Henning Trsek

dblp:83/1844 · DBLP profile ↗
← Back
41ranked-venue papers
4as first author
17since 2021 · last 2025
0000-0002-0133-0656ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 39 · 4 first-author · 17 since 2021Applied, interdisciplinary, general and emerging computing · 7 · 4 since 2021Computer networks · 1
YearPublicationVenuePosition
2025 Automated Documentation of Security Risk Assessments with Large Language Models
abstract
The general development of Industry 4.0 and the highly dynamic threat landscape extend the need for continuous security engineering of industrial components, especially during the development phase. Security risk assessments play an important role to ensure the secure and safe development of Industrial Automation and Control Systems (IACSs), but they are based on sophisticated manual and typically time-consuming tasks for human experts. Therefore, this publication identifies and analyzes the information required to document the results of the security risk assessment throughout the development phase. Furthermore, the currently present concepts for documentation are integrated and aligned towards the initially automated and tool-based results by the utilization of Large Language Models (LLMs).
Marco Ehrlich, Lisa Gebauer, Uwe Mönks, Henning Trsek
ETFA5
2025 Enhancing OT Security with the Asset Administration Shell: A Semi-Automated Modeling Framework for Threat Hunting
abstract
The manufacturing industry is facing an escalating threat landscape, as cybercriminals develop increasingly sophisticated attack vectors that exploit the convergence of IT and Operational Technology (OT) through the proliferation of Internet of Things devices. Effective security management demands up-to-date and comprehensive knowledge of systems under protection. This paper presents a novel approach to modeling OT networks, significantly enhancing threat hunting capabilities and leveraging the power of the Asset Administration Shell. We detail a methodology for accurately modeling network aspects, alongside a robust framework for securing collected data, enabling its utilization as a trusted and centralized knowledge base for security-critical applications. Built upon established Industry 4.0 standards, our preliminary metamodel demonstrates the potential for semi-automated modeling of complex OT environments and the associated data flows. This facilitates improved situational awareness, supports proactive threat detection, and addresses the inherent challenges of data inconsistency often found within OT environments. Furthermore, the model provides powerful visualization of relationships within OT processes, enabling the detection of yet undiscovered attack patterns.
Robin W. Foster, Natalia Moriz, Henning Trsek
ETFA3
2025 Concept for Model Driven Verification of Production Quality in B2B-Scenarios
abstract
Checking and ensuring product quality is an important element in many B2B scenarios. However, the process of quality management is often not yet digitalized and therefore usually comes with large efforts. This is especially true in food productions industry. This paper presents a model based approach for a digitalized quality audit in production of food beverages. The proposed method used the Asset Administration Shell (AAS) in combination with Business Process Model and Notation (BPMN) to provide an open interface for machine operators to conduct quality audits. The concept follows a model based approach, where every part can be processed on different IT infrastructure depending on the demanded requirements for data sovereignty and security.
Philip Sehr, Natalia Moriz, Henning Trsek
ETFA3
2025 DeSiRe-NG: An Architecture for Autonomous and Assisted 5G Network Measurement and Emulation
abstract
5G (and beyond) cellular networks have gained much attraction in the past for various application domains in context of industry automation, autonomous and cooperative mobility, as well as smart cities. A main commonality of those use cases is their strong reliance on specific Quality-of-Service (QoS) metrics, which are crucial for seamless operation of those applications. This especially holds true for 5 G use cases in the aviation domain, where a prominent application is the Virtual Table Inspection (VTI) - a process in which aircraft maintenance, disassembly, and reassembly are continuously monitored in real time via high-quality video and audio streams, enabling end-to-end tracking of quality control for all aircraft components. Providing concurrent high-quality video streams requiring high data rates and low latencies together with guaranteed packet delivery ratios is a main challenge of 5 G networks - that particularly holds for 5 G campus networks which are often difficult to scale. Our project DeSiRe-NG tackles exactly these shortcomings by providing a versatile architecture to detect under-performance of 5G networks. Further, our proposed architecture allows to generate the Digital Twin (DT) of a 5G network’s QoS, which helps to improve the research and development process of novel networking architectures and applications, as well as aid the continuous supervision of a network. In a first proof of concept study, we present the functionality of our system in an industrial environment.
