EDBT 2026 Demo / reviewers in the wild / expert
Karl-Heinz Niemann
dblp:120/5608
· DBLP profile ↗
10ranked-venue papers
1as first author
5since 2021 · last 2023
0000-0001-8931-6789ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 9 · 1 first-author · 5 since 2021Databases, data management, data science and information retrieval · 1Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2023 | PROFINET Security: A Look on Selected Concepts for Secure Communication in the Automation DomainabstractWe provide a brief overview of the cryptographic security extensions for PROFINET, as defined and specified by PROFIBUS & PROFINET International (PI). These come in three hierarchically defined Security Classes, called Security Class 1,2 and 3. Security Class 1 provides basic security improvements with moderate implementation impact on PROFINET components. Security Classes 2 and 3, in contrast, introduce an integrated cryptographic protection of PROFINET communication. We first highlight and discuss the security features that the PROFINET specification offers for future PROFINET products. Then, as our main focus, we take a closer look at some of the technical challenges that were faced during the conceptualization and design of Security Class 2 and 3 features. In particular, we elaborate on how secure application relations between PROFINET components are established and how a disruption-free availability of a secure communication channel is guaranteed despite the need to refresh cryptographic keys regularly. The authors are members of the PI Working Group CB/PG10 Security. Andreas Walz, Karl-Heinz Niemann, Julian Göppert, Kai Fischer, Simon Merklin, Dominik Ziegler 0001, Axel Sikora |
INDIN | 2 |
| 2022 | Universal energy information model for industrial communicationabstractWith the use of an energy management system in an industrial company according to ISO 50001, a step-by-step increase in energy efficiency can be achieved. The realization of energy monitoring and load management functions requires programs on edge devices or PLCs to acquire the data, adapt the data type or scale the values of the energy information. In addition, the energy information must be mapped to communication interfaces (e.g. based on OPC UA) in order to convey this energy information to the energy management application. The development of these energy management programs is associated with a high engineering effort, because the field devices from the heterogeneous field level do not provide the energy information in standardized semantics. To mitigate this engineering effort, a universal energy data information model (UEIM) is developed and presented in this paper. Maxim Runge, Leif-Thore Reiche, Karl-Heinz Niemann, Alexander Fay |
ETFA | 3 |
| 2021 | User-guided engineering of integrated energy management functions in automation systemsabstractIn the area of manufacturing and process automation in industrial applications, technical energy management systems are mainly used to measure, collect, store, analyze and display energy data. In addition, PLC programs on the control level are required to obtain the energy data from the field level. If the measured data is available in a PLC as a raw value, it still has to be processed by the PLC, so that it can be passed on to the higher layers in a suitable format, e.g. via OPC UA. In plants with heterogeneous field device installations, a high engineering effort is required for the creation of corresponding PLC programs. This paper describes a concept for a code generator that can be used to reduce this engineering effort. Jan-Niklas Puls, Maxim Runge, Karl-Heinz Niemann |
ETFA | 3 |
| 2021 | Requirements for an energy data information model for a communication-independent device descriptionabstractWith the help of an energy management system according to ISO 50001, industrial companies obtain the opportunities to reduce energy consumption and to increase plant efficiencies. In such a system, the communication of energy data has an important function. With the help of so-called energy profiles (e.g. PROFIenergy), energy data can be communicated between the field level and the higher levels via proven communication protocols (e.g. PROFINET). Due to the fact that in most cases several industrial protocols are used in an automation system, the problem is how to transfer energy data from one protocol to another with as less effort as possible. An energy data information model could overcome this problem and describe energy data in a uniform and semantically unambiguous way. Requirements for a unified energy data information model are presented in this paper. Maxim Runge, Leif-Thore Reiche, Karl-Heinz Niemann, Alexander Fay, Andreas Würger |
ETFA | 3 |
