白丝美女被狂躁免费视频网站,500av导航大全精品,yw.193.cnc爆乳尤物未满,97se亚洲综合色区,аⅴ天堂中文在线网官网

Method of accessing functions of an embedded device

專利號
US10867077B2
公開日期
2020-12-15
申請人
Schneider Electric Automation GmbH(DE Marktheidenfeld)
發(fā)明人
Ralf Berner; Thomas Gleixner
IPC分類
G06F21/76; G05B19/042; G05B19/05; G06F21/31; G06F21/60
技術(shù)領域
embedded,functional,level,access,device,in,can,firewall,key,management
地域: Marktheidenfeld

摘要

A method for accessing functions of an embedded device, for example a controller programmable from memory, wherein function blocks of the embedded device are assigned to at least two hierarchically superimposed levels, an access to a function block of the embedded device occurs from outside of the embedded device by a data interface, and for access an authentication must occur for the level to which the respective function block is assigned, and again for each individual level above the level to which the function block is assigned, to permit execution of a function of the function block, wherein the functions of the function blocks permit access to a firmware of the embedded device.

說明書

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16

In accordance with a further advantageous embodiment, a fourth functional block that permits access to a web server of the embedded device is arranged in a fourth level that is disposed above the third level. In this respect, a function belonging to the fourth functional block in particular permits a data input and a data output at the web server. This means that the access to the web server itself can also already be protected by an authentication.

Access to functions of the embedded device is preferably checked by a firewall of the embedded device. The firewall can be provided by the embedded device itself, i.e. it can, for example, be integrated in the embedded device as separate hardware. The firewall can provide additional security for the embedded device in that the firewall, for example, carries out a preselection of authorized queries with reference to predefined rules.

In addition, the firewall can serve as the end point of a VPN (virtual private network) connection. In this case, only access attempts by means of the VPN connection can be authorized by the embedded device.

In accordance with a further advantageous embodiment, a user management is used in which users are stored to whom an authentication is permitted for predefined functional blocks. The authentication can take place centrally, for example by means of an access control matrix (ACM) or in the respective level. An access control list (ACL) can be present for the respective level. Those users can be stored in the access control matrix and in the access control list who may respectively access the functional blocks of a specific level. The access control list for a level can be respectively stored in the level disposed above it.

權(quán)利要求

1
微信群二維碼
意見反饋