Simon Welzel, Niels Hendrik Fliedner, Maxim Friesen, Christian Tismer, Philip Mildner, Syed Abdullah Rizvi, Claudius Noack, Lukas Dalhoff, Henning Trsek, Florian Klingler
WFCS9
2024 GraphWatch: A Novel Threat Hunting Approach for APT Activities based on Anomaly Detection
abstract
Cyber-physical systems (CPS) have become integral to critical infrastructure, making their security an important concern. Integrating information technology (IT) and operational technology (OT) in CPS has introduced complex security challenges. Established security measures often fall short in defending against sophisticated threats such as advanced persistent threats (APT), characterized by their stealth and persistence. This underscores the need for proactive security measures like threat hunting. Threat hunting combines automated and manual techniques to detect threats that bypass common security defenses. Threat hunting is based on hypothesis generation and investigation. In this context, our work presents GraphWatch, a novel approach to threat hunting in CPS. It leverages graph-based anomaly detection and graph neural networks (GNN) to model system behavior and detect deviations from normal activity, which could indicate a potential threat. This leads to a semi-automated hypothesis generation and investigation. The effectiveness of GraphWatch is evaluated using real-world demonstrators, digital twins, and public datasets. Future work aims to implement the concept and improve automation to increase the resilience of CPS against cyber threats and to incorporate automated responses in the long term.
Robin Buchta, Carsten Kleiner, Felix Heine, Daniel Mahrenholz, Uwe Mönks, Henning Trsek
ETFA6
2024 Evaluation of an Automated Security Risk Assessment Based on a Manual Reference
abstract
The overall Industry 4.0 developments and the highly dynamic threat landscape enhance the need for continuous security engineering of industrial components, modules, and systems. Security risk assessments play a major role to ensure a secure operation of Industrial Automation and Control Systems (IACSs) but are often neglected due to missing resources and a lack of human experts for the sophisticated manual tasks. To relieve this situation and to increase the degree of automation of security risk assessments, a method for information and process modelling was developed in a previous work. The approach was also implemented prototypically as an expert system but has not been validated, yet. This work therefore presents the validation as an integral part of the overall evaluation of the automated security risk assessment concept. For a systematic validation, a reference security risk assessment is manually defined as a set of data for the comparison with the results of the automated expert system. In addition, the two main hypotheses with regard to the result quality and the process automation evaluated.
Marco Ehrlich, Georg Lukas, Lisa Gebauer, Henning Trsek, Jürgen Jasperneite, Wolfgang Kastner, Christian Diedrich
ETFA4
2024 Concept for Software-Supported Automated Security Risk Assessments for Industrial Components
abstract
In view of the dynamic cybersecurity threat land-scape and the increasingly interconnected information technol-ogy (IT) and operational technology (OT) environments, the management of security risks to both IT and OT systems becomes paramount, including efficient and comprehensive risk assessment. Such risk assessments, however, require extensive manual work, the availability of trained security personnel as well as considerable time and financial resources. Additionally, a consistent quality of results often cannot be guaranteed due to a dependency on individual expert knowledge and experience. A promising approach to alleviate these challenges is to use software-based support to automate risk assessment processes and increase efficiency and consistency. This work proposes a con-cept for software-supported automated security risk assessments with a focus on industrial components and the manufacturing industry. It presents key challenges, solution approaches, and further research directions that need to be considered in order to practically implement the concept. Additionally, current research that is already in process towards a practical implementation and a preliminary software prototype are presented.
Lisa Gebauer, Marco Ehrlich, Dimitri Harder, Luca Schäfer, Henning Trsek, Natalia Moriz
ETFA6
2024 Requirements Analysis for the Evaluation of Automated Security Risk Assessments
abstract
The overall Industry 4.0 developments and the highly dynamic threat landscape enhance the need for continuous security engineering of industrial components, modules, and systems. Security risk assessments play a major role to ensure a secure operation of Industrial Automation and Control Systems (IACSs) but are mostly neglected due to missing resources and a lack of human experts for the sophisticated manual tasks. Therefore, a method for information and process modelling regarding the automation of security risk assessments has been previously designed, but not yet evaluated. This work in progress begins the evaluation of the automated security risk assessment concept by investigating the related work and identifying the main deficits. The results include a requirements analysis for the verification and an outlook towards future evaluation aspects.
Marco Ehrlich, Georg Lukas, Henning Trsek, Jürgen Jasperneite, Wolfgang Kastner, Christian Diedrich
WFCS3
2023 Evaluation Concept for Prototypical Implementation towards Automated Security Risk Assessments
abstract
Due to Industry 4.0 developments, the demanded modularity of manufacturing systems generates additional manual efforts for security experts to guarantee a secure operation. The rising utilization of information and the frequent changes of systems necessitate continuous security engineering. Therefore, this work in progress presents the specification and prototypical implementation for automated security risk assessments. In addition, an outlook towards the associated validation, verification, evaluation, and hypothesis testing is given.
Marco Ehrlich, Andre Bröring, Henning Trsek, Jürgen Jasperneite, Christian Diedrich
ETFA3
2023 Determining the Target Security Level for Automated Security Risk Assessments
abstract
Due to Industry 4.0 developments, the demanded modularity of manufacturing systems generates additional manual efforts for security experts to guarantee a secure operation. The rising utilization of information and the frequent changes of system structures necessitate a continuous and automated security engineering, especially by application of the mandatory security risk assessments. Collecting the required information for these assessments and formalising expert knowledge shall improve the security of modular manufacturing systems in the future. In order to automate the security risk assessment process, this work proposes a method to determine the Target Security Level (SL-T) in conformance to the IEC 62443 standard based on the MITRE ATT&CK framework and the Intel Threat Agent Library (TAL).
