AUTOMATIC COMMUNICATION NETWORK SYSTEM HARDENING

    公开(公告)号:WO2018162599A1

    公开(公告)日:2018-09-13

    申请号:PCT/EP2018/055676

    申请日:2018-03-07

    Applicant: ABB SCHWEIZ AG

    Abstract: A method for automatically improving security of a network system (10) comprises: collecting security relevant information (30') from network devices (14) of the network system (10), the security relevant information (30') including security settings (32) and operational information (34) of the network devices (14); analyzing the security relevant information (30') for determining weak security settings (32') of a network device (14), the weak security settings (32') being not necessary for a regular operation of the network system (10); determining hardened security settings (32'') for the network device (14) based on the weak security settings (32'), the hardened security settings (32'') restricting a possible operation of the network device (14) but allow a regular operation of the network system (10); and applying the hardened security settings (32'') to the network device (14).

    METHOD AND SYSTEM FOR DETECTING AND MITIGATING CABLING ISSUES WITH DEVICES IN SUBSTATION AUTOMATION SYSTEMS

    公开(公告)号:WO2020254852A1

    公开(公告)日:2020-12-24

    申请号:PCT/IB2019/055014

    申请日:2019-06-17

    Applicant: ABB SCHWEIZ AG

    Abstract: The invention relates to a method and system for detecting and mitigating cabling issues with devices connected in industrial redundant networks. An agent runs on each device and generates information about traffic received at the corresponding device. The agent running on a node generates indicators of traffic received at each port, and error rates for traffic at each port. The agent running on a switch generates information about switch misconfiguration by collecting device identifiers for each port of the switch. The agents send the information to a network manager, which determines switch misconfigurations and wrong cabling from the received information. The network manager also mitigates cabling issues by sending a signal to the affected device(s) or sending a communication to mitigate the issue.

    METHOD FOR AUTHENTICATING MESSAGES IN RESOURCE LIMITED SYSTEMS

    公开(公告)号:WO2020161201A1

    公开(公告)日:2020-08-13

    申请号:PCT/EP2020/052897

    申请日:2020-02-05

    Applicant: ABB SCHWEIZ AG

    Abstract: The present invention provides a method for message authentication, in particular in case of low of transmission or storage capacities. The present invention further provides corresponding devices for generating or sending authenticated messages and for receiving or retrieving authenticated messages as well as a system comprising such devices. In an embodiment, the method may comprise (a) preparing a data block having an uncompressed length; (b) compressing the data block so that the data block has a compressed length smaller than the uncompressed length; (c) determining an available length from at least the compressed length and a maximum length of a data frame; (d) calculating a message authentication code, MAC, from at least the data block, having a MAC length not greater than the available length; and (e) creating the data frame, comprising the data block and the MAC.

    TUNNELLING TIME-CRITICAL MESSAGES BETWEEN SUBSTATIONS OVER WAN
    5.
    发明公开
    TUNNELLING TIME-CRITICAL MESSAGES BETWEEN SUBSTATIONS OVER WAN 审中-公开
    屯门屯门Z EN Z WAN WAN WAN WAN WAN WAN WAN WAN WAN WAN WAN WAN WAN WAN WAN WAN

    公开(公告)号:EP3114802A1

    公开(公告)日:2017-01-11

    申请号:EP15702800.2

    申请日:2015-02-06

    Applicant: ABB Schweiz AG

    Abstract: The present invention discloses a method of transmitting time-critical messages in an OSI layer 2 network tunnel from an IED in a first substation to an IED in a second substation over a WAN, wherein each of the first and second substation comprises an edge IED and is associated with a substation LAN, wherein each of the time-critical messages comprises message parameters. The method comprises the steps of: a) creating a translation table comprising corresponding values of the message parameters, between the LANs and the WAN, b) defining a virtual IED model in the second substation using the translated values of the message parameters, to impersonate the IED of the first substation, c) translating the message parameters according to the translation table, d) forwarding the time-critical messages from the IED in the first substation to the WAN, and e) receiving the time-critical messages by the IED of the second substation from the WAN.

    Abstract translation: 本发明公开了一种将OSI第二层网络隧道中的时间关键消息从第一变电站中的IED传输到WAN上的第二变电站中的IED的方法,其中第一和第二变电站中的每一个包括边缘IED和 与变电站LAN相关联,其中每个时间关键消息包括消息参数。 该方法包括以下步骤:a)创建包括LAN和WAN之间的消息参数对应值的转换表,b)使用消息参数的转换值来定义第二变电站中的虚拟IED模型,以模拟 第一变电站的IED,c)根据转换表翻译消息参数,d)将来自第一变电站中的IED的时间关键消息转发到WAN,以及e)由IED接收时间关键消息 的第二个变电站。

    CONTROL METHOD, AND CONTROL SYSTEM FOR A SUBSTATION

    公开(公告)号:EP4277082A1

    公开(公告)日:2023-11-15

    申请号:EP22173037.7

    申请日:2022-05-12

    Applicant: ABB SCHWEIZ AG

    Abstract: A technique for a control method (100) and a control system in a substation is provided. The control system comprises a substation feeder (30), an intelligent electronic device, IED, (36), a merging unit (34), and BUS network (38a, 38b) connecting the IED (36) and the merging unit (34). The control method comprises providing (10) measurement signals by the substation feeder (30) to the merging unit (34); transmitting (12), by the merging unit (34), measurement data based on the measurement signals of the substation feeder to the IED (36) via the BUS network (38a, 38b); identifying (14), by the IED (36), a fault condition based on the measurement data, the fault condition being indicative of a potentially forthcoming fault; transmitting (16), by the IED (36), a conditional control command to the merging unit (34) via the BUS network (38a, 38b), the conditional control command comprising a control measure and a condition for executing the control measure; determining (18), by the merging unit, whether the condition of the conditional control command is met, and if so initiating (20), by the merging unit, the control measure of the substation feeder circuit.

Patent Agency Ranking