| 2021 | Communication of energy data in automation systemsabstractWith regard to climate change, increasing energy efficiency is still a significant issue in the industry. In order to acquire energy data at the field level, so-called energy profiles can be used. They are advantageous as they are integrated into existing industrial ethernet standards (e.g. PROFINET). Commonly used energy profiles such as PROFIenergy and sercos Energy have been established in industrial use. However, as the Industrial Internet of Things (IIoT) continues to develop, the question arises whether the established energy profiles are sufficient to fullfil the requirements of the upcoming IIoT communication technologies. To answer this question the paper compares and discusses the common energy profiles with the current and future challenges of energy data communication. Furthermore, this analysis examines the need for further research in this field. Leif-Thore Reiche, Maxim Runge, Karl-Heinz Niemann, Alexander Fay |
WFCS | 3 |
| 2019 | IT security extensions for PROFINETabstractThe impact of vertical and horizontal integration in the context of Industry 4.0 requires new concepts for the security of industrial Ethernet protocols. The defense in depth concept, basing on the combination of several measures, especially separation and segmentation, needs to be complimented by integrated protection measures for industrial real-time protocols. To cover this challenge, existing protocols need to be equipped with additional functionality to ensure the integrity and availability of the network communication, even in environments, where possible attackers can be present. In order to show a possible way to upgrade an existing protocol, this paper describes a security concept for the industrial Ethernet protocol PROFINET. Karl-Heinz Niemann |
INDIN | 1 |
| 2018 | Concept for an Energy Data Aggregation Layer for Production Sites A Combination of AutomationML and OPC UAabstractIn industrial production facilities, technical Energy Management Systems are used to measure, monitor and display energy consumption related information. The measurements take place at the field device level of the automation pyramid. The measured values are recorded and processed at the control level. The functionalities to monitor and display energy data are located at the MES level of the automation pyramid. So the energy data from all PLCs has to be aggregated, structured and provided for higher level systems. This contribution introduces a concept for an Energy Data Aggregation Layer, which provides the functionality described above. For the implementation of this Energy Data Aggregation Layer, a combination of AutomationML and OPC UA is used. Andreas Würger, Karl-Heinz Niemann, Alexander Fay |
ETFA | 2 |
| 2015 | Knowledge-based Engineering of Automation Systems using Ontologies and Engineering DataabstractOntologies provide an effective way for describing and using knowledge of a specific domain. In engineering workflows the reusability and quick adoption of knowledge is needed for solving several tasks in efficient ways. Engineering data is mostly structured in hierarchical documents and exchange formats and not represented in ontologies. Therefore a connection between engineering data and the knowledge in ontologies is needed. In this article we present a bridge concept for connecting engineering data with an OWL-based ontology. For this we use an example ontology containing security knowledge of automation systems. Matthias Glawe, Christopher Tebbe, Alexander Fay, Karl-Heinz Niemann |
KEOD | 4 |
| 2013 | Performance evaluation of an IT security layer in real-time communicationabstractCurrent trends like Cloud Computing dissolve the known structure of the automation pyramid and lead towards a higher level of connectivity between different networks. Classical security methods like separation do not necessarily yield the needed level of protection. This paper describes the evaluation of a new security layer to protect the PROFINET communication by cryptographic means under real-time conditions to support current existing IT security measures. Markus Runde, Christopher Tebbe, Karl-Heinz Niemann |
ETFA | 3 |
| 2012 | Automated decentralized IT security supervision in automation networksabstractThis paper introduces a concept and a software prototype for a distributed supervision of Ethernet based Automation Components. First an introduction shows the focus of this paper followed by relevant IT security basics in this context. Further, main requirements for creating a distributed supervision concept are shown. Here digital signatures and methods of checksums are used. Finally, the software and especially the procedures are described to provide a distributed automated supervision of automation components. Markus Runde, Christopher Tebbe, Karl-Heinz Niemann, Jonas Toemmler |
INDIN | 3 |