Marco Ehrlich, Andre Bröring, Christian Diedrich, Jürgen Jasperneite, Wolfgang Kastner, Henning Trsek
INDIN6
2022 Towards an Asset Administration Shell Integrity Verification Scheme
abstract
Integrity as one property of trustworthiness is an important aspect for the adoption of the Asset Administration Shell (AAS) as a data exchange format and source for data driven services. Until now, the AAS offers an access control solution as a preventive integrity measure. Nevertheless, preventive methods lack in detecting integrity violations due to accidental or malicious modifications from access permitted endpoints. This work in progress paper proposes a concept to complement the access control with a detective integrity measure. By signing submodels of the AAS, business partners along the life cycle can verify the integrity of the data inside the AAS. Therefore, a Certificates Submodel and a Signature Submodel are proposed in the concept to enable a flexible and interoperable integrity verification. In future work, the concept will be implemented and evaluated.
Andre Bröring, Marco Ehrlich, Lukasz Wisniewski, Henning Trsek, Stefan Heiss
ETFA4
2022 Evil SteVe: An Approach to Simplify Penetration Testing of OCPP Charge Points
abstract
The reduction of CO2 emissions caused by auto-mobile traffic relies on the development of electric mobility infrastructure which in turn relies on efficient communication between charge points, used to connect electric vehicles to the power network, and central systems, used to manage users and transactions. The Open Charge Point Protocol (OCPP) is an open communication protocol designed to connect charge points to a central system. An important aspect of the communication between these entities is the security of the connection. It is conceivable, for instance, that an adversary could compromise a central system to attack charge points.This work devises three different attack scenarios which could be executed by a malicious OCPP central system to attack an OCPP charge point. It also assesses the feasibility and potential consequences of such attacks. Additionally, it presents an approach of an "evil" OCPP server implementation, based on the SteVe server which was originally developed at the RWTH Aachen. The "evil" OCPP server implements various attack scenarios and is intended to be used for penetration testing of OCPP charge points that connect to the central system via WebSockets/JSON or SOAP/XML.
Lisa Gebauer, Henning Trsek, Georg Lukas
ETFA2
2022 Towards an Industrial Converged Network with OPC UA PubSub and TSN
abstract
Technologies such as TSN and OPC UA are enablers for converged networks in industrial applications. TSN enables the coexistence of network traffic with real-time requirements and best-effort requirements. On the other hand, OPC UA defines a common information model in addition to secure communication, scalability, and platform independence. The new specification of OPC UA PubSub enables the possibility of implementing OPC UA on the lower levels of the automation pyramid, the field level. Therefore, combining these two technologies can in principle be implemented for every vertical and horizontal communication. This document analyzes the state of the art of OPC UA over TSN and explains the first steps towards an easy to use proof-of-concept for a converged network that is also designed to be a testbed. The testbed will be used to evaluate the interoperability of TSN-capable devices from different vendors. In addition to that, different OPC UA PubSub implementations will be used and benchmarked. These future results will present an overview of the currently available products and provides hands-on experiences for practical implementations of converged networks.
Oliver Konradi, André Mankowski, Lukasz Wisniewski, Henning Trsek
ETFA4
2022 Am I Done Learning? - Determining Learning States in Adaptive Assembly Systems
abstract
In order to utilize the full potential of an assembly assistant, it is necessary for the system to be able to adapt to the worker’s individual needs and capabilities. The required amount of necessary assistance changes during the assembly work because the worker memorizes the steps and learns the task and might be bothered by unnecessary assistance. Finding the point in time where the learning phase of the worker is finished is therefore an important aspect. In this work, we propose and evaluate a novel method to identify the end of the worker’s learning phase. The method makes use of learning curve models and curve fitting in order to determine the progress of the worker.
Philip Sehr, Natalia Moriz, Mario Heinz-Jakobs, Henning Trsek
ETFA4
2022 Investigation of Resource Constraints for the Automation of Industrial Security Risk Assessments
abstract
The current static risk assessment processes and concepts do not match the increasing requirements with regard to flexibility within the industrial automation domain. The amount of manual tasks and needed efforts for risk assessments are too high in order to adequately cover the rising rate of system reconfigurations. Analysing the typical risk assessment processes from the IEC 62443 will show resource constraints with regard to time, bottlenecks, and the main cost drivers. If the most rewarding process steps can be identified and automated, the overall performance of risk assessments can be enhanced to keep up with the demanded flexibility.
