Apparatus and method for establishing seamless secure communications between components in an industrial control and automation system

    公开(公告)号:US10244000B2

    公开(公告)日:2019-03-26

    申请号:US14460256

    申请日:2014-08-14

    Abstract: A method includes establishing, using a connection policy at a first device, a security association with a second device of an industrial process control and automation system. The method also includes, once the security association is established, activating a process data policy at the first device. The security association is established during first and second types of negotiations. The process data policy is activated during the second type of negotiation without the first type of negotiation. The second type of negotiation is faster than the first type of negotiation. The connection policy defines a communication channel between the devices using a non-process communication port of the first device. The process data policy defines a communication channel between the devices for real-time industrial process data. The first type of negotiation could include an IKE main mode negotiation, and the second type of negotiation could include an IKE quick mode negotiation.

    APPARATUS AND METHOD FOR ESTABLISHING SEAMLESS SECURE COMMUNICATIONS BETWEEN COMPONENTS IN AN INDUSTRIAL CONTROL AND AUTOMATION SYSTEM
    4.
    发明申请
    APPARATUS AND METHOD FOR ESTABLISHING SEAMLESS SECURE COMMUNICATIONS BETWEEN COMPONENTS IN AN INDUSTRIAL CONTROL AND AUTOMATION SYSTEM 审中-公开
    在工业控制和自动化系统中组件之间建立无缝安全通信的装置和方法

    公开(公告)号:US20150244742A1

    公开(公告)日:2015-08-27

    申请号:US14460256

    申请日:2014-08-14

    Abstract: A method includes establishing, using a connection policy at a first device, a security association with a second device of an industrial process control and automation system. The method also includes, once the security association is established, activating a process data policy at the first device. The security association is established during first and second types of negotiations. The process data policy is activated during the second type of negotiation without the first type of negotiation. The second type of negotiation is faster than the first type of negotiation. The connection policy defines a communication channel between the devices using a non-process communication port of the first device. The process data policy defines a communication channel between the devices for real-time industrial process data. The first type of negotiation could include an IKE main mode negotiation, and the second type of negotiation could include an IKE quick mode negotiation.

    Abstract translation: 一种方法包括在第一设备处使用连接策略建立与工业过程控制和自动化系统的第二设备的安全关联。 该方法还包括,一旦建立了安全关联,则激活第一设备处的过程数据策略。 安全协会是在第一和第二类谈判期间建立的。 过程数据策略在第二类协商期间被激活,而没有第一类协商。 第二种谈判速度比第一类谈判要快。 连接策略使用第一设备的非进程通信端口来定义设备之间的通信信道。 过程数据策略定义了用于实时工业过程数据的设备之间的通信通道。 第一种类型的协商可以包括IKE主模式协商,第二种类型的协商可以包括IKE快速模式协商。

Patent Agency Ranking