Firewall with application packet classifer

    公开(公告)号:US10110561B2

    公开(公告)日:2018-10-23

    申请号:US14554621

    申请日:2014-11-26

    Abstract: An improved system for establishing rules in a firewall for an industrial network is disclosed. Rules are established at an application level, identifying, for example, actions to occur between two devices. The action may be, for example, read data table or get attribute, and each action may require multiple message packets to be transmitted between the two devices in order to complete. A network device executing the firewall is configured to receive message packets from a sending device and to inspect the message packets to determine which action the sending device is requesting to perform. If the action corresponds to a rule in the database, the network device manages communications between the two devices until all message packets have been transmitted. Thus, a single action, or application, may be defined in the rules database to permit multiple data packets to be communicated between the devices.

    Internet protocol addressing of devices employing the network ring topology
    6.
    发明授权
    Internet protocol addressing of devices employing the network ring topology 有权
    使用网络环形拓扑的设备的互联网协议寻址

    公开(公告)号:US09413552B2

    公开(公告)日:2016-08-09

    申请号:US14446905

    申请日:2014-07-30

    Abstract: Aspects of the present invention provide a ring supervisor operating as a server for maintaining and allocating addresses for devices in a ring topology. The ring supervisor may obtain an ordered list of devices in the ring by sending a data collection frame that passes through each device around the ring with each device appending its preconfigured address information. The ring supervisor may then operate to apply the addressing provided by each device, or alternatively, allocate different addresses to each device from a separate pool. As a result, control program software for ring devices can be developed using a general pool of addresses without requiring specific knowledge of actual addresses. Also, if a device requires replacement, the device may be replaced without requiring modification to the control program to provide the address for the replacement device.

    Abstract translation: 本发明的方面提供一种作为服务器操作的环形监控器,用于维护和分配环形拓扑中的设备的地址。 环形监控器可以通过发送一个数据收集帧来获取环中的设备的有序列表,每个设备附加其预先配置的地址信息,通过环路上的每个设备。 然后,环形管理器可以操作以应用由每个设备提供的寻址,或者替代地,从单独的池向每个设备分配不同的地址。 因此,可以使用一般的地址池来开发环形设备的控制程序软件,而不需要具体的实际地址知识。 此外,如果设备需要更换,则可以更换设备而不需要修改控制程序来提供更换设备的地址。

    Hardware-based granular traffic storm protection
    7.
    发明授权
    Hardware-based granular traffic storm protection 有权
    基于硬件的细粒度流量风暴保护

    公开(公告)号:US09374387B2

    公开(公告)日:2016-06-21

    申请号:US13650308

    申请日:2012-10-12

    CPC classification number: H04L63/1458 H04L47/24 H04L47/32 H04L63/0227

    Abstract: Aspects of the present invention provide a device, method and system which utilize hardware-based granular evaluation of industrial control protocol packets to withstand traffic storms. In an embodiment, packet evaluation circuitry coupled to a port may be adapted to evaluate one or more protocol fields contained in each inbound packet before switching circuitry can send the inbound packet to the proper destination. The inbound packet may be sent by the switching circuitry if it is a particular message, or may be selectively inhibited from being sent by the switching circuitry if the inbound packet does not contain the particular message for being sent and if the total number of bytes of the inbound packet type exceeds a threshold for the outbound port during a given period of time. As such, critical industrial applications may continue to operate in the presence of a traffic storm.

    Abstract translation: 本发明的方面提供一种利用工业控制协议分组的基于硬件的粒度评估来承受交通风暴的装置,方法和系统。 在实施例中,耦合到端口的分组评估电路可以适于在切换电路可以将入站分组发送到适当目的地之前评估每个入站分组中包含的一个或多个协议字段。 如果入口分组是特定消息,则可以由切换电路发送入站分组,或者如果入站分组不包含用于发送的特定消息,则可以选择性地禁止由切换电路发送入局分组,以及如果总共的字节数 入站分组类型在给定的时间段内超出出站端口的阈值。 因此,关键的工业应用可能会在存在交通风暴的情况下继续运行。

    Method and Apparatus for Full Duplex Serial Shifting Mode and Switch Mode Data Transmission
    8.
    发明申请
    Method and Apparatus for Full Duplex Serial Shifting Mode and Switch Mode Data Transmission 有权
    全双工串行转换模式和开关模式数据传输方法与装置

    公开(公告)号:US20140334341A1

    公开(公告)日:2014-11-13

    申请号:US14340082

    申请日:2014-07-24

    CPC classification number: H04L45/745 H04L12/28 H04L12/40032

    Abstract: An industrial network with bidirectional communication for real time control includes nodes selectively operable in either a switch mode or a serial shifting mode. Nodes operating in the switch mode are capable of initiating data frames for transmission on the network and receiving data frames from the network. Nodes operating in either the switch mode or the serial shifting mode are capable of extracting and/or inserting data into a data frame as it is transmitted through that node. An initialization procedure determines end nodes and intermediate nodes within the network. The end nodes are configured to initially operate in the switch mode and the intermediate nodes are configured to initially operate in the serial shifting mode. The intermediate nodes are additionally operable to selectively toggle between operation in switch mode and serial shift mode and may operate in both modes during a single scan cycle.

    Abstract translation: 具有用于实时控制的双向通信的工业网络包括可选择性地以开关模式或串行移位模式操作的节点。 以切换模式工作的节点能够启动用于在网络上传输的数据帧并从网络接收数据帧。 以切换模式或串行移位模式工作的节点能够在通过该节点发送数据帧时将数据提取和/或插入到数据帧中。 初始化过程确定网络中的终端节点和中间节点。 端节点被配置为最初在交换模式下操作,并且中间节点被配置为以串行移位模式初始化。 中间节点还可操作以选择性地在开关模式和串行移位模式之间切换,并且可以在单个扫描周期期间以两种模式操作。

    Fault Tolerant Backplane Slot Assignment

    公开(公告)号:US20220163954A1

    公开(公告)日:2022-05-26

    申请号:US16953948

    申请日:2020-11-20

    Abstract: A method and system for assigning slot addresses to modules in a fault tolerant industrial control system includes a pair of backplane switches on each base. Each backplane switch is configured to communicate between one backplane and the modules located on the base and to communicate between backplane switches located at adjacent bases. A backplane switch on a bank master base first assigns a base address and slot addresses to itself. The backplane switches on each additional base initiate transmission of a base address request. A base address response, including a base address and slot numbers for the adjacent base, is transmitted after a base has its own address assigned. Each base repeats the process in sequence along the bank, incrementing the base address by one and the slot address by the number of slots on the base and passing the new base and slot addresses along the bank.

Patent Agency Ranking