Marco Ehrlich, Georg Lukas, Henning Trsek, Jürgen Jasperneite, Christian Diedrich
WFCS3
2022 Secure Communication in Factories - Benchmarking Elliptic Curve Diffie-Hellman Key Exchange Implementations on an Embedded System
abstract
Securing factory communication to protect corporate data is an important concern in the context of the Industrial Internet of Things (IIoT). Various cryptographic protocols can be used to establish secure communication channels. One of these protocols is the Transport Layer Security 1.3 (TLS 1.3) protocol. A key component of the TLS handshake protocol is the Elliptic Curve Diffie-Hellman Key Exchange (ECDHKE), a public key cryptosystem used to exchange keys over insecure channels which can be based on a number of standardized elliptic curves. A special form of elliptic curves are Montgomery curves which are advantageous compared to more traditional Weierstrass curves due to their fast arithmetic. This is especially important when the ECDHKE is performed on embedded devices and in time-critical situations. In this work, the performance of ECDHKE implementations using standardized Montgomery curves Curve25519 and Curve448 included in the wolfSSL library are evaluated on an embedded 32-bit STM32L476RG Nucleo development board designed by STMicroelectronics. The benchmark results show that using Curve25519 with around 220ms for the key pair generation and the key agreement respectively is approximately 75% faster than using Curve448 with around 900ms for each of the algorithms, which can be attributed to their differing security levels. These results suggest that the algorithms might not be fast enough for time critical situations.
Lisa Gebauer, Henning Trsek, Stefan Heiss
WFCS2
2021 Model-based approach for adaptive assembly assistance
abstract
In production environments, manual assembly is often used, when there is a high demand for flexibility which needs to be met economically. In this circumstance, assembly assistance systems are often used to ensure production standards. However, the individual requirements of each worker call for a way for the system to adapt towards the workers needs. This often requires modelling and configuration effort to include expert knowledge into an assistance system. This hinders an economical operation in an industrial environment. In this paper, an approach is presented, facilitating methods of online modelling, to generate a model, which represents the workers behavior during an assembly process. This behavior model is then used to deduce suitable adaptive assembly assistance in real time.
Philip Sehr, Natalia Moriz, Mario Heinz, Henning Trsek
ETFA4
2020 Towards Automated Security Evaluation within the Industrial Reference Architecture
abstract
The current developments towards the visions of Industrie 4.0 will create open and dynamic architectures being supervised by Industrial Automation and Control Systems. Due to this new connectivity and flexibility, future industrial production systems need to be inspected during all phases of the whole lifecycle from a security point of view as well. Frequent reconfiguration and adaptation based on smart services impose advanced requirements on the audits and certification with regard to security. To facilitate that, this work presents an approach for the modeling of security requirements and capabilities within the Industrial Reference Architecture and evaluates it based on the concrete system architectures of a number of industrial use cases. The result is the Sec4ICS tooling-based concept for the automated assessment of security-related functionalities within industrial systems.
Marco Ehrlich, Martin Gergeleit, Henning Trsek, Georg Lukas
ETFA3
2020 Controller of Controllers Architecture for Management of Heterogeneous Industrial Networks
abstract
Increasing heterogeneity of industrial network systems is a fact and the chances that in the future one communication standard will be able to fulfill the requirements of all possible applications are utopian. With the increasing number of communication systems, their management, configuration, and maintenance become a significant issue. Additionally, due to the increasing amount of network services and traffic, the management of available network resources and the possibility of delivering certain levels of communication quality of service, especially across different network solutions becomes a big challenge. Therefore, in this paper a Controller of Controllers (CoC) concept for management of heterogeneous industrial networks is proposed. The concept is designed to support still widely spread legacy fieldbus systems, different Ethernetbased industrial solutions, and potentially upcoming network technologies. The goal is achieved by leveraging state-of-theart architectural concepts such as software-defined networks, which allows for integration of abstract models in network management. The concept is described and discussed by way of a demonstrator concept for a heterogeneous system of fieldbus and Ethernet-based time-sensitive networks.
Ansah Frimpong, Santiago Soler Perez Olaya, Dennis Krummacker, Christoph Fischer, Alexander Winkel, René Guillaume, Lukasz Wisniewski, Marco Ehrlich, Waseem Mandarawi, Henning Trsek, Hermann de Meer, Martin Wollschlaeger, Hans D. Schotten, Jürgen Jasperneite
WFCS10
2019 Secure and Flexible Deployment of Industrial Applications inside Cloud-Based Environments
abstract
Future industrial production systems following the paradigms of Industrie 4.0 will be reconfigured frequently and new system configurations will be deployed automatically as part of the engineering processes. In order to keep pace with this requirement of increased flexibility, it will be needed to achieve the adequate security levels in an automated way and to reduce the current static procedures and manual efforts as much as possible. Therefore, a modelling of all security-related functionalities and capabilities is mandatory. This paper further describes an approach for such a modelling based on the IEC 62443 security standard and an implementation of an automated deployment of components inside an industrial environment established with the OASIS Tosca and Ansible tools. The first results of the whole tool chain are evaluated with a real-world use case of software deployment in a suitable lab environment.
