23.03.2017 Views

wilamowski-b-m-irwin-j-d-industrial-communication-systems-2011

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Virtual Automation Networks 15-7<br />

Important functionalities are, e.g., the runtime tunnel establishment and maintenance, security<br />

(including ACL), device and network management, VAN name-based addressing routing, and VAN<br />

(provider) switching.<br />

15.3 Name-Based Addressing and Routing, Runtime<br />

Tunnel Establishment<br />

To exchange distributed application data objects (runtime objects), two phases of the connection establishment<br />

have to be considered [NPM08]:<br />

The establishment of a runtime tunnel, i.e., to organize the VAN infrastructure, comparable with<br />

laying a wired line between the applications processes (e.g., automation application process handling<br />

the automation objects to be exchanged). For this, Web services are used. This runtime tunnel is<br />

capable of offering the necessary quality of service (QoS) (e.g., availability, real-time capabilities, or<br />

security level).<br />

The establishment of the application layer connection between the application objects itself (e.g.,<br />

PROFINET application objects [IEC61158] to be exchanged) using the established runtime tunnel.<br />

That connection establishment follows the rules of the protocols that are used to realize the distributed<br />

application (e.g., PROFINET ASE definitions and protocols), and is, therefore, not in the scope of VAN<br />

(instead within the scope of e.g., PROFINET). In the following, the important aspects for establishing a<br />

runtime tunnel will be described.<br />

A VAN domain usually consists of several subdomains that are interconnected via public or private<br />

WANs. Within a subdomain also, further subdomain structures can be realized.<br />

Figure 15.6 depicts a typical VAN scenario [SOPSA07,WM08]: two subdomains, containing VAN-ADs<br />

and VAN-PDs, connected via a WAN. The subdomains are parts of <strong>industrial</strong> automation networks.<br />

In a demilitarized zone (DMZ) of the company’s network, a VAN-AP is situated as a bastion host. The<br />

DMZ<br />

VAN-AP<br />

DMZ<br />

VAN-AP<br />

WAN<br />

Subdomain 1 Subdomain 2<br />

Profinet<br />

VAN-proxy<br />

network<br />

VAN-proxy<br />

with several<br />

D1 devices<br />

D3<br />

D1<br />

Profinet<br />

network<br />

with several<br />

devices<br />

D3<br />

D2<br />

D2<br />

VAN-device<br />

D4<br />

D5<br />

VAN-device<br />

D4<br />

D5<br />

FIGURE 15.6<br />

Connected subdomains (AP, access point; DMZ, demilitarized zone).<br />

© <strong>2011</strong> by Taylor and Francis Group, LLC

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!