号:PCT/IB2008053575

    申请日:2008-09-04

    Abstract: The invention relates to a network with a first node (102) comprising first pre-distributed keying material being assigned to the first node before the first node is connected to the network and a second node (104) comprising second pre- distributed keying material being assigned to the second node before the second node is connected to the network. The first node is configured to establish a secure communication (112) to the second node based on the first and second pre-distributed keying materials, without relying on a trust center (108). Pre-distributed keying materials can be replaced in a secure manner with post-deployed keying materials by the network trust center. Nodes can establish further secure communications based on post-deployed keying materials.

    Abstract translation: 本发明涉及具有第一节点(102)的网络,第一节点(102)包括在第一节点连接到网络之前被分配给第一节点的第一预分布密钥资源,以及包括第二预分布密钥材料的第二节点(104) 在第二节点连接到网络之前分配给第二节点。 第一节点被配置为基于第一和第二预分布密钥材料建立到第二节点的安全通信(112),而不依赖于信任中心(108)。 预分配的密钥材料可以通过网络信任中心的后处理密钥材料安全地替换。 节点可以基于后期部署的密钥材料建立进一步的安全通信。

Patent Agency Ranking