Marco Ehrlich, Henning Trsek, Martin Gergeleit, Julius Paffrath, Kostyantyn Simkin, Jürgen Jasperneite
ETFA2
2019 Survey of Security Standards for an automated Industrie 4.0 compatible Manufacturing
abstract
Due to the dynamic nature of the Industrie 4.0 developments, future production systems will be reconfigured more frequently and new system configurations will be deployed automatically. In order to keep pace with this development, it will be required to observe and ensure the needed security functionalities and corresponding certifications in an automated way. This implies an improvement of today's static procedures and manual efforts as much as possible in favor of a dynamic standard establishment. Therefore, this paper evaluates the state of the art of the industrial security standardization landscape and proposes a concept for the automated support of certification processes with information from industrial communication networks in order to enhance the usability of the standards establishments and the certifications within organizations and companies, especially small and medium-sized enterprises.
Marco Ehrlich, Henning Trsek, Lukasz Wisniewski, Jürgen Jasperneite
IECON2
2017 Automatic mapping of cyber security requirements to support network slicing in software-defined networks
abstract
The process of digitalisation has an advanced impact on social lives, state affairs, and the industrial automation domain. Ubiquitous networks and the increased requirements in terms of Quality of Service (QoS) create the demand for future-proof network management. Therefore, new technological approaches, such as Software-Defined Networks (SDN) or the 5G Network Slicing concept, are considered. However, the important topic of cyber security has mainly been ignored in the past. Recently, this topic has gained a lot of attention due to frequently reported security related incidents, such as industrial espionage, or production system manipulations. Hence, this work proposes a concept for adding cyber security requirements to future network management paradigms. For this purpose, various security related standards and guidelines are available. However, these approaches are mainly static, require a high amount of manual efforts by experts, and need to be performed in a steady manner. Therefore, the proposed solution contains a dynamic, machine-readable, automatic, continuous, and future-proof approach to model and describe cyber security QoS requirements for the next generation network management.
Marco Ehrlich, Lukasz Wisniewski, Henning Trsek, Daniel Mahrenholz, Jürgen Jasperneite
ETFA3
2017 Cyber security in production networks - An empirical study about the current status
abstract
Classical Information Technology (IT) systems and Operational Technology (OT) are quickly converging technically. Furthermore, the upcoming digitalization, the corresponding information transparancy and the increased number of networked systems poses new challenges on the security of industrial production systems. In order to perform an analysis of the current security situation of manufacturing companies in Germany, an empirical survey has been conducted with companies of different sizes ranging from small and medium-sized enterprises to large enterprises of the DAX-30. The companies are mainly from the area of discrete manufacturing. The survey has been performed either by individual interviews or by an online questionnaire. The main analysis results as well as other findings and conclusions are presented in this work.
Wilhelm Nüßer, Eckhard Koch 0001, Henning Trsek, Ralf Schumann, Daniel Mahrenholz
ETFA3
2017 Clock Synchronization Over IEEE 802.11 - A Survey of Methodologies and Protocols
abstract
Just like Ethernet before, IEEE 802.11 is now transcending the borders of its usage from the office environment toward real-time communication on the factory floor. However, similar to Ethernet, the availability of synchronized clocks to coordinate and control communication and distributed real-time services is not a built-in feature in WLAN. Over the years, this has led to the design and use of a wide variety of customized protocols with varying complexity and precision, both for wired and wireless networks, in accordance with the increasingly demanding requirements from real-time applications. This survey looks into the details of synchronization over IEEE 802.11 with a particular focus on the infrastructure mode which is most relevant for industrial use cases. It highlights the different parameters which affect the performance of clock synchronization over WLAN and compares the performance of existing synchronization methods to analyze their shortcomings. Finally, it identifies new trends and directions for future research as well as features for wireless clock synchronization which will be required by the applications in the near future.
Aneeq Mahmood, Reinhard Exel, Henning Trsek, Thilo Sauter
IEEE Trans. Ind. Informatics3
2016 Analysis of the Cyber-Security of industry 4.0 technologies based on RAMI 4.0 and identification of requirements
abstract
The exhaustive digitalization of the economy, and to be more specific, of industrial production systems results in a new quality of information transparency. This is the basis for added values in terms of effectiveness, quality, and individuality. However, these added values also result in an increased exposure to Cyber-Security threats, due to the increased digitalization, information transparency and standardization. In this work, the procedural model for a Cyber-Security analysis based on reference architecture model Industry 4.0 (RAMI 4.0) and the VDI/VDE guideline 2182 is exemplary shown for the use case of a Cloud-based monitoring of the production. The derived procedure supports the identification of protection demands and allows a risk-based selection of suitable countermeasures.
Holger Flatt, Sebastian Schriegel, Jürgen Jasperneite, Henning Trsek, Heiko Adamczyk
ETFA4
2016 OPC UA extension for IP auto-configuration in cyber-physical systems
abstract
The ability to remotely discover and configure devices in an automation network without the need for prior knowledge of the network topology or the identities of hosts and servers is a key requirement for industrial networks and cyber-physical systems. The Dynamic Host Configuration Protocol (DHCP) as a UDP-based standardized network protocol became very successful in computer networking and also to some extent in industrial networking, but it conceptually allows only device-initiated parameter assignment. This has led to the development of several other device configuration protocols that allow host-initiated device discovery and configuration. In this work, a survey on existing protocols is performed. Based on the results, a future solution is proposed as an extension of the OPC UA protocol suite. The proposal is able to meet the industrial needs for both device- and host-initiated operation with minimal invasive implementation.
Markus Rentschler, Henning Trsek, Lars Duerkop
INDIN2
2016 Methods and performance aspects for wireless clock synchronization in IEEE 802.11 for the IoT
abstract
IEEE 802.11 Wireless Local Area Networks are an appealing complement, if not an alternative, to Ethernet-based industrial solutions because it not only can match Ethernet's high throughput but also leads to reduced costs and more system-design flexibility. However, like in Ethernet, clock synchronization service for applications has not been inherently present in IEEE 802.11. This paper analyzes the clock synchronization mechanisms of IEEE 802.11, which has become a major communication technology to establish the Internet of Things in industries, and how they can be used to provide high precision clock synchronization. In doing so, this work discusses the different parameters which can affect the performance of clock synchronization over the wireless channel, such as timestamping quality, clock adjustment, and synchronization overhead. An outlook to the future includes the new trends for synchronization for wired-wireless hybrid and fully wireless mesh networks where the IEEE 802.1AS audio video bridging networks and IEEE 802.11s mesh networks are leading the line, respectively.
Aneeq Mahmood, Thilo Sauter, Henning Trsek, Reinhard Exel
WFCS3
2014 Application of an intelligent network architecture on a cooperative cyber-physical system: An experience report
abstract
Cooperative cyber-physical systems (CCPS) are driven by the tight coordination between computational components, physical sensors and actuators, and the interaction with each other over system bounds. The software development of CCPS is getting more complex because of the tight integration, heterogeneous technologies, as well as safety and timing requirements. Therefore, new engineering approaches, such as model-driven development methods, are required, along with communication architectures with self-* capabilities. Both will support the developer in specifying such a system effectively and efficiently. However, the application of such techniques for the development of CCPS has not been addressed sufficiently so far. This paper presents an experience report of developing a cooperative delta-robot system that juggles a ball without a central control or camera system. For the development, an intelligent network architecture and model-driven development method for CCPS are applied.
Uwe Pohlmann, Henning Trsek, Lars Duerkop, Stefan Dziwok, Felix Oestersotebier
ETFA2
2013 Cloud computing for industrial automation systems - A comprehensive overview
abstract
Cloud computing has recently emerged as a new computing paradigm in many application areas comprising office and enterprise systems. It offers various solutions to provide a dynamic and flexible infrastructure to host computing resources and deliver them as a service on-demand. Since industrial automation systems of the future have to be adaptable and agile, cloud computing can be considered as a promising solution for this area. However, the requirements of industrial automation systems differ significantly from the office and enterprise world. This paper provides an overview of the latest concepts of cloud computing technology for industrial automation. Existing works are categorized based on the levels of automation systems and research gaps are discussed based on these findings. A general cloud model for automation is derived from existing proposals by refining them further. This cloud model will offer automation functions as services from a dynamic infrastructure.
Omid Givehchi, Henning Trsek, Jürgen Jasperneite
ETFA2
2013 Towards an isochronous wireless communication system for industrial automation
abstract
Deploying wireless technologies in industrial automation becomes more and more common. It is an enabler for many innovative applications where moving system components are involved, e. g. rotating parts of machines. However, many of such applications impose high temporal requirements on the wireless system, for instance isochronous data communication. Today, these requirements can not be met by existing solutions, such as IEEE802.11 Wireless Local Area Networks (WLANs). In this paper, an isochronous wireless communication system is investigated. It mainly consists of a deterministic medium access control, based on IEEE 802.11, which is extended with additional features for isochronous communication. The presented preliminary analysis shows the system's feasibility for the targeted industrial applications and presents promising performance improvements in comparison with standard mechanisms.
Henning Trsek, Tim Tack, Omid Givehchi, Jürgen Jasperneite, Edgar Nett
ETFA1
2013 Using OPC-UA for the autoconfiguration of real-time Ethernet systems
abstract
In the future, production systems will consist of modular and flexible production components, being able to adapt to completely new manufacturing processes. This requirement arises from market turbulences caused by customer demands, i. e. highly customized goods in smaller production batches, or phenomenon like commercial crisis. In order to achieve adaptable production systems, one of the major challenges is to develop suitable autoconfiguration mechanisms for industrial automation systems. This paper presents a two-step architecture for the autoconfiguration of real-time Ethernet (RTE) systems. As a first step, an RTE-independent device discovery mechanism is introduced. Afterwards, it is shown how the parameters of an RTE can be configured automatically using Profinet IO as an exemplary RTE system. In contrast to the existing approaches, the proposed discovery mechanism is based on the OPC Unified Architecture (OPC-UA). In addition, a procedure to autoconfigure modular IO-Devices is introduced.
Lars Duerkop, Jahanzaib Imtiaz, Henning Trsek, Lukasz Wisniewski, Jürgen Jasperneite
INDIN3
2012 Towards autoconfiguration of industrial automation systems: A case study using Profinet IO
abstract
Nowadays the deployment and commissioning of complex production processes or Internet-enabled applications interacting with production systems requires a time consuming and error-prone manual system configuration process. This is due to the need to maintain a high level of determinism, safety, and security of the production process itself and avoiding both safety-critical failures and costly production interruptions. The project “IoT@Work - Internet of Things at Work” aims at delivering tools and runtime mechanisms to significantly simplify commissioning, operating, and maintaining complex production processes, thus enabling Plug-and-Produce for automation systems. This paper presents a novel approach for the autoconfiguration of real-time Ethernet systems, and all relevant mechanisms. A case study, based on Profinet IO, evaluates the approach and shows its feasibility.
Lars Duerkop, Henning Trsek, Jürgen Jasperneite, Lukasz Wisniewski
ETFA2
2012 Agile manufacturing: General challenges and an IoT@Work perspective
abstract
This paper describes the potential impact of the Internet of Things (IoT) technologies and architecture on factory automation. Whereas, IoT use cases range from intelligent infrastructure and smart cities to health care and shopping assistants, it is important to note that factory automation could benefit as well from an IoT approach. In this paper, we argue that there will not be one IoT but many IoTs that could differ in the type of infrastructure they are running or applications they support. In IoT@Work we focus on the potential of making manufacturing environments more agile and flexible. We explain how the IoT-centric architecture for manufacturing also needs a deep understanding of the manufacturing system and its state today. We, therefore, do a reverse engineering based on the requirements and the description of the agility expected in the automation system itself.
Amine M. Houyou, Hans-Peter Huth, Christos Kloukinas, Henning Trsek, Domenico Rotondi
ETFA4
2011 Implementation of an advanced IEEE 802.11 WLAN AP for real-time wireless communications
abstract
Wireless technologies are increasingly deployed in factory automation systems. They enable completely new application scenarios. Especially, IEEE 802.11 systems are of a high interest, due to their similarities to existing realtime Ethernet networks. However, existing implementations are only offering prioritization of frames and are lacking to meet certain real-time constraints when additional best-effort traffic is present. Therefore, an implementation of an isochronous medium access control is presented in this paper which is able to provide real-time guarantees based on time division multiple access. The hardware and software architecture is introduced and a first preliminary evaluation of the implementation shows its performance in terms of temporal behaviour.
Henning Trsek, Stefan Schwalowsky, Bjoern Czybik, Jürgen Jasperneite
ETFA1
2011 A flexible approach for real-time wireless communications in adaptable industrial automation systems
abstract
Due to several advantages, such as flexibility, increased mobility, and lower costs, the deployment of wireless technologies in factory automation systems is rapidly growing. However, current wireless technologies, e. g., IEEE802.11 Wireless Local Area Networks (WLANs), are not able to satisfy the requirements of industrial applications in terms of real-time communication. In this paper medium access control mechanisms in IEEE 802.11 are investigated and a new isochronous MAC is proposed. In combination with a traffic scheduler specifically designed for it, typical constraints of soft real-time flows found on the factory floor can be satisfied. A preliminary analysis shows the effectiveness of the proposed combination.
Henning Trsek, Lukasz Wisniewski, Emanuele Toscano, Lucia Lo Bello
ETFA1
2010 Identification of traffic flows in Ethernet-based industrial fieldbuses
abstract
Ethernet-based fieldbus protocols, are rapidly becoming the preferred choice for networked control systems (NCS) in Factory Automation. Identification of real-time Ethernet (RTE) traffic flows (TFs) is needed for networks that support parameterized QoS services. In this paper, we present a method based on cross-layer packet inspection to identify TFs of RTEs. The method is tested on hardware that uses some of the most popular RTEs used in industrial automation: PROFINET RT, EtherNet/IP and Modbus TCP/IP. The set of parameters chosen to generate the TF signature lead to a correct identification of all cyclic flows in all tested scenarios.
Ivan Dominguez-Jaimes, Lukasz Wisniewski, Henning Trsek
ETFA3
2010 Location-based handover in cellular IEEE 802.11 networks for Factory Automation
abstract
The use of wireless technologies in Factory Automation is attractive due to several advantages (mobility, cost, etc.); however, to satisfy the requirements of industrial applications, they have to be improved in terms of real-time performance. Handover is a particular weakness in cellular wireless systems, e. g., in IEEE 802.11, since it may introduce delay beyond acceptable bounds. The project “flexWARE - Flexible Wireless Automation in Real-Time Environments” aims at implementing such an infrastructure based on IEEE 802.11. To enhance overall system performance, it offers a localisation service. In this paper we present theflexWARE handover mechanism which exploits localisation to reduce the discovery phase. A performance evaluation, based on simulation and empirical measurements, shows that the mechanism results in a seamless handover for a class of industrial applications.
Lukasz Wisniewski, Henning Trsek, Ivan Dominguez-Jaimes, Anetta Nagy, Reinhard Exel, Nikolaus Kerö
ETFA2
2009 Security Concepts for Flexible Wireless Automation in Real-time Environments
abstract
Wireless technologies in industrial automation increase flexibility, but pose challenges to the design of security strategies. The typical requirements regarding integrity protection, authentication, and availability need to be transferred from the traditional wired network domain to wireless networks without impairing the benefits of wireless communication. This article presents results of the security concept for flexible wireless automation in real-time environments devised in theflexWARE project. It includes the results of the security requirement analysis, a description of the procedural design approach towards security, and describes innovative communication protection mechanisms for wireless domains including seamless handover and novel location-based security services.
Albert Treytl, Thilo Sauter, Heiko Adamczyk, Svilen Ivanov, Henning Trsek
ETFA5
2009 Fast and seamless handover for secure mobile industrial applications with 802.11r
abstract
Concerning its temporal behavior the latency caused by a handover from one access point (AP) to another is of particular interest for mobile industrial applications, e.g. automated guided vehicles, due to their real-time requirements in the range of a few milliseconds. With the advancements of wireless local area networks, fast roaming support has become one of the most important issues in IEEE 802.11. The IEEE 802.11r standard amendment has been specified to address roaming capabilities of real-time applications with an attempt to minimize BSS transition time while still providing the 802.11i security and 802.11e QoS. 802.11r permits seamless connectivity with a fast and secure handover from one AP to another within the same mobility domain. It provides an opportunity to derive encryption keys prior to a reassociation to reduce the connectivity loss during the handover. It also provides features for resource reservation and central mobility management. This paper presents an implementation of 802.11r based on a Linux operating system. It uses a softMAC approach that allows moving the processing of MAC layer management entity (MLME) from kernelspace to userspace. Measurement results show the performance gain of 802.11r as compared to a legacy implementation in terms of a handover time reduction, which is a core requirement of wireless industrial networks.
Ahmad Ali Tabassam, Henning Trsek, Stefan Heiss, Jürgen Jasperneite
LCN2
2008 Performance investigation and optimization of IEEE802.15.4 for industrial wireless sensor networks
abstract
This paper evaluates the performance of IEEE 802.15.4 for industrial wireless sensor networks. The IEEE 802.15.4 protocol has got the ability to provide real time data transmission in wireless sensor networks using guaranteed time slots (GTS) as medium access control mechanism. According to the standard, a maximum of 7 GTSs can be allocated in one superframe. All GTSs are exclusively dedicated to a corresponding node. Hence, the GTS mechanism is rather limited regarding the number of nodes and the needed scalability is missing. In this paper we introduce a new scheduling algorithm called ldquoEarliest Due Date GTS Allocationrdquo which can be implemented at the medium access control layer. Using this scheduling scheme and an appropriate scheduler, the GTS mechanism is enhanced, in order to enable a deployment in large scale networks with real-time requirements.
Mohsin Hameed, Henning Trsek, Olaf Graeser, Jürgen Jasperneite
ETFA2
2006 A Simulation Case Study of the new IEEE 802.11e HCCA mechanism in Industrial Wireless Networks
abstract
The advantages of using IEEE 802.11-based wireless local area networks (WLAN) in industrial automation applications are substantial and comprise a higher flexibility, greater mobility and reduced maintenance costs. However, the currently used medium access mechanism makes WLANs non-deterministic and hence not suitable for industrial real-time traffic. The new amendment IEEE 802.11e introduces the HCF controlled channel access (HCCA) for parameterized QoS and the enhanced distributed channel access (EDCA) for prioritized QoS. This paper evaluates the performance of the HCCA in an industrial automation network with real-time requirements by means of a simulation case study with the network simulator OPNET and compares the results with the EDCA in terms of latency in various scenarios.
Henning Trsek, Jürgen Jasperneite, Sugun Pradeep Karanam
ETFA1